Live data from Hacker News

Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

reuters.com

241–250 of 285 posts

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#241

Earlier quoted context omitted.

I corrected my And to an OR so yes, good point but overall, it still doesn't impact "entire startup community". There are plenty of tech. businesses that don't hit 50 Million in revenue AND don't have a million users. I am talking about those.

True, but the issue is that getting 1M+ installs isn't under the control of the developer. Sometimes things go viral - look at Flappy Bird. Under this law, that guy (if he were in the US) could be looking at decades in prison unless he took enough investment money to comply. This law also uses a very broad definition of "personal information" that could possibly include IP addresses. So it does have an effect on the…

> Like GDPR, it locks in entrenched competitors.

This just isn't true.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#242

Earlier quoted context omitted.

there's only one offense in the bill that includes that thread: knowingly certifying fraudulent data protection reports. That's what it says, but one would have to believe that failing to file such reports would also be a criminal violation in any final draft of the bill. Otherwise what would be the point of the bill? Does it make sense to you that they would have a bill like this, and provide a simple way to avoid i…

You've now moved the goalposts past the present text of the proposal and into hypothetical future versions of it .

That's not "moving goalposts" as you put it. Are you saying that you believe that they would allow such an enormous loophole in such a bill?

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#243
post #157

Earlier quoted context omitted.

What I mean is that it's become a major part of the US's economy. Globally, this industry probably generates 100s of billions of dollars, and those companies mostly spend their revenue on more software, more hardware, more research, more computer scientists, more computer engineers, etc. Indirectly, probably almost all of us here are partially paid from the ad-network-value-chain. And, what about all of the open sour…

Sounds like a labor mis-allocation bubble. Bubbles burst. Furthermore bubbles should burst, for the health of the economy.

I have been blocking advertising on my computers and phones for close to a decade now. I am ad-free. And yet the bubble persists. This industry is beyond mere logic.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#244
post #195

Earlier quoted context omitted.

If you read the bill's text: > (12) PERSONAL INFORMATION. —The term 6 ‘‘personal information’’ means any information, re-gardless of how the information is collected, in-ferred, or obtained that is reasonably linkable to a specific consumer or consumer device. So if you use an email address for your users to log in, or even a username, you are collecting personal information based on the vague nomenclature of this la…

Email address yes, anonymous username not likely You are posting like this is a bad thing, I think it is great, companies need to be held accountable for gobbling up personal data, and should be discouraged from collecting anything including email addresses, I get enough spam thank you.

A lot of people can be tracked down by their online aliases unless the person has gone through a lot of work to make sure they keep their aliases separate (which isn't as easy as it sounds). That means that by definition most aliases and usernames can be googled to find a specific person and thus would fall under personal information according to the law.

You think email addresses are bad but the masses hate having to remember usernames. Emails aren't used for logins because of marketing (all those systems already had email verification in addition to usernames, thus email was required). Furthermore, without an email it becomes impossible to recover your account if you forget your password. If the app has no personal information and email and you forget your password (which most general users do) then it's impossible to recover your account.

So this law isn't going to discourage companies from collecting your email address, it just has the potential to add burdens to companies that end up with 1 million signups (even for a free website).

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#246
post #144

Earlier quoted context omitted.

So then big corps do all their customer information risking behavior in spun out small wholly owned subsidiaries or even arms length non owned ones and if successful acquire them for some fixed amount but if they screw up with this law the company just folds and the parent is free from financial damage.

Generally speaking, judges and juries aren't idiots, and you can't hack around laws by claiming that your dog did it.

That's the meme, but it's not true. Look at Trump's abuse of tax law, just to pick a popular example. Or Hollywood accounting, a classic example.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#247

I read this and immediately thought "oh shit, yet another regulation for a small bootstrapped software business where we try to be honest while the big guys will still find a way to circumvent it". Thankfully, I looked into the fine print and was wrong. This bill is only for Corporations that do over $50,000,000 in revenues or higher OR (EDITED from AND) have info on at least 1,000,000 or more customers. Of course, I…

That ultimately doesn't matter. The bill has zero shot at passing and becoming law. Wyden doesn't have anywhere near the votes he would need, so it's essentially his fantasy idea of a bill. There's no privacy law that is going to get passed by the US Government, focused on large corporations, that involves sending violators to prison for up to 20 years.

Right, this is just an election gimmick.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#248

Earlier quoted context omitted.

So is the only difference between lying and knowingly misleading the point in time of the subject in question?

> the only difference between lying and knowingly misleading the point in time of the subject in question? If I say “this stock will rise in value” and then it doesn’t, that isn’t lying. If I say that while knowing the CEO is committing felonies, it still wouldn’t be lying, but it would be problematic. If I say “this is a share of Apple” when it’s actually Twitter, that’s lying. Bad forecasts aren’t lies, they’re mis…

>Bad forecasts aren’t lies, they’re mistakes.

What if the weatherman knows there's going to be a massive shitstorm tomorrow, but decides to tell everyone that it's going to be clear and sunny?

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#249

This is an extremely frustrating headline. The draft bill we're discussing does not appear to establish "prison time" for "data privacy violations". The bill "covers" any entity with over 1MM users (Flappy Bird) or $50MM in revenue over 3 years (most mid-sized startups). It creates a compliance regime, violations of which can be pursued by the FTC under its "Unfair Trade Practices" authority. A subset of Covered Enti…

> I don't think this bill is going anywhere

You can actually also tell that by the fact that the article states that privacy regulations are backed by FAANG or similar et al. They think that an eventual bill would be so watered down or not matter that they don't even mind stating up front that they support such a bill.

This is similar to a technique that I have used with my wife. She wants to know say if we can do this or that at some future date. I know that we won't end up doing it so I don't put up a fight (even though I don't agree) and I actually support it fully. Later if it looks like it might happen I use my initial agreement to change the exact terms and she is less likely to think I am gaming her. Or figure out some other way out.

Curious if others think this is wrong and sneaky or smart.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#250

Earlier quoted context omitted.

You've now moved the goalposts past the present text of the proposal and into hypothetical future versions of it .

That's not "moving goalposts" as you put it. Are you saying that you believe that they would allow such an enormous loophole in such a bill?

It is often the case under US law that failing to file paperwork is treated as a much less serious act than filing fraudulent paperwork. If you fail to file a tax return, you're nearly always assessed a penalty (it's a misdemeanor). If you file a fraudulent tax return, you can easily go to prison for a long time (it's a felony).
Post reply on HN