Live data from Hacker News

Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

reuters.com

161–170 of 285 posts

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#161

Earlier quoted context omitted.

Phew! That would be a net positive for the world, long term, to bear less of a greasy footprint from american startup antics.

No, it would kill all American software/web startups by limiting them to 999,999 users, unless they have millions of dollars in VC funding that they can use to comply with this law. It would strangle the startup community, as most startups (even those with 1M+ users) can never hope to have the resources to comply. You have to remember that the reason that startups get any funding is because investors hope that they w…

What requirements of this law do you believe would be impracticable to comply with without millions of VC funding?

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#162

Earlier quoted context omitted.

No, it would kill all American software/web startups by limiting them to 999,999 users, unless they have millions of dollars in VC funding that they can use to comply with this law. It would strangle the startup community, as most startups (even those with 1M+ users) can never hope to have the resources to comply. You have to remember that the reason that startups get any funding is because investors hope that they w…

So no more Facebooks, Tweeters, Ubers, Instagrams, Snapchats, etc? Sign me up!

That's a non-sequitur response; all of these are VC-funded startups that could easily have paid to comply with this proposal.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#163

Earlier quoted context omitted.

I hear this a lot and have never had anyone explain what laws were broken by those executives.

Fraud. The ratings agencies lied about the credit worthiness of the mortgages that they bundled.

As the Devil's Advocate, one can argue that the fraud was perpetrated at the peon level of the loan originators, who originated loans to people that could not afford the loans. The executives hands were washed clean by the ratings agencies that gave out AAA ratings. Those high ratings were "reasonable" because the loans were consolidated into CDOs and the top traunche(s) of the CDOs can handle a few missed payments from some of the debtors. In hindsight, many of those products probably should not have been AAA rated (especially ones that consolidated lower traunches of other CDOs). If there was a law that stated that ratings agency executives go to jail when AAA rated products fail (i.e., make them strictly liable for top rated products instead of relying on reputation alone), those executives would likely pay better attention to which products get AAA ratings. Looking back, there was no such law and the ratings agencies were free to give out improper ratings backed by their reputations.

Skipping back to private consumer data, a law that clearly states that executives go to jail when there is a breach of private consumer data would likely increase the chances that the executives will pay better attention to what data is collected, how data is stored, and how data is protected.

Tangential topic: an interesting regulatory idea would be to have mandatory jail time for all executives (and board members) of a company of a minimum size that is successfully sued in a class action for more than X dollars. Make it strictly liable so that no direct knowledge is required to convict so as to punish executives who allow their companies to harm the public. If an executive allows their company to harm the public, then that person is not fit to serve as an executive.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#164

Earlier quoted context omitted.

I corrected my And to an OR so yes, good point but overall, it still doesn't impact "entire startup community". There are plenty of tech. businesses that don't hit 50 Million in revenue AND don't have a million users. I am talking about those.

True, but the issue is that getting 1M+ installs isn't under the control of the developer. Sometimes things go viral - look at Flappy Bird. Under this law, that guy (if he were in the US) could be looking at decades in prison unless he took enough investment money to comply. This law also uses a very broad definition of "personal information" that could possibly include IP addresses. So it does have an effect on the…

You think someone can compete with Google or Facebook without massive amounts of capital?

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#165

Earlier quoted context omitted.

I corrected my And to an OR so yes, good point but overall, it still doesn't impact "entire startup community". There are plenty of tech. businesses that don't hit 50 Million in revenue AND don't have a million users. I am talking about those.

True, but the issue is that getting 1M+ installs isn't under the control of the developer. Sometimes things go viral - look at Flappy Bird. Under this law, that guy (if he were in the US) could be looking at decades in prison unless he took enough investment money to comply. This law also uses a very broad definition of "personal information" that could possibly include IP addresses. So it does have an effect on the…

No, he couldn't. I think you need to read the draft more carefully. Flappy Bird, in the scenario you describe, is explicitly exempt from imprisonment under this proposal.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#166

Earlier quoted context omitted.

So the app developer has to be able to demonstrate they followed some form of best practice with regard to user data. I’m having trouble thinking of any other type of work that manages to escape all liability.

So the app developer has to be able to demonstrate they followed some form of best practice with regard to user data. I think you're downplaying the requirements of this law. You should read it, it's pretty onerous and carries decades in prison with it - even GDPR didn't go that far. One interesting caveat, however, is that at least as written, I can't find anything imposing penalties for simply not filing the report…

Again, I believe this is simply false. The provision carrying "decades in prison" applies only to companies making over a billion dollars in revenue, and only in the very limited case where a particular officer of the company knowingly mis-certifies a report to the FTC.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#167
post #157

Earlier quoted context omitted.

What I mean is that it's become a major part of the US's economy. Globally, this industry probably generates 100s of billions of dollars, and those companies mostly spend their revenue on more software, more hardware, more research, more computer scientists, more computer engineers, etc. Indirectly, probably almost all of us here are partially paid from the ad-network-value-chain. And, what about all of the open sour…

Sounds like a labor mis-allocation bubble. Bubbles burst. Furthermore bubbles should burst, for the health of the economy.

How is this a bubble? Unlike previous bubbles, the current technology surge is actually funded by real value, real demand, real revenues, and gigantic profits.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#168
post #43

This would probably mean more compensation at executive level for the increased risks!

Maybe. That compensation would still have to come out of company's coffers. Either way, this law will definitely make large companies spend money - as it should, because that's what you buy back risk with.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#169
post #153

Earlier quoted context omitted.

I am not an expert bill reader but seems like this loophole is covered as there is another point that says : "(ii) is not substantially owned, oper ated, or controlled by a person, partner ship, or corporation that does not meet the 6 requirements under clause"

Contracting it out still seems to bypass the regulation

Tbh thats still a better outcome than the status quo isn’t it: a single hack is now limited in damage, and multiple are required to do the equivalent of todays scenarios

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#170
post #153

Earlier quoted context omitted.

I am not an expert bill reader but seems like this loophole is covered as there is another point that says : "(ii) is not substantially owned, oper ated, or controlled by a person, partner ship, or corporation that does not meet the 6 requirements under clause"

Contracting it out still seems to bypass the regulation

“Controlled”
Post reply on HN