Technically, this is against most merchant agreements anyway. I've often wanted to create an "I have to adhere to my credit card contract and so do you" tearsheet to hand out to merchants who require insane minimums (like bars and their $10-$20 minimums) and require ID for verification.
But as techtalsky pointed out above, the merchant agreements between the credit card company and merchant often prohibit requiring ID for a signed, valid card and your matching signature.
Why is there a Song-Beverly Credit Card act making it unlawful to ask for corroborating identification for credit cards in California? What is the societal benefit to this law?
The law prohibits recording personally identifiable information, unless it's absolutely required for the transaction (for instance if your CC contract requires it, another law requires it, you're delivering something, etc).
In particular, it explicitly allows checking ID:
(d) This section does not prohibit any [retailer] from requiring the cardholder, as a
condition [blahblah], to provide reasonable forms of positive
identification, which may include a driver's license [...], or [...],
another form of photo identification, provided that none of the
information contained thereon is [...] recorded [...].
All I have is wild speculation, but I'll attempt an answer.
I believe there was quite a bit of concern about providing any identification along with a in-person CC purchase. The idea was that by providing identifying information, plus a credit card number, you were making it extremely easy for someone to lift your identity. The clerk could pick up the phone immediately after you left the store and order whatever he wanted using your card.
So the theory was: ID check in person -> bad. ID check by internet or phone -> good.
That seems so backwards to me. I've had physical cards stolen before, and they get used, in person, immediately. I write "ASK ID" on the back of all my cards and thank clerks when they ask me.
I'm not a security guy, so I'm at a loss with analyzing whether it makes sense or not.
It did occur to me, though, that I would not want to be the clerk asking for ID if the guy on the other end of the counter had just mugged somebody at gunpoint and was now looking to buy something so he could go down the street and pawn it to purchase drugs.
But I can definitely see the other side of the argument too.
The article talks about the plaintiff being asked for their zip code, but not ID. I don't see in the article or in the snippets of law it references where proof of ID is unlawful. Perhaps its perfectly fine to ask for proof of id to authenticate the credit card holder, but not ok to record the ID info into the company's marketing database.
I've always just told them I'm from Canada (which I am) and that normally just gets a pass.
Sometimes the checkout person can be quite forceful and require me to tell them my 'zip code', ok, V5J 021. There systems only accept numbers, so not alot of good that is going to do them.
The only place this is annoying is at gas stations where I have to go inside and give them my cc card to hold while I fill up. Hopefully this new law means that gas stations can't do that anymore.
The Song-Beverly Credit Card Act is a California-only animal. Having said that, it is unenforceable in interstate commerce. The only people who need to worry about this for their online stores are retailers with a business presence in California.
I've always wondered why they asked you for this information. Best Buy has been doing this for years. The article points out that online retailers have access to this a lot of info, but when you shop online you expect it. I actually hate purchasing for William Sonoma online because after I bought a wedding gift they spammed me from here in to 2027.
It's amazing to me how merchants feel entitled to your information and will be so aggressive in their procurement of it.
I understand the basics of marketing, but asking a customer for their zip code isn't going to tell you much about them personally. It's the reverse engineering that is the real key and problem with this strategy. I'm pretty sure that when any internet user with half a brain goes to a website they know they're giving up info of some sort, what page they came from, IP addy, etc. My only point is that you don't expect that same level of privacy invasion (if you will) when you go buy some headphones from Best Buy.
I doubt that most people expect the site owner to find their IP address (let alone what an IP address even is and what we can do with it) or what page they came from. When I bring up analytics with normal people, they tend to be a bit shocked.
It's much more fun to put a bit of research in, and find out the store's phone number before buying batteries. When they ask for your number, give them theirs. They'll start typing it in, then pause in confusion, which you are then free to enjoy!