Live data from Hacker News

Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

reuters.com

131–140 of 285 posts

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#131
post #107

Earlier quoted context omitted.

That sounds like the renaissance we've all been waiting for. Every would-be entrepreneur's wet dream is a $20/month subscription for Facebook.

i would pay $2/month at most for facebook.

$50bn/year would be more revenue than fb had in 2017, though of course the majority of their 2.23bn monthly users would disappear if asked for $.01/mo.

It is an interesting thought experiment, though, to consider what facebook would look like if its revenue was derived from convincing users that it was worth a monthly subscription.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#132

Why are bills like these always drafted after the fact? E.g. Equifax, Google+, Facebook hack, etc. It would be common sense to pass laws before it happened and would of incentivize companies to beef up security.

Or make the bill retroactive ... ?

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#133

I read this and immediately thought "oh shit, yet another regulation for a small bootstrapped software business where we try to be honest while the big guys will still find a way to circumvent it". Thankfully, I looked into the fine print and was wrong. This bill is only for Corporations that do over $50,000,000 in revenues or higher OR (EDITED from AND) have info on at least 1,000,000 or more customers. Of course, I…

You read that wrong. In order to NOT be a "covered entity," you must meet ALL of the following criteria: 1) Revenue of less than $50 million; AND 2) Must not have info on 1 million or more people; AND 3) cannot be a data broker That means an independent app developer who gets more than 1 million installs, or a website with more than 1 million users, IS a covered entity, regardless of revenue . Also, ANY "data broker,…

> gets more than 1 million installs, or a website with more than 1 million users,

Incorrect, that would only be true if they collected and stored personal info on their users. Hopefully we see more apps and websites stop collecting this info, or a minimum started purging the data (i.e if you visited a site 1 time 5 years go they should not still have your data but many do)

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#134

I read this and immediately thought "oh shit, yet another regulation for a small bootstrapped software business where we try to be honest while the big guys will still find a way to circumvent it". Thankfully, I looked into the fine print and was wrong. This bill is only for Corporations that do over $50,000,000 in revenues or higher OR (EDITED from AND) have info on at least 1,000,000 or more customers. Of course, I…

You read that wrong. In order to NOT be a "covered entity," you must meet ALL of the following criteria: 1) Revenue of less than $50 million; AND 2) Must not have info on 1 million or more people; AND 3) cannot be a data broker That means an independent app developer who gets more than 1 million installs, or a website with more than 1 million users, IS a covered entity, regardless of revenue . Also, ANY "data broker,…

So the app developer has to be able to demonstrate they followed some form of best practice with regard to user data.

I’m having trouble thinking of any other type of work that manages to escape all liability.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#135

I read this and immediately thought "oh shit, yet another regulation for a small bootstrapped software business where we try to be honest while the big guys will still find a way to circumvent it". Thankfully, I looked into the fine print and was wrong. This bill is only for Corporations that do over $50,000,000 in revenues or higher OR (EDITED from AND) have info on at least 1,000,000 or more customers. Of course, I…

You read that wrong. In order to NOT be a "covered entity," you must meet ALL of the following criteria: 1) Revenue of less than $50 million; AND 2) Must not have info on 1 million or more people; AND 3) cannot be a data broker That means an independent app developer who gets more than 1 million installs, or a website with more than 1 million users, IS a covered entity, regardless of revenue . Also, ANY "data broker,…

Phew! That would be a net positive for the world, long term, to bear less of a greasy footprint from american startup antics.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#137
post #62

That is a stiffer sentence than a second degree murder charge which is 15-years in California. https://en.wikipedia.org/wiki/Murder_(United_States_law)#Cal...

That's not a fair comparison - you're measuring the bill's maximum against a murder charge's minimum. The bill allows anything from fines up to 20 years in prison, while a murder charge has a mandatory minimum of 15 years (up to life).

Second degree murder from one jurisdiction to another. In California I stand mostly corrected: The penalty is: 15-years to Life. At the 15-year mark they are eligible for parole.

https://en.wikipedia.org/wiki/Murder_(United_States_law)#Cal...

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#138

Earlier quoted context omitted.

You read that wrong. In order to NOT be a "covered entity," you must meet ALL of the following criteria: 1) Revenue of less than $50 million; AND 2) Must not have info on 1 million or more people; AND 3) cannot be a data broker That means an independent app developer who gets more than 1 million installs, or a website with more than 1 million users, IS a covered entity, regardless of revenue . Also, ANY "data broker,…

So the app developer has to be able to demonstrate they followed some form of best practice with regard to user data. I’m having trouble thinking of any other type of work that manages to escape all liability.

So the app developer has to be able to demonstrate they followed some form of best practice with regard to user data.

I think you're downplaying the requirements of this law. You should read it, it's pretty onerous and carries decades in prison with it - even GDPR didn't go that far.

One interesting caveat, however, is that at least as written, I can't find anything imposing penalties for simply not filing the reports this law claims to require after all of the expensive audits etc it wants. It only imposes penalties for lying on the reports. I'm not sure if that was an oversight on the author's part or if that's intentional though. Any final version would likely "fix" that issue.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#139
On one hand, I think this is a good thing. That is, I certainly would like to have more control over who uses my own data.

But, on the other hand, the scope of this bill has some risk of bringing about a technology winter. Most people outside of tech don't realize how much of the software they use has been indirectly subsidized by the ad and data brokering industries.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#140

Earlier quoted context omitted.

The question isn't whether the door lock was great, but instead was there a door lock in the first place and if it was locked. If not do you continue to operate with an unlocked door or do you lock the damn door? You cannot stop all criminals, but you can take reasonable actions (due diligence) to ensure a reasonable effort, according to industry, and timely corrective actions once a breach is known.

The problem is there's way too many developers being given AWS keys who don't even know what a lock looks like.

And one solution is enforcing consequences for incompetence.

If a construction company sends a bunch of untrained yahoos out with explosives, well, maybe the yahoos should have known better, but the company absolutely should have known better and I have no problem holding them liable.

Post reply on HN