Live data from Hacker News

Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

reuters.com

191–200 of 285 posts

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#191

This is an extremely frustrating headline. The draft bill we're discussing does not appear to establish "prison time" for "data privacy violations". The bill "covers" any entity with over 1MM users (Flappy Bird) or $50MM in revenue over 3 years (most mid-sized startups). It creates a compliance regime, violations of which can be pursued by the FTC under its "Unfair Trade Practices" authority. A subset of Covered Enti…

> (For what it's worth: I don't think this bill is going anywhere; it's a discussion draft by a single member of the minority party.)

Ron Wyden is indeed a single member of the minority party, but he is establishing himself as one of the leading voices on these issues. Christopher Soghoian probably played a big role in drafting this bill as his Senior Advisor for Privacy and Cybersecurity.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#192

Earlier quoted context omitted.

Phew! That would be a net positive for the world, long term, to bear less of a greasy footprint from american startup antics.

No, it would kill all American software/web startups by limiting them to 999,999 users, unless they have millions of dollars in VC funding that they can use to comply with this law. It would strangle the startup community, as most startups (even those with 1M+ users) can never hope to have the resources to comply. You have to remember that the reason that startups get any funding is because investors hope that they w…

"It costs money to comply" is a tired argument that gets trotted out every time a new business regulation gets proposed, no matter what the regulation is. All regulations cost money to comply with. Are you arguing against all business regulations?

If your problem is actually with the number of users, please propose a specific number of users that would make a better limit.

EDIT: This is also the exact same kind of "sky is falling" rhetoric that came with HIPPA. Lo and behold, we still have large and small doctors' offices, and have taken the first steps towards actually protecting customer health records.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#193

Earlier quoted context omitted.

I'm not GP, but it looks like the more burdensome things are on pages 26-33, and they are too lengthy to post here. I can see compliance costing significant sums that would be out of reach to a typical startup.

Could you be specific about any of the "burdensome" requirements? You don't need to post all of them; I've read the same draft you have.

The question is not "is there anything that would clearly be burdensome?", but "am I confident enough that I am complying with these items, as retroactively interpreted by regulators?"

You need to pay a lawyer to evaluate that for you, that's the cost, not whoever the bills sponsor says this is intended to target.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#194
post #182

Earlier quoted context omitted.

Currently the price we all collectively pay for these “free” services is a decrease in the sanity of public discourse. Is that really a better option?

How would subscription fees improve the discourse on social media sites?

Currently, social media users are the goods being sold, so the companies running the networks don’t have much interest in offering tools and algorithms for high quality discussion. With paying customers the situation would be very different. (Not that it’s going to happen – I’m just saying that we already pay a hefty price for the “free” services.)

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#195
post #133

Earlier quoted context omitted.

> gets more than 1 million installs, or a website with more than 1 million users, Incorrect, that would only be true if they collected and stored personal info on their users. Hopefully we see more apps and websites stop collecting this info, or a minimum started purging the data (i.e if you visited a site 1 time 5 years go they should not still have your data but many do)

If you read the bill's text: > (12) PERSONAL INFORMATION. —The term 6 ‘‘personal information’’ means any information, re-gardless of how the information is collected, in-ferred, or obtained that is reasonably linkable to a specific consumer or consumer device. So if you use an email address for your users to log in, or even a username, you are collecting personal information based on the vague nomenclature of this la…

Email address yes, anonymous username not likely

You are posting like this is a bad thing, I think it is great, companies need to be held accountable for gobbling up personal data, and should be discouraged from collecting anything including email addresses, I get enough spam thank you.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#196

This is an extremely frustrating headline. The draft bill we're discussing does not appear to establish "prison time" for "data privacy violations". The bill "covers" any entity with over 1MM users (Flappy Bird) or $50MM in revenue over 3 years (most mid-sized startups). It creates a compliance regime, violations of which can be pursued by the FTC under its "Unfair Trade Practices" authority. A subset of Covered Enti…

> (For what it's worth: I don't think this bill is going anywhere; it's a discussion draft by a single member of the minority party.) Ron Wyden is indeed a single member of the minority party, but he is establishing himself as one of the leading voices on these issues. Christopher Soghoian probably played a big role in drafting this bill as his Senior Advisor for Privacy and Cybersecurity.

When the bill gets a Republican co-sponsor, it'll be time to take it seriously as "news".

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#197

Why are bills like these always drafted after the fact? E.g. Equifax, Google+, Facebook hack, etc. It would be common sense to pass laws before it happened and would of incentivize companies to beef up security.

Because not enough people care enough for it to register politically until a disaster brings it to public attention.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#198

Earlier quoted context omitted.

Could you be specific about any of the "burdensome" requirements? You don't need to post all of them; I've read the same draft you have.

The question is not "is there anything that would clearly be burdensome?", but "am I confident enough that I am complying with these items, as retroactively interpreted by regulators?" You need to pay a lawyer to evaluate that for you, that's the cost, not whoever the bills sponsor says this is intended to target.

Can you cite an example of one of these requirements that you wouldn't be confident in being able to comply with? Also: how much do you think a legal consult costs? For any one item, I think we're talking a couple hundred bucks.

Almost all of the language in the section we're referring to applies to just one requirement, which is to make data tech companies retain about consumers available upon request to those consumers. That's something responsible companies already do, many because they're already by regulation required to do so.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#199
The problematic aspect of regulation is that you don't just need to comply, you need to _convince the regulators_ that you've complied. A better approach is to create liability for certain specific failures if the company didn't follow reasonable best practices, which means you might get sued, but in that case it would be on the plaintiff to show that you didn't follow best practices, rather than the regulatory approach which makes it a burden on the company to prove to regulators (who have no incentive to keep costs of compliance down, or even limit themselves to cases where customers are in some sense harmed).

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#200
post #194

Earlier quoted context omitted.

How would subscription fees improve the discourse on social media sites?

Currently, social media users are the goods being sold, so the companies running the networks don’t have much interest in offering tools and algorithms for high quality discussion. With paying customers the situation would be very different. (Not that it’s going to happen – I’m just saying that we already pay a hefty price for the “free” services.)

If I had to test that hypothesis I would consider the comments section on the NYT (a website that requires a subscription to access more than 10 articles a month). Just checking the comments section there shows that people are just as vitriolic there _even_ if they've posted on more than 10 articles that month.

I'm comfortable saying that paid networks won't in-and-of-themselves improve conversation.

Post reply on HN