For those interested, I can highly recommend the documentary Democracy: Im Rausch der Daten (2015) [0]. For 9 month the documentary follows MEP rapporteur Jan Philipp Albrecht and his policy advisor Ralf Bendrath [1] (hacked a C64 in his youth, frequent attendee at C3) and gave a rare inside in the negotiation & process in Brussels. They even recorded the final negotiations in the backrooms and for those knowledgeable on the topic it is very interesting to see how some of the deals where made. After the screening at IDFA the director said he wasn't onset to make a documentary on the EU data protection reform and that Jan Phillip's rapporteur topic was chosen as an example EU process. Regretfully this documentary isn't exemplary for the EU process because most of the time the lobbyists of the large corporations have a far larger influence. The documentary clearly shows that the final text has been the result of the persistence & integrity of the the 3 main characters Albrecht, Bendrath and Redding. And as we're experience now, this has great influence on data protection for more than only Europe.
[0] http://www.democracy-film.de http://www.imdb.com/title/tt5053042/
> Each supervisory authority shall have all of the following corrective powers:
> [...]
> (b) to issue reprimands to a controller or a processor where processing operations have infringed provisions of this Regulation;
(IANAL)
See this recent example, where a sexual health centre accidentally leaked a list of 800 people who had attended HIV clinics.
They ended up with a £180,000 fine: http://www.bbc.co.uk/news/technology-36247186
If I'd been affected by this Let's Encrypt email thing I frankly wouldn't care, other than to question why it happened. (Just speaking for myself, I'm sure some people would care.) But if I was data in a leak revealing a personal serious medical issue, I absolutely would care.
(There would probably not be a fine; the company would be investigated and warned by the various regulators).
Once your email is out there, there's no going back.
Email addresses are personally identifiable information, and revealing a relationship between a business and a person is potentially very dangerous.
For example: http://www.bbc.co.uk/news/technology-36247186
If you look at the past 5 years, there is almost not a single major website that hasn't been hacked and hasn't leaked personal data. Not only do I see no sign of improvement, but it is rather accelerating. Leaking information on 30m+ people is now becoming common and barely makes the news outside of a few specialized websites like HN.
If you have a better alternative than feeding garbage data to websites who want to collect data they won't need (why would an online retailer give a shit that they are shipping a product to someone called Mr X rather than Mr Y?), I want to hear it.