

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- Does this mean people can delete comments from HN?by echelon
- Does this mean people can delete comments from HN?
This is already a thing. One can reach out to dang to request their account or their comments be removed. They do not like to remove comments as it breaks some of the interaction and context people had on the site but they will not refuse to do it. hn@ycombinator.com
by Bender - Only if HN counts as a "data broker" under the corresponding law [0]. It states:
> “Data broker” means a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship. “Data broker” does not include any of the following:
> An entity to the extent that it is covered by the federal Fair Credit Reporting Act (15 U.S.C. Sec. 1681 et seq.).
> An entity to the extent that it is covered by the Gramm-Leach-Bliley Act (Public Law 106-102) and implementing regulations.
> An entity to the extent that it is covered by the Insurance Information and Privacy Protection Act (Article 6.6 (commencing with Section 791) of Chapter 1 of Part 2 of Division 1 of the Insurance Code).
> An entity, or a business associate of a covered entity, to the extent their processing of personal information is exempt under Section 1798.146. For purposes of this paragraph, “business associate” and “covered entity” have the same meanings as defined in Section 1798.146 [1].
I don't think HN counts as a "data broker" under this definition since they state that they "do not collect any Personal Information unless you choose to provide your email address and/or information in the "about" field" for HN accounts and "do not sell or share your Personal Information (as those terms are defined under the CCPA)."
[0]: https://cppa.ca.gov/regulations/pdf/data_broker_reg_delete_a...
[1]: https://leginfo.legislature.ca.gov/faces/codes_displaySectio....
by aw1621107 - What about unregistered data-brokers? I would he happy to sign up to webhooks for when someone wants to delete data.
Problem is though, you'd be revealing more data about them than I probably have by sending it.
by hackernud3s - Do you think you could be an unregistered data broker? You should probably reach out to me directly so I can give you more targeted advice.
All of the requests are SHA-256 hashvalues, they aren't transmitting any usable information in the process of sending the deletion requests.
by jboggan - Let me guess, to delete your data you need to give them your data so that they can keep track that you want your data to be deleted.by m4xp
- > Companies that fail to comply can face fines of $200 per day for each affected Californian.
Does this cover things like credit reports/scores? If someone submits a request to this DROP thing, is it possible data gets deleted that they don't intend?
- I hope this is true! Consumer credit is a serious problem. How much better would it be if only corporate entities could take on debt? That goes for school, home, and car loans too. Imagine the return to sanity in pricing when Big Finance can no longer scam time-preferenced and desperate buyers! Society might have a real savings rate again!by rustcleaner
- Probably not. Under TITLE 1.81.48:
“Data broker” does not include any of the following:
(1) An entity to the extent that it is covered by the federal Fair Credit Reporting Act (15 U.S.C. Sec. 1681 et seq.).
(2) An entity to the extent that it is covered by the Gramm-Leach-Bliley Act (Public Law 106-102) and implementing regulations.
(3) An entity to the extent that it is covered by the Insurance Information and Privacy Protection Act (Article 6.6 (commencing with Section 791) of Chapter 1 of Part 2 of Division 1 of the Insurance Code).
(4) An entity, or a business associate of a covered entity, to the extent their processing of personal information is exempt under Section 1798.146. For purposes of this paragraph, “business associate” and “covered entity” have the same meanings as defined in Section 1798.146.
<https://leginfo.legislature.ca.gov/faces/codes_displayText.x...>
Credit bureaus are, I think, covered as item (1).
by dredmorbius - I've been thinking of making a service which automatically sends deletion requests for all my service companies every month. Like, I currently keep a bunch of spyware features in my car turned of, but I have to keep location turned on to use the built in navigation which keeps track of range for me. Would be nice to have a ceiling on that data's retention.
Long term, if compliance with data deletion requests becomes a pain, maybe companies will finally give us an opt out of surveillance capitalism? Or maybe they'll just lock me out of my own car (I guess it's their car since I don't have root on it, lol)
by igor47 - If it's a VW, pick up a Ross-Tech VAG-COM + VCDS, locate your Telematics unit (OCU, online communications unit) and remove it; mine was behind the instrument cluster. Then use VCDS on a laptop plugged into your car with VAG-COM, and code out the OCU from every module giving fault codes for its absence. You will probably lose the microphone, as in my Mk7 the microphone line goes through the OCU. Finally, optionally, you can code out your infotainment module's bluetooth features thus taking away another avenue for passive surveillance.by rustcleaner
- Does this apply to Google, car companies, etc, or did they bribe in exceptions for themselves (like California grocery stores did for the Do Not Sell My Personal Information law)?
Also, who gets the $200/day? If I issue a drop request, wait 145 days, then buy my data from brokers, do they have to pay me $20,000 per record they return?
by hedora - Fast workers make $20 an hour in Cali, except for panera bread workers OBVIOUSLY.by ransom1538
- Well the CPPA (state regulator) just hit General Motors with a $12.75M fine for selling data to two registered data brokers, and made the brokers who received the data delete it all: https://ccpa.world/enforcement/gm-onstar-smart-driver
Does it apply to Google? Well that's an interesting question. I think the answer is yes but the practical matter is that the CPPA is going to get some legal precedent and some more lawyers on staff before they take on Google. At the current number of requests in the DROP platform they could determine Google is an unregistered data broker and fine them $25B+, but I don't think they are going to do that this year.
I think within 36 months they will take the legal victories from prosecuting the first set of unregistered data brokers and apply it to the real players in the data ecosystem. At least, that's what I would do if I were Michael Macko.
by jboggan - Some previous Delete / Drop Act discussion:
The Delete Act
https://news.ycombinator.com/item?id=46449694
California residents can now request all data brokers delete personal info
- I wonder if there will be any funny data issues that happen because companies keep track of such requests in a table named "drop"by bdcravens
- mom should look up little bobby tablesby m463
- Out of curiosity, does anyone know how this is enforceable for a company not based in California? Can CA fine a data broker that is based in another state but that is selling CA residents' information?by MrZander
- Yes. We talk to our lawyers here in FL. We take the legal document from CA and throw them in the garbage while laughing is the current policy.by ransom1538
- The company would have to not have any interstate presence at all. If you are a business based in the united states that has customers in California, you are easily reachable under California law.by connicpu
- Yes; the nexus for legal purposes is generally the location of the user, not the brokerby Xorakios
- I've been building the infra for data brokers to connect to DROP (easy), actually effect deletions (hard), and make sure the data stays deleted (harder): forgetmenaut.com
DROP is pretty significant considering that it's the first compliance system meant to have an immediate effect (delete the data), backward-looking effect (forward a legally-binding deletion request to everyone that data was sold to or shared with), and a forward-looking effect (never let that record re-enter your system, in perpetuity). This is significantly more tracking and auditing infrastructure than anyone in the industry has ever normally run, not to mention that the request volume is 100-10000x what most of these brokers would process in previous years.
We'll see how well companies actually managed to comply when audits are performed for every registered broker in 24 months. I also think the impending prosecutions (and likely bankruptcies) of several unregistered data brokers will encourage the others to take it more seriously.
by jboggan - How are you supposed to ensure you never store that info without storing info about what info to never storeby Ferret7446
- I hope other states adopt this. One of the biggest mistakes I have made is giving my real phone number to Dun & Bradstreet. Now the spam calls and messages (from people they sold my info to) won't stop. I don't want to change my phone number.by petilon
- Out of curiosity, did you do this as part of Android's awful app submission processby cyanregiment
- My number used to belong to an elderly woman, so I keep getting spam texts intended for her. I block the numbers, but they somehow keep sending me spam messages from different ones.
I don't think there is any solution other than changing my phone number at this point. The issue is fucking sites keep using phone number as 2fa.
by cute_boi - I don’t know if this is worth the cost to you but I’ve found that the cheapest $5 Tello plan as a second line is great for business use like this.by Grombobulous
- I noticed this too. It's a number I've had for years and have barely given out to anyone. Registered for a DUNS number last month and have been getting all sorts of spam calls from all different area codes. I assumed it was due to the DUNS form.
I noticed D&B have recently had FTC violations/settlements but not sure they touch this specific situation, but I'm honestly curious if there's anything we can do about this.
https://www.ftc.gov/news-events/news/press-releases/2025/09/...
by ThePinion - As good intentioned as it is, I don't like the wording used around this law. "Request" and "Ask" and "please delete my information." Notice that regular users have to "ask nicely" but when it's something like the DMCA, which benefits corporations, they use "takedown notices" and "demand letters."
I don't want to ask data brokers, pretty please with sugar on top. I want to be able to demand they do it, and require them to immediately do it and provide proof that they did, under penalty of perjury.
by ryandrake - here-hereby kooi