Californians' data deletion requests, DROP, become enforceable Aug. 1
Posted by MilnerRoute 20 hours ago
Comments
Comment by ryandrake 14 hours ago
I don't want to ask data brokers, pretty please with sugar on top. I want to be able to demand they do it, and require them to immediately do it and provide proof that they did, under penalty of perjury.
Comment by ooterness 12 hours ago
I don't know if it's apocryphal, but it shows up in the Hornblower novels and at least one episode of Star Trek.
Comment by dragonwriter 11 hours ago
You are being distracted from the substance by non-substantial surface features.
Comment by inigyou 6 hours ago
Comment by Y-bar 13 hours ago
https://munley.com/tag/request/
I’m not a US lawyer, but the word ”request” seems like it has a solid legal basis and can be used to compel action.
Comment by brookst 13 hours ago
Comment by wilg 12 hours ago
Comment by kooi 13 hours ago
Comment by petilon 19 hours ago
Comment by ThePinion 16 hours ago
I noticed D&B have recently had FTC violations/settlements but not sure they touch this specific situation, but I'm honestly curious if there's anything we can do about this.
https://www.ftc.gov/news-events/news/press-releases/2025/09/...
Comment by cyanregiment 17 hours ago
Comment by ThePinion 15 hours ago
Comment by xeromal 15 hours ago
Comment by cyanregiment 15 hours ago
A random person releasing an app or game on the App Store - you won't need it.
But on Android you still might, even for something small, since they changed the rules for new developers. As of November 2023, any new developer account releasing an app basically has to have an Organization account to publish.
Otherwise, the only way to do it as a solo dev is to go through some arduous testing phase with Google, where you have to find 12 or more people to help test at certain times for 14 consecutive days. If even 1 tester doesn't show up or deletes the app, it resets. Comical, but it's how they lowkey force you to create an Organization.
And people should form companies (and operate as Organizations on platforms). It will protect you in the long run, and you can pay lower taxes on revenues. The main problem I have with it - and this also goes for certain payment processors - sometimes I just want to try an idea. Or like your example, build an app for a friend or relative without a ton of hoops to jump through. Involving a 3rd party credit bureau that operates as a private company - that apparently sells people's data to shit ball marketers, doing whatever else they want with basically no oversight - seems in almost all cases overkill and whack as a process as big as Apple or Google app submission that is borderline a public service if you're willing to not pretend we don't have 2 main choices in this market.
The app store platform should just forward on to the downloading user that it's a corporation in Delaware, or whatever. They kinda do - with the "copyright" field, but that field and value has no legal bearing on anything and can be changed without a review - where even being an individual or "sole" proprietor is a legal designation. You could still form a company under your own name later. Adding a business license should be some optional thing IMO that links through to a local registry if possible and if not, then the end user can deduce that it is not "verified" to be that entity.
Comment by xeromal 14 hours ago
Comment by Grombobulous 15 hours ago
Comment by cute_boi 18 hours ago
I don't think there is any solution other than changing my phone number at this point. The issue is fucking sites keep using phone number as 2fa.
Comment by _dark_matter_ 15 hours ago
Comment by hackernud3s 18 hours ago
Comment by jboggan 12 hours ago
DROP is pretty significant considering that it's the first compliance system meant to have an immediate effect (delete the data), backward-looking effect (forward a legally-binding deletion request to everyone that data was sold to or shared with), and a forward-looking effect (never let that record re-enter your system, in perpetuity). This is significantly more tracking and auditing infrastructure than anyone in the industry has ever normally run, not to mention that the request volume is 100-10000x what most of these brokers would process in previous years.
We'll see how well companies actually managed to comply when audits are performed for every registered broker in 24 months. I also think the impending prosecutions (and likely bankruptcies) of several unregistered data brokers will encourage the others to take it more seriously.
Comment by MrZander 19 hours ago
Comment by Xorakios 18 hours ago
Comment by connicpu 17 hours ago
Comment by metalcrow 17 hours ago
Comment by teraflop 16 hours ago
Comment by what 16 hours ago
Comment by dredmorbius 14 hours ago
A seller is deemed to be doing business in the state if the seller solicits prospective purchasers from locations in California or solicits prospective purchasers who are located in this state.'
<https://oag.ca.gov/consumers/general/telreg>
The DROP act creates a right to California residents. To the extent I've read the statute, it doesn't define what entities are covered (see: <https://leginfo.legislature.ca.gov/faces/codes_displayText.x...>), which seems to me to suggest that affected entities are defined by their data collection from California residents, not where or how they engage in activities otherwise in California.
Comment by braiamp 16 hours ago
Comment by edmundsauto 15 hours ago
Comment by connicpu 14 hours ago
Comment by newsomix9xl 14 hours ago
That's my guess
Comment by ransom1538 13 hours ago
Comment by vvbull 12 hours ago
Comment by tatersolid 2 hours ago
Comment by hackernud3s 18 hours ago
Comment by hedora 14 hours ago
Also, who gets the $200/day? If I issue a drop request, wait 145 days, then buy my data from brokers, do they have to pay me $20,000 per record they return?
Comment by jboggan 12 hours ago
Does it apply to Google? Well that's an interesting question. I think the answer is yes but the practical matter is that the CPPA is going to get some legal precedent and some more lawyers on staff before they take on Google. At the current number of requests in the DROP platform they could determine Google is an unregistered data broker and fine them $25B+, but I don't think they are going to do that this year.
I think within 36 months they will take the legal victories from prosecuting the first set of unregistered data brokers and apply it to the real players in the data ecosystem. At least, that's what I would do if I were Michael Macko.
Comment by ransom1538 13 hours ago
Comment by bdcravens 18 hours ago
Comment by m463 15 hours ago
Comment by igor47 19 hours ago
Long term, if compliance with data deletion requests becomes a pain, maybe companies will finally give us an opt out of surveillance capitalism? Or maybe they'll just lock me out of my own car (I guess it's their car since I don't have root on it, lol)
Comment by rustcleaner 14 hours ago
Comment by m4xp 7 hours ago
Comment by hackernud3s 19 hours ago
Problem is though, you'd be revealing more data about them than I probably have by sending it.
Comment by jboggan 12 hours ago
All of the requests are SHA-256 hashvalues, they aren't transmitting any usable information in the process of sending the deletion requests.
Comment by hackernud3s 10 hours ago
Comment by ChrisArchitect 15 hours ago
The Delete Act
https://news.ycombinator.com/item?id=46449694
California residents can now request all data brokers delete personal info
Comment by kmfrk 6 hours ago
Because of this, be sure to pay attention to companies getting too clever in interpreting this law, even after it's passed. It ain't over 'til it's over, so be sure to keep fighting it until we actually get the desired outcome, and track the actual compliance with the law.
The law itself sounds great, just remember that people often aren't.
Comment by tjwebbnorfolk 17 hours ago
Does this cover things like credit reports/scores? If someone submits a request to this DROP thing, is it possible data gets deleted that they don't intend?
Comment by dredmorbius 13 hours ago
“Data broker” does not include any of the following:
(1) An entity to the extent that it is covered by the federal Fair Credit Reporting Act (15 U.S.C. Sec. 1681 et seq.).
(2) An entity to the extent that it is covered by the Gramm-Leach-Bliley Act (Public Law 106-102) and implementing regulations.
(3) An entity to the extent that it is covered by the Insurance Information and Privacy Protection Act (Article 6.6 (commencing with Section 791) of Chapter 1 of Part 2 of Division 1 of the Insurance Code).
(4) An entity, or a business associate of a covered entity, to the extent their processing of personal information is exempt under Section 1798.146. For purposes of this paragraph, “business associate” and “covered entity” have the same meanings as defined in Section 1798.146.
<https://leginfo.legislature.ca.gov/faces/codes_displayText.x...>
Credit bureaus are, I think, covered as item (1).
Comment by rustcleaner 14 hours ago
Comment by Razengan 13 hours ago
Comment by aw1621107 11 hours ago
Comment by echelon 19 hours ago
Comment by aw1621107 18 hours ago
> “Data broker” means a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship. “Data broker” does not include any of the following:
> An entity to the extent that it is covered by the federal Fair Credit Reporting Act (15 U.S.C. Sec. 1681 et seq.).
> An entity to the extent that it is covered by the Gramm-Leach-Bliley Act (Public Law 106-102) and implementing regulations.
> An entity to the extent that it is covered by the Insurance Information and Privacy Protection Act (Article 6.6 (commencing with Section 791) of Chapter 1 of Part 2 of Division 1 of the Insurance Code).
> An entity, or a business associate of a covered entity, to the extent their processing of personal information is exempt under Section 1798.146. For purposes of this paragraph, “business associate” and “covered entity” have the same meanings as defined in Section 1798.146 [1].
I don't think HN counts as a "data broker" under this definition since they state that they "do not collect any Personal Information unless you choose to provide your email address and/or information in the "about" field" for HN accounts and "do not sell or share your Personal Information (as those terms are defined under the CCPA)."
[0]: https://cppa.ca.gov/regulations/pdf/data_broker_reg_delete_a...
[1]: https://leginfo.legislature.ca.gov/faces/codes_displaySectio....
Comment by Bender 8 hours ago
This is already a thing. One can reach out to dang to request their account or their comments be removed. They do not like to remove comments as it breaks some of the interaction and context people had on the site but they will not refuse to do it. hn@ycombinator.com
Comment by testing22321 18 hours ago
Comment by tomhow 15 hours ago
Comment by adzm 17 hours ago
Comment by downrightmike 17 hours ago
Comment by tomhow 15 hours ago
Comment by testing22321 13 hours ago
This is the identical line dang fed me, and what he did is useless. It changes nothing.
Stop saying you’ll go out of your way to help users when you clearly won’t. Changing my username on all my old comments to some other username is not enough. It’s trivial to figure out who I am, and then have all my comments attributed to me.
You should aim to actually do better, not just say that what you do now is good enough when it clearly isn’t.
Comment by tomhow 12 hours ago
On a case-by-case basis we can move a selection of comments to a separate username. We of course don't want anyone to be in danger.
Comment by testing22321 12 hours ago
Middle ground: on any given topic change all my comments to some random user I’d, then a different one for every topic.
threads will stay coherent, but people won’t be able to follow my old user name around topics for 14 years.
I’ll send an email in the morning. I have to sleep.
Comment by tomhow 12 hours ago
This is obviously not true. We care about thread persistence and coherence as a default, because some of HN's most historically significant threads are from the earliest years. We will take reasonable steps to protect people's identity and safety once we know the specifics of the situation. We routinely redact URLs, company names, project names and other identifying details from historical comments to prevent people's identity from being inferred.
Comment by BigTTYGothGF 3 hours ago
Comment by testing22321 4 hours ago
You’re saying “we do minimum effort” .
I am telling you It is not enough, and you refuse to even acknowledge that. You are saying “tough luck” in fancier language.
Comment by unstatusthequo 19 hours ago
Comment by dwattttt 17 hours ago
EDIT: Android also surfaces this information more generally, I just found it under More Privacy Settings -> Ads
Comment by sourcecodeplz 12 hours ago
Comment by faucetl 15 hours ago
Comment by garpoon 16 hours ago
Comment by amazingamazing 19 hours ago
Comment by millerm 18 hours ago
Comment by amazingamazing 18 hours ago
Comment by EA-3167 17 hours ago
Comment by amazingamazing 17 hours ago
Comment by EA-3167 17 hours ago
Comment by amazingamazing 16 hours ago
Comment by tomhow 13 hours ago
Comment by aw1621107 18 hours ago
> In case it's of interest, here's the standard language from emails I send people:
> We try not to delete posts that got replies, because doing so would be unfair to the other commenters in the thread. What I've done so far is reassign it to a random user ID, so it's as if you'd used a throwaway account to post it and there's no link to your main account. Does that work?
Comment by testing22321 18 hours ago
When I asked dang to do better after me and my family got death threats online, dang told me “tough luck”
To this day thousands of my comments from my old username are on this site and trivially east to link to my real name. (Links to my website, etc)
Comment by tomhow 14 hours ago
He (nor I) would never write that or anything like it. What we always say is that we aim to find a compromise between a user's wish for their entire history to be erased and the rest of the community's expectation that when they participate in discussion threads, those threads will persist unadulterated into the future.
We are always willing to redact PII and do other things to prevent people's real identities from being recognized from their HN activity. We help people with requests like this all the time.
Edit:
Now I can see the email in question, I can confirm that dang did not write “tough luck”. We were, and still are, happy to work with this user to redact material that reveals their identity or location from their old comments.
Comment by testing22321 13 hours ago
Changing my username to something random doesn’t help, because it’s trivial to find a comment or two that make it clear that random user ID is me, and then you can see all my comments.
There are two much better approaches.
1. Make every single comment of mine a new random user if so they’re all separate.
2. Make the user id of everyone who has ever asked for deletion ”deleted-user” so my comments are lost in the sea.
Either of those approaches would make it impossible to find all my old comments and know they all belong to the real me in the real world.
Please help. Death threats are not fun, especially when you have a 2 year old daughter. There is a 100+ page forum thread of people betting on when I (real name, real person) am going to die. Just saying that somewhat Doxxes me.
Comment by tomhow 13 hours ago
We can't necessarily do the exact things you've asked, because it makes all the discussion threads you participated in incoherent. We can take reasonable steps to disassociate personally-identifying comments from others.
> Please help. Death threats are not fun, especially when you have a 2 year old daughter. There is a 100+ page forum thread of people betting on when I (real name, real person) am going to die. Just saying that somewhat Doxxes me.
This sounds terrible, and of course we don't want anything like that for you. It's just not clear (and I still haven't received an email from you so I can't look into the details of the case) how the actions you're specifying that we need to take on HN will fix this issue on some other website. I don't know any details other than the limited information you're sharing here. I can't find any emails about this matter linked to the username you're commenting from here.
Comment by mindslight 12 hours ago
For example, reserve the usernames 'deleted-xxxx' where x is a number. Then when someone wants their history obliterated, loop over every thread they have commented in. For each thread, choose a random number deleted-xxxx and assign that username to every comment of theirs in that thread.
Thus comments in the thread remain linked with one another, other deleted users in the thread remain distinct, and comments in one thread aren't linkable to a user's comments in another thread (perhaps lamentable, but required for unlinking spilled personal info in the general case)
(I chose random numbers rather than incrementing so that one can't start making inferences about users based on deletion order)
Comment by vvbull 12 hours ago
Comment by dredmorbius 4 hours ago
That information might be possible to determine from a comprehensive archive of HN, but it would be much harder to obtain.
The ability to disown a specific set of content (I'm not sure HN permits this) would avoid that issue. The associated account would just have a limited history, not an empty one. That would be equivalent to an after-the-fact throwaway account, which is much less attention-grabbing.
Comment by testing22321 3 hours ago
The only thing they do is change your username on every comment you’ve ever made to something else. But they’re all the same , so you can still link all the comments to one identity, and if even one comment makes it clear it’s a real person, then they all are.
Requesting anything more results in them saying “oh yes, we respect users wishes, blah, blah” and no action.
Comment by tomhow 1 hour ago
We are willing to do this.
> Requesting anything more results in them saying “oh yes, we respect users wishes, blah, blah” and no action
We gladly work with users to redact any material that identifies a person or reveals their location, or that otherwise poses risk to their welfare.
Comment by mindslight 13 minutes ago
Comment by altairprime 18 hours ago
Comment by testing22321 17 hours ago
In 2012 when I started commenting here I had no idea it would lead to death threats and I’d have a two year old daughter.
Comment by vlovich123 16 hours ago
Comment by testing22321 13 hours ago
There is a 100+ page forum thread of people betting on when I’m going to die. Redditors have commented in public “I wish he did die”, etc etc
Comment by cindyllm 13 hours ago
Comment by altairprime 15 hours ago
No topic is truly safe from other sociopaths getting their jollies from writing anonymous hatemail. Yeah, sociopathy makes it difficult to feel something, I empathize — but that's no excuse for them abusing their people-toys. Imagine Sid as an adult on the Internet if he'd never been scared straight: it doesn't matter what topics you play with to a Sid, they're adaptable and will find ways to issue death threats for personal pleasure, on whatever topics they find in the sandbox.