I've said it before and I'll say it again: - Companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers. - I think EULAs are a ridiculous run-around the law. They should be non-enforceable. Its far from perfect, but case law is pretty clear that people and companies are liable for damages due to foreseeable harm that they cause. (Except EULAs dodge thi…
I kinda agree with you but it’s a tough one because what you’re describing is fining the victims of a crime. We don’t fine homeowners who fit cheap locks and get burgled do we. Pragmatically, it might be the right thing to do, but it feels wrong. Would you consider a due diligence to security threshold? That would certainly make it easier the well resourced to weasel out of fines, but when a small startup comes up ag…
Wouldn't you want your bank get fined if they aren't secure enough and loose your money? Or your local government if they loose your tax records because they think they don't need to lock their door?
The hard part will be determining whether the company could have done something about it (like locking the doors or the windows). If they could, they for sure should get a fine if they didn't.