Earlier quoted context omitted.
Very true in some cases, i.e. unrollme. But I also like free content and am mostly willing to trade a little privacy for access.
I think the trade-off should be a lot more explicit though, e.g. you get to choose whether pay 5€ per month or your usage data gets sold.
Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
201–210 of 285 posts
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#202Earlier quoted context omitted.
So then big corps do all their customer information risking behavior in spun out small wholly owned subsidiaries or even arms length non owned ones and if successful acquire them for some fixed amount but if they screw up with this law the company just folds and the parent is free from financial damage.
Generally speaking, judges and juries aren't idiots, and you can't hack around laws by claiming that your dog did it.
But, of course, it doesn't. Not even close.
By way of analogy, if someone looked at a link to a github repo and said "yeah well I can't see any GOTO 10 lines, I bet this will crash when the IP trace becomes Apache'd" I hope someone would be patient and polite in explaining the several levels of wrongness involved.
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#203Earlier quoted context omitted.
The question is not "is there anything that would clearly be burdensome?", but "am I confident enough that I am complying with these items, as retroactively interpreted by regulators?" You need to pay a lawyer to evaluate that for you, that's the cost, not whoever the bills sponsor says this is intended to target.
Can you cite an example of one of these requirements that you wouldn't be confident in being able to comply with? Also: how much do you think a legal consult costs? For any one item, I think we're talking a couple hundred bucks. Almost all of the language in the section we're referring to applies to just one requirement, which is to make data tech companies retain about consumers available upon request to those consu…
As you said in one of your comments, fortunately this bill as written will never come into law, both due to its implications, and the fact that its author is a single member of a minority party. This is one instance in which I am happy with our system of government.
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#204Earlier quoted context omitted.
If you read the bill's text: > (12) PERSONAL INFORMATION. —The term 6 ‘‘personal information’’ means any information, re-gardless of how the information is collected, in-ferred, or obtained that is reasonably linkable to a specific consumer or consumer device. So if you use an email address for your users to log in, or even a username, you are collecting personal information based on the vague nomenclature of this la…
Email address yes, anonymous username not likely You are posting like this is a bad thing, I think it is great, companies need to be held accountable for gobbling up personal data, and should be discouraged from collecting anything including email addresses, I get enough spam thank you.
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#205Earlier quoted context omitted.
Can you cite an example of one of these requirements that you wouldn't be confident in being able to comply with? Also: how much do you think a legal consult costs? For any one item, I think we're talking a couple hundred bucks. Almost all of the language in the section we're referring to applies to just one requirement, which is to make data tech companies retain about consumers available upon request to those consu…
Most competent lawyers cost $400+/hr. For them to review your internal compliance policies and procedures (including your opt-in/out procedures. etc), privacy policy, etc. you could easily be looking at a few hundred hours. That doesn't include the external auditors that the bill wants you to have. As you said in one of your comments, fortunately this bill as written will never come into law, both due to its implicat…
My read is that it's less onerous than the California privacy statute that already covers a huge fraction of tech startups.
We do both security and privacy engineering work for our clients, most of whom are encumbered in one way or another by regs, and it is not the norm for legal to do line-item review of policies and procedures. SOC2 Type 1 audits are much closer to a mainstream practice, would almost certainly satisfy the "data protection" requirements in any rule the FTC would come up with, and certainly do not involve "a few hundred hours" of legal.
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#206Prison time for this is madness.
Prison time for executives is the only thing that gets taken seriously. Fines to executives can just be paid by executive insurance, and unless you crank them up to 4% of global revenue like GDPR, fines to the company will likely simply become cost of doing business. But threaten the executives with prison, and they'll suddenly make sure that the company complies with the law. I bet e.g. SOX would be taken a lot less…
Data leak? Death.
In this way, all software will be secure.
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#207Earlier quoted context omitted.
Most competent lawyers cost $400+/hr. For them to review your internal compliance policies and procedures (including your opt-in/out procedures. etc), privacy policy, etc. you could easily be looking at a few hundred hours. That doesn't include the external auditors that the bill wants you to have. As you said in one of your comments, fortunately this bill as written will never come into law, both due to its implicat…
This proposal doesn't require companies to do formal internal compliance reviews. It's not SOX or GLBA. For most startups, the legal overhead here would probably amount to a few phone calls with a lawyer. My read is that it's less onerous than the California privacy statute that already covers a huge fraction of tech startups. We do both security and privacy engineering work for our clients, most of whom are encumber…
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#208Earlier quoted context omitted.
> gets more than 1 million installs, or a website with more than 1 million users, Incorrect, that would only be true if they collected and stored personal info on their users. Hopefully we see more apps and websites stop collecting this info, or a minimum started purging the data (i.e if you visited a site 1 time 5 years go they should not still have your data but many do)
If you read the bill's text: > (12) PERSONAL INFORMATION. —The term 6 ‘‘personal information’’ means any information, re-gardless of how the information is collected, in-ferred, or obtained that is reasonably linkable to a specific consumer or consumer device. So if you use an email address for your users to log in, or even a username, you are collecting personal information based on the vague nomenclature of this la…
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#209Earlier quoted context omitted.
I corrected my And to an OR so yes, good point but overall, it still doesn't impact "entire startup community". There are plenty of tech. businesses that don't hit 50 Million in revenue AND don't have a million users. I am talking about those.
True, but the issue is that getting 1M+ installs isn't under the control of the developer. Sometimes things go viral - look at Flappy Bird. Under this law, that guy (if he were in the US) could be looking at decades in prison unless he took enough investment money to comply. This law also uses a very broad definition of "personal information" that could possibly include IP addresses. So it does have an effect on the…
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#210Earlier quoted context omitted.
So no more Facebooks, Tweeters, Ubers, Instagrams, Snapchats, etc? Sign me up!
That's a non-sequitur response; all of these are VC-funded startups that could easily have paid to comply with this proposal.