Live data from Hacker News

Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

reuters.com

211–220 of 285 posts

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#211

Earlier quoted context omitted.

This proposal doesn't require companies to do formal internal compliance reviews. It's not SOX or GLBA. For most startups, the legal overhead here would probably amount to a few phone calls with a lawyer. My read is that it's less onerous than the California privacy statute that already covers a huge fraction of tech startups. We do both security and privacy engineering work for our clients, most of whom are encumber…

That's just not accurate. You should read pages 26-33 in detail. It wants external auditors to come in, and while consultation with a lawyer isn't required , companies would offensively have to use them to review everything they do, lest they be found non-compliant. That could easily range into hundreds of hours of legal work.

I believe I'm one of the "auditors or independent technical experts" this bill refers to (trust me, we don't need Wyden's help getting work), and for the most part the only time we talk to client legal is when we're negotiating our contract. Note also the "if reasonably possible" attached to getting external assessment.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#212
post #131

Earlier quoted context omitted.

$50bn/year would be more revenue than fb had in 2017, though of course the majority of their 2.23bn monthly users would disappear if asked for $.01/mo. It is an interesting thought experiment, though, to consider what facebook would look like if its revenue was derived from convincing users that it was worth a monthly subscription.

Running Facebook would become much cheaper if they could focus on being a social network instead of being an ad selling business. Right now they have to do both.

I think you're right. When they bought Instagram, it had less than 20 employees because all they had to do was keep the service running.

I compare that with Twitter at the time had two thousand employees. It makes no sense to me.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#213
post #169
post #153

Earlier quoted context omitted.

Contracting it out still seems to bypass the regulation

Tbh thats still a better outcome than the status quo isn’t it: a single hack is now limited in damage, and multiple are required to do the equivalent of todays scenarios

What if everyone contracts out the data collection to a single party? Only giving the data a larger exposure.

I'm really glad this is coming to light and I hope it passes. It will be very interesting to see how companies try to avoid it, but at first glance, it seems well thought out.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#214

Earlier quoted context omitted.

No it’s not. People should be jailed for messing with other people’s lives. Don’t gather data if you can’t protect it.

The part that scares me that management could held legally accountable for a mistake of a developer.

Hire good developers. Or prove the developer is at fault. Then the developer should be jailed. Developers should be responsible for deploying good code. Software engineers act like they are professionals, want to get paid like they are professionals, want to be treated like they are professionals but don’t want to take on the ethical argument. Maybe they should be required to take ethical exams like other professions.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#215

Earlier quoted context omitted.

That's just not accurate. You should read pages 26-33 in detail. It wants external auditors to come in, and while consultation with a lawyer isn't required , companies would offensively have to use them to review everything they do, lest they be found non-compliant. That could easily range into hundreds of hours of legal work.

I believe I'm one of the "auditors or independent technical experts" this bill refers to (trust me, we don't need Wyden's help getting work), and for the most part the only time we talk to client legal is when we're negotiating our contract. Note also the "if reasonably possible" attached to getting external assessment.

You're referring to that specific provision, but again you aren't considering the fact that any business interested in complying will have to have an attorney review the law, and then review all aspects of their business, software implementation, and policies/procedures in order to ensure they are compliant. That's not a requirement of the law, but how else can they ensure that they are compliant?

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#216

Earlier quoted context omitted.

i would pay $2/month at most for facebook.

That cost is actually spot on: Facebook, for US users, makes about $26 per user per year IIRC.

I know the majority of people I know have at least 2 fb accounts. And then considering bots and other things. I'd imagine then that at least double your quoted amount per real human.

Which is bonkers to me personally considering how little I use it.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#217

I read this and immediately thought "oh shit, yet another regulation for a small bootstrapped software business where we try to be honest while the big guys will still find a way to circumvent it". Thankfully, I looked into the fine print and was wrong. This bill is only for Corporations that do over $50,000,000 in revenues or higher OR (EDITED from AND) have info on at least 1,000,000 or more customers. Of course, I…

That ultimately doesn't matter. The bill has zero shot at passing and becoming law. Wyden doesn't have anywhere near the votes he would need, so it's essentially his fantasy idea of a bill.

There's no privacy law that is going to get passed by the US Government, focused on large corporations, that involves sending violators to prison for up to 20 years.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#218

Earlier quoted context omitted.

I believe I'm one of the "auditors or independent technical experts" this bill refers to (trust me, we don't need Wyden's help getting work), and for the most part the only time we talk to client legal is when we're negotiating our contract. Note also the "if reasonably possible" attached to getting external assessment.

You're referring to that specific provision, but again you aren't considering the fact that any business interested in complying will have to have an attorney review the law, and then review all aspects of their business, software implementation, and policies/procedures in order to ensure they are compliant. That's not a requirement of the law, but how else can they ensure that they are compliant?

At this point, we've scaled back the argument from "this bill would kill startups" to "any bill would kill startups".

That's a coherent position, but not one we can reasonably hope to debate about between each other.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#219

Earlier quoted context omitted.

You're referring to that specific provision, but again you aren't considering the fact that any business interested in complying will have to have an attorney review the law, and then review all aspects of their business, software implementation, and policies/procedures in order to ensure they are compliant. That's not a requirement of the law, but how else can they ensure that they are compliant?

At this point, we've scaled back the argument from "this bill would kill startups" to " any bill would kill startups". That's a coherent position, but not one we can reasonably hope to debate about between each other.

Not any bill, just bills with breathtaking fines and possible imprisonment.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#220
post #169

Earlier quoted context omitted.

Tbh thats still a better outcome than the status quo isn’t it: a single hack is now limited in damage, and multiple are required to do the equivalent of todays scenarios

What if everyone contracts out the data collection to a single party? Only giving the data a larger exposure. I'm really glad this is coming to light and I hope it passes. It will be very interesting to see how companies try to avoid it, but at first glance, it seems well thought out.

If that company has 1,000,000 or more customers' data, then they're no longer exempt. Maybe you came in after the OOP did their edit.
Post reply on HN