> ...including jail time, if their companies steal and sell user data,
> or allow a massive data breach to occur at their company.
What if the government loses our data? Then what? Will they go to jail too?Software is a moving target. It has become such a complex endeavor, always changing, always evolving. It's difficult to determine who's responsible for which part of the system; and by this I'm not suggesting we abolish responsibility. Good outcomes will be the result of multiple forces, balanced in the right mix:
A. Users should ask more of their favorite companies (and mean it, e.g. boycott your favorite tech company when they behave unethically)
B. Legislators should be more mindful of the legislation they propose (for one separate data (re)selling from data breaches, and what exactly is my data vs data generated by machines, etc)
C. Reckless tech leaders should have their reputation affected by lose security, privacy & business practices
D. And engineers should be more aware their craft affects the lives of millions and maintain a high standard of quality across their work
In the grand scheme of things, we've just barely gotten off the ground with this thing called software. And software changed everything, but so did agriculture, which is 10,000 years old.
If we develop careless regulation and start throwing people in jail for software faults, we're hardly encouraging innovation.