Earlier quoted context omitted.
A fine and a lawsuit are very different things, especially with 340M people involved [even a $340M fine would only be $1/person]; fines don't usually go to the people injured by it, which would make sense with personal data being leaked. A fine also misses companies who are "doing what the law says" but still have some horrible flaw anyways. If you are _genuinely_ responsible for the data, meaning if something happen…
> fines don't usually go to the people injured by it, Well they do. Our government takes money through fines and taxes and uses it to build infrastructure and provide services. > which would make sense with personal data being leaked. My preference would be that personal data not be leaked at all. Ideally the warnings and fines kick in long before that happens. > A fine also misses companies who are "doing what the l…
Me too! But not at any cost. This discussion involves thinking about scope (both in who and what is regulated), penalties (both in frequency and magnitude) and pre-emptive enforcement, if any. The trade-offs are far-reaching. A conservative approach is prudent. (It's also politically resilient.)
> GDPR is quite broad and open to interpretation by both sides
That's a sin and a virtue.
> Requiring people to lawyer up to make the company responsible is far weaker
This, too, is a sin and a virtue. The sin is it may allow bad deeds to go unpunished. But presently, everything is going unpunished. The virtue is in its prudence. It's unlikely to cause systemic harm, and we can observe its case law to more-precisely draft the next wave of rules.