Live data from Hacker News

Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

reuters.com

171–180 of 285 posts

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#171

That is a stiffer sentence than a second degree murder charge which is 15-years in California. https://en.wikipedia.org/wiki/Murder_(United_States_law)#Cal...

Also less of a sentence than purposely infecting others with aids in California.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#172

Earlier quoted context omitted.

No, it would kill all American software/web startups by limiting them to 999,999 users, unless they have millions of dollars in VC funding that they can use to comply with this law. It would strangle the startup community, as most startups (even those with 1M+ users) can never hope to have the resources to comply. You have to remember that the reason that startups get any funding is because investors hope that they w…

What requirements of this law do you believe would be impracticable to comply with without millions of VC funding?

I'm not GP, but it looks like the more burdensome things are on pages 26-33, and they are too lengthy to post here. I can see compliance costing significant sums that would be out of reach to a typical startup.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#173

The biggest unintended consequence I see is that more tech businesses will have to charge for their service rather than make money in opaque ways.

That's not a bad thing. The big tech companies are edging towards complete monopolies in their spaces and a significant part of this is that they know everything and they're allowed to leverage that data. Why would you go to anybody else to advertise? Unbundling this, making advertising harder again will spread out the budget, probably push more towards publishers rather than networks. Again, not a bad thing. It also…

I think it would be a pretty horrible thing if all these once free internet services suddenly cost money. Nobody seems to be thinking about the significant amount of people who wouldn't be able to afford monthly subscriptions to Facebook, Twitter, Reddit, etc. even if it did all add up to "only" $15/month. Poor people should not be priced out of the online spaces where modern discourse happens. Single mothers should not be priced out of getting to post baby pictures on Facebook. I think it's indicative of living in bubbles that nobody else seems to be giving this consideration any weight.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#174
post #122

Earlier quoted context omitted.

I wonder if the process could be modeled after the recording industry, where the owner of the information can sue for damages that are set at a pre-determined amount per violation.

Maybe we just need a doctrine where you own the copyright on your personal data.

As long as it's non-transferable.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#175

Earlier quoted context omitted.

So the app developer has to be able to demonstrate they followed some form of best practice with regard to user data. I think you're downplaying the requirements of this law. You should read it, it's pretty onerous and carries decades in prison with it - even GDPR didn't go that far. One interesting caveat, however, is that at least as written, I can't find anything imposing penalties for simply not filing the report…

Again, I believe this is simply false. The provision carrying "decades in prison" applies only to companies making over a billion dollars in revenue, and only in the very limited case where a particular officer of the company knowingly mis-certifies a report to the FTC.

The plain language of the law says that your interpretation is not correct. The criminal provisions apply to companies with over $1 billion in revenue or those those that have 1M or more users. That would expose a much larger range of independent developers to decades in prison.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#176
post #15

Earlier quoted context omitted.

I agree. The journalist who posted the original article was too busy to put a link to the proposed bill. [EDIT: link: https://www.wyden.senate.gov/imo/media/doc/Wyden%20Privacy%2... ] To those who say white collar crime is out of control, I agree, but we don't get it under control by criminalizing new things. We control it through fairer and better enforcement of things that are already illegal. I strongly suspect th…

> I strongly suspect the only people criminally prosecuted under such a bill will be patsies The only people that can be prosecuted under it are the chief executive officer, the chief privacy officer, and the chief information security officer. The thing that is criminal under this bill and thus can subject them to prosecution is, despite what most news stories imply, not violating privacy. The bill requires the comp…

> are the chief executive officer, the chief privacy officer, and the chief information security officer.

So what you are saying is companies should make sure not to have the latter two positions?

A CEO gets paid enough they can handle the risk, but the other two positions don't make nearly enough to exist in the face of risk like this.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#177

Earlier quoted context omitted.

What requirements of this law do you believe would be impracticable to comply with without millions of VC funding?

I'm not GP, but it looks like the more burdensome things are on pages 26-33, and they are too lengthy to post here. I can see compliance costing significant sums that would be out of reach to a typical startup.

Could you be specific about any of the "burdensome" requirements? You don't need to post all of them; I've read the same draft you have.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#178

Earlier quoted context omitted.

True, but the issue is that getting 1M+ installs isn't under the control of the developer. Sometimes things go viral - look at Flappy Bird. Under this law, that guy (if he were in the US) could be looking at decades in prison unless he took enough investment money to comply. This law also uses a very broad definition of "personal information" that could possibly include IP addresses. So it does have an effect on the…

No, he couldn't. I think you need to read the draft more carefully. Flappy Bird, in the scenario you describe, is explicitly exempt from imprisonment under this proposal.

That seems to be an entirely incorrect interpretation. Any app with more than 1 million users would fall under this law. You're simply reading it wrong, as the OP of this thread initially did. Any entity with personal information - as that term is (very broadly) defined in this document - on more than 1 million or more users is fully exposed to its civil and criminal penalties. This includes developers that just get lucky and get 1 million or more installs, and who have no way to pay for compliance.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#179
post #141
post #136

So Facebook, google, Microsoft, et al, will continue to sell my attention, and now pass the insurance bill onto me. Lol. I know, it’s for my security.

As you mentioned Facebook, Google, & in large part Microsoft sell your attention. How do you propose that they are going to pass the insurance tab onto you?

Internet tax

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#180

Earlier quoted context omitted.

No, he couldn't. I think you need to read the draft more carefully. Flappy Bird, in the scenario you describe, is explicitly exempt from imprisonment under this proposal.

That seems to be an entirely incorrect interpretation. Any app with more than 1 million users would fall under this law. You're simply reading it wrong, as the OP of this thread initially did. Any entity with personal information - as that term is (very broadly) defined in this document - on more than 1 million or more users is fully exposed to its civil and criminal penalties. This includes developers that just get…

No, I think you're confused. Having 1MM users makes you a "Covered Entity" in this draft. But "Covered Entities" aren't required to file data protection reports to the FTC until they make $1B in revenue or have 50MM users.† And, again: the "decades of imprisonment" 'downandout is talking about refers only to the crime of deliberately misreporting those data protection reports. It is not the case that any failure to comply with this law has prison time attached.

Happy to be wrong about this; if I am, please offer a cite.

Sec 5. (a) (1)

Post reply on HN