Live data from Hacker News

Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

reuters.com

181–190 of 285 posts

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#181

Earlier quoted context omitted.

Again, I believe this is simply false. The provision carrying "decades in prison" applies only to companies making over a billion dollars in revenue, and only in the very limited case where a particular officer of the company knowingly mis-certifies a report to the FTC.

The plain language of the law says that your interpretation is not correct. The criminal provisions apply to companies with over $1 billion in revenue or those those that have 1M or more users. That would expose a much larger range of independent developers to decades in prison.

No. I responded to this here:

https://news.ycombinator.com/item?id=18377585

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#182

Earlier quoted context omitted.

That's not a bad thing. The big tech companies are edging towards complete monopolies in their spaces and a significant part of this is that they know everything and they're allowed to leverage that data. Why would you go to anybody else to advertise? Unbundling this, making advertising harder again will spread out the budget, probably push more towards publishers rather than networks. Again, not a bad thing. It also…

I think it would be a pretty horrible thing if all these once free internet services suddenly cost money. Nobody seems to be thinking about the significant amount of people who wouldn't be able to afford monthly subscriptions to Facebook, Twitter, Reddit, etc. even if it did all add up to "only" $15/month. Poor people should not be priced out of the online spaces where modern discourse happens. Single mothers should…

Currently the price we all collectively pay for these “free” services is a decrease in the sanity of public discourse. Is that really a better option?

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#183

Earlier quoted context omitted.

I corrected my And to an OR so yes, good point but overall, it still doesn't impact "entire startup community". There are plenty of tech. businesses that don't hit 50 Million in revenue AND don't have a million users. I am talking about those.

True, but the issue is that getting 1M+ installs isn't under the control of the developer. Sometimes things go viral - look at Flappy Bird. Under this law, that guy (if he were in the US) could be looking at decades in prison unless he took enough investment money to comply. This law also uses a very broad definition of "personal information" that could possibly include IP addresses. So it does have an effect on the…

Flappy Bird might have a million customers but he could opt to not collect information on those users. If Apple/Google had the information that is their issue, not that of the app developer.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#184
post #182

Earlier quoted context omitted.

I think it would be a pretty horrible thing if all these once free internet services suddenly cost money. Nobody seems to be thinking about the significant amount of people who wouldn't be able to afford monthly subscriptions to Facebook, Twitter, Reddit, etc. even if it did all add up to "only" $15/month. Poor people should not be priced out of the online spaces where modern discourse happens. Single mothers should…

Currently the price we all collectively pay for these “free” services is a decrease in the sanity of public discourse. Is that really a better option?

How would subscription fees improve the discourse on social media sites?

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#185
This is an extremely frustrating headline. The draft bill we're discussing does not appear to establish "prison time" for "data privacy violations".

The bill "covers" any entity with over 1MM users (Flappy Bird) or $50MM in revenue over 3 years (most mid-sized startups). It creates a compliance regime, violations of which can be pursued by the FTC under its "Unfair Trade Practices" authority.

A subset of Covered Entities (those with over 50MM users [very few startups] or $1B in revenue [virtually no startups]) are further obligated by this proposal to file annual Data Protection Reports. If the CEO, CISO, or Chief Privacy Officer of one of those entities deliberately certifies such a report knowing it to be false, those specific people are liable for imprisonment.

Actual failure to comply with data protection and privacy requirements are not enough to get you charged criminally in this proposal. The violation that can actually get you imprisoned in this proposal would constitute a deliberate attempt to defraud the government. You have to be a relatively big company, fail to comply with the requirements of this draft, and then lie about it to the FTC to end up in prison.

(For what it's worth: I don't think this bill is going anywhere; it's a discussion draft by a single member of the minority party.)

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#186

I read this and immediately thought "oh shit, yet another regulation for a small bootstrapped software business where we try to be honest while the big guys will still find a way to circumvent it". Thankfully, I looked into the fine print and was wrong. This bill is only for Corporations that do over $50,000,000 in revenues or higher OR (EDITED from AND) have info on at least 1,000,000 or more customers. Of course, I…

IIRC from my brief skim this morning, it's $50MM over three years , so it might make more sense to think about it in terms of $16MM/yr. edit: I misread this

This is where it gets tricky as it says annually over past 3 years. So i thought it means 50 mil every year for past 3 years ?

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#187

Earlier quoted context omitted.

The plain language of the law says that your interpretation is not correct. The criminal provisions apply to companies with over $1 billion in revenue or those those that have 1M or more users. That would expose a much larger range of independent developers to decades in prison.

No. I responded to this here: https://news.ycombinator.com/item?id=18377585

A closer reading indicates seem to be correct that the criminal provisions only apply to those larger entities. However, ALL of the provisions in pages 26-33, which are significantly burdensome, still apply to All covered entities, which you can hit by just having 1 million user accounts.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#188

Earlier quoted context omitted.

No. I responded to this here: https://news.ycombinator.com/item?id=18377585

A closer reading indicates seem to be correct that the criminal provisions only apply to those larger entities. However, ALL of the provisions in pages 26-33, which are significantly burdensome, still apply to All covered entities, which you can hit by just having 1 million user accounts.

I responded to your comment about that here: https://news.ycombinator.com/item?id=18377564

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#189

Earlier quoted context omitted.

IIRC from my brief skim this morning, it's $50MM over three years , so it might make more sense to think about it in terms of $16MM/yr. edit: I misread this

This is where it gets tricky as it says annually over past 3 years. So i thought it means 50 mil every year for past 3 years ?

Oh, I think you're right. Thanks!

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#190
post #133

Earlier quoted context omitted.

You read that wrong. In order to NOT be a "covered entity," you must meet ALL of the following criteria: 1) Revenue of less than $50 million; AND 2) Must not have info on 1 million or more people; AND 3) cannot be a data broker That means an independent app developer who gets more than 1 million installs, or a website with more than 1 million users, IS a covered entity, regardless of revenue . Also, ANY "data broker,…

> gets more than 1 million installs, or a website with more than 1 million users, Incorrect, that would only be true if they collected and stored personal info on their users. Hopefully we see more apps and websites stop collecting this info, or a minimum started purging the data (i.e if you visited a site 1 time 5 years go they should not still have your data but many do)

If you read the bill's text:

> (12) PERSONAL INFORMATION. —The term 6 ‘‘personal information’’ means any information, re-gardless of how the information is collected, in-ferred, or obtained that is reasonably linkable to a specific consumer or consumer device.

So if you use an email address for your users to log in, or even a username, you are collecting personal information based on the vague nomenclature of this law. Device IDs might be the case too (though I think Apple at least now gives a per-app id, which means it can't be linked to external sources much now iirc).

Post reply on HN