Live data from Hacker News

Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

reuters.com

271–280 of 285 posts

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#271

Earlier quoted context omitted.

So no more Facebooks, Tweeters, Ubers, Instagrams, Snapchats, etc? Sign me up!

That's a non-sequitur response; all of these are VC-funded startups that could easily have paid to comply with this proposal.

Only as much as the parent's argument was a non-sequitur argument.

Parent mentioned startups with lim -> 1 million users unable to comply. If they can't find VC money at the million user stage, then perhaps they didn't have a viable model in the first place.

(Plus, where all these I mentioned "VC funded" from the first user? If not, the argument holds for them too).

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#272
post #144

Earlier quoted context omitted.

Generally speaking, judges and juries aren't idiots, and you can't hack around laws by claiming that your dog did it.

Software engineers tend to assume that (a) they are the smartest in the room, (b) legislation is exactly like code, (c) caselaw doesn't exist and (d) nobody has ever had to write complex rules before software was invented. All of which, we feel, qualifies us to poke holes in any legislation we happen to stumble across. But, of course, it doesn't. Not even close. By way of analogy, if someone looked at a link to a git…

There are jurisdictions were caselaw doesn't exist (which a lot of software engineers also conveniently forget a lot of the time) or law is written differently from the anglo-american legislations (which software engineers also conveniently forget a lot)

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#273

Earlier quoted context omitted.

If you want to be GDPR compliant I don't think you can do that. If you offer the "usage data gets sold" option you also have to make that full opt-in _and_ not deny the service if they don't opt-in.

Is charging a (reasonable) fee 'denying the service'?

Possibly.

Under GDPR, if your data processing is based on user consent, then that consent must be given freely. That means you should provide equivalent service, regardless of consent being given. Providing one service for free and another for a fee is not equivalent, so I'd argue that such consent would be invalid, as it was not freely given.

However, consent is only one of several conditions for processing data. Another would be "legitimate interests" of the business. If you choose to process data based on it, then you do not need consent at all. In such case you can provide separate services: free with data sharing, and paid without data sharing.

The trick here is that you actually need to be able to prove that "legitimate interests" of your business require collection and processing of that data. And additionally such interests are overridden by "fundamental rights and freedoms" of users. Which is probably why most businesses went the consent route, as it appears to be more clear-cut.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#275
post #179
post #141

Earlier quoted context omitted.

As you mentioned Facebook, Google, & in large part Microsoft sell your attention. How do you propose that they are going to pass the insurance tab onto you?

Internet tax

Sooo to be clear... Your theory is:

1. Large companies by insurance for data privacy violations

2. They then lobby to repeal H.R. 3086 (Permanent Internet Tax Freedom Act

3. They then lobby for another bill for taxation on internet use.

4. Then they lobby for what would be equivalent to a hand out in order to recoup losses.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#276

Earlier quoted context omitted.

I think it would be a pretty horrible thing if all these once free internet services suddenly cost money. Nobody seems to be thinking about the significant amount of people who wouldn't be able to afford monthly subscriptions to Facebook, Twitter, Reddit, etc. even if it did all add up to "only" $15/month. Poor people should not be priced out of the online spaces where modern discourse happens. Single mothers should…

They could still be freemium, or could use less targeted advertising. Would it be a catastrophe if Mark Zuckerberg only made $20B off Facebook instead of $40B? Also, today, privacy conscious users are cut off from the main forums of discourse. Is that better?

People who refuse to use these services out of privacy concerns are still a fringe minority.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#277
It would be nice if the government imposed the same requirements on its own departments for violations of privacy as it does on private companies.

Seems to me that government is eager to punish private companies for violations, while increasing its own storage of personal information on innocent people.

In this comments section, someone else said:

> [..] when it comes to mass surveillance,intentionally malicious backdoors and general societal loss of ptivacy, the solution should be primarly legislative not technical.

I'd object to this, given that a legislative solution is unable to restrict government collection of private data, while a technical one isn't (case in point: cryptography).

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#278
post #272

Earlier quoted context omitted.

Software engineers tend to assume that (a) they are the smartest in the room, (b) legislation is exactly like code, (c) caselaw doesn't exist and (d) nobody has ever had to write complex rules before software was invented. All of which, we feel, qualifies us to poke holes in any legislation we happen to stumble across. But, of course, it doesn't. Not even close. By way of analogy, if someone looked at a link to a git…

There are jurisdictions were caselaw doesn't exist (which a lot of software engineers also conveniently forget a lot of the time) or law is written differently from the anglo-american legislations (which software engineers also conveniently forget a lot)

That the doctrinal basis is different does not change that law requires interpretation by experts using something more sophisticated than "it's just code".

Civil jurisdictions don't have caselaw as an independent source of legal rules, but they still have cases and they still have interpretation. It is not uncommon for an ancient Roman jurist's opinion to be cited in argument in Scots law, just as it is not uncommon to cite very old English cases in Australian law. And it is also common to have civil codes in common law jurisdictions -- the criminal law I was taught was based on a statutory instrument which asserted itself to be the whole of the criminal law and which was frequently amended whenever courts began to accrete rulings around it.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#279

Earlier quoted context omitted.

This is a frustrating thread. It starts with the claim that this law could put Flappy Bird on the hook for decades of prison time. I rebut, and you say (paraphrased) "no, read the law, anyone with 1MM users could be sent to prison for failure to comply". This is obviously not true. Then the claim becomes that pp26-33 of the statute has so many burdensome requirements that it would be impracticable for many startups t…

It starts with the claim that this law could put Flappy Bird on the hook for decades of prison time. I rebut, and you say (paraphrased) "no, read the law, anyone with 1MM users could be sent to prison for failure to comply". This is obviously not true. Actually, with specific regard to Flappy Bird, it is true because it had more than 100 million installs, far surpassing the 50 million requirement to expose him to cri…

Don't worry, free market competition among auditing companies will reduce any necessary compliance to pennies. Right? The free market works, right?

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#280

lets see how do we put a legal corporation in jail? anyone have the answer to this that our congress people lack?

The board replaced by military officers along with suspension of business license of original owners.
Post reply on HN