Live data from Hacker News

Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

reuters.com

101–110 of 285 posts

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#101
post #26

This is going to make it impossible to start a startup. We need to organize a movement against this.

Startups aren't even covered by this bill until they've gained lots of traction (1 million users and 50MM+ gross receipts). At which point, again again IFF their business is data hoarding, they will need to hire approx. one additional employee.

I'm sure startups/consultants will step in to provide regulator compliance as a service as well, so maybe not even that.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#102

The biggest unintended consequence I see is that more tech businesses will have to charge for their service rather than make money in opaque ways.

That would be a very positive consequence.

Very true in some cases, i.e. unrollme. But I also like free content and am mostly willing to trade a little privacy for access.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#103
post #92

I'm fine with fines, but I hope prison time is restricted to intentional and malicious illicit behavior and not anything due to neglect or oversight. I'm not a fan of people being put in cages unless they're violent or have ruined people's lives intentionally.

It is. Read Sec 5.(d). It's not like people will be thrown in prison because their DB wasn't patched quickly enough. They have to knowingly and intentionally lie to the federal government in an annual report.

They have to knowingly and intentionally lie to the federal government in an annual report

So it's a nonstarter, since the people being prosecuted for these things will have lawyers adept at whittling down intent to only the most brazen and malicious behavior. Not only that, but Sarbanes-Oxley showed us how effective "annual report" red lines are.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#104
post #43

This would probably mean more compensation at executive level for the increased risks!

Companies will have a Chief Privacy Officer whose job is basically to provide oversight and, of course, absorb the risk. That person will probably be paid well.

I'm actually OK with that. We're always complaining that companies don't take security/privacy seriously because there's no incentive to do so. See e.g. the Equifax HN threads. Having a person in the C suite who'll end up in jail if the company seriously fucks up is, IMO, a net positive for the world.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#105

The biggest unintended consequence I see is that more tech businesses will have to charge for their service rather than make money in opaque ways.

Not only that:

1) It encourages companies to be silent or remain ignorant.

2) I didn't see anything mentioned about the cyber-sec aspect, but I would imagine this will put a bounty on the heads of the largest companies.

Perhaps I watch too many (bad?) movies but shorting a stock on the cusp of being hacked could be lucrative.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#106

Earlier quoted context omitted.

It is. Read Sec 5.(d). It's not like people will be thrown in prison because their DB wasn't patched quickly enough. They have to knowingly and intentionally lie to the federal government in an annual report.

They have to knowingly and intentionally lie to the federal government in an annual report So it's a nonstarter, since the people being prosecuted for these things will have lawyers adept at whittling down intent to only the most brazen and malicious behavior. Not only that, but Sarbanes-Oxley showed us how effective "annual report" red lines are.

Perhaps. But that's not a compelling argument against this bill. Perfect enemy of better and all that.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#107

The biggest unintended consequence I see is that more tech businesses will have to charge for their service rather than make money in opaque ways.

That sounds like the renaissance we've all been waiting for. Every would-be entrepreneur's wet dream is a $20/month subscription for Facebook.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#108
Fortunately, this is just a "discussion draft" and I don't believe it would ever be passed as it is written. This clause would expose mom-and-pop app developers who have apps that happen to go viral and get more than 1 million installs to the same expensive, onerous requirements as an entity with $1 billion or more in revenue:

Each covered entity that has not less than $1,000,000,000 per year in revenue and stores, shares, or uses personal information on more than 1,000,000 consumers or consumer devices or any covered entity that stores, shares, or uses personal information.."

Putting those two vastly different classes of entities under the same umbrella and exposing them to decades in prison seems like it would have a chilling effect on the startup community. You would just have to hope that your app/website doesn't get to 1 million users, otherwise you're exposed to requirements where the implementation will bankrupt a small team or independent developer.

I guess you could simply stop allowing new registrations at 999,999 people, but it seems like a bad idea to discourage businesses from growing beyond that.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#109
post #14

Earlier quoted context omitted.

This. Leaving databases exposed to the net. Leaving S3 buckets open to the public. All of these sorts of things needs to carry punishments not for the people who are told to set the stuff up. It needs punishment for the management who doesnt allow time to set things up properly

> It needs punishment for the management who doesnt allow time to set things up properly Hard to show it was management's fault, and not the result of a developer who really didn't have the AWS skills (though that's probably still the fault of management, for not verifying skillsets before hiring or giving AWS keys) Everything we know about iteration cycles, quick access to devops resources, etc, will change when pri…

> Hard to show it was management's fault, and not the result of a developer...

No. A leader is ultimately responsible for everything that happens or fails to happen under his or her leadership. Full stop.

The people in charge of your hypothetical developer are the only ones with the ability to put processes in place to prevent it from happening. They are the least-cost avoider. Therefore, the power and the responsibility belong there.

Strict liability for the least-cost avoider is a sound strategy from both a moral perspective and a law & economics perspective. When proving knowledge and proximate cause are difficult, and someone is clearly in charge, and the harm is great - you place the liability on the people in charge whenever something goes wrong, and be done with it.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#110

Earlier quoted context omitted.

That would be a very positive consequence.

Very true in some cases, i.e. unrollme. But I also like free content and am mostly willing to trade a little privacy for access.

I think the trade-off should be a lot more explicit though, e.g. you get to choose whether pay 5€ per month or your usage data gets sold.
Post reply on HN