Live data from Hacker News

Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

reuters.com

121–130 of 285 posts

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#121

The biggest unintended consequence I see is that more tech businesses will have to charge for their service rather than make money in opaque ways.

Or it could make things more transparent.

Twitter wouldn’t need to pretend that it didn’t know that a substantial part of its user base is fraud-bots if it just charged some nominal fees for something other than advertising.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#122
post #13

Earlier quoted context omitted.

It should be heavy per leaked datum fines like HIPAA. This would transform huge troves of personal data from assets to liabilities, which is what we need.

I wonder if the process could be modeled after the recording industry, where the owner of the information can sue for damages that are set at a pre-determined amount per violation.

Maybe we just need a doctrine where you own the copyright on your personal data.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#123
post #3

Earlier quoted context omitted.

It reads to me like the prison time in this bill is reserved for the crime of knowingly mis-certifying annual reports to the FTC on data protection (ie, for defrauding the government) --- those reports are also only required from businesses with $1B+ of revenue. The rest of the penalties in the bill seem to take the form of liability under FTC's "Unfair Trade Practices" authority.

Thanks for clarifying; I completely misunderstood that. If only journalists were half as good as you at reporting information...

Journalists are much better than me at obtaining and reporting information. This story just isn't very important; it's a "discussion draft" of controversial legislation by a lone member of the minority party. It wasn't allocated many resources by Reuters.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#124

I read this and immediately thought "oh shit, yet another regulation for a small bootstrapped software business where we try to be honest while the big guys will still find a way to circumvent it". Thankfully, I looked into the fine print and was wrong. This bill is only for Corporations that do over $50,000,000 in revenues or higher OR (EDITED from AND) have info on at least 1,000,000 or more customers. Of course, I…

You read that wrong. In order to NOT be a "covered entity," you must meet ALL of the following criteria:

1) Revenue of less than $50 million; AND 2) Must not have info on 1 million or more people; AND 3) cannot be a data broker

That means an independent app developer who gets more than 1 million installs, or a website with more than 1 million users, IS a covered entity, regardless of revenue. Also, ANY "data broker," regardless of size, is covered.

This info is on page 4 and 5.

Edit: How is a factual comment getting downvotes? OP read it wrong, and I told him so. There's nothing in this comment to disagree with. There are only facts.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#125

Earlier quoted context omitted.

Nope. The bill defines covered entities in Sec. 2.(5)(A) and 2.(5)(B). In particular, companies with less than $50,000,000 in gross receipts and information on fewer than 1,000,000 customers are not covered by this legislation. And even if those apply to your local coffee shop or whatever, Sec. 2(5)(B)(iii) further limits the definition of covered entity so that businesses that do not provide 3rd party access to info…

Unless inflation happens... This only applies to big businesses now, but in 25 years it will start effecting medium sized firms and it will eventually hit small businesses. This will create a morass of bureaucratic regulations stifling entrepreneurship...

Granting the assumption of monotonically increasing inflation at a wild rate, this is still only true ceteris paribus. I can't imagine inflation that would make a small coffee shop chain into 50m/year revenue (customer floor requirement notwithstanding) would happen in a vacuum.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#126

I read this and immediately thought "oh shit, yet another regulation for a small bootstrapped software business where we try to be honest while the big guys will still find a way to circumvent it". Thankfully, I looked into the fine print and was wrong. This bill is only for Corporations that do over $50,000,000 in revenues or higher OR (EDITED from AND) have info on at least 1,000,000 or more customers. Of course, I…

So then big corps do all their customer information risking behavior in spun out small wholly owned subsidiaries or even arms length non owned ones and if successful acquire them for some fixed amount but if they screw up with this law the company just folds and the parent is free from financial damage.

I am not an expert bill reader but seems like this loophole is covered as there is another point that says :

"(ii) is not substantially owned, oper ated, or controlled by a person, partner ship, or corporation that does not meet the 6 requirements under clause"

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#127
post #107

Earlier quoted context omitted.

That sounds like the renaissance we've all been waiting for. Every would-be entrepreneur's wet dream is a $20/month subscription for Facebook.

i would pay $2/month at most for facebook.

That cost is actually spot on: Facebook, for US users, makes about $26 per user per year IIRC.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#128

Earlier quoted context omitted.

> It needs punishment for the management who doesnt allow time to set things up properly Hard to show it was management's fault, and not the result of a developer who really didn't have the AWS skills (though that's probably still the fault of management, for not verifying skillsets before hiring or giving AWS keys) Everything we know about iteration cycles, quick access to devops resources, etc, will change when pri…

> Hard to show it was management's fault, and not the result of a developer... No. A leader is ultimately responsible for everything that happens or fails to happen under his or her leadership. Full stop. The people in charge of your hypothetical developer are the only ones with the ability to put processes in place to prevent it from happening. They are the least-cost avoider. Therefore, the power and the responsibi…

As a member of upper management, how would you address this then? More QA? More management of development practices? Move way from "devops" and back toward a world where there's a clear isolation between ops and development?

Over the past few years, developers have seen more and more autonomy and power. I can't imagine there's a way to avoid walking some of that back (if it can be)

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#130

I read this and immediately thought "oh shit, yet another regulation for a small bootstrapped software business where we try to be honest while the big guys will still find a way to circumvent it". Thankfully, I looked into the fine print and was wrong. This bill is only for Corporations that do over $50,000,000 in revenues or higher OR (EDITED from AND) have info on at least 1,000,000 or more customers. Of course, I…

You read that wrong. In order to NOT be a "covered entity," you must meet ALL of the following criteria: 1) Revenue of less than $50 million; AND 2) Must not have info on 1 million or more people; AND 3) cannot be a data broker That means an independent app developer who gets more than 1 million installs, or a website with more than 1 million users, IS a covered entity, regardless of revenue . Also, ANY "data broker,…

I corrected my And to an OR so yes, good point but overall, it still doesn't impact "entire startup community". There are plenty of tech. businesses that don't hit 50 Million in revenue AND don't have a million users. I am talking about those.
Post reply on HN