Would these rules also apply to NSA/CIA misuse of surveillance?
Those are already criminal, just rarely prosecuted even when known.
Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
81–90 of 285 posts
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#82Unintended consequences: This could make running a public Wifi hotspot a losing proposition for many businesses that operate one today.
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#83so they admit, that the war on drugs is not working anymore. a new paper dragon is needed.
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#84Earlier quoted context omitted.
Prison time for executives is the only thing that gets taken seriously. Fines to executives can just be paid by executive insurance, and unless you crank them up to 4% of global revenue like GDPR, fines to the company will likely simply become cost of doing business. But threaten the executives with prison, and they'll suddenly make sure that the company complies with the law. I bet e.g. SOX would be taken a lot less…
Easily disproven. The 2008 crash is full of executives who did not comply with the law, and did not take the threat of prison seriously. I think to this date you can count the number in prison on two hands, and most of those were more foot soldiers than masterminds.
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#85Facebook, Google and all the others will be BURYING politicians with boatloads of bribes to stop this.
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#86Earlier quoted context omitted.
I think there are states in America where you can go to prison for stealing a pack of bubble gum. So I won't really cry for the targets here.
Would you if developers start going to jail for leaks?
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#87Unintended consequences: This could make running a public Wifi hotspot a losing proposition for many businesses that operate one today.
Given that most (all?) public Wi-Fi's primary function is to collect data & stalk people for advertising, it's not a big loss.
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#88Earlier quoted context omitted.
Say you have a medical office, and you installed a cheap door lock which most burglars can easily crack, then a burglar breaks into your office, steals Ssn and other private info, should the doctor who runs the office go to prison for that?
I think it would be reasonable to have a law that says you need to have X level of security for certain information. Then it would be criminal to provide less than that level of security, especially just to save money. I just think it would have to somehow have exemptions for honest mistakes, and clever attackers.
Say for instance there is a requirement that there must be DES encryption of passwords. That would be a downright terrible law on several levels - first of which is that the best way to secure passwords is not keeping them in the first place but a hash. The encryption standard is as laughable now as requiring banks lock their vaults with a simple warded lock - the kind where skeleton keys work because shaving the teeth from the key means it no longer has anything to catch on while it turns the lock.
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#89Prison time for this is madness.
Throwing around prison lightly is dangerous. For some reason data privacy gets people emotionally charged instead of thinking clearly, and it's easy to say "lock them up", but that's exactly the same attitude that led to such heavy criminalization of other things that now takes up resources, fills up courts, wastes lives, and accomplishes almost nothing.
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#90Unintended consequences: This could make running a public Wifi hotspot a losing proposition for many businesses that operate one today.
The bill defines covered entities in Sec. 2.(5)(A) and 2.(5)(B). In particular, companies with less than $50,000,000 in gross receipts and information on fewer than 1,000,000 customers are not covered by this legislation.
And even if those apply to your local coffee shop or whatever, Sec. 2(5)(B)(iii) further limits the definition of covered entity so that businesses that do not provide 3rd party access to information are not covered.
So Starbucks and other huge coffee chains/retail shops are the only organizations that would have to re-evaluate data collection from their public Wifi hotspots, and even then might be exempt depending on what they are collecting and how they are using that information. And, I should point out, these companies will need privacy experts on staff anyways, so this provision is highly unlikely to cause them to shutter their in-store Wifi networks...
Additionally, some of the more onerous requirements only apply to a subset of covered entities with yet larger gross receipts and yet larger numbers of tracked consumers.
But, unequivocally, your locally owned mom & pop coffee shop is excluded from consideration under this provision multiple times over.