Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Difficult to interpret field in usnat string #42

Open
patmmccann opened this issue Dec 14, 2022 · 0 comments
Open

Difficult to interpret field in usnat string #42

patmmccann opened this issue Dec 14, 2022 · 0 comments

Comments

@patmmccann
Copy link
Contributor

patmmccann commented Dec 14, 2022

Under the referenced California legislation:

(C) A business’ collection, use, retention, and sharing of a consumer’s personal information shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected or processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.

However, field PersonalDataConsents of the usnat string seems to imply a user can consent to purposes they were not notified of or that are incompatible with the collection.

<td>Consent to Collection, Use, Retention, Sale, and/or Sharing of the Consumer&rsquo;s Personal Data that Is Unrelated to or Incompatible with the Purpose(s) for which the Consumer&rsquo;s Personal Data Was Collected or Processed&nbsp;<p><p>References:

This seems to be a logical impossibility; how can a user consent to something they were not notified of? Either the section does not apply or the user did not consent. As soon as notice occurs, the consent is no longer covered under this section, or the use of the data remains illegal as it is not compatible with the purpose it was collected for. Under this section of law, there does not seem to be the possibility of opting into incompatible purposes.

Under what scenario might someone populate '01' in this field of the usnat string? It doesn't appear to ever be legal by my reading. The law says data shall not be used in this manner, regardless of consent.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant