Live data from Hacker News

Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

reuters.com

61–70 of 285 posts

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#61
post #42

Earlier quoted context omitted.

Easily disproven. The 2008 crash is full of executives who did not comply with the law, and did not take the threat of prison seriously. I think to this date you can count the number in prison on two hands, and most of those were more foot soldiers than masterminds.

Maybe there needs to be consequences for selective law enforcement and/or selective prosecution?

That sounds somewhat naive, but on the other hand it also might help in getting all these unenforced, legacy laws of the book that result in anyone at all times being with one foot in prison if someone decided to enforce every law.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#62

That is a stiffer sentence than a second degree murder charge which is 15-years in California. https://en.wikipedia.org/wiki/Murder_(United_States_law)#Cal...

That's not a fair comparison - you're measuring the bill's maximum against a murder charge's minimum.

The bill allows anything from fines up to 20 years in prison, while a murder charge has a mandatory minimum of 15 years (up to life).

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#63
post #2

Prison time for this is madness.

agreed, but at the same time, we send small time druggies to prison for years, which is also madness.

these are all valuable humans, despite the othering identity politics of law and order rhetoric, and our focus should be bringing them back into the fold, not harshly and debilitatingly punishing them. very few people are so far gone that (long) prison terms make sense.

with that said, it'd be an injustice if we didn't also send privacy violators to prison, as it would unfairly advantage to them in the eyes of the law. above all, the legal system should strive evermore toward fairnesse. obviously the best solution is not to send any of these folks to prison.

ideally, privacy violators should have to face the consequences of their actions as part of their punishment (like personally making whole each victim, as an extreme example).

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#65
post #26

This is going to make it impossible to start a startup. We need to organize a movement against this.

Of course, Europe has had no startups at all since the Data Protection Directive (95/46/EC) was passed in 1995. /s

Europe does not have anything comparable to Silicon Valley, and heavy regulations are often cited as making it hard to do business there.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#67
post #13
post #2

Prison time for this is madness.

It should be heavy per leaked datum fines like HIPAA. This would transform huge troves of personal data from assets to liabilities, which is what we need.

I wonder if the process could be modeled after the recording industry, where the owner of the information can sue for damages that are set at a pre-determined amount per violation.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#68
post #20
post #14

Earlier quoted context omitted.

This. Leaving databases exposed to the net. Leaving S3 buckets open to the public. All of these sorts of things needs to carry punishments not for the people who are told to set the stuff up. It needs punishment for the management who doesnt allow time to set things up properly

Say you have a medical office, and you installed a cheap door lock which most burglars can easily crack, then a burglar breaks into your office, steals Ssn and other private info, should the doctor who runs the office go to prison for that?

Doctor no, owner yes.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#69
post #2

Prison time for this is madness.

Prison time for executives is the only thing that gets taken seriously. Fines to executives can just be paid by executive insurance, and unless you crank them up to 4% of global revenue like GDPR, fines to the company will likely simply become cost of doing business. But threaten the executives with prison, and they'll suddenly make sure that the company complies with the law. I bet e.g. SOX would be taken a lot less…

[deleted]

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#70
post #42

Earlier quoted context omitted.

Easily disproven. The 2008 crash is full of executives who did not comply with the law, and did not take the threat of prison seriously. I think to this date you can count the number in prison on two hands, and most of those were more foot soldiers than masterminds.

Maybe there needs to be consequences for selective law enforcement and/or selective prosecution?

That reminds me of itself a highly dysfunctional old system of private prosecutors. Especially with double jeopardy given that not having it turns it to a clear way to harass anyone. One obvious flaw is that trivially the best defense strategy isn't to hire a good defense attorney - it is to hire the absolutely worst prosecutor - against yourself.

Infamously prosecutors with conflicts of interest - often seen in cases of outrage over police misconduct. The prosecutors proceed to obviously present the worst possible case in what is an /unopposed/ hearing for a crime. There is a reason why the saying is 'they could indict a ham sandwich' - the standard is low enough that they just need to be able to present a very initial case to begin the process of proving guilt officially.

Post reply on HN