I hope other states adopt this. One of the biggest mistakes I have made is giving my real phone number to Dun & Bradstreet. Now the spam calls and messages (from people they sold my info to) won't stop. I don't want to change my phone number.
Out of curiosity, does anyone know how this is enforceable for a company not based in California? Can CA fine a data broker that is based in another state but that is selling CA residents' information?
I've been thinking of making a service which automatically sends deletion requests for all my service companies every month. Like, I currently keep a bunch of spyware features in my car turned of, but I have to keep location turned on to use the built in navigation which keeps track of range for me. Would be nice to have a ceiling on that data's retention.
Long term, if compliance with data deletion requests becomes a pain, maybe companies will finally give us an opt out of surveillance capitalism? Or maybe they'll just lock me out of my own car (I guess it's their car since I don't have root on it, lol)
Only if HN counts as a "data broker" under the corresponding law [0]. It states:
> “Data broker” means a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship. “Data broker” does not include any of the following:
> An entity to the extent that it is covered by the federal Fair Credit Reporting Act (15 U.S.C. Sec. 1681 et seq.).
> An entity to the extent that it is covered by the Gramm-Leach-Bliley Act (Public Law 106-102) and implementing regulations.
> An entity to the extent that it is covered by the Insurance Information and Privacy Protection Act (Article 6.6 (commencing with Section 791) of Chapter 1 of Part 2 of Division 1 of the Insurance Code).
> An entity, or a business associate of a covered entity, to the extent their processing of personal information is exempt under Section 1798.146. For purposes of this paragraph, “business associate” and “covered entity” have the same meanings as defined in Section 1798.146 [1].
I don't think HN counts as a "data broker" under this definition since they state that they "do not collect any Personal Information unless you choose to provide your email address and/or information in the "about" field" for HN accounts and "do not sell or share your Personal Information (as those terms are defined under the CCPA)."
The Advertising ID field/ Nice of them to think of this, but it doesn't seem that I could actually get this from any of my Samsung TVs, Apple devices, apps?, etc? So while that field is nice and all, without transparency on getting the ad ID, those fields kind of do nothing.
Because someone commenting leads to others spending time and effort responding. Deleting the comment breaks the chain. Don't comment if you feel that it's something you might want to delete. Think of commenting as like sending an email, but you get a short window to delete in this place.
> In case it's of interest, here's the standard language from emails I send people:
> We try not to delete posts that got replies, because doing so would be unfair to the other commenters in the thread. What I've done so far is reassign it to a random user ID, so it's as if you'd used a throwaway account to post it and there's no link to your main account. Does that work?
And it’s utterly useless, because your username and all comments get THE SAME random user ID. So once someone identifies that ID as you, it does nothing.
When I asked dang to do better after me and my family got death threats online, dang told me “tough luck”
To this day thousands of my comments from my old username are on this site and trivially east to link to my real name. (Links to my website, etc)
I hope other states adopt this. One of the biggest mistakes I have made is giving my real phone number to Dun & Bradstreet. Now the spam calls and messages (from people they sold my info to) won't stop. I don't want to change my phone number.
I wonder if there will be any funny data issues that happen because companies keep track of such requests in a table named "drop"
Out of curiosity, does anyone know how this is enforceable for a company not based in California? Can CA fine a data broker that is based in another state but that is selling CA residents' information?
Yes; the nexus for legal purposes is generally the location of the user, not the broker
I've been thinking of making a service which automatically sends deletion requests for all my service companies every month. Like, I currently keep a bunch of spyware features in my car turned of, but I have to keep location turned on to use the built in navigation which keeps track of range for me. Would be nice to have a ceiling on that data's retention.
Long term, if compliance with data deletion requests becomes a pain, maybe companies will finally give us an opt out of surveillance capitalism? Or maybe they'll just lock me out of my own car (I guess it's their car since I don't have root on it, lol)
What about unregistered data-brokers? I would he happy to sign up to webhooks for when someone wants to delete data.
Problem is though, you'd be revealing more data about them than I probably have by sending it.
Does this mean people can delete comments from HN?
Only if HN counts as a "data broker" under the corresponding law [0]. It states:
> “Data broker” means a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship. “Data broker” does not include any of the following:
> An entity to the extent that it is covered by the federal Fair Credit Reporting Act (15 U.S.C. Sec. 1681 et seq.).
> An entity to the extent that it is covered by the Gramm-Leach-Bliley Act (Public Law 106-102) and implementing regulations.
> An entity to the extent that it is covered by the Insurance Information and Privacy Protection Act (Article 6.6 (commencing with Section 791) of Chapter 1 of Part 2 of Division 1 of the Insurance Code).
> An entity, or a business associate of a covered entity, to the extent their processing of personal information is exempt under Section 1798.146. For purposes of this paragraph, “business associate” and “covered entity” have the same meanings as defined in Section 1798.146 [1].
I don't think HN counts as a "data broker" under this definition since they state that they "do not collect any Personal Information unless you choose to provide your email address and/or information in the "about" field" for HN accounts and "do not sell or share your Personal Information (as those terms are defined under the CCPA)."
[0]: https://cppa.ca.gov/regulations/pdf/data_broker_reg_delete_a...
[1]: https://leginfo.legislature.ca.gov/faces/codes_displaySectio....
When I asked them to for safety reasons after I got death threats online, HN told me to stick it.
The Advertising ID field/ Nice of them to think of this, but it doesn't seem that I could actually get this from any of my Samsung TVs, Apple devices, apps?, etc? So while that field is nice and all, without transparency on getting the ad ID, those fields kind of do nothing.
Why is there a time limit on deletion on this site?
Because someone commenting leads to others spending time and effort responding. Deleting the comment breaks the chain. Don't comment if you feel that it's something you might want to delete. Think of commenting as like sending an email, but you get a short window to delete in this place.
This comment [0] from dang might be relevant:
> In case it's of interest, here's the standard language from emails I send people:
> We try not to delete posts that got replies, because doing so would be unfair to the other commenters in the thread. What I've done so far is reassign it to a random user ID, so it's as if you'd used a throwaway account to post it and there's no link to your main account. Does that work?
[0]: https://news.ycombinator.com/item?id=40734348
And it’s utterly useless, because your username and all comments get THE SAME random user ID. So once someone identifies that ID as you, it does nothing.
When I asked dang to do better after me and my family got death threats online, dang told me “tough luck”
To this day thousands of my comments from my old username are on this site and trivially east to link to my real name. (Links to my website, etc)
[delayed]