Live data from Hacker News

Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

reuters.com

201–210 of 285 posts

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#201

Earlier quoted context omitted.

Very true in some cases, i.e. unrollme. But I also like free content and am mostly willing to trade a little privacy for access.

I think the trade-off should be a lot more explicit though, e.g. you get to choose whether pay 5€ per month or your usage data gets sold.

If you want to be GDPR compliant I don't think you can do that. If you offer the "usage data gets sold" option you also have to make that full opt-in _and_ not deny the service if they don't opt-in.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#202
post #144

Earlier quoted context omitted.

So then big corps do all their customer information risking behavior in spun out small wholly owned subsidiaries or even arms length non owned ones and if successful acquire them for some fixed amount but if they screw up with this law the company just folds and the parent is free from financial damage.

Generally speaking, judges and juries aren't idiots, and you can't hack around laws by claiming that your dog did it.

Software engineers tend to assume that (a) they are the smartest in the room, (b) legislation is exactly like code, (c) caselaw doesn't exist and (d) nobody has ever had to write complex rules before software was invented. All of which, we feel, qualifies us to poke holes in any legislation we happen to stumble across.

But, of course, it doesn't. Not even close.

By way of analogy, if someone looked at a link to a github repo and said "yeah well I can't see any GOTO 10 lines, I bet this will crash when the IP trace becomes Apache'd" I hope someone would be patient and polite in explaining the several levels of wrongness involved.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#203

Earlier quoted context omitted.

The question is not "is there anything that would clearly be burdensome?", but "am I confident enough that I am complying with these items, as retroactively interpreted by regulators?" You need to pay a lawyer to evaluate that for you, that's the cost, not whoever the bills sponsor says this is intended to target.

Can you cite an example of one of these requirements that you wouldn't be confident in being able to comply with? Also: how much do you think a legal consult costs? For any one item, I think we're talking a couple hundred bucks. Almost all of the language in the section we're referring to applies to just one requirement, which is to make data tech companies retain about consumers available upon request to those consu…

Most competent lawyers cost $400+/hr. For them to review your internal compliance policies and procedures (including your opt-in/out procedures. etc), privacy policy, etc. you could easily be looking at a few hundred hours. That doesn't include the external auditors that the bill wants you to have.

As you said in one of your comments, fortunately this bill as written will never come into law, both due to its implications, and the fact that its author is a single member of a minority party. This is one instance in which I am happy with our system of government.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#204
post #195

Earlier quoted context omitted.

If you read the bill's text: > (12) PERSONAL INFORMATION. —The term 6 ‘‘personal information’’ means any information, re-gardless of how the information is collected, in-ferred, or obtained that is reasonably linkable to a specific consumer or consumer device. So if you use an email address for your users to log in, or even a username, you are collecting personal information based on the vague nomenclature of this la…

Email address yes, anonymous username not likely You are posting like this is a bad thing, I think it is great, companies need to be held accountable for gobbling up personal data, and should be discouraged from collecting anything including email addresses, I get enough spam thank you.

Perhaps you could take some personal responsibility, and, you know, not give your email address to sites/apps that you don't want to have it?

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#205

Earlier quoted context omitted.

Can you cite an example of one of these requirements that you wouldn't be confident in being able to comply with? Also: how much do you think a legal consult costs? For any one item, I think we're talking a couple hundred bucks. Almost all of the language in the section we're referring to applies to just one requirement, which is to make data tech companies retain about consumers available upon request to those consu…

Most competent lawyers cost $400+/hr. For them to review your internal compliance policies and procedures (including your opt-in/out procedures. etc), privacy policy, etc. you could easily be looking at a few hundred hours. That doesn't include the external auditors that the bill wants you to have. As you said in one of your comments, fortunately this bill as written will never come into law, both due to its implicat…

This proposal doesn't require companies to do formal internal compliance reviews. It's not SOX or GLBA. For most startups, the legal overhead here would probably amount to a few phone calls with a lawyer.

My read is that it's less onerous than the California privacy statute that already covers a huge fraction of tech startups.

We do both security and privacy engineering work for our clients, most of whom are encumbered in one way or another by regs, and it is not the norm for legal to do line-item review of policies and procedures. SOC2 Type 1 audits are much closer to a mainstream practice, would almost certainly satisfy the "data protection" requirements in any rule the FTC would come up with, and certainly do not involve "a few hundred hours" of legal.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#206
post #2

Prison time for this is madness.

Prison time for executives is the only thing that gets taken seriously. Fines to executives can just be paid by executive insurance, and unless you crank them up to 4% of global revenue like GDPR, fines to the company will likely simply become cost of doing business. But threaten the executives with prison, and they'll suddenly make sure that the company complies with the law. I bet e.g. SOX would be taken a lot less…

Fair point. Maybe we should use this technique to protect software. Software engineers should go to jail for exposing vulnerabilities that are known. SQL Injection possible? You go to jail for ten years. Get root on your webserver? Fifteen years.

Data leak? Death.

In this way, all software will be secure.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#207

Earlier quoted context omitted.

Most competent lawyers cost $400+/hr. For them to review your internal compliance policies and procedures (including your opt-in/out procedures. etc), privacy policy, etc. you could easily be looking at a few hundred hours. That doesn't include the external auditors that the bill wants you to have. As you said in one of your comments, fortunately this bill as written will never come into law, both due to its implicat…

This proposal doesn't require companies to do formal internal compliance reviews. It's not SOX or GLBA. For most startups, the legal overhead here would probably amount to a few phone calls with a lawyer. My read is that it's less onerous than the California privacy statute that already covers a huge fraction of tech startups. We do both security and privacy engineering work for our clients, most of whom are encumber…

That's just not accurate. You should read pages 26-33 in detail. It wants external auditors to come in, and while consultation with a lawyer isn't required, companies would offensively have to use them to review everything they do, lest they be found non-compliant. That could easily range into hundreds of hours of legal work.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#208
post #133

Earlier quoted context omitted.

> gets more than 1 million installs, or a website with more than 1 million users, Incorrect, that would only be true if they collected and stored personal info on their users. Hopefully we see more apps and websites stop collecting this info, or a minimum started purging the data (i.e if you visited a site 1 time 5 years go they should not still have your data but many do)

If you read the bill's text: > (12) PERSONAL INFORMATION. —The term 6 ‘‘personal information’’ means any information, re-gardless of how the information is collected, in-ferred, or obtained that is reasonably linkable to a specific consumer or consumer device. So if you use an email address for your users to log in, or even a username, you are collecting personal information based on the vague nomenclature of this la…

That's analogous to a construction already in place in California privacy law, which is more prescriptive and onerous than this law is, so it's hard to make the argument that this federal act would wreck the startup ecosystem.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#209

Earlier quoted context omitted.

I corrected my And to an OR so yes, good point but overall, it still doesn't impact "entire startup community". There are plenty of tech. businesses that don't hit 50 Million in revenue AND don't have a million users. I am talking about those.

True, but the issue is that getting 1M+ installs isn't under the control of the developer. Sometimes things go viral - look at Flappy Bird. Under this law, that guy (if he were in the US) could be looking at decades in prison unless he took enough investment money to comply. This law also uses a very broad definition of "personal information" that could possibly include IP addresses. So it does have an effect on the…

I hope it passes. If there are significant problems, updates and changes can always be made. As for your comparison with the GDPR, I think it's way too early to start drawing conclusions.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#210

Earlier quoted context omitted.

So no more Facebooks, Tweeters, Ubers, Instagrams, Snapchats, etc? Sign me up!

That's a non-sequitur response; all of these are VC-funded startups that could easily have paid to comply with this proposal.

There are (I have reason to believe) plenty of non-VC funded social media apps. Easy to make, and people think they’re going to be as big as Facebook. I think that type of app will still get made, as people who can’t sort out funding are people I don’t expect to know the law.
Post reply on HN