> The reason we’ve stepped away from making blanket claims that “We never sell your data” is because, in some places, the LEGAL definition of “sale of data” is broad and evolving. As an example, the California Consumer Privacy Act (CCPA) defines “sale” as the “selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or othe…
They also said "Mozilla doesn’t sell data about you (in the way that most people think about “selling data”)", and I'm struggling to fathom what they could possibly think that "most people" think selling data could mean other than "giving your data to someone else for compensation", which seems pretty much exactly what the California law says. Yes, it's embedded in some legalese, but surely Mozilla has lawyers?
> (1) “Sell,” “selling,” “sale,” or “sold,” means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer’s personal information by the business to a third party for monetary or other valuable consideration.
Most people would view a sale as Mozilla getting cash back for the data. But that "other valuable consideration" (which the AG declined to clarify or create a factor-based approach for deciding) makes Mozilla vulnerable to lawyers.
The same parasites that claimed that embedding a chatbot on your website violates the California wiretapping laws and have been extracting cash from sites will figure out a way to do the same to Mozilla. see the wave of CIPA chatbot lawsuits.
For instance, suppose Mozilla partners with a search engine and could be claimed to get a discount or some other consideration for letting that search partner use search terms to improve the search engine. Something that isn't advertising related at all. That's probably a sale under CPRA.