Live data from Hacker News

California passes bill to make it easier to delete data from data brokers

latimes.com

141–150 of 154 posts

Re: California passes bill to make it easier to delete data from data brokers

#142
post #90

So every 45 days, the CPPA will tell these companies to delete your data. I wonder how many people realize that that means the CPPA or these companies have to keep a record of some of your PII, so that they can look you up and delete you from the database. Maybe privacy conscious people are fine with the California government keeping their PII?

It needs to be changed from opt out to opt in. Explicit consent to sale with opt out assumed by default.

Re: California passes bill to make it easier to delete data from data brokers

#143

Earlier quoted context omitted.

Do you not feel privacy is worthwhile? Do you believe that these companies aren't collecting data for advertising reasons?

Hi - good questions. In general I think some privacy concerns are valid and others are not. Specifically I believe government surveillance is problematic and I wish there were more visibility and restrictions on it. I do believe many companies are collecting data for reasons other than advertising. For example CRM tools (eg Salesforce) have heaps of personal information their customers store with them for a bunch of…

Company surveillance is government surveillance. The companies may be collecting information for profit but once the data exists, it can be collected by the Government. In the US, the government can take data and make it so you legally can't even say it happened. But many times they can just buy the data. Companies like Salesforce may not be advertising to individuals, but the companies that use the crm software may be. The existence of the data itself makes it vulnerable to breach. I'd argue that privacy can't be compromised because any data can be used for any purpose (perhaps not always legally, but it doesn't matter since it is irreversible)

Re: California passes bill to make it easier to delete data from data brokers

#144

Although interesting I always also see this as erase poor people data policy, same as people deleting their reddit comments In 100 years they'll be investigating the real history of 2023, and most records were deleted, only aggregates survived by CNN and FoxNews, and other billion dollar institucions preserving their point of view Today you can go 100 back and that John Panini traveled by boat from UK to US on what d…

That's quite a hyperbolic stance.

There's plenty of unerase-able public data on all of us, especially data that's going to be interesting in 100+ years from now. For example, things like owning property are recorded in the county registrar and will be there as long as the county registrar is.

Everything else, like travel logs and diaries will continue to exist for everyone who wants them to exist. Just as people did 100 years ago, who intentionally kept diaries, these things will remain indefinitely.

Regardless, there's so much content being pooped out right now that a single year will keep future anthropologists busy for centuries.

There may be some overcorrection going on, but there's no way this is a bad thing. We had no idea what Einstein had for breakfast on May 5, 1903, and we're doing just fine.

Re: California passes bill to make it easier to delete data from data brokers

#145

Earlier quoted context omitted.

This hasn't been my experience. Do you work in a large company? My experience has been that there are heaps and piles of data including (or potentially including, unstructured) personal information. And lots of reasons why complete deletion isn't possible - because certain other information nearby the personal information is necessary for business purposes (like submitting invoices), or because the person requesting…

I work at one of the largest, and have also worked at startups and in between. Having PII littered about in ways that aren’t easily deletable is quite a canary. Companies with these issues are the same companies that end up with data breaches due to their cavalier treatment of user data. Perhaps these companies should be grateful they have a regulatory body ensuring they don’t fall too far behind the basic data stewa…

> Having PII littered about in ways that aren’t easily deletable is quite a canary.

"We can't figure out how to delete PII" and "Our schema is flexible" are the same canary in my view.

Everything goes back to founders & business owner giving enough of a shit to force a good architecture from the beginning.

You can't build an effective schema to store complex information if your mission isn't clear yet. If concerns over PII storage are "we'll worry about that later", then whatever schema is invented from that point will mirror that vision.

If the vision is "PII == high-level radioactive waste", then the resulting schema may not even offer places to store it, outside of specially-controlled tables.

Re: California passes bill to make it easier to delete data from data brokers

#146

Earlier quoted context omitted.

I work at one of the largest, and have also worked at startups and in between. Having PII littered about in ways that aren’t easily deletable is quite a canary. Companies with these issues are the same companies that end up with data breaches due to their cavalier treatment of user data. Perhaps these companies should be grateful they have a regulatory body ensuring they don’t fall too far behind the basic data stewa…

Not sure why this is being downvoted. It’s precisely these companies that haven’t architected their systems well or prioritized the safety and security of PII by littering it about in various systems and making it “undeletable” in their processes, that need a swift kick in the ass to get it together. I can’t believe people consider the argument that because companies have poorly managed systems and PII centered datab…

Translation of your comment: you believe legal requirements around data deletion will reduce the risk of data breach and therefore are good.

My pov: maybe, but the cost isn't worth the benefit of doing it this way.

Re: California passes bill to make it easier to delete data from data brokers

#147
post #135

Earlier quoted context omitted.

Couldn't disagree more as someone who works in tech and guides companies in complying with laws like this. So expensive for so little real gain. We're spending more on making companies who don't use your data for anything nefarious (basically all companies outside of the advertising industry, if you even consider advertising nefarious) than we're spending on fixing climate change. Or preventing war. What a joke. Edit…

As a California resident who regularly opts out of data collection (and also, incidentally, works in tech), as a consumer I don't really care what you or your clients think. I just want you to comply with the law. A remarkably high percentage of our legal framework is designed to protect a very small number of people from being exploited by another small number of people. Yes, the costs of implementing these laws are…

I completely disagree that the benefits are huge.

I like laws that say we can opt out of and must consent to email marketing. It leaves companies freedom to implement however they want.

CCPA requires complete deletion, which isn't easy to achieve these days, of data that no one is using in an out of the way data store that otherwise wouldn't need to be touched.

It's just a lot of effort for no benefit. I think you should be allowed to tell a company not to use your information. You shouldn't be able to tell them how not to use it.

Re: California passes bill to make it easier to delete data from data brokers

#148

I've been quite pleased with California and the CCPA thus far. I've submitted a few deletion requests a now, and despite my jadedness all but one went through without a hitch. I reported the one to the California AG and within two weeks the AG had followed up on it and forced the company to delete my data and the company fixed their processes. Color me slightly less jaded. Of course, it's all still a manual process.…

On the other hand I've been highly disgruntled with California after living here a few years.

The DMV, PG&E, and voter registration have all leaked my PII to third parties. F all of them.

I don't intend to register to vote again unless they can prove themselves worthy of keeping my personal information confidential.

I never use USPS forwarding. If you ever register for USPS forwarding, they will GLADLY tell stalkers your new address if they ask. This should have been made constitutionally illegal 100+ years ago if I were in charge of this country.

Governments need to protect PII before waving these laws around at companies. I don't enjoy companies leaking my info either, but as of now governments have done it way more.

On another note, US and California law need to stop requiring residential addresses for everything. Banks, voter registration, DMV, etc. don't need to know where I sleep to a 20-meter radius, they only need to know what state and MAYBE county I file my taxes in.

Re: California passes bill to make it easier to delete data from data brokers

#149

Without giving everyone read rights, this is still pretty much “take their word for if”. I have no doubt California businesses will immediately ship data outside California and play dumb.

Moving the servers that store Californians' data out of California doesn't move Californians out of California. How could they play dumb?

Re: California passes bill to make it easier to delete data from data brokers

#150
post #128

I've gained a tremendous amount of respect for PII while selling software to banks. My position on this type of data is that I am simply a temporary custodian over it. The identifiable person owns this information. I recognize it as pure liability for us. All downside in our business models. We go out of our way to keep this stuff out of our systems. We spent the better part of a month talking about various architect…

This is the path to enlightenment. The best way to protect PII is to ruthlessly minimize it in your system. Better for compliance and better for customer security. And get to avoid whole sections of scrutiny and review when infosec comes knocking.

> The best way to protect PII is to ruthlessly minimize it in your system.

Absolutely, been trying to preach this for ~10 years now at various companies.

Another argument to make is that I can guarantee 100% certainty against leaks with a budget of $0, for all the data columns that I never had. Such a deal!

Any other choice is going to cost a lot more and have reduced chance of success.

Sure, we need to handle some sensitive data to run the business but choose selectively, since every one just adds both cost and risk.

Post reply on HN