CHEQ’s Jason Patel Breaks Down the Delete Act
California is on its way to enacting the Delete Act. Recently passed by its legislature, the bill only needs the state governor’s signature to become law. Jason Patel, associate vice president of engineering & tech innovation at CHEQ, believes the Delete Act is a canary in the coal mine of future government action around online user privacy.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Jason Patel, who is Associate Vice President for Engineering and Innovation for Check-in.
We're talking about this new law floating around in California, which there are probably many, but this one in particular is the delete act. Everybody's gonna have the right to have themselves removed, and it's gonna create some headaches that it will be interesting and challenging. Jason, welcome to show.
Thanks for having me. Walk us through what is it that this act requires? 'cause, well, not everybody watching this lives in California, and they may not be following it, but what's the fundamentals?
So, yeah, I mean, basically, uh, on the surface it's kind of simple, right? Like the idea is that there's a centralized place where, uh, residents will be able to request their data to be deleted from data brokers, right? And then, so any data broker operating in the state of California has to, uh, acknowledge and respond to that request, right?
And, you know, on the surface, like it sounds great and, you know, for the most part, I think it's a step in the right direction, but there's obviously nuance and challenges with any new legislation, right? Yeah. So I get this request and then I go to try to delete this data, but in my experience, the data doesn't sit in one place.
It's been used by developers for things. It's sitting in spreadsheets. So what are the mechanics of actually deleting someone's requests, Right?
So, you know, at the end day, right? You gotta take a step back and think about like how these data brokers work in the first place, right? So you're right.
Like the data is probably on their active production systems that they're using to buy, sell data for, uh, or lease data out to their customers, right? But on top of that, right? You, you just, like you said, the, the devs are probably have it in like some internal environment to do research on, or, uh, do some, do some testing on, or like, you know, maybe you have it in like spreadsheets or analysis or when, like, you know, these data brokers even acquired their data in the first place, right?
Who knows how they got it, right? So it could have came through like, you know, uh, uh, just data buys from other, uh, data brokers that came to form it of like CSVs and flat files and stuff like that. So it is a pretty complic, uh, complicated ask, right?
On the, the easiest one, or theoretically the easiest one is like, hey, in your like live like production system or whatever else that you're using to se uh, build out data to sell to your customer, you should be able to identify those records and delete them. But then, uh, beyond that, right? Like, you know, it kind of comes down down to that, uh, natural challenge in any corporation where you have data living in 20 different places.
So, you know, data mapping, inventory, all those types of, uh, requirements become more and more and more like importance. How does somebody know whether or not it was actually done and done to their satisfaction? Yeah, no.
So that's gonna be the, the interesting part. It's gonna be, uh, definitely dependent on the state of California to, to have some, uh, strong auditing capabilities. Because the data broker world itself, even prior to the delete act, was a very dark world, right?
You did not even know that. Most people didn't even know this world existed if you didn't work in MarTech ad tech or, or any of these companies that like, you know, bought data, right? So, um, the transparency, uh, to be honest, is just kind of not there yet, right?
Like the data broker will just have to say like, yeah, I deleted it, but like, without barring an audit, or, you know, if you could show that like, Hey, I'm not targeting this person anymore, or whatever else, or, you know, someone who purchases data can validate that like, yeah, um, you know, these are the people that requested their data to be deleted, and I just purchased this data from this broker, and I'm gonna compare that data set to the delete requests that California's housing right Now, maybe I could audit, do some self-auditing, right? But it's, it's very gray right now as far as how you actually make sure that was, uh, done and done to a thoroughness that is acceptable. Who's gonna get in trouble for, is it gonna be the data broker or are the customer of the data broker?
Where do those fines wind up getting levied? Right now it's mainly targeted at the data broker world, right? So, you know, like, think of like your, your axioms, your live ramps, like, you know, um, and, and you know, those are just kind of the bigger players, but like, there's hundreds of these companies, right?
And, uh, you know, at the moment they're probably the, uh, they are the main target in, in the eyes of California. Um, and, uh, again, the question though is like, how does California actually audit and verify, right? They have like the privacy office, but at the end day, you know, like, uh, private businesses have some protections under law that like protect their own ip, protect their own business processes from un like, you know, unfair scrutiny or even like disruption, right?
So I think eventually what we'll see is something similar to like how we, uh, build out like, uh, accounting and reporting requirements around fiduciary needs, right? Um, you know, you'll see some similar model emerge where there has to be a standardized form of transparency. So do you think other states are gonna follow suit?
And if that's the case, wouldn't it be just easier to have some sort of unified national approach to this thing? I think in general, right? Like you, I think we're gonna see states follow eventually, right?
But I think, uh, yeah, in the long term, like we need the federal government to step in, right? We need a uniformed blanket of laws because at the moment there is like a thematic through line for a lot of the data privacy laws that are emerging in the United States, right? But it's very nuanced across like, uh, how each company, uh, or sorry, each state, um, is deciding to implement or what they're trying to protect, right?
So, you know, obviously for me in Illinois, for example, uh, we have great biometric privacy protections, right? But like in terms of like data sharing, opt-out, stuff like that, California protections are significantly better. The through line though is still that like, you know, uh, the limit, uh, limiting and transparency use of data to the customer that the data is being collected on, right?
Um, but how that is perceived still, like very much up to, uh, each state's imagination of what they feel they need to protect, right? And then also generically, it is a balancing act, right? Both between like the fact that like the economy of the internet has worked a certain way for, you know, the last 30, 40 years, and this will have some changes on that.
So how can I implement these requirements from a federal or even a local level in a way that allows for a smooth transition into a internet economy that still is open and robust, but enables consumer privacy choices, right? And transparency, I get the sense that other countries are moving down a similar path. You can look at some of the things that come out of the eu, and if that's the case, do I just find the one that affects me the most and make that the standard that I'm gonna go work against on the assumption?
The other is will either I'll be compliant, but the other ones are probably getting more stringent over time anyway. Yeah. So that is actually a pattern we're seeing across our own customer base, even where we are seeing a lot of our customers just take the harshest regulations and say like, that is gonna be our global standard, right?
Because like, you know, and that does come correct for the most part, right? So, you know, you'll see, uh, where in the world is like the harshest like data collection and privacy laws, right? So GDPR is probably the, the framework of reference there.
You know, you'll see like protections around child data and stuff like that where like, or children's data, and that's like, you know, both GDPR and California has some robust protections around that stuff, right? So you'll see, so when you see some of these organizations where they like go, they basically will tell us like, look man, we, uh, don't want to have to revisit this topic every six months every year, right? We'd rather just go with the hardest version of this.
We'll take the business hit now because we're gambling on two things. One, that like, as you said, all these, uh, uh, piecemeal regulations, eventually it'll get hardened and hardened and hardened over time and we'll become more strict. So we just wanna be ready for them.
Two is that, like, you know, if we accept this as an inevitability, right? Where, you know, there's going to be a privacy focused world, um, we're gonna need to change the way that we work. We'd rather learn that now and learn how to work in this environment now than wait until that environment is placed on us and we're being re uh, reactive to the entire ecosystem changing underneath us.
I would say one of the dirty little secrets of it in general is that we're not all that good at managing data in the first place. So, um, do you think as we go along, we're gonna have to have some advances here. Will AI save us from ourselves to go find all this data?
Or what's your sense of what's possible here? Yeah, so I think, um, you know, and I think when we talk about ai, right? Usually really what we're talking about is a couple different things, right?
Like when we talk about like, like, you know, the, the large language learning models like chat GPT and stuff like that, or like, you know, the standard machine learning stuff, right? And I think that stuff will definitely have a place and use in this, uh, environment because like, you know, when we're talking about the scale of data and the fact that some of it's like just in text or pros, right? You need something that like is not a human that could process and kind of catalog catalog some of this data at scale, right?
So I think those types of solutions are naturally fitting in that environment, right? Because you're not giving them too much decisioning power, but you're letting them do what they're good at, right? Which is like, Hey, classify this piece of data right to the best of your ability.
Um, and then from there, I think also, uh, like you said on the engineering and IT side, like we are good at storing and securing data, right? But we're not good at like knowing what data is where, right? Um, or like generically have like a perfect map, right?
And I think like, you know, if you think about like the analogous, uh, thing that happened maybe 20, 30 years ago is where security became more and more forefront in mind. It went from just like that one dude's office, uh, job in the office to like every it, every engineer in your company, security is part of their day-to-day responsibility, right? When you build code now, or when you build systems, you think about it from a security lens as well, right?
Like, am I honoring permission boundaries? Am I making sure that I'm closing all the doors I need to close? Stuff like that.
I think what we, we'll see, what we will see and should expect to see is a maturation thought in, in that entire motion as well, where not, it's not just security. Now that's gonna be part of your day-to-day job as engineering. It, it's gonna be security and privacy, right?
You also need to understand like what are gonna be, um, potential rights that the people or data subjects that I have in my databases, uh, can enact on my data, right? Make sure I build systems in a way that both can catalog what's data, what data types of data I have. So, you know, for auditing purposes or even per, uh, company inventory, we have those records.
It would also make them in such a way that uh, should, uh, someone try to enact their data rights. You know, my system is capable of supporting that, right? Mm-Hmm.
Are we worried that these regulations might, uh, to your earlier point kill the proverbial golden goose? Because so much of what we do for online e-commerce is data driven. So, and I wonder, you know, the folks running these laws are not necessarily business people or even IT people.
So, you know, do we need to really review this and think twice or what's your sense of how severe is this? Yeah, so I think the direction is right. You know, I've been in the ad tech MarTech world for over, like, for a decade now, basically, right?
And like, you know, it's one of the things I've definitely even had concerns of, even when I started as an engineer around like, how many people, fingers were in the pot, how many people had access to your data and stuff like that, right? I think in there is gonna, there needs to be some changes though, in like the legislation, right? Or like, at least how we, uh, act on it or define it because there is, um, a lack of clarity around, uh, how this legislation behaves in the real world.
For example, like, you know, some of these data brokers, like if you say to a data broker that like primarily is in the online player, they like, they, they do like, um, ad tracking or like audience building and they sell those IDs to you somewhere else, right? Like, you know, they might not know your first name, last name, whatever else. They're just able to solidly identify you as a person every time you appear on the internet, right?
com, they're like, oh, like, you know, this is Michael. Like, I know that like, or like, this is the person that, like we've created, it might be your persona, right? com, right?
And so when you request your data to be deleted in that world, right, what does that mean to that company, right? Because you're gonna give them like, here's my first name, last name, email address, delete every data points associated with that. But the data points that they have that are arguably your data are not associated with those PII identifiers, right?
So, you know, it's like how do you act on that? What is the expectation of these companies, right? It's very unclear.
Um, and yeah, I think there needs to be, uh, I think both as a population, like as a consumer population, but also from a legislative way, right? We need to think about like, how do we transition the economy? I don't think it's gonna kill the golden goose, uh, proverb really.
'cause like, you know, at the end of the, like, um, you know, you, corporations have always been able to adapt, right? Like, you know, no one's ever gonna say like, well, I'm gonna just give up on advertising, right? We just gotta get smarter about how we do it.
And, you know, I think also you'll get more effective of, uh, I think in the long term term, we'll see more effective advertising because, you know, while, uh, for the last like 20 years when data was like kind of just widely available and accessible, right? Uh, the traditional advertising model was like, okay, here are all the people that bought stuff from my site. Find another 5 million people that look just like them and shuck in the ads to them across the internet, right?
And like, now you have to be a little bit more thoughtful and intentful about that, right? Like, you know, who are the people they're buying? What are, what, what do what, what types of things do they like, you know, what characteristics do they exhibit, like when they come into my store?
Okay. And from that, what will I be able to derive from that and decide how to advertise, right? So advertising might like, you know, not be breakneck speeds anymore, in sense that like, you know, we've all had those moments where we googled a product and then like the next thing you know, you're watching a YouTube video a minute later and you're getting an ad for that product.
You might not see that turnaround anymore, which, who knows? Maybe that's okay. But I think we still will see a different, different but effective advertising strategies.
All right, folks. Well, you heard it here. I would say the only thing worse than a, well-intentioned law is 52 conflicting, well-intentioned laws.
So, yeah. No, It would be very nice if the, if the federal government decided to say, let's put some conformity to this. 'cause, you know, I think if you think about it, right, like that's always been one of America's, uh, best strengths is like, you know, we have, uh, a union of like 52, uh, uh, municipalities and jurisdictions that we could operate in under virtually a common set of commerce laws, right?
So ideally we create that for privacy, data privacy across the web too. Jason, thanks for being on the show. Yeah, thank you for having me.
Alright, back to the studio.