Bonum Certa Men Certa

Open Source Initiative (OSI) Privacy Fiasco in Detail: In Conclusion and Enforcement Action Proceeds Against OSI at the California Privacy Protection Agency (CPPA)

posted by Roy Schestowitz on Apr 17, 2025,
updated Apr 17, 2025

What OSI wants you to think it does vs What OSI does; 'deep dive' sponsored by Microsoft

IN THE introduction and the following two parts we gave sufficient background for people who are not familiar with this fiasco. The previous three parts - including the last part - showed most of the complaint (as a PDF). It named Stefano Maffulli and Deb Nicholson. It pointed the finger at culprits, whether it was willful or not (no need for a "ringleader" when sufficiently advanced incompetence begets what seems like deliberate failure).

We meanwhile got some good news as well. The complaint is advancing. There's merit found by the regulator/enforcer. To show the quote in full: (text version follows beneath)

RE: CCPA Complaint and Open Source Initiative et al.

From the above, as text (message to the complainant, whose name is redacted):

April 9, 2025

Via Email ([redacted])

RE: CCPA Complaint and Open Source Initiative et al.

Dear [redacted],

Thank you for submitting a sworn complaint to the California Privacy Protection Agency (Agency) on March 3, 2025. The Agency has completed a preliminary review of your complaint. This letter details the action the Agency has taken or plans to take, together with the reason for that action or nonaction.

The Agency will be referring your complaint to the Enforcement Division for additional review. The Enforcement Division’s additional review might result in a formal investigation based on the allegations contained within your complaint and further fact-finding. The Agency has taken this action because your complaint appears to raise at least one issue within the Agency’s jurisdiction.

The Agency may reach out to you again for additional information. The absence of a request for additional information does not indicate, one way or another, whether the Agency is investigating, and any requests for information might come later. We are unable to share further developments, as the Agency’s investigations are generally confidential unless and until a matter becomes public through an enforcement action.

We're not overzealous with redaction. Remember that the OSI had a habit of chasing critics to censor and deplatform them, even libel them. Like the OSI's masters - notably Microsoft - there is no tolerance of dissenting/opposing views.

It's not about sharing or Software Freedom; it's all about money and control (even over the narrative).

Back in March we published the previous chapter with a number of other OSI blunders - some of which we'll revisit later this month and next month. Like the Linux Foundation, today's OSI is a part-time Microsoft front group. No matter what it used to be (or could be or was supposed to be), the general public must understand what it is right now. Information is essential here; transparency is imperative.

With proper understanding, which is perpetually needed (even imperative), the OSI might simply cease to exist. Its purpose at this point is detrimental to many things due to rogue stewardship.

Other Recent Techrights' Posts

Microsoft-Sponsored Xenophobia and Nationalism
IBM is very similar in this regard
Tentative Summary of Things to Publish in Project 2030
I'll still be in my forties by then
 
Google's Software is Malware and Malware in Mobile Devices
Originally posted by Rob Musial
Links 20/09/2025: Hegemony Coming to a Close, Luigi Mangione Ruled Not Terrorist
Links for the day
Gemini Links 21/09/2025: "Charlie Kirk Was a Hateful Piece of Shit" and Slop Code Attempted by Microsofter
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, September 20, 2025
IRC logs for Saturday, September 20, 2025
Gemini Links 20/09/2025: Snowy Photos and utism is a Spectrum
Links for the day
Vintage is Sometimes Better
Why can't we get back to "simple" if (or where) "simple" means better?
Climate Breakdown Means We'll be Publishing More, Not Less
Press freedom will be a common, recurring theme
Our 5-Year Geminispace Anniversary is Coming Up
I still remember when Gemini Protocol was quite new
It's Right to Point Out Violence From the Right
Violence is a recurring theme
Web Browsers That "Do Hey Hi" (AI)
State-of-the-art plagiarism or "autocomplete on steroids" (not coined by us, nevertheless a nice description) don't have much/any prospect
Links 20/09/2025: Hardware Projects in View, Some Independent Publishers About Russia Prosper After Cheeto Cuts Funding
Links for the day
Gemini Links 20/09/2025: Options and TV Time Machine
Links for the day
Links 20/09/2025: Retrocomputer, Antique Phone Experience, and More
Links for the day
Links 20/09/2025: Internet Shutdowns, Media Censorship, and Climate Worries
Links for the day
About 700 New Gemini Capsules in 13 Months (or 54 Per Month)
4.8K would represent a 20% increase
Rust People: Drain the Swap, You're Holding It Wrong
Does Rust make sense?
Techrights the Name Turns 15
About 6 weeks from now we turn 19
Microsoft is Running Out of Time and Floating Fake Figures, Fake Projects, Fake Narratives, Fake Excuses
Also, a lot of Microsoft's "revenue" claims are circular financing (i.e. Microsoft buying from itself, which means Ponzi-like fraud)
Slopwatch: LinuxSecurity, linuxconfig.org, and Plagiarised Phoronix
Many articles out there are nowadays fake
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, September 19, 2025
IRC logs for Friday, September 19, 2025
Gemini Links 20/09/2025: Navigating the Pressures of Modern Life and SpellBinding Accidentally Wrote Another Gemini Server
Links for the day
Links 19/09/2025: Press Freedom Dying in US, Anti-Austerity Strikes in France, and Alan Rusbridger to Leave 'Prospect'
Links for the day
European Patent Office Illegally Gutting and Outsourcing Its Functions, Acting Like an Above-the-Law Commercial Business (It Won't Stop at Formalities Officers (FOs) and Classification Slop at the EPO)
breaking/violating laws and conventions
Offloading to the Sister Site
In the interest of not overwhelming readers
Links 19/09/2025: Coffee Club and "SpellBinding is Now Absurdly Fast"
Links for the day
Links 19/09/2025: Lobbyist of American GAFAM Becomes Data Protection Commissioner in Europe
Links for the day
Links 19/09/2025: Media Freedom Ceases to Exist in US, "Consider Dropping Twitter/X"
Links for the day
Gemini Links 19/09/2025: Thinking and Insect Bites
Links for the day
Microsoft E.E.E.: Git Will Now (or Very Soon) Fully Depend on Rust, Which is Controlled by Microsoft
Microsoft now makes Git dependent on Rust, or making Git dependent on GitHub, which is proprietary
The Right to Punch People (Apparently)
At Brett Wilson, Brett's job title is "Head of Crime" and Wilson normalises calls for violence
Slop or Fake Articles Have Turned Linux Journal From a Pioneering/Trailblazing "Linux" Magazine Into a Nuisance
some sites with former reputation - good reputation - turn into cesspools
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, September 18, 2025
IRC logs for Thursday, September 18, 2025