101 pointsby MilnerRoute5 hours ago12 comments
  • petilon4 hours ago
    I hope other states adopt this. One of the biggest mistakes I have made is giving my real phone number to Dun & Bradstreet. Now the spam calls and messages (from people they sold my info to) won't stop. I don't want to change my phone number.
    • ThePinion40 minutes ago
      I noticed this too. It's a number I've had for years and have barely given out to anyone. Registered for a DUNS number last month and have been getting all sorts of spam calls from all different area codes. I assumed it was due to the DUNS form.

      I noticed D&B have recently had FTC violations/settlements but not sure they touch this specific situation, but I'm honestly curious if there's anything we can do about this.

      https://www.ftc.gov/news-events/news/press-releases/2025/09/...

    • Grombobulous25 minutes ago
      I don’t know if this is worth the cost to you but I’ve found that the cheapest $5 Tello plan as a second line is great for business use like this.
    • cyanregiment3 hours ago
      Out of curiosity, did you do this as part of Android's awful app submission process
      • ThePinion37 minutes ago
        I recently did and have been getting crazy spam calls that I never had before. I've already replied to GP about this but didn't mention I registered the DUNS number due to it being a requirement to release and Android app.
      • xeromal37 minutes ago
        I think Apple requires it too or did when I made an app for my mom a few years ago
    • cute_boi3 hours ago
      My number used to belong to an elderly woman, so I keep getting spam texts intended for her. I block the numbers, but they somehow keep sending me spam messages from different ones.

      I don't think there is any solution other than changing my phone number at this point. The issue is fucking sites keep using phone number as 2fa.

      • _dark_matter_32 minutes ago
        Keep the old number and get a new one. You'll have to gradually switch all 2fa if you want to lose the old number, otherwise keep it forever on a separate device.
    • hackernud3s3 hours ago
      [dead]
  • ChrisArchitect10 minutes ago
    Some previous Delete / Drop Act discussion:

    The Delete Act

    https://news.ycombinator.com/item?id=46449694

    California residents can now request all data brokers delete personal info

    https://news.ycombinator.com/item?id=46495220

  • MrZander4 hours ago
    Out of curiosity, does anyone know how this is enforceable for a company not based in California? Can CA fine a data broker that is based in another state but that is selling CA residents' information?
    • Xorakios3 hours ago
      Yes; the nexus for legal purposes is generally the location of the user, not the broker
    • connicpu3 hours ago
      The company would have to not have any interstate presence at all. If you are a business based in the united states that has customers in California, you are easily reachable under California law.
      • metalcrow2 hours ago
        Curious, how so?
        • teraflop2 hours ago
          Look up "long arm statutes". State courts can have jurisdiction over out-of-state entities, subject to limitations established by federal precedent. Doing business with customers who reside in a state generally puts you under that state's jurisdiction, at least for purposes related to that business.
          • whatan hour ago
            Define “doing business”. If no money is exchanged, how are you “doing business” with them?
            • edmundsauto8 minutes ago
              I’m not sure the definition matters here. Either you are doing business and this regulation makes certain things now illegal; or you are not doing business and it’s unsolicited and spam.
            • braiamp39 minutes ago
              Doing business is doing business, money isn't necessary to "do business". If you hold any interest and that person has any relationship with you in a way that can be inferred that a contract is implied, then that's business. That's why travel to get an "agreement" is considered a business expense, even if the agreement never materialize.
              • what13 minutes ago
                > doing business is doing business

                That’s not much of a definition.

    • hackernud3s3 hours ago
      [dead]
  • igor474 hours ago
    I've been thinking of making a service which automatically sends deletion requests for all my service companies every month. Like, I currently keep a bunch of spyware features in my car turned of, but I have to keep location turned on to use the built in navigation which keeps track of range for me. Would be nice to have a ceiling on that data's retention.

    Long term, if compliance with data deletion requests becomes a pain, maybe companies will finally give us an opt out of surveillance capitalism? Or maybe they'll just lock me out of my own car (I guess it's their car since I don't have root on it, lol)

  • bdcravens3 hours ago
    I wonder if there will be any funny data issues that happen because companies keep track of such requests in a table named "drop"
    • m46333 minutes ago
      mom should look up little bobby tables
  • hackernud3s4 hours ago
    What about unregistered data-brokers? I would he happy to sign up to webhooks for when someone wants to delete data.

    Problem is though, you'd be revealing more data about them than I probably have by sending it.

  • tjwebbnorfolk2 hours ago
    > Companies that fail to comply can face fines of $200 per day for each affected Californian.

    Does this cover things like credit reports/scores? If someone submits a request to this DROP thing, is it possible data gets deleted that they don't intend?

  • echelon4 hours ago
    Does this mean people can delete comments from HN?
    • aw16211074 hours ago
      Only if HN counts as a "data broker" under the corresponding law [0]. It states:

      > “Data broker” means a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship. “Data broker” does not include any of the following:

      > An entity to the extent that it is covered by the federal Fair Credit Reporting Act (15 U.S.C. Sec. 1681 et seq.).

      > An entity to the extent that it is covered by the Gramm-Leach-Bliley Act (Public Law 106-102) and implementing regulations.

      > An entity to the extent that it is covered by the Insurance Information and Privacy Protection Act (Article 6.6 (commencing with Section 791) of Chapter 1 of Part 2 of Division 1 of the Insurance Code).

      > An entity, or a business associate of a covered entity, to the extent their processing of personal information is exempt under Section 1798.146. For purposes of this paragraph, “business associate” and “covered entity” have the same meanings as defined in Section 1798.146 [1].

      I don't think HN counts as a "data broker" under this definition since they state that they "do not collect any Personal Information unless you choose to provide your email address and/or information in the "about" field" for HN accounts and "do not sell or share your Personal Information (as those terms are defined under the CCPA)."

      [0]: https://cppa.ca.gov/regulations/pdf/data_broker_reg_delete_a...

      [1]: https://leginfo.legislature.ca.gov/faces/codes_displaySectio....

    • testing223213 hours ago
      When I asked them to for safety reasons after I got death threats online, HN told me to stick it.
      • adzm3 hours ago
        Conversely, they did help me out.
        • downrightmike2 hours ago
          really just whatever dang feels like that day
  • unstatusthequo4 hours ago
    The Advertising ID field/ Nice of them to think of this, but it doesn't seem that I could actually get this from any of my Samsung TVs, Apple devices, apps?, etc? So while that field is nice and all, without transparency on getting the ad ID, those fields kind of do nothing.
    • dwattttt2 hours ago
      Google TV surfaces this under settings (along with the ability to regenerate it, or remove it)

      EDIT: Android also surfaces this information more generally, I just found it under More Privacy Settings -> Ads

  • faucetl21 minutes ago
    [flagged]
  • garpoonan hour ago
    [dead]
  • amazingamazing4 hours ago
    Why is there a time limit on deletion on this site?
    • millerm3 hours ago
      Because someone commenting leads to others spending time and effort responding. Deleting the comment breaks the chain. Don't comment if you feel that it's something you might want to delete. Think of commenting as like sending an email, but you get a short window to delete in this place.
      • amazingamazing3 hours ago
        Do you believe the same about search results not being able to be deleted? I also assume this means you disagree with gdpr?
        • EA-31673 hours ago
          Do you not see the difference between a person volunteering to broadcast a post, vs a bird party scraping the web to index it for searching?
          • amazingamazing2 hours ago
            You believe volunteered information must stay on internet forever?
            • EA-31672 hours ago
              If you knew those were the conditions when you joined? Yes.
              • amazingamazingan hour ago
                Ok. Luckily people who make the rules don’t have such ideas.
    • aw16211073 hours ago
      This comment [0] from dang might be relevant:

      > In case it's of interest, here's the standard language from emails I send people:

      > We try not to delete posts that got replies, because doing so would be unfair to the other commenters in the thread. What I've done so far is reassign it to a random user ID, so it's as if you'd used a throwaway account to post it and there's no link to your main account. Does that work?

      [0]: https://news.ycombinator.com/item?id=40734348

      • testing223213 hours ago
        And it’s utterly useless, because your username and all comments get THE SAME random user ID. So once someone identifies that ID as you, it does nothing.

        When I asked dang to do better after me and my family got death threats online, dang told me “tough luck”

        To this day thousands of my comments from my old username are on this site and trivially east to link to my real name. (Links to my website, etc)

        • altairprime3 hours ago
          My first BBS handle was my full real name, and I barely managed to purge myself from DejaNews before Google bought it, so I empathize. The modern internet has been a severe learning experience and, given how many replicas of HN exist, the cat is well out of the bag. Teach others to be more careful, as I do.
          • testing223212 hours ago
            100%

            In 2012 when I started commenting here I had no idea it would lead to death threats and I’d have a two year old daughter.

            • vlovich123an hour ago
              What kind of topics/comments did you make that got you death threats? Really want to make sure I stay away from such topics.