My name is Ryan Rix and I'm writing in support of SB619. I am a resident of Eugene in Senate District 4 and House District 8. My apologies that I am not submitting this as official testimony, I only discovered this bill this week. After hearing Senator Prozanski and Representative Fahey speak about civic engagement through OLIS at the recent Friends of Family Farmers Rally Day I found that my state senator and representative are proposing this bill which is quite near and dear to my heart! I moved to Eugene last year after spending most of my 20s working for tech companies in San Francisco, CA and Seattle, WA culminating in work implementing data portability compliance software and privacy-by-design programs for the European GDPR privacy legislation and the California Consumer Privacy Act at a data hungry business-to-consumer startup. Since then I have been engaged in independent privacy research while also consulting with the consumer rights non-profit Consumer Reports on the design and implementation of a technical messaging standard for exchange of data rights requests between authorized agents and businesses[fn:1]. I also provide services in the development of an authorized agent application currently being built by Consumer Reports called Permission Slip[fn:2].
I must make it clear that while my research is funded in part by Consumer Reports and I am in broad agreement with the official testimony already presented by Consumer Reports, the Electronic Frontier Foundation, and the ACLU, I am writing in my personal capacity as a local technologist who understands the data economy, as a privacy engineer with experience implementing innovative solutions to data privacy legislation, and as an individual whose hobby centers around opting out of many cloud services and attempting to "self-host" open source alternatives to "cloud software" on computers under my control with software I can modify, extend, and share with my friends and family. Despite spending quite a large fraction of my free time on this hobby, I am still an unwilling participant in the data economy -- eCommerce sites rely on consumers providing their email address, phone number, and address and ask to do whatever they please with them and whatever else they can connect to me when I sign up; I must have an account with Google to install applications for my Bank, and by default this account will catalog my whereabouts, my web browser history, and my video watching history; companies I consult with require the use of Google or Microsoft accounts to maintain access to calendars and communication suites; employers and payroll software suites report my income data and accomplishments directly to data brokers like Experian and Equifax; and there are some 200+ other logins stored in my password manager.
I understand from reading the privacy policies of many of these sites that they have broad consent to collect my information, transfer it, buy it from data brokers, sell it in "anonymized" bundles, profile and "machine learn" it to auction off pixels on my screen to the highest bidder, etc, yet I still have these accounts. Participation in the American digital economy currently necessitates giving unwilling, uninformed consent to businesses to do whatever they please with whatever they can get their hands on as the table stakes for participating in a post-COVID digital society. In response to shifting tides and sentiments, big businesses have begun to rally behind certain watered down regulatory frameworks which rely on the continuation of this unwilling, uninformed consent like those in Colorado and Virginia and claim that more consumer-friendly regulation like the CCPA or SB-619 would harm small businesses and further entrench large players.
However, many of the accounts I hold are with smaller businesses that would not need to implement some of the sweeping changes outlined privacy legislation like SB619 and would not be harmed in large ways by consumers having the right to opt out of large brokers' games. As a young "plugged-in" technologist with a career on both sides of the table, I have seen that businesses who build products which respect their customers' data- and civil-rights can still provide innovative products and high quality services, and make money in the process. Unfortunately, my industry's sensibilities have been warped by surveillance-enabled advertising super-charged by ubiquitous yet sometimes unheard of high-tech giants like Acxiom, Oracle, Facebook, and Google. Companies like these have built a sort of "trickle up" economy where a measurable percentage of almost every marketing budget in the country is fed from small businesses and NGOs straight to these large players. Small business owners I have spoken to and read from currently feel an implicit need to participate in these data economies whether they want to or not because of the business advantage that treating data as "the new oil" grants them.
What legislative frameworks like the GDPR, CCPA, and SB619 help underscore is that consumer data as "the new oil" is just that: a sticky, messy business liability when indefinitely stored in bulk, and a society-scale ecological issue.
It is with some jealously that I have seen my compatriots and coworkers in California gain powerful tools to combat this inequality since the California Consumer Privacy Act went in to effect, and I am excited to see similar tools move forward in Oregon.
Please find below some concrete feedback.
I am excited to see CCPA-style legislation as opposed to Colorado or Virginia Legal Frameworks
I am excited to see CCPA-style legislation put forward in Oregon, and I implore you to not consider a move towards more business friendly regulatory frameworks like those in Colorado and Virginia. While I think there is a very real risk of a "California Prop 65 Warning" effect[fn:3] with businesses unwilling or unable to situate real compliance of CCPA within America's other legal frameworks, legislation like SB619 helps solidify the rights of consumers both inside and outside of Oregon while easing regulatory uncertainty for inter-state businesses.
I believe that private right of action is critical in building a mass of case law and prior art which companies can use to eliminate legal uncertainty and comply with the law without the risk of an under-staffed or under-funded AG allowing for a free-for-all in the future. Having mentioned Prop 65, however, it may be worth considering limitations or guard-rails in the private right of action which can ease concern over frivolous lawsuits without weakening this critical right by requiring plaintiffs to submit a certificate of merit including supporting evidence of data rights violations to the Attorney General beforehand like the AB-227 reforms to Prop 65 have done for environmental and chemical safety issues in California[fn:4]. I will admit that I am no policy wonk outside the limited domain of data rights, but I believe this is a good counter-balance to alleviate the fear of spurious lawsuits against businesses while ensuring that the AG cannot be the sole bottle-neck in the protection of Oregonian's rights.
I am excited for an automated future, but more can be done.
I believe that the emancipating and multiplicative nature of software automation and the Internet, like tools that can be held in the hands of the individual and communities, can lighten our load and free our minds to participate more in the act of living and community engagement in the same way that they have super-charged enterprises and software startups since the App Store revolutionized how we interact with each other and our digital world. To that end, I think it is great to see sections of the bill specifically enabling the tools of digital automation to land in the hands of consumers, the provisions around "automated signaling" and the explicit design of authorized agents in to the framework.
Enshrining the legal right for consumers to use automated agents will bring the power of automation and "economies of scale" to the hands of individual. In this world where Google and Microsoft increasingly use their control of the web browser to shape it to their ends, it's easy to forget that these software are user agents and should be able to act in the interest and at the direction of those who use it rather than only those who produce it.
However I think there are some improvements which can be made to these sections. I implore you to make clear that such a signal under Section 5(5)(e) is valid if the consumer chooses to use a software application which sends the signal by default but is not provided by default on a device. By this logic, choosing to install a specific privacy-enhancing browser application like the DuckDuckGo Privacy Essentials browser which emits the Global Privacy Control signal to all websites by default[fn:5] should be seen as "affirmative, voluntary and unambiguous" action taken by the consumer. Without such a signal being seen as affirmative, voluntary and unambiguous businesses will be free to constantly provide wearying, annoying opt-out consent dialogs or simply ignore this signal while consumers believe they have made a choice to move to privacy-respecting software solutions.
Additionally: the intention or implication of Section 5(5)(e)(A) is not clear to me; and I believe it is important that section 5(5)(e)(E) should be amended to make it clear that systems like IP-based Geolocation would be sufficient so that Global Privacy Control may be compatible with this statute.
The data minimization requirement in Section 5(1)(b) is effectively useless
As written, the data minimization requirements in SB619 are constrained to what a business has listed in their privacy notice. While this is indeed a step up in transparency from "we do whatever we want with whatever we can get our hands on", it does little to alleviate the underlying problems of over-collection and over-sharing of data with our current "take it or leave it, we'll update this policy whenever we see fit" based approach to consent of privacy notices and terms of service. I encourage you to consider limiting this to what is reasonably required to fulfill a transaction with the consumer.
I think that the exclusions for reward programs, club cards, or any "value-add" features enabled by consent of data sales as currently implemented in section 5(6) is a loop-hole big enough to drive a truck through especially when taken in concert with these weak rules around data minimization and I urge you to close it. As currently written, I believe there is a real risk that Oregonians who can afford to pay for privacy with their dollars will be the only ones with privacy, the rest being disproportionately priced out by "premium" subscription services and forced to trade for a persistent surveillance apparatus and a world of data brokers to participate in the digital economy.
This "pay to play" standard does not serve the interests of consumers.
Requiring businesses to list the third parties they transfer consumer data to is daring and innovative
As I said above, I am particularly excited to see this bill explicitly setting the stage for authorized agents. These innovative tools ensure that data rights are accessible to consumers in a world where consumers will interact with hundreds of data controllers and those will in turn transfer data to hundreds of processors and data brokers.
Sending data rights requests to the these companies is an incredible time burden and often ineffective and error-prone. My friend Yael Grauer has assembled a list of resources[fn:6] for removing your personal information from data broker and people search sites and it's clear from only looking at it that it would take dozens of hours to do this yourself. Without any clear guidance on which brokers a consumer's data is flowing in to, a consumer is forced to send hundreds of possibly spurious data rights requests rather than specifically tailor their requests to businesses who have definitively ingested their data. SB619's transparency requirements will enable consumers to more efficiently take these data rights actions.
Business process tools will take some time to evolve to this new paradigm but I have seen that "privacy by design" practices like data labeling and lifecycle management undertaken by businesses and software providers will enable them to service fewer spurious data requests while easing their compliance with the rest of the statute's provisions.
Portability Rights remain a minefield
Since its enactment in 2017, the European General Data Protection Regulation (EU GDPR) has required businesses to provide personal data which was originally provided by the data subject[fn:7] in a "a structured, commonly used and machine-readable format"[fn:8]. I believe that any portability right in privacy statutes should follow this pattern. As currently drafted, I believe that SB619 could allow for data controllers to produce data which is not actually portable to other data controllers, or useful for technologically savvy consumers like myself, in the form of a PDF or Excel spreadsheet which would not be readily usable by the receiver.
That said, speaking strictly in terms of portability between services, these legislative efforts have largely fallen short in my opinion. I cannot easily take, for example, my email inbox and filter rules with me when I leave Google's GMail product and set up an account on a smaller host; I cannot import my trip history or favorite locations or even my profile information from Uber when I sign up for Lyft or a Taxi hailing app; I cannot move my mobile app subscriptions or data from iPhone to Android; I cannot even bring my favorite playlists from Spotify to Tidal without relying on a paid middleman service!
All of this is to say that while I think that the goal of data portability is laudable and exciting from a consumer's perspective, in practice businesses see these rights only as "access-lite" and steer consumers from making larger or more detailed requests for data which businesses may seek to protect from competitors or regulators or activists. We should at least ensure that the output of these requests is something which can be used by consumers and not simply gawked at.
In conclusion
In conclusion, I find this bill to be very much aligned with what consumers in Oregon and America need in an increasingly technological world and with some small tweaks it could be a great example for other states to also follow the California model and I am excited to see this work done by my local representatives. I'd like to offer my apologies once again for missing the opportunity to present this as testimony on the bill and for providing this hopefully valuable feedback so close to the legislative deadline. Thank you for your time and your important work representing Oregonians like myself.
Ryan Rix
Footnotes
[fn:1] https://datarightsprotocol.org
[fn:2] https://www.permissionslipcr.com/
[fn:3] https://en.wikipedia.org/wiki/1986_California_Proposition_65#Controversy_and_abuse
[fn:4] See California Assembly Bill 227 amending Prop 65 https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=201320140AB227
[fn:5] https://help.duckduckgo.com/duckduckgo-help-pages/privacy/gpc/
[fn:6] https://github.com/yaelwrites/Big-Ass-Data-Broker-Opt-Out-List/
[fn:7] I will briefly note that while CCPA and SB619 are consumer rights laws, the EU GDPR is a human-rights framework, so rather than talking about consumers, business interactions and consumer rights, the GDPR talks about data subjects and human rights, but the fundamental rights are quite similar in practice.
[fn:8] See GDPR article 20 & Recital 68 https://gdpr-info.eu/art-20-gdpr/ https://gdpr-info.eu/recitals/no-68/
[fn:9] Matt Schwartz's testimony on 3/7/2023 to the Senate Committee On Judiciary https://olis.oregonlegislature.gov/liz/2023R1/Downloads/PublicTestimonyDocument/60412