Techlore Talks brings you in-depth conversations with the experts at the forefront of privacy, security, and digital rights. Hosted by Henry Fisher, founder of Techlore and long-time digital rights educator, each episode features meaningful discussions with the people building, researching, and advocating for digital freedom.
From cybersecurity researchers and privacy tool developers to open-source advocates and digital rights activists—if they're shaping how we protect ourselves online, they're on this show.
Topics include: privacy tools and technologies, cybersecurity threats and defenses, open-source software, surveillance and digital rights, encryption, tech policy, and digital sovereignty.
New episodes released regularly. Subscribe and join the community at techlore.tech.
If you multiply 15 by 600 plus data brokers, that's 10 full days worth of work.
Who has time for that?
The data broker industry has been out of control for years.
And the best advice I've had to share thus far is to sign up for a service to remove it for you or do it manually.
Neither of which is necessarily a great choice because either you have to hand over money and data to a private middleman company to do it for you,
or you have to go through the gruesome process of doing it yourself on a frequent basis,
because it's not just a one-time thing.
So when California, the state I reside in, announced DROP,
which is a government-run operation to try to take care of this problem in a slightly different way,
I was quite interested.
But I avoided it for myself because I didn't quite know what to expect,
if it was safe, and if it's something that was worth recommending to you all.
So today, I am honored to have Tom on from the CPPA, where I ask,
How does Drop work? Is it privacy respecting? How does it compare to a private company's opt-out?
What inspired it? Are other states or countries looking to follow it? And who have they spoken to
to try to help them in this journey as well? It is a very fascinating interview. I learned a lot
about Drop, and it cleared up pretty much every question I had about Drop. This is one of those
interviews where I'm literally asking everything I've been thinking about. So I learned just as
much as you all do. Without further ado, let's go over to Tom. Hello, today I have Tom Kemp on. Do
you want to quickly just introduce yourself and what you do? Sure. Thanks for having me on. My name
is Tom Kemp. I'm the executive director of the California Privacy Protection Agency, or commonly
known as Cal Privacy. Yeah, so my first question actually on that note is that it used to be CPPA.
That's still your domain, like on the emails that we exchange is still CPPA. But now I saw the Cal Privacy rebrand. Do you want to maybe speak to that for a second? Yeah, sure. Here in California,
we have the CCPA, the California Consumer Privacy Act, that was amended with the passage of Prop 24,
the California Privacy Rights Act, or CPRA, that created the CPPA, the California Privacy Protection
Agency. So I think we've got a four-letter acronym overload going on here. And here in
California, the transportation is known as Caltran. Here I live in the peninsula, it's Caltrain,
you know, Cal Water, Cal This. So I just thought we would remove one four-letter acronym from
what we have to memorize and just kind of streamline and say, we're the agency in California
that does privacy. So that's the genesis of trying to be more user-friendly and spare people from
having to learn another acronym. So yeah, that's fun. And what was your history beforehand? And
what kind of led you to this role and what you do now? Yeah, so I've historically been an
entrepreneur in Silicon Valley, and started companies and really got heavily involved in
my last company in cybersecurity. And after that company was acquired, I really started digging
into privacy. I did volunteer on Prop 24 on the campaign, which passed overwhelmingly here in
California with 9.3 million voters. And as I said before, that was CPRA 2020. That was CPRA,
which amended the CCPA and created the Cal Privacy Agency. And then that really gave me the bug
to do policy work. And so I just started advising state legislators. So I was the one that proposed
the California Delete Act to State Senator Josh Becker that became SB 362 that created this drop
system. We could probably talk more about that later. I worked with legislators in Washington,
state of Vermont, other places as well. And so when this opportunity came up to run the Cal Privacy Agency, I jumped at the opportunity. One reason was to be able to implement this system that
the Delete Act called for, but also just given my strong interest and desire in enabling privacy
rights at scale and making privacy easier, I just thought it was a really good fit, especially with
my management background that I had. So this is my first time in government. I've been doing it for
a year and a half. It's an amazing team. And we're doing some really cool things here in California
as it relates to privacy. Yeah, it's interesting. You don't see that kind of, especially, I guess,
it's from a lot of people listening's perspective, right? The big tech companies in Silicon Valley
aren't privacy friendly. And a lot of times what we've seen is they try to water down a lot of the
maybe you now want to do. So do you want to speak to that relationship? And if anybody's listening
to this going, oh, is this another entrepreneur from Silicon Valley trying to get involved in
politics and not be pro-consumer? Because I know that's probably where a lot of people's minds go.
Well, I did write a book called Containing Big Tech. So I think that kind of shows where I'm at.
But I'm also historically been an entrepreneur. And I think that there is an opportunity
to balance the innovation economy while providing guardrails and protecting people.
And so clearly there are things that are legal in the United States from a constitutional
perspective, as well as state laws.
But at the same time, there's more that can be done in terms of trying to balance innovation
with protecting people as well.
And I think that's been a big focus of mine, which is making sure that Californians can operationalize privacy rights.
Because the fundamental problem that we have in the United States is that we have an opt out system.
And so the onus is on the consumer to tell businesses not to do things with with their data.
People also refer to that as the notice and choice where you get the privacy policy.
And of course, to participate in today's modern economy, people usually say yes to the collection because they want to communicate with their friends.
They want to buy goods, et cetera.
And so in the end, what privacy really represents is a never ending set of chores that the consumer is forced to do in terms of contacting each of every site and say, well, don't sell my information or with these data brokers, delete my information, please.
And so what we're trying to do here in California is rebalance thing by providing this drop system, the delete request and opt out platform that enables mass deletion at scale from data brokers.
We're really heavily pushing what we call an opt out preference signal, which is a switch you can put in your browser that sends messages to every business that you visit via browser to not sell or share.
So we're trying to kind of.
That's GPC.
Yeah, the global privacy control, we call it in our regulations, the opt-out preference. So yeah, it's a balancing act that we have and we have to work within the framework of the laws that exist. But we're working very hard to kind of make sure that Californians have a fair shot, so to speak, to be able to protect themselves in an economy that really considers personal information as part of the oil that it consumes.
That's kind of the challenge and the focus.
It's a quality opportunity for us to make things better.
And that's what we're trying to do here at Cal Privacy.
Yeah, to start with just Cal Privacy, you know, my order of events here is that we had the GDPR in Europe.
And it was kind of the first of its time where we have real privacy rights that were given to regular people that they can actually act on.
And for the most part, it's still really the main thing.
I think Brazil has done something similar.
We have other countries finally start to pop up.
But the U.S. has never, to my understanding, done anything like this.
And so do you mind expanding on what this looks like and why it's done on a state level?
Yeah, just overall the origin and how it compares to other things that exist right now.
Yeah, sure.
So, I mean, at the federal level, there are privacy laws, but they're very focused on a given sector of the economy.
So you have HIPAA that has protections for health information.
There is some protections in Gramm-Leach-Bliley as it relates to financial information.
But those laws were passed 25, 30 years ago.
And obviously, Europe, as you said, was the first with GDPR.
And then there was a person here in California, a gentleman by the name of Alistair McTaggart,
who after GDPR came out was at, I think, a cocktail party.
He was talking with, I think, someone from Google or one of the big tech companies.
And that person started describing to Alistair, like, you won't believe the type of information we have on each and every one.
And that inspired him to try a ballot proposition in 2018 to actually have the first state comprehensive privacy law.
And he was in a good enough financial situation to pay for the ballot signatures.
And so he actually qualified to have the California Consumer Privacy Act be a ballot initiative.
Now, California had just passed a law that said that in the 2018 timeframe that the legislature has within 30 days the opportunity,
if they work with the entity bringing forth a ballot initiative, that if they're able to pass
a comparable law, that the ballot initiative would go away. And what happened in 2018 is that the tech
industry started really rallying against having the nation's first comprehensive privacy law.
And then all of a sudden Cambridge Analytica happened. And then that opposition went away.
And the legislature here in California said, you know, we're going to look really stupid that this
on the ballot. And so they took over the California Consumer Privacy Act. And then within 30 days of
the ballot initiative being qualified, they passed the CCPA. And that was signed by then
Governor Brown. But guess what happened in 2019 that industry said, let's water it down, right?
And all these bills came forth to kind of weed whack at the CCPA. And then Alistair in 2020 said,
Well, nuts to that. What I'm going to do is I'm going to come up with this ballot proposition, Prop 24, that sets a high floor and a higher floor than what existed with the CCPA.
And you can't go below that. And I'm going to take that directly to the voters.
And that's how I got involved. I worked six months as a full time volunteer on the campaign.
Didn't know Alistair from before. And it was amazing that nine point three million people voted for this ballot initiative.
That's one of the top vote getters for any type of legislation in any state in the history of the United States.
So that tells you people really care about privacy.
It created the actual agency itself, took a year or so for the agency to get up and running.
And I'm the second executive director.
We're an independent agency. We're the only independent agency that does privacy in the United States.
were governed by a five-member board, and they appoint the executive director to run the day-to-day
operations. And that's what I do. So that's kind of the brief history. And so clearly,
the CCPA was influenced by GDPR, and people often refer to it as the California's equivalent to GDPR.
There's a lot of similarities, but there are some differences. An opt-out, which we have,
versus an opt-in is the primary difference.
And then that really kind of kicked off
the other states going out there.
And we now have 23 states that actually have privacy laws
and we still don't have a federal equivalent.
I see.
And there's a lot of good stuff there.
So I'm going to try to keep my questions here
as punctual as I can.
I think the first thing,
initial reaction hearing this is it's really cool to hear. You know, there's this sentiment that
people don't care about privacy, but when you have one of the top votes be in support of something
that's pro-privacy, I think it means that people just don't know what to do to reclaim their privacy
is probably my guess. I 100%. You know, people always talk about the privacy paradox, and they
say, you know, consumers talk a big game about privacy, but they just go ahead and just hit the
accept button, right? And so they talk the talk, but they don't walk the walk. And from my perspective
is that, well, they have to hit the accept button to participate in today's modern economy,
right? But they really do care about privacy. And then once they hit the accept button,
it's just too darn difficult for them to kind of control the usage of their information.
And so what we're trying to do is within this opt-out paradigm, we're trying to say is like, look, let's give consumers tools to enable privacy at scale. Case in point, the drop system with data brokers. There are hundreds of data brokers that you and I don't have a direct relationship with.
And if we were to reach out under CCPA and exercise our right to delete, we would have to contact each one individually, maybe spend 10, 15 minutes.
Each one kind of has a different process.
And if you multiply 15 by the 600 plus data brokers that are registered with the state, that's 10 full days worth of work.
Who has time for that?
Similarly, to tell businesses not to sell or share your personal information, you have to go to each website, scroll to the bottom, configure cookies.
That may take a couple of minutes.
Who has time for that as well?
And that's why we're very supportive of the opt-out preference signal, the global privacy control, which is a switch that you can flip on your browser to universally send that message.
And what we did was last year is we sponsored AB 566 that requires browser vendors to put that into their actual product itself.
That becomes effective January 1st, 2027.
So, yeah, this whole operationalizing privacy, enabling privacy at scale, dealing with the after effects of an opt out model are all things that we literally here at Cal Privacy think about every day.
And we just want to make privacy easy for Californians.
Drop is a huge step forward.
The opt-out preference signal is a huge step forward, plus a bunch of privacy tips that
we put at privacy.ca.gov.
So we are laser focused on that, if that's any consolation, as you think about all the
issues associated with surveillance, privacy, et cetera.
Yeah, and I want to touch on the drop in just a second here.
But just very quickly, you mentioned opt-in versus opt-out as a difference between what California is doing versus what Europe's doing.
And do you mind just quickly teasing what you've seen, what you like about different implementations outside of California and what you think other people might be doing better, where you think California is doing better, just to kind of help people understand the landscape of the different approaches to these different laws around the world right now?
Yeah, I mean, Europe has opt-in and that's unless you explicitly, you know, say, OK, you can collect my information by default, the collection does not occur.
The issue that they have in Europe is that if you're an American, travel to Europe, or if one of your listeners is there's this concept of cookie fatigue, where every time you visit a website, you got to deal with this pop-up and just kind of confirm your choices.
And so people are frustrated with what they call cookie fatigue. In the United States, it's an opt-out model that by default, if you accept the terms, they're going to collect your information and there's further stuff buried in the fine print with what they do with it.
And then you have to go back and explicitly tell the business to not sell it or delete it, etc.
And as I just walked you through, that can be very time consuming.
And all the other states, because of, you know, kind of constitutional rulings, and I won't bore your listeners with that.
That's kind of why we have, you know, it's a First Amendment.
Seems like, you know, tech history always plays the First Amendment card, but that was kind of the card that was played.
And so by default, privacy laws in the U.S. to not run the risk of constitutional challenges have defaulted to an opt out model.
So that's kind of where where we're at. And then but the opt out model has the painful choices of chasing after all the businesses.
While in Europe, you've got the cookie fatigue aspect of it as well.
So we're just trying to kind of break the wheel, so to speak, here in California.
And I think other states are looking to adopt it.
I was very encouraged to see Connecticut.
They just passed a DeleteX style law.
There's 12 other states that require businesses to support the opt-out preference signal.
And I think all consumers will be able to take advantage of the fact that California is requiring browser vendors to add this into the solution.
So things are getting better and California is impacting other states, which is what we've historically done when it comes to consumer protection.
It's called the California effect.
You know, we did that with food safety.
We did that with automobiles, emissions and other things as well.
But that's almost a whole nother podcast in itself.
Yeah.
And I guess just to clarify, because I know some people are using acronyms like GPC, opt out signals.
A lot of our audience is more technical who's already been here and aren't new.
They're probably using Brave, which I think auto enables this by default for everybody.
So privacy-first browsers are already doing this.
But is the regulation that you said that's coming out January of 2027,
it requires it to be baked into any browser?
And then does it require it to be on or off by default?
Or it just requires the functionality?
So if you're using Chrome, you're probably going to have to turn it on when that happens.
Yeah, it's actually a law.
So it's in the statute, to get technical.
Regulations are things that are associated with laws that provide further clarity.
And the law says that browsers have to offer this capability.
GPC is an implementation.
It's probably the implementation of an opt-out preference signal.
And so browsers have to offer it to the extent that which ones have it turned on by default
and the other, that will be determined by the actual browser vendors themselves.
Got it.
Okay.
Do you want to quickly just expand on Drop first?
Why this was the next?
There's, I feel like so many different privacy issues right now in the world that I'm sure
you're more than familiar with with everything that you've done.
So why was this the first thing that you guys wanted to target?
Well, as an agency, we just can't do something as significant without the legislature and
the governor signing laws that tell us to do something like this. And so we deliver this
to Californians on January 1st because we were required to by statute. So in 2023,
Senate Bill 362, the California Delete Act passed. And as I mentioned before,
I advised State Senator Becker on this. And this is not an original idea. In fact,
Tim Cook at Apple in a op-ed in Time magazine talked about a data broker clearinghouse.
There's obviously earlier variations of this, like the FDC's do not call list.
Obviously, that has some, you know, it's not the most perfect thing.
You know, it's not an original idea.
But what happened in 2023 was that there were a lot of headlines about how, for example, hackers were using data broker data to dox individuals.
And, you know, this is in the COVID timeframe where education leaders, health care, local health care leaders were being targeted and doxed.
We had the overturn of Roe v. Wade.
And so there were significant concerns about reproductive health information being sold
or people being tracked down based on geolocation, visiting a reproductive health care clinic,
et cetera.
So there was just a lot of negative headlines about the misuse of geolocation information,
et cetera.
And so what existed in California was a registry law that passed in 2019.
The first data broker registry law was passed in Vermont in 2018.
The goal of the registry was to at least provide some transparency to who data brokers are,
because by definition, data brokers are entities that you or I don't have a direct relationship
with that collect and sell our personal information.
So the thought process is combined with the CCPA that if you had a list, you could then manually contact each and every one.
But what I recommended to Senator Becker is to let's create through legislation an accessible deletion mechanism that allows a consumer to put some basic personal information into a website, have it stored in a secure manner.
And then the registered data brokers will have to connect into that secure website, do record matching and then delete their information.
So in the end, it becomes kind of a big delete button in the sky.
So instead of spending 10, 15 minutes contacting 600 plus data brokers, that you could spend five, six, seven minutes at this one website and have it be done with.
So the beauty of this drop system that was called forth by the accessible deletion mechanism, it does enable the deletion at scale.
It also addresses another kind of a loophole or actually two loopholes that are in California's privacy law.
The first of which is the right to delete in CCPA is data collected from a consumer.
But by the very nature of data brokers, they don't collect data from consumers.
They collect data about consumers.
And so a lot of times people were doing deletion requests to data brokers and data brokers said, I don't have to delete anything because I didn't get it from you.
And that frustrated consumers.
And so this addresses that, that data brokers have to delete any personal information about the consumer submitting a drop request.
And then the second issue is data brokers, after doing a deletion, assuming that they agree to do a deletion with this loophole about collected from versus about,
that they could just simply just repopulate their databases with personal information, thus forcing a consumer to rinse and repeat and go back.
So if you have to spend 10 days to go through 600 data brokers, guess what?
Six months later, you have to repeat.
But the drop system is you do it once.
It deletes all the information irrespective of how it's collected.
And it's a perma delete in that data brokers have to maintain a suppression list and not
import any information from people that submitted requests through the drop system as well.
So it's an incredibly powerful solution that addresses loopholes.
It enables scale that is kind of unheard of in this digital economy in terms of enabling privacy rights.
Yeah, okay, there's a lot there.
So just some of the facts first, because I do have some of the facts that I have here.
So you open these requests in January 1st of this year, so people could have already started submitting earlier this year.
Brokers have to act on August 1st, which is in just a little over a week from the time we're recording.
So by the time you're listening to this, I'm assuming it's already live.
Is that accurate?
Yeah.
So January 1st, we open up the website.
It's at privacy.ca.gov.
It's on the homepage right there.
You just click.
I want to be very clear to anyone that this is, well, A, it's only available to Californians.
So hopefully it'll be California envy.
Oftentimes people trash California, but this is an example of some innovation happening in California.
And as I mentioned before, Connecticut did that.
And there's like six or seven other states that are proposing this or thinking about this.
And of course, if we're successful, I think this will further drive.
So it's free and it's paid for by the actual data brokers as part of their registration process.
I saw that. So it doesn't use taxpayer money, right?
Zero. Zero, zero, zero.
I wanted to actually say something funny that I normally,
because you mentioned California hate,
and I'm very biased because I live in California,
but when I travel abroad to other states,
they always ask, oh, so how's it going over there?
Kind of with this implication that everything's burning down
in this state, apparently.
Well, sometimes there are bad fires, but that aside,
I normally say, yeah, you know,
people always say nobody wants to live in California.
There's just too many people there.
And that's kind of what I always tell them.
Again, I'm very biased.
I do love this state, but I just like,
wanted to share that. That actually is from Yogi Berra. He said that about a restaurant,
no one goes there anymore because it's too crowded. So I agree with you about California.
I saw, you know, there's this weird stat. Again, I'm trying to understand how this works because
you mentioned it's permanent. It's a permanent suppression list. Yes. But I also saw that drop
checks things every 45 days.
So do you mind expanding on this nuance here?
Yeah, sure.
So actually, yeah.
So it opened January 1st.
And so far, we've had 375,000 people sign up,
which is pretty incredible in that deletions haven't begun.
So starting August 1st,
the data brokers have to connect into the system.
And then they have a 45-day window starting August 1st
to download the list, and I'll explain that if you want in more detail, and then process the
deletions. And then they have another 45 days to report back the statuses so Californians can see
the status of the deletions. And then after that, on a 45 rolling day basis, any net new requests
or updates from existing consumers that put their information, like they've added a new email,
they have to process. So it's a rolling process that starts on August 1st. So if anyone submitted
their request, they'll see the deletions really kicking in by mid-September. And then probably by
the end of October, their drop profile will be updated to tell you exactly who deleted your data.
And then it just starts rolling from there as well. So that's it at a high level, right? And I can
kind of get into the guts of how it works and how it's secure. But basically, the point is,
is that the site's open, it's free. And then starting August 1st on a 45 day basis,
all the 600 plus data brokers will connect in and begin deleting and then subsequently giving
you updates that you can view inside your little portal or your profile inside the drop system.
So I think this is the biggest piece here
because for the last five plus years,
I feel like when I started doing this 10 years ago,
this wasn't as much of a well-known thing,
these people searching websites.
But I feel like five to seven years ago
is when I started seeing these commercial services
that try to remove them
and they try to automate this painful process
that you discussed.
Because like you said, it's not just one time.
I feel like that's the biggest misconception.
People say, I'm going to do it manually.
I can set a weekend aside to do this.
They do it, but then the information comes back up
in two months.
So is what you're building its own brand new system?
Because you're implying this is a whole system that data brokers have to register for, sign up for.
There's a portal.
And so is this something that private companies cannot hook into, which means they're going down a completely different avenue of accomplishing this goal than what you guys are doing now?
Well, I mean, certainly this does commodify certain aspects of paid solutions in terms of what they offer, because we do facilitate deletions from 600 data brokers.
And we also do have the advantage that by law, it does require a perma deletion and kind of an on by an ongoing suppression list that the data brokers have to maintain.
The other advantage is that the enforcement that we have is very significant.
So we have a dedicated enforcement agency and the statute, i.e. the law itself, allows us to do fines of $200 per day per incident.
So just imagine, say, at the end of the year, there's close to a million Californians signed up.
And in a given data broker's database, there's, say, 200,000 records that would have matched.
But for whatever reason, the data broker decides not to delete it.
Maybe they're playing games or something like that.
And we find out about that.
The fines would then be $200 times 200,000, which is $40 million per day.
So that's a pretty big stick that Cal Privacy has.
Now, I am very supportive of third-party privacy tools.
So we basically, with DROP, we in California are raising the floor, but we're not placing
a ceiling.
I think that there is a lot of value for third-party privacy tools because sometimes their ecosystem of businesses that they do deletions are not technically data brokers and are not registered under our definition in the law, number one.
Number two, there's additional things that can be done from a privacy perspective that third-party tools can help, like, for example, helping facilitate deletions from Google search results.
There's locking down social media settings, things of that nature as well.
So what we're trying to do is we're just raising the floor, but there's still a very high ceiling for third parties that consumers should take advantage.
And that's actually in the original Prop 24.
It did talk about the concept of authorized agents, creating a healthy third party privacy ecosystem as well.
And we want to encourage that.
Now, the last question is that you had is currently today, there isn't a way for a third party software product to help facilitate deletions.
There is the ability within drop. There is the ability for someone to help like an elderly parent submit it.
But then they have to sign under perjury that they actually did it.
So we do allow the usage of authorized agent, but it's more on a one off basis today.
but there is not a programmatic way for a third party to kind of feed information into drop.
But that's something that we're going to continue to explore. We do want to plug into other ecosystems.
And so that's something that could be on the table. And we're just right now just trying to launch it and have the successful deletion.
So that could be a potential version, too. But all TBD, we're just focused on making sure the data brokers process the deletions at this stage of the game.
That's great. Yeah. And I guess just to keep it really practical, I think I can use myself here as a pretty probably reflective example of at least our audience. And then it'll tie into people who don't do this as well in a second here. But traditionally, the way I deal with this problem, I don't have the time to do this manually. I focus a lot on prevention. And I do want to ask about prevention in a second here because I still personally see these tools as a removal. It's not dealing with whatever is actually causing that data to be collected in the first place.
And I went with Consumer Reports.
They did a research paper, which was from back in 2024.
So it's over two years old now.
So it's hard to know how relevant it still is today.
But Optory and Easy Opt-Outs were the two best performers.
And Easy Opt-Outs is far cheaper.
And so I just went to use Easy Opt-Outs.
And that's pretty much what I do.
If someone is using a tool just for data removal,
they're not trying to do the Google search removal,
then it almost becomes this, it seems like a choice
between do I do California drop
or do I pay for a service like easy opt-outs?
But I don't want to single them out,
just any paid provider.
And let's say someone finds that it's effective.
How do I as a consumer decide between
do I do both of them?
Do I only have to do drop?
Is there some other benefit to using the paid service?
What's your suggestion to a person like that?
And if someone's new
and they don't have anything right now,
what would you say to them?
Well, people that are very privacy conscious,
you know, someone that may have been in a,
unfortunately, a domestic violence situation, someone that's worrying about being doxxed,
someone that has experienced identity theft or identity fraud, someone that has an elderly
parent that may have dementia or Alzheimer's that could be targeted. I certainly would recommend
for those people to have kind of a defense in depth type approach to use multiple tools at
your disposal to ensure the individuals are protected. Now, clearly, if you're a Californian,
it's free. We clearly tell you that these are the 600 plus data brokers that will check and see if
their deletions occur. As I said before, we have a very definitive definition of what a data broker
is. And what we see with some of these authorized agent solutions, and there's a lot of good ones
out there, that they may be doing deletions from companies that may have first-party relationships
or are not technically a data broker under our law. So from a Venn diagram perspective,
a lot of these kind of supplement, complement what we're doing as well. And so I would
But, you know, simply if you're a Californian, I would sign up for drop.
But if you're highly sensitive to the potential misuse of your personal information, I would encourage to check out third party tools as well.
Again, what we're trying to do is just raise the floor.
But there's so much that needs to be done from the ceilings always growing.
And you do need free to other free tools, not from the state, paid solutions.
We need to raise education, et cetera.
I never want to send the message,
just use Drop and everything will be hunky-dory, right?
You need to do multi-factor authentication,
maybe get a password manager.
The list goes on right there.
But at least we raised the floor.
Yeah, when you were mentioning those really,
I guess, more extreme situations
where people really need the utmost privacy,
I know there's also California Safe at Home program.
Is that done by a different agency?
Are you guys involved with that too?
We're not involved in that particular one.
Yeah, that's a great example of kind of a defense in depth type approach.
And then obviously when January 1st kicks in, you know, we probably won't have the same marketing campaign with the cute raccoon here in California telling people to use the drop system.
But we will heavily promote in January people turning on the switch to do the opt out preference signal to do not sell share.
So that's another aspect of a protection layer that people should be doing, which is a tool.
And then furthermore, we do have a bunch of privacy tips.
We tell people to turn third-party cookies off.
We tell people to stop tracking, to enable app tracking transparency, things of that nature.
We do have a set of recommendations.
What we're trying to do is if we can get the five or six top recommendations and have people do it in a 15-minute time period,
then that will go a massive way,
but there's still always going to be more things
that need to be done that could be done
by other free tools, third parties, et cetera.
Got it.
Okay, and now I want to get into
just a few technical pieces here
on how data is stored,
what happens when someone submits their data,
how they can trust the privacy and security here.
But before I get there, just a very quick question.
I think it's important to address
because it's something I hear a lot from people in my life,
and I know you guys might get it too, I don't know,
but there's this association that every politician in the world has never used a computer before.
And so I think people have this inherent distrust towards a government-run program from a tech perspective.
So do you mind just expanding on who runs the tech behind the scenes and some of their backgrounds
so people can understand the people who built this?
And then we can kind of dive into that, what they built.
Well, it starts at the leadership, which is myself.
So I was a longtime Silicon Valley technologist with a computer science degree.
And my last company had a multi-tenanted cloud service that supported hundreds of thousand users across the world.
And we've built a product team from some top experts that have come from industry.
The infrastructure is hosted by the California Department of Technology.
that hosts the Franchise Tax Board and other government platforms.
And so there's a very robust security.
So we're part of that ecosystem of state government services that provide even more sensitive use cases for consumers,
like the filing of their taxes.
So we're part of that infrastructure.
And again, this was proposed.
And I advised, you know, as a technologist, the state senator a few years ago on this.
So I think it's a pretty robust platform.
Knock on wood, we haven't had any unplanned downtime.
The satisfaction ratings that we get are very high.
They're in the 4.x range on a scale of 5, which is really good for a consumer facing
products.
take into account that, you know, California has a population of people speaking dozens of languages.
And, you know, we have people that are in their 80s and 90s using this system.
So to be able to maintain in such a diverse consumer population, such high ratings says that we're doing a good job.
Great. Yeah, I'm not questioning this.
It's just I think it's important to ask because I know there's an association.
Yeah, no, it's a good question.
And I think, you know, some of the one question is like, well, you know, are you going to keep my data secure?
So let's just jump right into that. Right.
You first have to verify your residency and we leverage a technology called the California Identity Gateway.
And it either uses your personal information to do quick lookups with state records to like your taxes and all that stuff to verify if you're a resident.
or it uses your login.gov federal account, which you use for Social Security, and you have to be at
level two, which is that at some point you may have had to provide your ID to login.gov. And at
that point, if you are verified that you're a resident, we simply just get back the message,
yes, this is a resident. We don't know anything about your login.gov account, etc. Then you go to
the drop form and you put your name or variations of your name, you put your data birth and you put
your zip code. Now you can stop there, right? But you can also put your email addresses and we
require multi-factor authentication. You can put phone numbers. We require multi-factor authentication.
You can also stop there. Or we ask for three bits of additional information, mobile advertising ID,
which is used by data brokers that track your geolocation, a connected TV ID, or your VIN,
because a lot of data brokers kind of sell car-related stuff. When you hit submit after
spending, again, five, six minutes putting this basic information in about you, and you can control
how much information you want, the more information you provide will facilitate more matching,
you hit the submit button. And immediately that data is stored in kind of five separate areas,
and it's hashed. And so what we do is we have identifiers associated with your name,
date of birth, and zip code. That's one. We have it with your email address, hashed. We have it with
your phone number, hashed. We have it with your mobile advertising ID or connected TV ID, hashed,
and your VIN. So those are kind of like the five separate databases. All the data is hashed.
Starting August 1st, the data brokers using the same hashing algorithm and based on the data they have and the identifiers have to hash their information.
And then every 45 days, they see if they can match their data with one of the five or multiple of the five hashed information of identifiers that we have.
if there is a match, then they know who that individual is and they're required to then delete
all the information, even if it just matches against an email address. So if they have email
address and all this other data right there, and then they have to maintain a suppression list of
all these hash values from here on out. So if they ever get any new data, they have to validate it
against that right there. So I don't even know if, Henry, if you signed up because the data
has been hashed and the data brokers can't figure out, they can't supplement their databases,
which would be against the law and illegal. And we would hammer them if they did,
because the algorithm doesn't allow you to magically unlock all the hash values. The only
time they know if someone's in the system, if they already had that user's information in the system
itself. So that's kind of at a technical level what happens. After they do the deletion processing,
they go back and 45 days after they've done the deletion, they can then update the statuses of
each and every record. And then Californians can go back into the drop system and see for the 600
plus data brokers, 75 deleted, 410 said, you know, not record, not found, etc. And there's different
kind of statuses associated with records right there. So it's a closed loop system. And the last
thing is, is that Californians, if they have a new zip code, phone number, email address, or they
figure out how to get their mate on their Android phone, they can go back and update it, their
existing profile to enhance the ability to match against these different databases that the data
brokers have. Got it. So for a non-technical person, pretty much, let's say, I'll just use my
name Henry. Henry is never actually sitting on a database somewhere. There's just a derivative of
the name Henry that's just random gibberish that nobody as a human or a computer can read directly
unless someone else also created a hash of the name Henry and then those two derivatives
essentially match. So is that like the basic TLDR? Yes, basically. But obviously it's not just Henry.
your full name concatenated with your date of birth, concatenated with your zip code. That's
one unique identifier. The easier one is your email address. That is just by itself. There's
no concatenated information. So if you're, it's, you know, henry at gmail.com and we validated
through multi-factor authentication that you control that, right? Then that becomes a bunch
of random numbers and letters and all that stuff.
And only if you actually have that in your database
and you do a hashing of that and it matches,
then you'll know like, oh, well, Henry used this system.
And so any records associated with henry at gmail.com
has to be deleted by the data broker.
Wow, nice system.
I mean, I feel like it's one of those underrated things
that you guys probably geek out about behind the scenes
that most people won't know, but it's well thought out.
I mean, look, I understand there's a healthy skepticism like, oh, well, if I give my information,
the data brokers are just going to get it and they're going to sell it.
Well, no, it's actually based on the technical implementation.
Unfortunately, I just don't have an easy elevator pitch to say besides saying no,
there's a bunch of hashing and secure technology that ensures that.
With folks like yourself, I do get into details.
The other kind of objection is like, well, this only applies to California data brokers.
Actually, no, it applies to data brokers that have Californians data, irrespective of where they are in the world.
So we have people that have registered in our registry that are overseas and other states, et cetera.
Yeah. So those are some of the two top kind of like concerns that people have at the initial reaction.
But most people are like, you know what, I'm in so much pain.
I'm just going to go ahead and sign up for it anyways, even without hearing that we actually address some of the concerns.
Yeah. And let's say somebody doesn't like it anymore. They say, I don't trust this anymore.
I assume they can delete their account when they're.
Yeah. Or they can also specify like, actually, I love these data brokers. I'm going to uncheck
the data brokers. So as opposed to doing all data brokers, you can select which data brokers
you do or don't want to have process your information.
Great. Is there anything else technical that you wanted to clear up before I kind of
start zooming back out again that you see that are any common misconceptions?
No, no. I think that, you know, people also ask about the timing and there's actually a piece of proposed legislation that would move the 45 window to 30 days as well. So sometimes say, well, why is it every 45 days? Or other people in January said, well, why is it August 1st? Why isn't it real time? And, you know, that's what the law called for.
It kind of makes sense to give time for the data brokers to figure out how to connect into the system, what to do and all that stuff.
But some data brokers will wait to the very last day to connect in and begin the 45-day clock.
But if you have submitted before August 1st, you'll definitely see the impact by less data floating out there by mid-September.
And all the statuses will come back by the end of October inside the drop system.
Got it.
I guess this is a consumer complaint, right?
I go on these sites, one of them claims they remove your data
from 6 million data brokers, I'm exaggerating.
And then one says 200, one says 500, one says 800.
There's these various numbers, but when I look at the sites that they claim,
a lot of them look like the same site,
just with a slightly different domain.
And so you guys have your own number as well.
Do you have any kind of insight into how this works?
What is maybe a little bit more accurate, what's less accurate,
and why there's this discrepancy?
I can't talk about third-party products, but we do have the data broker registry.
It's actually, we're going to move it over to privacy.ca.gov.
It's on the cppa.ca.gov website.
And it's going to be updated in early August.
Right now, it shows 581 registered data brokers.
That number is going to go up because we've gotten some additional registrations as people
look to meet the August 1st deadline.
But once you go to the data broker registry, you can see who's registered.
And there's a couple of things.
So when I say we have over 600 data brokers, that means there's 600 distinct businesses that have that.
But we also ask, like, well, what websites do you operate?
And you can be able to see that some of these businesses operate five, 10 different types of websites, right?
And so if you were to actually look at the websites that would be covered by the drop system, it's well over 700, you know, maybe close to 800 as well.
I just don't know what the numbers are off the top of my head.
But there's a lot of data brokers operate multiple ones as well.
So you could argue that we address in excess of 700 different websites that may have your
information, but in the end, it maps to 600 sites as well.
And we've been very active with our enforcement of going after businesses that need to register.
And in fact, over the last year or so, we've had 12 enforcement actions against data brokers
and fine them tens of thousands of dollars.
So this is a constant thing that we're focusing on
is making sure that all the data brokers
that are in the system are in the system
or should be in the system are in the system.
What have the data brokers said about this?
Do you have any notable examples of an interaction?
I assume most of them are against this kind of stuff,
but what's been the overall reaction from that?
Well, clearly in 2023, they weren't happy with this
And they spent a lot of money lobbying here in Sacramento, hundreds of thousands of dollars.
The data brokers had one of those trucks that just drove around the Capitol with puppies on it for some reason.
I don't know what the significance of puppies and data brokers are, but they had some puppies and dogs on it.
But, you know, they had their shot, right?
They were unable to convince the legislature and the governor that this bill should not go forward.
And to the data broker's credit, now that they've saw kind of the, you know, what was passed, that we've had very good interactions with data brokers.
And I think they now realize that from a society perspective, that society wants this particular industry to be more, instead of being the Wild West, to be a little bit more regulated and giving consumers more control.
and since you know the delete act passed we've seen other states come up with registries
and we saw connecticut adding this and i think you know again people are all eyes are in california
in this one little area and if we're successful and so far we have been it's going to get to the
point where politicians and other states that their constituents are going to say why does my
aunt in california or why does henry and you know have this on the podcast i listen to but i don't
have it. So that will apply pressure if we're successful in this. And I kind of jokingly say
that people will have California envy because we have tools like this and people in other states
don't. Yeah, I hope to see this expand. But this is perhaps a silly question, but it's important
to ask, I think, because it's an overly simplistic way of looking at things. But why is this
retroactive at all? Like, why can't California just go and ban the data brokers? Like, you guys
just can't exist, go away. So why, why is that still allowed to exist? Like, what is the valid
kind of role that they're playing, perhaps from a legal side of things?
Obviously, we're in a democracy and businesses and people have constitutional rights. And the
people here in California, as well as the legislature have the power, people via the
ballot propositions and people in the legislatures have, you know, the power to do that. And so,
You know, I think what's happening is there has been a realization that this kind of unchecked collection and selling of our information, while it has generated billion dollar plus businesses, it's facilitated e-commerce, it provides more targeted advertising.
So in theory, businesses could be more effective in selling their goods to people that are interested, that there's been a double-edged sword that some of this data has become increasingly weaponized.
And we see that with surveillance pricing.
We see that with geolocation being sold to the federal government, like DHS, ICE, etc.
We've seen instances in which a gay priest's geolocation was tracked down from that person being in gay bars and he got fired from that.
We've seen instances in which data from Muslim prayer apps and the users a number of years ago was sold even to the government.
We've seen instances in which Minneapolis politicians have been killed because their killers were able to look very easily look up their home addresses.
So that's the downside. Right. And so what's happening is the legislature is looking at this.
And the kind of the one major step was the Delete Act. And now this year in California, there's additional legislation.
For example, there is a bill to ban the sale of geolocation, which there's over 100 data brokers.
If you go to the registry, you'll be able to sort by geolocation.
I think there's 110 different data brokers that sell geolocation.
That would kind of put them out of business right there.
There's another proposed law that would ban the sale of all sensitive personal information.
So there is movement happening.
I think it just kind of takes, you know, specific harms to occur before the visibility is raised.
There was enough harm happening to pass the LEAD Act.
Now, I think because of the sale of geolocation to the federal government that states, other states have actually leapfrogged California and have enacted laws to ban the sale of geolocation information.
And now we're looking at sensitive.
So it's happening.
Sometimes it takes a little bit longer.
And unfortunately, people may have to suffer some harms.
But I do see kind of the evolution of privacy laws occurring kind of in real time, not only in California, but across the U.S.
Great. That's a perfect segue.
You know, I think I want to say, yes, near verbatim here.
How does someone in another state actually advocate for their own version of drop?
So just a regular person, they have that envy, perhaps, for this thing.
How can they help in this journey of getting it and wherever they live around the state or even in other countries, I suppose, too?
What I would do is contact your local state house or assembly person.
Oftentimes they have town halls and or your whoever your state senator is and just go to a town hall and just say, hey, I'm sick of getting like here's the big thing.
People are so sick of getting text scams.
I don't know if you get them as well about like, I forgot to pay a bridge toll, right?
That's a very common one as well.
And there's been other instances in which people's elderly parents have been defrauded because you can literally buy from data brokers lists of people with Alzheimer's.
Now, obviously, oftentimes purchases are for very good reason to advertise medicine or do studies.
But there's also bad people that will buy lists of Californians or people from Kansas with Alzheimer's to do negative things as well.
So, you know, if you're a citizen in another state, just bring up these real world harms and say, hey, there is something that is very popular in California.
And by the way, part of our statute requires Cal Privacy to work with other jurisdictions, because if other jurisdictions are doing privacy-centric things, it further cements the privacy rights we have in California.
So we're actively talking with people in other states and collaborating.
In fact, we even have foreign nations contacting us about the data broker industry as well.
So we're in a very much collaborative share, best practices.
There's a willingness that we have to potentially even share technology with other states and other jurisdictions as well, because that would benefit all of us.
You know, all votes would rise. So, yeah, start like what I did, which is like, you know, have a conversation with your local state center and say, I got a good idea.
What do you think about it? And to be candid, I actually find a lot of politicians to be very receptive of ideas and want to show that they care about their constituents.
ones. Yeah. Are you able to share the four countries or is that confidential? It's factual
that there's seven other states that have been or are considering delete act style laws, one of which
is Connecticut that did pass it. Vermont passed a law that they're going to do a study of a delete
act style system. But there have been proposals in Nebraska, Illinois, and a couple other states,
New Jersey as well.
They just come out with a law with the registry and they're also and New York is also considering
it.
And then, yes, there have been other foreign countries that have expressed interest in
this.
It is public knowledge as it relates to states and proposed legislation.
Got it.
When do you think this will ever go federal?
Just privacy regulation, not necessarily drop, but you said 23 states have this and it's
still not federal.
So what's been the hold up there?
There's been two big issues. Issue number one is a private right of action. And most states don't
have a private right of action. And enforcement is done by attorney general. In the case of
California, enforcement is done by attorney general and Cal Privacy. But there are a lot of people that
want the ability for consumers to sue if their privacy has been violated. And so that's been a
hang-up. The second big hang-up, but probably the biggest hang-up, is preemption. Because what is
happening is that oftentimes federal proposals have a very low ceiling. And so, yes, privacy would be
in all 50 states, but existing states like California would actually lose privacy rights
because these federal proposals don't include this. Best example is that there is a federal
proposal called the Secure Data Act that Republicans have submitted, and it doesn't
have anything equivalent to the DELETE Act, and it doesn't require an opt-out preference signal or
global privacy control, which means that given that 12 states support and require the GPC,
100 million residents would lose the ability to do the opt-out preference signal, and 40 million
Californians plus I don't know how many people are in Connecticut, 43 million people would lose this
drop. And so that's unacceptable for states like California to not be able to go over federal
standards, which is very common with other federal laws like HIPAA and Gramm-Leach-Bliley, that we have
the opportunity and ability to build upon these. And so we always prefer a federal piece of
legislation to be a high floor. But unfortunately, what we've seen is when a privacy bill is submitted,
It's a very low ceiling and it removes rights that people have and that caused problems with certain politicians as well.
And so that's kind of the bottleneck that that's occurred at the federal level.
So in the meantime, states have just moved forward.
Got it. Makes a lot of sense. And thanks for cleaning it up.
But that's the context that is it's hard to just find without having someone to ask.
Kind of the last thing I want to ask you, and this is how I'm overall going to close this interview.
It starts with a bit of a story here.
I started to create a Venmo account
because I had to share some money with friends.
And I used to have a Venmo account.
I stopped using it, so I deleted it.
And then I spun up this new one.
And it's not uncommon because I use privacy tools sometimes
and I have an email alias that I use for different things.
So it's not uncommon for sometimes them to be like,
hey, we need to verify your information a little bit more.
And I expected it to be KYC, upload my ID and all that.
I was fine going into it with that.
So I did everything they asked.
I uploaded my ID, I gave them all my information,
and then they froze my account.
And then this kind of data,
it was pretty much held hostage, this account,
because they froze the account,
which means I couldn't do anything with the account.
But then when I asked them to delete the account,
they said they won't delete an account that's frozen.
So then I was like, what do I do here as a consumer?
So I started doing research,
so I did reach out to privacy at Venmo.com,
which is, and I started like a CPA request
to try to maybe, you know, go down a different avenue.
But then they also rejected it.
They said, well, we have to keep the account frozen.
We can't delete any data on the frozen account.
And so where I'm going here with this is,
A, I think it's pretty crappy what they did.
I think it really sucks because now I don't have the service
and also my data is being held hostage.
But how can people utilize their rights?
You know, there's all these tools right now
to come out around the world between states, countries, and I want this to be pretty global
advice if you're able to. How can people locate what tools they have and actually utilize those
tools? And when those tools aren't working, what's kind of next? Like, what do I have
as my next point of action in this kind of personal saga for me?
Yeah. Last year, a social media account deletion bill was passed. And I don't know when it becomes
effective, but that kind of hit upon that issue, not with Venmo per se, but more like, you know,
the social accounts that they were kind of in that same trap that they could just couldn't get rid
of it, et cetera. And so you may want to look at that and you may even want to say, hey, this
actually should, you can talk to your local assembly or state senator and say, love this, but
tell them this story and maybe the bill can be enhanced to include these type of apps as well.
So trust me, there is the power of advocacy that if you go to a town hall or pick up the phone and
call, people will listen to you. And I've seen so many examples of that. The second thing is,
is that if your privacy rights have been violated, you can actually, if you're a Californian,
You can file a complaint with us.
Since inception, we've gotten 14,000 complaints.
We, on average, get 150 plus complaints per week.
We have a team that goes through that.
We've actually have had enforcement actions against companies that were triggered by privacy
complaints.
So there are government agencies, at least in California, we're the privacy agency.
DFPI is for financial issues.
There's the attorney general. They have complaint forms. And I can't speak for the other ones,
but I know for a fact that we've actually done enforcement actions based on consumer complaints.
And then finally, on privacy.ca.gov, even if you're not in California, if you go to the tips
area, those are tips that anyone can take advantage of where we document the things
that you can do to better protect your privacy. A lot of them are things that you probably have
talked about on your podcast, you know, password managers, multi-factor authentication, turn off
location tracking, reset your mobile advertising ID or delete it, you know, things of that nature
as well. We document those things, turn off third-party cookies, all that stuff is documented.
That's great. Is there anything that you feel like we didn't cover today that you wanted to
share? No, this has been a great conversation. I greatly appreciate all the questions and the
interest you have. Hopefully this was a value or checked off some questions that you may have had.
Huge. I mean, so, you know, I've been using a private service and even when I try to give
like recommendations for people, when they ask me what I'm doing or they want to get advice,
I'm always saying, well, I don't know yet about Drop. You know, it hasn't actually started yet.
And I'm still a bit unclear in some of the details. And so I think actually later today,
I'm going to go ahead and I haven't done it yet. So I'm going to do it. I'm going to do the Drop.
I know, right?
I'm one of the later people.
But I'm also more skeptical of these kind of things
because I know what it means
to have to upload your identification.
And so having this conversation
really cleared a lot of things up for me.
So I'm going to go ahead and give that a shot.
And I'm sure I'll do a video reporting
how it all goes once I get through it.
That'd be great.
Let me know.
And yeah, you only have to do your photo ID
if you use the login.gov
to verify that you're resident right there.
And that's not our requirement.
That's just login.gov.
And we made that as one of the options that there's a lot of people, especially older people, have social security accounts.
So it just made it easy for them to get in.
Most people use the first option for residency verification, which is put some basic personal information.
And then it's like, OK, yeah, you pay taxes here.
You look to be a real human.
You've got a real phone number.
Boom, you're a resident.
And then you can go straight in and put the basic information into the drop platform.
That's perfect.
Yeah, well, thank you, Tom.
This has been invaluable to myself and I know many other people listening.
And I will keep up with everything that you guys are doing.
This is awesome.
Yeah, well, thanks a lot.
And that, everybody, is the interview with Tom from the CPPA regarding most particularly
Drop.
It's something that I've avoided for months now because I didn't know whether or not to
trust it.
But after having this interview, I felt a lot more confident proceeding with Drop and combining
it with easy opt-outs, at least for now, is going to be my strategy leaving this interview.
I think no matter what, if you have friends or family members and you are based out of California, this is a great tool to recommend to them, especially if they're using nothing right now.
I think this is probably one of the best entry points that we've seen.
And if you're outside of California and you want something similar to this, it's worth pointing to the California stuff that they're doing and saying, hey, we want this too.
And maybe other people will start communicating that as well and we can start to see this spread.
If you enjoyed this interview, you can support Techlore Talks down in the description by becoming a TechLorean.
or just join our newsletter.
If you want to keep up with the latest news,
I'll keep you all updated on if there's anything going on to drop,
any data breaches, and anything to help keep control of your digital life
so that you know what's going on without needing to follow all the news yourself.
Thank you all for listening.
Thank you all for learning.
And I'll see you next time on Techlore Talks.