Live data from Hacker News

Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

reuters.com

231–240 of 285 posts

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#231

Earlier quoted context omitted.

Not any bill, just bills with breathtaking fines and possible imprisonment.

This is a frustrating thread. It starts with the claim that this law could put Flappy Bird on the hook for decades of prison time. I rebut, and you say (paraphrased) "no, read the law, anyone with 1MM users could be sent to prison for failure to comply". This is obviously not true. Then the claim becomes that pp26-33 of the statute has so many burdensome requirements that it would be impracticable for many startups t…

It starts with the claim that this law could put Flappy Bird on the hook for decades of prison time. I rebut, and you say (paraphrased) "no, read the law, anyone with 1MM users could be sent to prison for failure to comply". This is obviously not true.

Actually, with specific regard to Flappy Bird, it is true because it had more than 100 million installs, far surpassing the 50 million requirement to expose him to criminal as well as civil penalties. So, in contrast to your statement, it actually is true.

Now, the proposal does not in fact have an auditor requirement, but also, the clause that discusses auditors goes out of its way to make it clear that the types of third parties they're referring to are technical experts, which startups already use.

I'm not sure what you mean here. There is an auditor requirement "where reasonable," and presumably "reasonable" would be entirely up to a court's discretion. Also, "technical experts" in the context of this law, wouldn't necessarily be the developer of the site, but rather technical experts who are trained in complying with this law. Likely, that means someone brought in by a law firm or professional auditing outfit, at enormous expense.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#232

Earlier quoted context omitted.

That seems to be an entirely incorrect interpretation. Any app with more than 1 million users would fall under this law. You're simply reading it wrong, as the OP of this thread initially did. Any entity with personal information - as that term is (very broadly) defined in this document - on more than 1 million or more users is fully exposed to its civil and criminal penalties. This includes developers that just get…

No, I think you're confused. Having 1MM users makes you a "Covered Entity" in this draft. But "Covered Entities" aren't required to file data protection reports to the FTC until they make $1B in revenue or have 50MM users.† And, again: the "decades of imprisonment" 'downandout is talking about refers only to the crime of deliberately misreporting those data protection reports. It is not the case that any failure to c…

You are both right and wrong. Flappy Bird indeed had over 50MM users (in fact it had over 100MM users), and therefore its owner would have criminal liability under this law regardless of revenue. However you are right that the lower limit excludes people from criminal penalties. Having just 1MM user accounts still exposes them to the full brunt of the civil penalties available under this law that could easily bankrupt them. So if you have between 1MM and 50MM users, you won't go to prison, you'll just be broke.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#233
I find the notion of a do-not-track registry disturbing. It would actually become an identifier for you that could be used to link all the disjointed information collected under that identity. Kind of the opposite of what it's intended to do.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#234

Earlier quoted context omitted.

This is a frustrating thread. It starts with the claim that this law could put Flappy Bird on the hook for decades of prison time. I rebut, and you say (paraphrased) "no, read the law, anyone with 1MM users could be sent to prison for failure to comply". This is obviously not true. Then the claim becomes that pp26-33 of the statute has so many burdensome requirements that it would be impracticable for many startups t…

It starts with the claim that this law could put Flappy Bird on the hook for decades of prison time. I rebut, and you say (paraphrased) "no, read the law, anyone with 1MM users could be sent to prison for failure to comply". This is obviously not true. Actually, with specific regard to Flappy Bird, it is true because it had more than 100 million installs, far surpassing the 50 million requirement to expose him to cri…

No, you're still not correct, because the problem with your claim isn't simply that you have to be a larger company to face prison time, but that there's only one offense in the bill that includes that thread: knowingly certifying fraudulent data protection reports. I'm like the 4th person on this (broader) thread to point that out, and this is at least the 3rd time I've pointed it out to you.

By the way, did Flappy Bird even collect NPI? Or is this an even sillier example?

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#237
I've said it before, when it comes to mass surveillance,intentionally malicious backdoors and general societal loss of ptivacy, the solution should be primarly legislative not technical.

Good example: every store with a camera uses ML to identify customers and passerby's and shares this info with 3rd parties. Should we talk about how to best facial and gait ML analysis or is the answer simply criminally outlawing this practice?

Why can't I file a restraining order against big tech that states "if you identify activity and you correlate it with my identity,immediately erase it and take steps to avert similar activity data collection": because I feel bigtech's abuse of this data pauses a danger to my liberties and free excercise of my civil rights.

Modern privacy laws are overdue as it is and they need to be criminal,not civil.

Another one: ISPs would think twice about selling your celltower correlated location data and web/dns activity to 3rd parties if this meant jail time to the CEO. If this practice is outlawed with only fines and regulations as the penalty,the only person that can sue them is a well resourced attorney general or a very very wealthy person that can afford a multi year legal battle. Unfortunately,even when bigcorps break CFAA the FBI won't even listen to civilian complaints.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#238

Earlier quoted context omitted.

It starts with the claim that this law could put Flappy Bird on the hook for decades of prison time. I rebut, and you say (paraphrased) "no, read the law, anyone with 1MM users could be sent to prison for failure to comply". This is obviously not true. Actually, with specific regard to Flappy Bird, it is true because it had more than 100 million installs, far surpassing the 50 million requirement to expose him to cri…

No, you're still not correct , because the problem with your claim isn't simply that you have to be a larger company to face prison time, but that there's only one offense in the bill that includes that thread: knowingly certifying fraudulent data protection reports. I'm like the 4th person on this (broader) thread to point that out, and this is at least the 3rd time I've pointed it out to you. By the way, did Flappy…

there's only one offense in the bill that includes that thread: knowingly certifying fraudulent data protection reports.

That's what it says, but one would have to believe that failing to file such reports would also be a criminal violation in any final draft of the bill. Otherwise what would be the point of the bill? Does it make sense to you that they would have a bill like this, and provide a simple way to avoid it: just don't file? That appears to be an oversight by the author, but one would undoubtedly be fixed.

By the way, did Flappy Bird even collect NPI?

Since this bill uses a vague and legally untested definition of "personal information," simply maintaining weblogs containing IP addresses could trigger this.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#239

Earlier quoted context omitted.

No, you're still not correct , because the problem with your claim isn't simply that you have to be a larger company to face prison time, but that there's only one offense in the bill that includes that thread: knowingly certifying fraudulent data protection reports. I'm like the 4th person on this (broader) thread to point that out, and this is at least the 3rd time I've pointed it out to you. By the way, did Flappy…

there's only one offense in the bill that includes that thread: knowingly certifying fraudulent data protection reports. That's what it says, but one would have to believe that failing to file such reports would also be a criminal violation in any final draft of the bill. Otherwise what would be the point of the bill? Does it make sense to you that they would have a bill like this, and provide a simple way to avoid i…

You've now moved the goalposts past the present text of the proposal and into hypothetical future versions of it.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#240

Earlier quoted context omitted.

True, but the issue is that getting 1M+ installs isn't under the control of the developer. Sometimes things go viral - look at Flappy Bird. Under this law, that guy (if he were in the US) could be looking at decades in prison unless he took enough investment money to comply. This law also uses a very broad definition of "personal information" that could possibly include IP addresses. So it does have an effect on the…

Flappy Bird might have a million customers but he could opt to not collect information on those users. If Apple/Google had the information that is their issue, not that of the app developer.

Merely having web logs with IP addresses would seem to qualify under the definition of "personal information" in this bill.
Post reply on HN