Privacy Digest 17/26
California Fines Data Broker for First Time Under Privacy Law
California’s privacy regulator fined data broker LocateSmarter $116,490 after finding that it made opting out of personal data sales unnecessarily difficult. The company required people to provide the last four digits of their Social Security numbers before processing requests, despite already collecting information including names, driver’s license details, employment records, bankruptcies, and litigation history. Regulators said demanding additional sensitive information violated data minimization requirements and discouraged people from exercising their rights. The enforcement action, the first covering violations of both California’s privacy and data broker laws, signals growing scrutiny of how easily consumers can actually opt out.
news.bloomberglaw.com
DROP Is Coming Due: What California’s Delete Act Means for Data Brokers in August
California’s data brokers must now regularly process deletion requests submitted through the state’s Delete Request and Opt-Out Platform, known as DROP. The system lets residents send one request to hundreds of registered brokers instead of contacting each individually. From August 1, brokers must check the platform at least every 45 days, process requests, report their status, and ensure deleted information does not reappear. Requests that cannot be verified must generally be treated as opt-outs from data sales or sharing. Noncompliance can trigger penalties of $200 per request for each day of violation, potentially making failures costly at scale.
alstonprivacy.com
Aw, It’s Baby’s First A.I. Surveillance System
Baby-monitoring companies are expanding beyond sleep tracking toward continuous health and development monitoring. Nanit plans to use artificial intelligence to analyze children’s speech, motor skills, coughs, and other behaviors, potentially extending monitoring into early adolescence. The growing babytech industry promises parents greater insight and reassurance, but it also creates detailed records of children who cannot meaningfully consent to their collection. While Nanit says its data is secure and never sold or used for marketing, its ambitions highlight a larger privacy question: what happens when intimate childhood data is collected for years before anyone knows how it might eventually be used?
nytimes.com
Adversarial Patterns Can Prevent Surveillance Cameras From Detecting You
A computer-generated pattern designed to confuse surveillance algorithms has successfully passed its first public real-world test. Developed through 31 million tests, noRecognition patterns can prevent some camera systems from automatically identifying people, vehicles, faces, or license plates. The cameras still capture footage, but their detection software may fail to recognize what the pattern covers, potentially allowing people to avoid automated tracking. The technology has been tested against 11 open-source detection algorithms associated with widely deployed surveillance systems. Its creator frames the project as a way for individuals to opt out of algorithmic surveillance in public spaces.
techcrunch.com
Those Anti-AI, Dumb Sunglasses Were a Smart Move: They Sold Out
DuckDuckGo’s satirical “anti-surveillance” sunglasses sold out after launching in late July, with another batch now planned. Created with eyewear brand Knockaround, the $35 glasses deliberately feature no cameras, microphones, artificial intelligence, or connectivity, positioning ordinary eyewear as an alternative to increasingly popular smart glasses. The campaign argues that camera-equipped wearables can capture people without their knowledge or consent, turning bystanders into potential subjects of surveillance. Strong demand and millions of views for the launch suggest that concerns about always-on wearable technology and its impact on people nearby are resonating with consumers.
cnet.com
Join our 450,000 + subscribers
Feel more secure and empowered online with every new edition of Ghostery’s Privacy Digest.