CA Privacy Agency Goes DOGE on Data Regulations for AI and Algorithms

Published on

After enormous pushback from large companies, the governor and from within, California’s top privacy agency today approved a package of gutted regulations surrounding personal information and automated decisions deployed by businesses.

Perhaps most significantly, the definition of what constitutes an automated decision has been narrowed to systems that “substantially facilitate” a decision. Our worry is that companies who have their decisions systematically driven by an algorithm will now argue that it’s still a human who is in control, even though that might really just mean a person signing off on hundreds of automated decisions a day.  

The regulations unanimously approved by the five-member California Privacy Protection Agency still give Californians more protections than most states. Californians are on track to have protections over their personal information and how algorithms use data for the approval or denial of financial lending, employment, housing, education, and healthcare matters.

But the regulations have been significantly narrowed to simplify rules and reduce business costs, explained the agency. Under initial draft regulations, consumers possessed broader protections from automated decisions, including any decision that involved a person’s geolocation or biometric data, for example.

But the privacy agency over the course of a year started to get cold feet. Fears began to grow, starting with board member Alastair Mactaggart, who said the board was going statutorily too far and drafting regulations too burdensome on businesses. Unrelenting industry opposition and a letter from the governor and concerned legislators followed, causing the board to slash pro-consumer protections. Among the opposition to the regs was the California Chamber of Commerce and the trade group TechNet, which count Google and Amazon as members.

As a result, the privacy agency has drifted from its pro-consumer origins to cave to the demands of large companies. It didn’t have to be this way.

Opt out, transparency and appeal rights for automated decisions now only pertain to what the board defines as “significant decisions,” the aforementioned areas of financial lending, employment, housing, education, and healthcare.

For example, if a school uses an algorithm to decide who to award a scholarship, then the prospective student deserves to know that, and what factors the algorithm considers, like GPA, financial need, or zip code. And the school should give the option to allow for a human to make that decision, not the algorithm.

But what the board considered “significant decisions” was also narrowed, as it deleted insurance, criminal justice and essential goods from the scope of the law.

For example, an algorithm that considers location, order history, income, and device usage patterns could pick and choose which customers get groceries delivered the fastest. This could especially impact people during natural disasters, peak times, and various states of emergency. The current draft regs would do nothing to stop this.

Sensitive personal information such as race, immigration status, financial status or location don’t trigger any opt-out rights, unless they fall into the category of significant decisions. Instead, they fall into the purview of risk assessments that companies will have to perform. However, risk assessments will not be publicly disclosed and only disclosed to state regulators if they ask for them.

In addition, the agency loosened consumer data protections surrounding behavioral targeted advertising, and artificial intelligence has been scrubbed from the regs altogether. Previously, workers possessed opt-out rights if they were profiled by AI.

“This is in better shape than they were,” said Mactaggart, the co-sponsor of the law that was supposed to deliver Californians strong data privacy protections.  

Board Chair Jennifer Urban, who has been at the CPPA from the beginning, said the board “cut to the bone” regarding the law.

She expressed concern about policy choices regarding cyber security audits, sighting global costs accounting for cybercrime at nearly $10 trillion.

“Cyber security in the U.S. is provided by private businesses,” said Urban, who teaches the subject. “You’re on your own completely.”

Drew Liebert, a more recent addition to the board, echoed Urban’s comments and said, “we are absolutely in a data risk emergency.”

It was an odd disconnect. Privacy board members offered dire warnings about the state of our data, but didn’t go far enough in protecting people. 

The regulations aren’t final quite yet. There remains a 15-day comment period that closes on June 2, and regs aren’t expected to be officially done until later in the year. 

Justin Kloczko
Justin Kloczko
Justin Kloczko follows tech and privacy for Consumer Watchdog. He’s a recovering daily newspaper reporter whose work has also appeared in Vice, Daily Beast and KCRW.
Latest Privacy Videos
Video thumbnail
KCAL-LA - Los Angeles, CA: Personal Data Used To Target Shoppers
06:36
Video thumbnail
KCBA (FOX) - Monterey, CA: CA Bill Aims To Put An End To Surveillance Price Gouging
00:55
Video thumbnail
KLAS-LV (CBS) - Las Vegas, NV: Surveillance Pricing
00:46
Video thumbnail
KIRO-SEA (CBS) - Seattle, WA: CA Lawmakers Consider Bill On Price Gouging
00:51
Video thumbnail
AB 446 Press Conference
13:52
Video thumbnail
Consumer Alert: Surveillance Pricing
02:07
Video thumbnail
KTTV-LA (FOX) - Los Angeles, CA: Prices Are being Adjusted Based On Your Shopping Habits
03:42
Video thumbnail
KTVU-SF (FOX) - San Francisco, CA: Surveillance Price Gouging
05:49
Video thumbnail
KCAL-LA - Los Angeles, CA: Surveilance Price Gouging
03:17
Video thumbnail
KBCW 44 Cable 12 - San Francisco, CA: Meta Holiday Hack
03:25
Video thumbnail
KTVU-SF (FOX) - San Francisco, CA: Several Tech Bills Head To Governor's Desk
06:12
Video thumbnail
Al Jazeera: Google antitrust law trial US court says google is a monopolist, violated law
02:16
Video thumbnail
Consumer Alert — National Data Breach
01:24
Video thumbnail
KTVU-SF (FOX) - San Francisco, CA: Calm App, Doordash Software Sued For Data Sharing
05:40
Video thumbnail
Consumer Alert: No Opt Out
00:49
Video thumbnail
KCAL-LA - Los Angeles, CA: Investigation Into California's Newborn DNA Database
03:39
Video thumbnail
Consumer Alert: Data Parasites
02:07
Video thumbnail
KCBS - Los Angeles, CA: California Biobank Stores Every Baby's DNA; Parents Had No Idea
04:26
Video thumbnail
Consumer Alert: Wall Street using AI
01:48
Video thumbnail
KCBA (FOX) CA: Clearview AI Is Creating An AI Facial Recognition Software That Violates Privacy Laws
00:35
Video thumbnail
KGO CA: Consumer Watchdog Calls Attorney General to Investigate Clearview AI For Violating State Law
03:06
Video thumbnail
KNTV-SF (NBC) - San Francisco, CA: Tesla Recalls Millions of Cars
02:29
Video thumbnail
Consumer Alert: Clearview AI
01:19
Video thumbnail
Californians Now Have More Power Over Their Data
01:07
Video thumbnail
KPIX CBS TV-5 San Francisco, CA: Your Car's Computer Could Be Tracking And Reporting Your Every Move
00:48
Video thumbnail
California Votes YES on Privacy- Prop 24
13:14
Video thumbnail
Rage For Justice Report Podcast- Prop 24 For Your Privacy
19:18
Video thumbnail
Consumer Watchdog Hacks Tesla
02:00
Video thumbnail
FOX KSWB: New Internet-Connected Cars Could Get Hacked
01:05
Video thumbnail
ABC: Kill Switch Report Highlights Widespread Hacking Vulnerability of Connected Cars
02:12
Video thumbnail
KTTV FOX: Consumer Watchdog Report Warns That Hackers Can Take Over Your Car
05:02
Video thumbnail
SPECNEWS1: Watchdog Warns Cars With Internet Connection Vulnerable to Hacking
00:37
Video thumbnail
KBCW: Connected Cars Pose Risk to Driver Safety Due to Hacking Vulnerability
02:31
Video thumbnail
ABC KGO: Whistleblower Engineers Warn Connected Cars Need A Kill Switch to Stop Hacking
02:10
Video thumbnail
KCAL: Alarming Watchdog Report Shows Connected Cars Are Vulnerable to Hacking
02:51
Video thumbnail
ABC KGTV: Report Says Internet-Linked Cars Are Vulnerable To Hackers
00:30
Video thumbnail
KTTV Fox 11: Consumer Watchdog Report Shows How Vulnerable Connected Cars Are To Dangerous Hacking
01:05
Video thumbnail
NBC: Watchdog Report Show Connected Cars Lack of Cybersecurity Put Drivers at Risk
03:38
Video thumbnail
CBS KGPE: Connected Cars Pose A Cybersecurity Risk
03:05
Video thumbnail
Fox WDAF: High-Tech Cars Put Drivers At Risk Of Hacking Interference
00:47
Video thumbnail
ABC WXYZ: Connected Cars Can Be Hacked Says Kill Switch Report
01:36
Video thumbnail
KTTV GDLA: US Senators Write NHTSA About Connected Car Concerns
01:17
Video thumbnail
FOX KPTV: Kill Switch Report Details Cybersecurity Issues With Internet Connected Cars
02:28
Video thumbnail
CBS LA: Kill Switch Study Finds Connected Cars Are Vulnerable to Hacking
01:41
Video thumbnail
FOX KTTV: Consumer Watchdog on Privacy Issues, Hacking Risks With Internet-Connected Toys
03:00
Video thumbnail
CBS Evening News With Norah O'Donnell: Jamie Court Explains the Value of CA's Consumer Privacy Act
02:04
Video thumbnail
WAFF TV-48 Alabama: Watchdog Report Highlights Car-Hacking Risks
03:16
Video thumbnail
ABC KFSN: Internet-Connected Vehicles At Risk Of Being Hacked Says New Watchdog Report
00:33
Video thumbnail
KPIX CBS: Connected Cars Need A Kill Switch To Stop Dangerous Hacking
02:31
Video thumbnail
KCAL: Kill Switch Report Warns of Hacking Risk For Connected Cars
01:29

Privacy In The News

Latest Privacy Report

Support Consumer Watchdog

Subscribe to our newsletter

To be updated with all the latest news, press releases and special reports.