Menu

California’s Delete Act and the Fight Against Data Brokers

3 weeks ago 0

Millions of Social Security numbers from Americans are listed on the dark web following significant data breaches in recent years. These numbers are available for those with credit cards, including fraudsters and spammers. When such information is misused, it can have severe consequences. Thieves can open new credit cards under your name, file false tax returns, and steal refunds or government benefits.

In California, many people aim to address this issue by asking data brokers to delete personal information. This is possible under the state’s pioneering Delete Act.

Understanding California’s Delete Act

The legislation, SB 362, enhances privacy rights for California residents. It permits them to request the removal of their personal data from numerous registered data brokers through a centralized platform called DROP (Delete Request and Opt-out Platform).

According to CalPrivacy, the personal data targeted for deletion includes:

  • Social Security numbers
  • Precise geolocation
  • Browsing history
  • Email addresses
  • Phone numbers
  • Interests
  • Health-related information
  • Shopping habits

Data not eligible for deletion includes information directly given to a business (first-party data), exempted data, and publicly available data. Californians can request deletion from brokers registered with the California Privacy Protection Agency (CPPA). Brokers must not only delete past data but also refrain from selling any collected data in the future.

“Our data is their product, and they don’t sell it back to us,” noted CalPrivacy Executive Director Tom Kemp.

Brokers must initiate a first round of deletions by August 1. They have 45 days to notify both CalPrivacy and Californians requesting the erasure of their actions. Failure to comply results in penalties of $200 per day per individual if their data is not erased as requested.

Over 300,000 Requests for Data Deletion

According to the Mercury News, 332,292 Californians had signed up for data deletion by July 1. Of nearly 600 registered data brokers, 110 sell location data, more than 40 sell identity data, nearly 70 sell information on gender identity, seven sell data on reproductive health, and six on union membership.

Some brokers also sell data on minors, with options for them or their parents to request deletions. Around 50 brokers sell data to the federal government, as many sell to state governments, 27 sell to police agencies, over 20 to foreign entities, and roughly 30 to developers of generative AI.

Challenges and Adoption Rates

Despite the sensitive nature of Social Security numbers, less than 1% of Californians have sought deletion. Kemp expects this number to rise once brokers start deleting data. By reducing your data footprint, you may see less targeted advertising, fewer scams, and potentially fewer fraud attempts.

Californians can check their eligibility and request deletion on the DROP platform by August 1.

Comparison Across the U.S.

No comprehensive federal law regulates data brokers or bans the sale of personal information. The U.S. has diverse regulations, with some states allowing residents to opt-out of data sales.

As of April, 20 states, including California, have enacted privacy laws. Examples include Colorado, Connecticut, Delaware, and others. Some states, like Connecticut and New Jersey, are crafting systems similar to California’s. They aim to provide centralized deletion platforms for residents.

Connecticut will introduce a deletion system by July 2028. New Jersey’s new law requires brokers to register publicly and allows residents to request information deletion. Oregon, Texas, and Vermont require broker registration but lack a unified deletion system like California.

Leave a Reply

Leave a Reply

Your email address will not be published. Required fields are marked *