OK, new evening project. I'm going to attempt to exercise my rights under CCPA from @joinClubhouse. I am not a user, but they harvest contact information and I believe that they have contact information about me.

First, I need to find out how to exercise my rights under CCPA....
Since they have no available privacy policy where they're supposed to disclose my rights, I'll attempt try [email protected].
This is kind of the legal/privacy version of pentesting.
Here's what I sent for those who are curious. Reminder - ALWAYS be kind to folks when exercising your rights or contacting support.
I emailed:
[email protected]
[email protected]

I've not received a bounce back for either, yet.
I would expect to hear some response (probably asking for more information) from them by EOD Tuesday. I sent my request after 4pm PT today, so someone may work on it tomorrow, and get back to me on Tuesday since Monday is a US holiday.
This is reasonable and under CCPA they have to "disclose and deliver the required information to a consumer free of charge within 45 days of receiving a verifiable consumer request from the consumer."
When does the 45 day clock start? After I was verified or at my request?

Is my request a "verifiable consumer request" once I've provided more info? Or is it presumed verifiable when I make the request?

These are the ambiguities of CCPA that make it hard to operationalize.
I'd probably argue that if the company asks for additional verification shortly after I make the request, that the clock starts when I make the original request.

Because its a "verifiable" request not a "verified" request, meaning the request can be verified in the future.
But it doesn't seem fair to the company if I made a request on Day 1, company responds on Day 3 asking for verification, and then I don't respond until day 35, that the response would be due from the company on day 45. That gives the company 10 days instead of 45 to execute...
In practice, it's generally accepted that the clock would pause when it's not the company creating the delay. So, follow up with your verification requests if you're exercising your rights.
Not surprising, but I have not heard from @joinClubhouse about my request to access my data. 40 days left...
For clarity and education, they have to acknowledge within 10 biz days under the new CCPA AG regs.

Since Monday was a holiday that's Friday the 26th. Some inconsistencies in counting regime: initial response is 10 biz days, but full response to the request is 45 calendar days.
You can follow @wbm312.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled:

By continuing to use the site, you are consenting to the use of cookies as explained in our Cookie Policy to improve your experience.