Rendered at 14:18:25 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
ryandrake 11 hours ago [-]
As good intentioned as it is, I don't like the wording used around this law. "Request" and "Ask" and "please delete my information." Notice that regular users have to "ask nicely" but when it's something like the DMCA, which benefits corporations, they use "takedown notices" and "demand letters."
I don't want to ask data brokers, pretty please with sugar on top. I want to be able to demand they do it, and require them to immediately do it and provide proof that they did, under penalty of perjury.
ooterness 9 hours ago [-]
I always liked the archaic form, "You are hereby requested and required to [insert naval orders here]." It's asking very politely, for now, but also making it clear that declining will result in jail or worse.
I don't know if it's apocryphal, but it shows up in the Hornblower novels and at least one episode of Star Trek.
dragonwriter 8 hours ago [-]
The penalty for not honoring a DROP “request” is more severe than perjury (and, conversely, there is no penalty at all for not honoring a DMCA notice, the only effect is that you do not benefit from the DMCA safe harbor if you would have been liable for copyright violation without it.)
You are being distracted from the substance by non-substantial surface features.
I’m not a US lawyer, but the word ”request” seems like it has a solid legal basis and can be used to compel action.
brookst 10 hours ago [-]
You’re free to label it as a demand, but unless you run a courtroom and swear them in, any failure to do so will not be perjury.
wilg 8 hours ago [-]
Well, I don't think any of these things are legally required, so call it whatever you want.
kooi 10 hours ago [-]
here-here
petilon 15 hours ago [-]
I hope other states adopt this. One of the biggest mistakes I have made is giving my real phone number to Dun & Bradstreet. Now the spam calls and messages (from people they sold my info to) won't stop. I don't want to change my phone number.
ThePinion 12 hours ago [-]
I noticed this too. It's a number I've had for years and have barely given out to anyone. Registered for a DUNS number last month and have been getting all sorts of spam calls from all different area codes. I assumed it was due to the DUNS form.
I noticed D&B have recently had FTC violations/settlements but not sure they touch this specific situation, but I'm honestly curious if there's anything we can do about this.
Out of curiosity, did you do this as part of Android's awful app submission process
ThePinion 12 hours ago [-]
I recently did and have been getting crazy spam calls that I never had before. I've already replied to GP about this but didn't mention I registered the DUNS number due to it being a requirement to release and Android app.
xeromal 12 hours ago [-]
I think Apple requires it too or did when I made an app for my mom a few years ago
cyanregiment 11 hours ago [-]
Not for most people. You definitely did not need it for making an app for your mom. I've released games under my own name and never did that.
A random person releasing an app or game on the App Store - you won't need it.
But on Android you still might, even for something small, since they changed the rules for new developers. As of November 2023, any new developer account releasing an app basically has to have an Organization account to publish.
Otherwise, the only way to do it as a solo dev is to go through some arduous testing phase with Google, where you have to find 12 or more people to help test at certain times for 14 consecutive days. If even 1 tester doesn't show up or deletes the app, it resets. Comical, but it's how they lowkey force you to create an Organization.
And people should form companies (and operate as Organizations on platforms). It will protect you in the long run, and you can pay lower taxes on revenues. The main problem I have with it - and this also goes for certain payment processors - sometimes I just want to try an idea. Or like your example, build an app for a friend or relative without a ton of hoops to jump through. Involving a 3rd party credit bureau that operates as a private company - that apparently sells people's data to shit ball marketers, doing whatever else they want with basically no oversight - seems in almost all cases overkill and whack as a process as big as Apple or Google app submission that is borderline a public service if you're willing to not pretend we don't have 2 main choices in this market.
The app store platform should just forward on to the downloading user that it's a corporation in Delaware, or whatever. They kinda do - with the "copyright" field, but that field and value has no legal bearing on anything and can be changed without a review - where even being an individual or "sole" proprietor is a legal designation. You could still form a company under your own name later. Adding a business license should be some optional thing IMO that links through to a local registry if possible and if not, then the end user can deduce that it is not "verified" to be that entity.
xeromal 11 hours ago [-]
It's probably because I registered the account in her business' name.
Grombobulous 12 hours ago [-]
I don’t know if this is worth the cost to you but I’ve found that the cheapest $5 Tello plan as a second line is great for business use like this.
cute_boi 14 hours ago [-]
My number used to belong to an elderly woman, so I keep getting spam texts intended for her. I block the numbers, but they somehow keep sending me spam messages from different ones.
I don't think there is any solution other than changing my phone number at this point. The issue is fucking sites keep using phone number as 2fa.
_dark_matter_ 12 hours ago [-]
Keep the old number and get a new one. You'll have to gradually switch all 2fa if you want to lose the old number, otherwise keep it forever on a separate device.
hackernud3s 15 hours ago [-]
[dead]
jboggan 8 hours ago [-]
I've been building the infra for data brokers to connect to DROP (easy), actually effect deletions (hard), and make sure the data stays deleted (harder): forgetmenaut.com
DROP is pretty significant considering that it's the first compliance system meant to have an immediate effect (delete the data), backward-looking effect (forward a legally-binding deletion request to everyone that data was sold to or shared with), and a forward-looking effect (never let that record re-enter your system, in perpetuity). This is significantly more tracking and auditing infrastructure than anyone in the industry has ever normally run, not to mention that the request volume is 100-10000x what most of these brokers would process in previous years.
We'll see how well companies actually managed to comply when audits are performed for every registered broker in 24 months. I also think the impending prosecutions (and likely bankruptcies) of several unregistered data brokers will encourage the others to take it more seriously.
MrZander 15 hours ago [-]
Out of curiosity, does anyone know how this is enforceable for a company not based in California? Can CA fine a data broker that is based in another state but that is selling CA residents' information?
Xorakios 14 hours ago [-]
Yes; the nexus for legal purposes is generally the location of the user, not the broker
connicpu 14 hours ago [-]
The company would have to not have any interstate presence at all. If you are a business based in the united states that has customers in California, you are easily reachable under California law.
metalcrow 14 hours ago [-]
Curious, how so?
teraflop 13 hours ago [-]
Look up "long arm statutes". State courts can have jurisdiction over out-of-state entities, subject to limitations established by federal precedent. Doing business with customers who reside in a state generally puts you under that state's jurisdiction, at least for purposes related to that business.
what 12 hours ago [-]
Define “doing business”. If no money is exchanged, how are you “doing business” with them?
dredmorbius 10 hours ago [-]
From another California regulation (requiring telemarketers to register and secure a bond):
A seller is deemed to be doing business in the state if the seller solicits prospective purchasers from locations in California or solicits prospective purchasers who are located in this state.'
The DROP act creates a right to California residents. To the extent I've read the statute, it doesn't define what entities are covered (see: <https://leginfo.legislature.ca.gov/faces/codes_displayText.x...>), which seems to me to suggest that affected entities are defined by their data collection from California residents, not where or how they engage in activities otherwise in California.
braiamp 12 hours ago [-]
Doing business is doing business, money isn't necessary to "do business". If you hold any interest and that person has any relationship with you in a way that can be inferred that a contract is implied, then that's business. That's why travel to get an "agreement" is considered a business expense, even if the agreement never materialize.
what 11 hours ago [-]
> doing business is doing business
That’s not much of a definition.
vvbull 8 hours ago [-]
You'd hate practicing law.
connicpu 10 hours ago [-]
If you've collected data on a California resident with the intent to profit from its sale then you're doing some type of business with respect to California
edmundsauto 11 hours ago [-]
I’m not sure the definition matters here. Either you are doing business and this regulation makes certain things now illegal; or you are not doing business and it’s unsolicited and spam.
newsomix9xl 10 hours ago [-]
Comity iirc is the legal principle of mutually recognizing other states laws (giving them jurisdiction) as in recognizing a marriage contract in other states (and they recognize yours).
That's my guess
ransom1538 9 hours ago [-]
Yes. We talk to our lawyers here in FL. We take the legal document from CA and throw them in the garbage while laughing is the current policy.
vvbull 8 hours ago [-]
This feels like bloviating. You are unlikely to be subject to this law, and even if you were your lawyers probably wouldn't advise you to ignore laws in states where you operate. (If you don't operate in California or on California residents, then you are obviously not subject to this law.) And you're lawyers would definitely not recommend posting publicly that you plan to willfully break this law. Which suggests to me that you are just blowing hot air online.
hackernud3s 15 hours ago [-]
[dead]
hedora 10 hours ago [-]
Does this apply to Google, car companies, etc, or did they bribe in exceptions for themselves (like California grocery stores did for the Do Not Sell My Personal Information law)?
Also, who gets the $200/day? If I issue a drop request, wait 145 days, then buy my data from brokers, do they have to pay me $20,000 per record they return?
jboggan 9 hours ago [-]
Well the CPPA (state regulator) just hit General Motors with a $12.75M fine for selling data to two registered data brokers, and made the brokers who received the data delete it all: https://ccpa.world/enforcement/gm-onstar-smart-driver
Does it apply to Google? Well that's an interesting question. I think the answer is yes but the practical matter is that the CPPA is going to get some legal precedent and some more lawyers on staff before they take on Google. At the current number of requests in the DROP platform they could determine Google is an unregistered data broker and fine them $25B+, but I don't think they are going to do that this year.
I think within 36 months they will take the legal victories from prosecuting the first set of unregistered data brokers and apply it to the real players in the data ecosystem. At least, that's what I would do if I were Michael Macko.
ransom1538 9 hours ago [-]
Fast workers make $20 an hour in Cali, except for panera bread workers OBVIOUSLY.
m4xp 3 hours ago [-]
Let me guess, to delete your data you need to give them your data so that they can keep track that you want your data to be deleted.
bdcravens 14 hours ago [-]
I wonder if there will be any funny data issues that happen because companies keep track of such requests in a table named "drop"
m463 12 hours ago [-]
mom should look up little bobby tables
igor47 15 hours ago [-]
I've been thinking of making a service which automatically sends deletion requests for all my service companies every month. Like, I currently keep a bunch of spyware features in my car turned of, but I have to keep location turned on to use the built in navigation which keeps track of range for me. Would be nice to have a ceiling on that data's retention.
Long term, if compliance with data deletion requests becomes a pain, maybe companies will finally give us an opt out of surveillance capitalism? Or maybe they'll just lock me out of my own car (I guess it's their car since I don't have root on it, lol)
rustcleaner 10 hours ago [-]
If it's a VW, pick up a Ross-Tech VAG-COM + VCDS, locate your Telematics unit (OCU, online communications unit) and remove it; mine was behind the instrument cluster. Then use VCDS on a laptop plugged into your car with VAG-COM, and code out the OCU from every module giving fault codes for its absence. You will probably lose the microphone, as in my Mk7 the microphone line goes through the OCU. Finally, optionally, you can code out your infotainment module's bluetooth features thus taking away another avenue for passive surveillance.
hackernud3s 15 hours ago [-]
What about unregistered data-brokers? I would he happy to sign up to webhooks for when someone wants to delete data.
Problem is though, you'd be revealing more data about them than I probably have by sending it.
jboggan 9 hours ago [-]
Do you think you could be an unregistered data broker? You should probably reach out to me directly so I can give you more targeted advice.
All of the requests are SHA-256 hashvalues, they aren't transmitting any usable information in the process of sending the deletion requests.
hackernud3s 6 hours ago [-]
[dead]
kmfrk 3 hours ago [-]
One thing to flag from Europe and GDPR is all the malicious compliance of companies and governments using the law as an excuse to not meet some basic obligations to users like storing and retrieving useful information, or getting pretty basic customer support. It's very reminiscent of companies deliberately making cookie warnings annoying instead of protecting user privacy. Who knows, maybe this will be used to obstruct FOIA too.
Because of this, be sure to pay attention to companies getting too clever in interpreting this law, even after it's passed. It ain't over 'til it's over, so be sure to keep fighting it until we actually get the desired outcome, and track the actual compliance with the law.
The law itself sounds great, just remember that people often aren't.
Does this mean people can delete comments from HN?
aw1621107 15 hours ago [-]
Only if HN counts as a "data broker" under the corresponding law [0]. It states:
> “Data broker” means a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship. “Data broker” does not include any of the following:
> An entity to the extent that it is covered by the federal Fair Credit Reporting Act (15 U.S.C. Sec. 1681 et seq.).
> An entity to the extent that it is covered by the Gramm-Leach-Bliley Act (Public Law 106-102) and implementing regulations.
> An entity to the extent that it is covered by the Insurance Information and Privacy Protection Act (Article 6.6 (commencing with Section 791) of Chapter 1 of Part 2 of Division 1 of the Insurance Code).
> An entity, or a business associate of a covered entity, to the extent their processing of personal information is exempt under Section 1798.146. For purposes of this paragraph, “business associate” and “covered entity” have the same meanings as defined in Section 1798.146 [1].
I don't think HN counts as a "data broker" under this definition since they state that they "do not collect any Personal Information unless you choose to provide your email address and/or information in the "about" field" for HN accounts and "do not sell or share your Personal Information (as those terms are defined under the CCPA)."
Does this mean people can delete comments from HN?
This is already a thing. One can reach out to dang to request their account or their comments be removed. They do not like to remove comments as it breaks some of the interaction and context people had on the site but they will not refuse to do it. hn@ycombinator.com
testing22321 14 hours ago [-]
[flagged]
tomhow 11 hours ago [-]
We are never rude or obstinate like this. We will always do whatever we can to protect people's privacy, which we do by redacting PII and moving posts to anonymized accounts.
adzm 14 hours ago [-]
Conversely, they did help me out.
downrightmike 13 hours ago [-]
really just whatever dang feels like that day
tomhow 11 hours ago [-]
We take users' privacy seriously and have had a consistent policy for years. If anyone is worried about personally identifying information, we're always happy to redact the PII and reassign comments/posts to an anonymous account. The only thing we don't do is wholesale wipe someone's entire history from HN, because it guts the threads and ruins them for everyone else who participated and who might find them interesting to read in the future.
testing22321 9 hours ago [-]
> If anyone is worried about personally identifying information, we're always happy to redact the PII and reassign comments/posts to an anonymous account
This is the identical line dang fed me, and what he did is useless. It changes nothing.
Stop saying you’ll go out of your way to help users when you clearly won’t. Changing my username on all my old comments to some other username is not enough.
It’s trivial to figure out who I am, and then have all my comments attributed to me.
You should aim to actually do better, not just say that what you do now is good enough when it clearly isn’t.
tomhow 9 hours ago [-]
We go to great effort to find the right balance between a user's need for privacy and the community/public benefit in keeping threads intact and coherent (moving every one of a user's comments to a different username makes the threads incoherent).
On a case-by-case basis we can move a selection of comments to a separate username. We of course don't want anyone to be in danger.
testing22321 9 hours ago [-]
It seems like you’re more concerned about keeping threads from years ago coherent than you are about my wishes and safety.
Middle ground: on any given topic change all my comments to some random user I’d, then a different one for every topic.
threads will stay coherent, but people won’t be able to follow my old user name around topics for 14 years.
I’ll send an email in the morning. I have to sleep.
tomhow 8 hours ago [-]
> It seems like you’re more concerned about keeping threads from years ago coherent than you are about my wishes and safety.
This is obviously not true. We care about thread persistence and coherence as a default, because some of HN's most historically significant threads are from the earliest years. We will take reasonable steps to protect people's identity and safety once we know the specifics of the situation. We routinely redact URLs, company names, project names and other identifying details from historical comments to prevent people's identity from being inferred.
testing22321 25 minutes ago [-]
It is impressive how you keep repeating that line while not addressing suggestions to fix the problem by myself and others.
You’re saying “we do minimum effort” .
I am telling you It is not enough, and you refuse to even acknowledge that.
You are saying “tough luck” in fancier language.
tjwebbnorfolk 13 hours ago [-]
> Companies that fail to comply can face fines of $200 per day for each affected Californian.
Does this cover things like credit reports/scores? If someone submits a request to this DROP thing, is it possible data gets deleted that they don't intend?
dredmorbius 10 hours ago [-]
Probably not. Under TITLE 1.81.48:
“Data broker” does not include any of the following:
(1) An entity to the extent that it is covered by the federal Fair Credit Reporting Act (15 U.S.C. Sec. 1681 et seq.).
(2) An entity to the extent that it is covered by the Gramm-Leach-Bliley Act (Public Law 106-102) and implementing regulations.
(3) An entity to the extent that it is covered by the Insurance Information and Privacy Protection Act (Article 6.6 (commencing with Section 791) of Chapter 1 of Part 2 of Division 1 of the Insurance Code).
(4) An entity, or a business associate of a covered entity, to the extent their processing of personal information is exempt under Section 1798.146. For purposes of this paragraph, “business associate” and “covered entity” have the same meanings as defined in Section 1798.146.
I hope this is true! Consumer credit is a serious problem. How much better would it be if only corporate entities could take on debt? That goes for school, home, and car loans too. Imagine the return to sanity in pricing when Big Finance can no longer scam time-preferenced and desperate buyers! Society might have a real savings rate again!
Razengan 10 hours ago [-]
How does this apply to shit like not being able to delete your past messages from a Discord server if you get banned from it?
aw1621107 7 hours ago [-]
I don't think Discord counts as a data broker under the act as it does not apply to entities with whom you have a "direct relationship"
sourcecodeplz 9 hours ago [-]
going the way of the gdpr eu
unstatusthequo 15 hours ago [-]
The Advertising ID field/ Nice of them to think of this, but it doesn't seem that I could actually get this from any of my Samsung TVs, Apple devices, apps?, etc? So while that field is nice and all, without transparency on getting the ad ID, those fields kind of do nothing.
dwattttt 14 hours ago [-]
Google TV surfaces this under settings (along with the ability to regenerate it, or remove it)
EDIT: Android also surfaces this information more generally, I just found it under More Privacy Settings -> Ads
faucetl 12 hours ago [-]
[flagged]
garpoon 12 hours ago [-]
[dead]
amazingamazing 15 hours ago [-]
Why is there a time limit on deletion on this site?
millerm 15 hours ago [-]
Because someone commenting leads to others spending time and effort responding. Deleting the comment breaks the chain. Don't comment if you feel that it's something you might want to delete. Think of commenting as like sending an email, but you get a short window to delete in this place.
amazingamazing 14 hours ago [-]
Do you believe the same about search results not being able to be deleted? I also assume this means you disagree with gdpr?
EA-3167 14 hours ago [-]
Do you not see the difference between a person volunteering to broadcast a post, vs a bird party scraping the web to index it for searching?
amazingamazing 14 hours ago [-]
You believe volunteered information must stay on internet forever?
EA-3167 13 hours ago [-]
If you knew those were the conditions when you joined? Yes.
amazingamazing 12 hours ago [-]
Ok. Luckily people who make the rules don’t have such ideas.
tomhow 9 hours ago [-]
GDPR doesn't require that a participant on a discussion forum be able to erase their entire history. Article 17(3) covers this. It is reasonable for a user to ask that their posts be anonymized.
aw1621107 15 hours ago [-]
This comment [0] from dang might be relevant:
> In case it's of interest, here's the standard language from emails I send people:
> We try not to delete posts that got replies, because doing so would be unfair to the other commenters in the thread. What I've done so far is reassign it to a random user ID, so it's as if you'd used a throwaway account to post it and there's no link to your main account. Does that work?
And it’s utterly useless, because your username and all comments get THE SAME random user ID. So once someone identifies that ID as you, it does nothing.
When I asked dang to do better after me and my family got death threats online, dang told me “tough luck”
To this day thousands of my comments from my old username are on this site and trivially east to link to my real name. (Links to my website, etc)
tomhow 11 hours ago [-]
> dang told me “tough luck”
He (nor I) would never write that or anything like it. What we always say is that we aim to find a compromise between a user's wish for their entire history to be erased and the rest of the community's expectation that when they participate in discussion threads, those threads will persist unadulterated into the future.
We are always willing to redact PII and do other things to prevent people's real identities from being recognized from their HN activity. We help people with requests like this all the time.
testing22321 10 hours ago [-]
Dang said exactly that. What’s your email, I’ll forward it.
Changing my username to something random doesn’t help, because it’s trivial to find a comment or two that make it clear that random user ID is me, and then you can see all my comments.
There are two much better approaches.
1. Make every single comment of mine a new random user if so they’re all separate.
2. Make the user id of everyone who has ever asked for deletion ”deleted-user” so my comments are lost in the sea.
Either of those approaches would make it impossible to find all my old comments and know they all belong to the real me in the real world.
Please help. Death threats are not fun, especially when you have a 2 year old daughter. There is a 100+ page forum thread of people betting on when I (real name, real person) am going to die. Just saying that somewhat Doxxes me.
tomhow 9 hours ago [-]
My email is the same as Dan's. hn@ycombinator.com. Yes you can forward it and I'll read it straight away.
We can't necessarily do the exact things you've asked, because it makes all the discussion threads you participated in incoherent. We can take reasonable steps to disassociate personally-identifying comments from others.
> Please help. Death threats are not fun, especially when you have a 2 year old daughter. There is a 100+ page forum thread of people betting on when I (real name, real person) am going to die. Just saying that somewhat Doxxes me.
This sounds terrible, and of course we don't want anything like that for you. It's just not clear (and I still haven't received an email from you so I can't look into the details of the case) how the actions you're specifying that we need to take on HN will fix this issue on some other website. I don't know any details other than the limited information you're sharing here. I can't find any emails about this matter linked to the username you're commenting from here.
mindslight 9 hours ago [-]
It seems like you should be able to do a middle ground that preserves the commenter identity in each individual thread, while destroying the links across different threads.
For example, reserve the usernames 'deleted-xxxx' where x is a number. Then when someone wants their history obliterated, loop over every thread they have commented in. For each thread, choose a random number deleted-xxxx and assign that username to every comment of theirs in that thread.
Thus comments in the thread remain linked with one another, other deleted users in the thread remain distinct, and comments in one thread aren't linkable to a user's comments in another thread (perhaps lamentable, but required for unlinking spilled personal info in the general case)
(I chose random numbers rather than incrementing so that one can't start making inferences about users based on deletion order)
vvbull 8 hours ago [-]
It should just be randomly generated when the page loads. "Oh, this user has the 'dormant' flag set? Generate a uid on page load" so all their comments have consistency for that one viewer for that single page load. Then if you click that user to see all the posts by them, you get an empty set. (Have the search queries return nothing for dormant users.)
dredmorbius 26 minutes ago [-]
Both the null search and dynamic generation per pageload (or any other randomisation across accesses or sessions) would reveal which comments/posts have been anonymised. That might be a cue to an adversary to dig deeper.
That information might be possible to determine from a comprehensive archive of HN, but it would be much harder to obtain.
The ability to disown a specific set of content (I'm not sure HN permits this) would avoid that issue. The associated account would just have a limited history, not an empty one. That would be equivalent to an after-the-fact throwaway account, which is much less attention-grabbing.
altairprime 14 hours ago [-]
My first BBS handle was my full real name, and I barely managed to purge myself from DejaNews before Google bought it, so I empathize. The modern internet has been a severe learning experience and, given how many replicas of HN exist, the cat is well out of the bag. Teach others to be more careful, as I do.
testing22321 14 hours ago [-]
100%
In 2012 when I started commenting here I had no idea it would lead to death threats and I’d have a two year old daughter.
vlovich123 12 hours ago [-]
What kind of topics/comments did you make that got you death threats? Really want to make sure I stay away from such topics.
testing22321 10 hours ago [-]
I don’t want to doxx myself.
There is a 100+ page forum thread of people betting on when I’m going to die. Redditors have commented in public “I wish he did die”, etc etc
cindyllm 9 hours ago [-]
[dead]
altairprime 11 hours ago [-]
I've gotten several death threats for saying, at one point, that Destiny 2 year 1 was enjoyable because it pivoted the game away from loot-box gambling and FOMO addiction-driven player hours.
No topic is truly safe from other sociopaths getting their jollies from writing anonymous hatemail. Yeah, sociopathy makes it difficult to feel something, I empathize — but that's no excuse for them abusing their people-toys. Imagine Sid as an adult on the Internet if he'd never been scared straight: it doesn't matter what topics you play with to a Sid, they're adaptable and will find ways to issue death threats for personal pleasure, on whatever topics they find in the sandbox.
I don't want to ask data brokers, pretty please with sugar on top. I want to be able to demand they do it, and require them to immediately do it and provide proof that they did, under penalty of perjury.
I don't know if it's apocryphal, but it shows up in the Hornblower novels and at least one episode of Star Trek.
You are being distracted from the substance by non-substantial surface features.
https://munley.com/tag/request/
I’m not a US lawyer, but the word ”request” seems like it has a solid legal basis and can be used to compel action.
I noticed D&B have recently had FTC violations/settlements but not sure they touch this specific situation, but I'm honestly curious if there's anything we can do about this.
https://www.ftc.gov/news-events/news/press-releases/2025/09/...
A random person releasing an app or game on the App Store - you won't need it.
But on Android you still might, even for something small, since they changed the rules for new developers. As of November 2023, any new developer account releasing an app basically has to have an Organization account to publish.
Otherwise, the only way to do it as a solo dev is to go through some arduous testing phase with Google, where you have to find 12 or more people to help test at certain times for 14 consecutive days. If even 1 tester doesn't show up or deletes the app, it resets. Comical, but it's how they lowkey force you to create an Organization.
And people should form companies (and operate as Organizations on platforms). It will protect you in the long run, and you can pay lower taxes on revenues. The main problem I have with it - and this also goes for certain payment processors - sometimes I just want to try an idea. Or like your example, build an app for a friend or relative without a ton of hoops to jump through. Involving a 3rd party credit bureau that operates as a private company - that apparently sells people's data to shit ball marketers, doing whatever else they want with basically no oversight - seems in almost all cases overkill and whack as a process as big as Apple or Google app submission that is borderline a public service if you're willing to not pretend we don't have 2 main choices in this market.
The app store platform should just forward on to the downloading user that it's a corporation in Delaware, or whatever. They kinda do - with the "copyright" field, but that field and value has no legal bearing on anything and can be changed without a review - where even being an individual or "sole" proprietor is a legal designation. You could still form a company under your own name later. Adding a business license should be some optional thing IMO that links through to a local registry if possible and if not, then the end user can deduce that it is not "verified" to be that entity.
I don't think there is any solution other than changing my phone number at this point. The issue is fucking sites keep using phone number as 2fa.
DROP is pretty significant considering that it's the first compliance system meant to have an immediate effect (delete the data), backward-looking effect (forward a legally-binding deletion request to everyone that data was sold to or shared with), and a forward-looking effect (never let that record re-enter your system, in perpetuity). This is significantly more tracking and auditing infrastructure than anyone in the industry has ever normally run, not to mention that the request volume is 100-10000x what most of these brokers would process in previous years.
We'll see how well companies actually managed to comply when audits are performed for every registered broker in 24 months. I also think the impending prosecutions (and likely bankruptcies) of several unregistered data brokers will encourage the others to take it more seriously.
A seller is deemed to be doing business in the state if the seller solicits prospective purchasers from locations in California or solicits prospective purchasers who are located in this state.'
<https://oag.ca.gov/consumers/general/telreg>
The DROP act creates a right to California residents. To the extent I've read the statute, it doesn't define what entities are covered (see: <https://leginfo.legislature.ca.gov/faces/codes_displayText.x...>), which seems to me to suggest that affected entities are defined by their data collection from California residents, not where or how they engage in activities otherwise in California.
That’s not much of a definition.
That's my guess
Also, who gets the $200/day? If I issue a drop request, wait 145 days, then buy my data from brokers, do they have to pay me $20,000 per record they return?
Does it apply to Google? Well that's an interesting question. I think the answer is yes but the practical matter is that the CPPA is going to get some legal precedent and some more lawyers on staff before they take on Google. At the current number of requests in the DROP platform they could determine Google is an unregistered data broker and fine them $25B+, but I don't think they are going to do that this year.
I think within 36 months they will take the legal victories from prosecuting the first set of unregistered data brokers and apply it to the real players in the data ecosystem. At least, that's what I would do if I were Michael Macko.
Long term, if compliance with data deletion requests becomes a pain, maybe companies will finally give us an opt out of surveillance capitalism? Or maybe they'll just lock me out of my own car (I guess it's their car since I don't have root on it, lol)
Problem is though, you'd be revealing more data about them than I probably have by sending it.
All of the requests are SHA-256 hashvalues, they aren't transmitting any usable information in the process of sending the deletion requests.
Because of this, be sure to pay attention to companies getting too clever in interpreting this law, even after it's passed. It ain't over 'til it's over, so be sure to keep fighting it until we actually get the desired outcome, and track the actual compliance with the law.
The law itself sounds great, just remember that people often aren't.
The Delete Act
https://news.ycombinator.com/item?id=46449694
California residents can now request all data brokers delete personal info
https://news.ycombinator.com/item?id=46495220
> “Data broker” means a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship. “Data broker” does not include any of the following:
> An entity to the extent that it is covered by the federal Fair Credit Reporting Act (15 U.S.C. Sec. 1681 et seq.).
> An entity to the extent that it is covered by the Gramm-Leach-Bliley Act (Public Law 106-102) and implementing regulations.
> An entity to the extent that it is covered by the Insurance Information and Privacy Protection Act (Article 6.6 (commencing with Section 791) of Chapter 1 of Part 2 of Division 1 of the Insurance Code).
> An entity, or a business associate of a covered entity, to the extent their processing of personal information is exempt under Section 1798.146. For purposes of this paragraph, “business associate” and “covered entity” have the same meanings as defined in Section 1798.146 [1].
I don't think HN counts as a "data broker" under this definition since they state that they "do not collect any Personal Information unless you choose to provide your email address and/or information in the "about" field" for HN accounts and "do not sell or share your Personal Information (as those terms are defined under the CCPA)."
[0]: https://cppa.ca.gov/regulations/pdf/data_broker_reg_delete_a...
[1]: https://leginfo.legislature.ca.gov/faces/codes_displaySectio....
This is already a thing. One can reach out to dang to request their account or their comments be removed. They do not like to remove comments as it breaks some of the interaction and context people had on the site but they will not refuse to do it. hn@ycombinator.com
This is the identical line dang fed me, and what he did is useless. It changes nothing.
Stop saying you’ll go out of your way to help users when you clearly won’t. Changing my username on all my old comments to some other username is not enough. It’s trivial to figure out who I am, and then have all my comments attributed to me.
You should aim to actually do better, not just say that what you do now is good enough when it clearly isn’t.
On a case-by-case basis we can move a selection of comments to a separate username. We of course don't want anyone to be in danger.
Middle ground: on any given topic change all my comments to some random user I’d, then a different one for every topic.
threads will stay coherent, but people won’t be able to follow my old user name around topics for 14 years.
I’ll send an email in the morning. I have to sleep.
This is obviously not true. We care about thread persistence and coherence as a default, because some of HN's most historically significant threads are from the earliest years. We will take reasonable steps to protect people's identity and safety once we know the specifics of the situation. We routinely redact URLs, company names, project names and other identifying details from historical comments to prevent people's identity from being inferred.
You’re saying “we do minimum effort” .
I am telling you It is not enough, and you refuse to even acknowledge that. You are saying “tough luck” in fancier language.
Does this cover things like credit reports/scores? If someone submits a request to this DROP thing, is it possible data gets deleted that they don't intend?
“Data broker” does not include any of the following:
(1) An entity to the extent that it is covered by the federal Fair Credit Reporting Act (15 U.S.C. Sec. 1681 et seq.).
(2) An entity to the extent that it is covered by the Gramm-Leach-Bliley Act (Public Law 106-102) and implementing regulations.
(3) An entity to the extent that it is covered by the Insurance Information and Privacy Protection Act (Article 6.6 (commencing with Section 791) of Chapter 1 of Part 2 of Division 1 of the Insurance Code).
(4) An entity, or a business associate of a covered entity, to the extent their processing of personal information is exempt under Section 1798.146. For purposes of this paragraph, “business associate” and “covered entity” have the same meanings as defined in Section 1798.146.
<https://leginfo.legislature.ca.gov/faces/codes_displayText.x...>
Credit bureaus are, I think, covered as item (1).
EDIT: Android also surfaces this information more generally, I just found it under More Privacy Settings -> Ads
> In case it's of interest, here's the standard language from emails I send people:
> We try not to delete posts that got replies, because doing so would be unfair to the other commenters in the thread. What I've done so far is reassign it to a random user ID, so it's as if you'd used a throwaway account to post it and there's no link to your main account. Does that work?
[0]: https://news.ycombinator.com/item?id=40734348
When I asked dang to do better after me and my family got death threats online, dang told me “tough luck”
To this day thousands of my comments from my old username are on this site and trivially east to link to my real name. (Links to my website, etc)
He (nor I) would never write that or anything like it. What we always say is that we aim to find a compromise between a user's wish for their entire history to be erased and the rest of the community's expectation that when they participate in discussion threads, those threads will persist unadulterated into the future.
We are always willing to redact PII and do other things to prevent people's real identities from being recognized from their HN activity. We help people with requests like this all the time.
Changing my username to something random doesn’t help, because it’s trivial to find a comment or two that make it clear that random user ID is me, and then you can see all my comments.
There are two much better approaches.
1. Make every single comment of mine a new random user if so they’re all separate.
2. Make the user id of everyone who has ever asked for deletion ”deleted-user” so my comments are lost in the sea.
Either of those approaches would make it impossible to find all my old comments and know they all belong to the real me in the real world.
Please help. Death threats are not fun, especially when you have a 2 year old daughter. There is a 100+ page forum thread of people betting on when I (real name, real person) am going to die. Just saying that somewhat Doxxes me.
We can't necessarily do the exact things you've asked, because it makes all the discussion threads you participated in incoherent. We can take reasonable steps to disassociate personally-identifying comments from others.
> Please help. Death threats are not fun, especially when you have a 2 year old daughter. There is a 100+ page forum thread of people betting on when I (real name, real person) am going to die. Just saying that somewhat Doxxes me.
This sounds terrible, and of course we don't want anything like that for you. It's just not clear (and I still haven't received an email from you so I can't look into the details of the case) how the actions you're specifying that we need to take on HN will fix this issue on some other website. I don't know any details other than the limited information you're sharing here. I can't find any emails about this matter linked to the username you're commenting from here.
For example, reserve the usernames 'deleted-xxxx' where x is a number. Then when someone wants their history obliterated, loop over every thread they have commented in. For each thread, choose a random number deleted-xxxx and assign that username to every comment of theirs in that thread.
Thus comments in the thread remain linked with one another, other deleted users in the thread remain distinct, and comments in one thread aren't linkable to a user's comments in another thread (perhaps lamentable, but required for unlinking spilled personal info in the general case)
(I chose random numbers rather than incrementing so that one can't start making inferences about users based on deletion order)
That information might be possible to determine from a comprehensive archive of HN, but it would be much harder to obtain.
The ability to disown a specific set of content (I'm not sure HN permits this) would avoid that issue. The associated account would just have a limited history, not an empty one. That would be equivalent to an after-the-fact throwaway account, which is much less attention-grabbing.
In 2012 when I started commenting here I had no idea it would lead to death threats and I’d have a two year old daughter.
There is a 100+ page forum thread of people betting on when I’m going to die. Redditors have commented in public “I wish he did die”, etc etc
No topic is truly safe from other sociopaths getting their jollies from writing anonymous hatemail. Yeah, sociopathy makes it difficult to feel something, I empathize — but that's no excuse for them abusing their people-toys. Imagine Sid as an adult on the Internet if he'd never been scared straight: it doesn't matter what topics you play with to a Sid, they're adaptable and will find ways to issue death threats for personal pleasure, on whatever topics they find in the sandbox.
https://www.youtube.com/watch?v=kjKuMCJqdW4