Live data from Hacker News

California passes bill to make it easier to delete data from data brokers

latimes.com

151–154 of 154 posts

Re: California passes bill to make it easier to delete data from data brokers

#151

Earlier quoted context omitted.

Not sure why this is being downvoted. It’s precisely these companies that haven’t architected their systems well or prioritized the safety and security of PII by littering it about in various systems and making it “undeletable” in their processes, that need a swift kick in the ass to get it together. I can’t believe people consider the argument that because companies have poorly managed systems and PII centered datab…

Translation of your comment: you believe legal requirements around data deletion will reduce the risk of data breach and therefore are good. My pov: maybe, but the cost isn't worth the benefit of doing it this way.

Agree. My argument is more along the lines of, “the companies that aren’t prepared for this are the ones who most desperately need to clean up their act in the first place, cost aside.”

But I’m inarticulate and do understand your reasoned point.

Re: California passes bill to make it easier to delete data from data brokers

#153
post #135

Earlier quoted context omitted.

As a California resident who regularly opts out of data collection (and also, incidentally, works in tech), as a consumer I don't really care what you or your clients think. I just want you to comply with the law. A remarkably high percentage of our legal framework is designed to protect a very small number of people from being exploited by another small number of people. Yes, the costs of implementing these laws are…

I completely disagree that the benefits are huge. I like laws that say we can opt out of and must consent to email marketing. It leaves companies freedom to implement however they want. CCPA requires complete deletion, which isn't easy to achieve these days, of data that no one is using in an out of the way data store that otherwise wouldn't need to be touched. It's just a lot of effort for no benefit. I think you sh…

Hard disagree. Many security "breaches" are really the discovery of customer data in an S3 bucket "that no one is using in an out of the way data store that otherwise wouldn't need to be touched."

Forcing companies to track and manage the data in their stewardship is necessary because clearly the economic incentive is not high enough - by your own admission. It's easier (and cheaper) to just leave around. But - when, not if - it's hacked, /I/ bear the cost of their negligence, not them.

This is exactly why consumer protection laws are needed.

Re: California passes bill to make it easier to delete data from data brokers

#154
post #153

Earlier quoted context omitted.

I completely disagree that the benefits are huge. I like laws that say we can opt out of and must consent to email marketing. It leaves companies freedom to implement however they want. CCPA requires complete deletion, which isn't easy to achieve these days, of data that no one is using in an out of the way data store that otherwise wouldn't need to be touched. It's just a lot of effort for no benefit. I think you sh…

Hard disagree. Many security "breaches" are really the discovery of customer data in an S3 bucket "that no one is using in an out of the way data store that otherwise wouldn't need to be touched." Forcing companies to track and manage the data in their stewardship is necessary because clearly the economic incentive is not high enough - by your own admission. It's easier (and cheaper) to just leave around. But - when,…

I think we're forcing them to manage the data in their stewardship inefficiently.

I'd actually love a law that says if my data gets stolen from a company and a hacker uses that stolen data to harm me, the company must pay for (some portion of) those harms.

But today it's setup so even if I don't get harmed they pay some lawyers to make the case go away.

Post reply on HN