Consumer Reports Study Shows California's Privacy Law Is A Poorly-Enforced Mess

from the not-helping dept

Over the last few decades, the U.S. government (more accurately the industries that lobby it) have made it abundantly clear most aren't keen on even the most basic of privacy law for the internet era. Sure, companies like Facebook and AT&T say they want a privacy law, but they don't. Not really. Even the most basic privacy laws would educate consumers and empower them to more easily opt out of tracking and behavioral ads, costing countless sectors billions of dollars. What they want, if we have to have a law at all, is a law their lawyers write, so riddled with loopholes and caveats as to legalize dodgy behavior, not ban it.

Since these bogus solutions don't sell well with consumer advocates and many privacy experts, we routinely hit gridlock. The result: the U.S. has no meaningful federal privacy law for the internet era decades after the fact. And, in the rare instances where U.S. leaders somehow manage to shake off lobbying influence and their own incompetence to pass even modest rules (like the FCC's dead broadband privacy rules), they're quickly dismantled by a Congress slathered in campaign contributions from multiple, coordinating industries.

This federal, lobbyist-induced apathy to passing any real federal privacy solutions has resulted in states rushing to fill the void. Often poorly. California, for example, has been lauded for passing one of the most comprehensive privacy solutions in the nation (which isn't saying much) in the form of the California Consumer Privacy Act (CCPA). The problem, as we've noted previously, is that it was a rushed mess cobbled together in a mad dash. Sloppy wording means the bill had a huge share of problems, which Mike has outlined previously. For a subject this complicated, a "mad dash" approach was never likely to work out that well.

Fast forward to this week, when a new report by Consumer Reports found the bill (surprise!) isn't really succeeding at its primary goal: clearly informing consumers what's going on in terms of access to their data, and making it easier to opt out of data collection and sale. This most basic provision also isn't being meaningfully enforced in any substantive way. The organization spent much of May testing numerous websites and found that actually trying to opt out of data collection and sales was either impossible, or very difficult to confirm with the companies in question:

  • Consumers struggled to locate the required links to opt out of the sale of their information. For 42.5% of sites tested, at least one of three testers was unable to find a DNS link. All three volunteers failed to find a “Do Not Sell” link on 12.6% of sites, and in several other cases one or two of three testers were unable to locate a link.
  • At least 14% of the time, burdensome or broken DNS processes prevented consumers from exercising their rights under the CCPA.
  • Consumers often didn’t know if their opt-out request was successful. Neither the CCPA nor the CCPA rules require companies to notify consumers when their request has been honored. As a result, about 46% of the time, consumers were left waiting or unsure about the status of their request. About 52% of the time, the tester was “somewhat dissatisfied” or “very dissatisfied” with opt-out processes.
  • Cool. The full report (pdf) is worth a read, and also found that data brokers fairly consistently violated the law without any penalty. One used data gleaned from opting out to actually sign the consumer up for additional marketing. Some brokers demanded data that consumers eager to opt-out of data monetization and tracking wisely weren't keen on providing to often-dodgy data brokers (like copies of government IDs). Again, none of these problems should be particularly surprising for a bill numerous experts say was rushed and undercooked, attempting to fix a problem that's global and massive.

    Consumer Reports was quick to note that some of these problems should be fixed by California Proposition 24, which will be voted on in November. Though still, questions remain as to whether California has the competency to pull this off given the scale of the problem we're talking about. Ideally, it would be best to have this problem tackled by a cohesive, federal level law and actually staffed and funded privacy regulators at places like the FTC. But most efforts to accomplish that are routinely undermined by a coalition of industries (and the lawmakers paid to love them) which would prefer consumers remain opted in and befuddled by fine print.

    But with major privacy scandals occurring weekly, doing nothing is starting to get harder to pull off. So instead, we're starting to see a laundry list of federal solutions by bad faith actors whose top interest isn't consumer protection, but bogus laws designed to pre-empt tougher, better, consensus-driven solutions on both the state and federal level. As such while California's proposal is a (hopefully fixable) mess, it's surprising the bill was even created at all in an environment where doing nothing or doing nothing but dressing it up as something is the preferred outcome for a large number of privacy-violating giants.

    Hide this

    Thank you for reading this Techdirt post. With so many things competing for everyone’s attention these days, we really appreciate you giving us your time. We work hard every day to put quality content out there for our community.

    Techdirt is one of the few remaining truly independent media outlets. We do not have a giant corporation behind us, and we rely heavily on our community to support us, in an age when advertisers are increasingly uninterested in sponsoring small, independent sites — especially a site like ours that is unwilling to pull punches in its reporting and analysis.

    While other websites have resorted to paywalls, registration requirements, and increasingly annoying/intrusive advertising, we have always kept Techdirt open and available to anyone. But in order to continue doing so, we need your support. We offer a variety of ways for our readers to support us, from direct donations to special subscriptions and cool merchandise — and every little bit helps. Thank you.

    –The Techdirt Team

    Filed Under: california, ccpa, privacy


    Reader Comments

    Subscribe: RSS

    View by: Time | Thread


    1. identicon
      Anonymous Coward, 5 Oct 2020 @ 6:22am

      Opt-out is a lousy goal

      Collection should only be allowed, if it's allowed at all, on an opt-IN basis.

      That means a specific positive action, independent of any other action, to consent to each and every single individual type of data collection, retention, distribution, or use not OBVIOUSLY NECESSARY to provide whatever service the user was looking for when the data were collected.

      Yes, it's complicated to express all the necessary detail for that, but it's no more complicated than expressing all the necessary detail for opt-out. And opt-out does not work; any opt-out based system is unacceptable from the get-go.

      link to this | view in thread ]

    2. identicon
      elections, 5 Oct 2020 @ 7:07am

      ...so what's the best voting strategy in this November's elections ?

      link to this | view in thread ]

    3. identicon
      Anonymous Coward, 5 Oct 2020 @ 7:29am

      Re:

      Emigrate!

      link to this | view in thread ]

    4. icon
      GHB (profile), 5 Oct 2020 @ 9:07am

      sites also DELEBRATELY make it hard to turn off data sharing

      on reddit assholedesign, some sites even made misleading interfaces, camouflaged texts, and even downright force the user to reenable data sharing. ad supported mobile games does this a lot.

      link to this | view in thread ]

    5. identicon
      Pixelation, 5 Oct 2020 @ 9:26am

      "Sure, companies like Facebook and AT&T say they want a privacy law, but they don't."

      They would love a privacy law. One which allows them to collect and sell all of your data to whomever they want.

      link to this | view in thread ]

    6. icon
      That One Guy (profile), 5 Oct 2020 @ 4:20pm

      Re:

      'We love the idea of a privacy law so much we wrote one up ourselves. No no, no need to read it, here's a completely unrelated campaign contribution and you just go off and pass this for us.'

      link to this | view in thread ]

    7. identicon
      Anonymous Coward, 5 Oct 2020 @ 6:22pm

      Re:

      The Yes It Is Confirmed That You Have No Privacy Law.

      link to this | view in thread ]

    8. icon
      Uriel-238 (profile), 6 Oct 2020 @ 12:55am

      If the states could align...

      We could have a solution similar to the one regarding Net Neutrality, in which all the states pass their own laws.

      If we made sure that a few states had a strong gold stand (which was different, but enforced with, say, fines) maybe that will get big data to plead for a fair federal standard that actually protects privacy.

      link to this | view in thread ]


    Follow Techdirt
    Essential Reading
    Techdirt Deals
    Report this ad  |  Hide Techdirt ads
    Techdirt Insider Discord

    The latest chatter on the Techdirt Insider Discord channel...

    Loading...
    Recent Stories

    This site, like most other sites on the web, uses cookies. For more information, see our privacy policy. Got it
    Close

    Email This

    This feature is only available to registered users. Register or sign in to use it.