And yet, when GDPR tries to address the issue, HN is full of "blocking the damned EU users completely" and "stop stifling honest companies".
And yet, when GDPR tries to address the issue, HN is full of "blocking the damned EU users completely" and "stop stifling honest companies".
I mean, I'm a "tin hat" privacy nut in the USA, but that doesn't mean that I'm a fan of 100% of the GDPR. It has plusses and minuses. It'd be nice to have a conversation about them.
Absolute liability for data losses. Exactis lost 360 million peoples' data. They should be able to (a) form a class and (b) extract money damages from Exactis without having to prove specific harm, which is difficult to do with data loss.
A good model is Illinois' Biometric Information Privacy Act [1]. Broaden the the definition from "biometric identifier" to a longer--but still specific--list. If you want to get fancy, create a regulator who can add things to the list after a public hearing. (The specificity avoids GDPR's "what's personal data?" mess. The public input mitigates the risk of unintended consequences and corruption.)
[1] http://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=3004
Well they do. Our government takes money through fines and taxes and uses it to build infrastructure and provide services.
> which would make sense with personal data being leaked.
My preference would be that personal data not be leaked at all. Ideally the warnings and fines kick in long before that happens.
> A fine also misses companies who are "doing what the law says" but still have some horrible flaw anyways.
What example are you thinking of?
The GDPR is quite broad and open to interpretation by both sides.
> If you are _genuinely_ responsible for the data, meaning if something happens to it you are liable for it, then you often take more care of it above and beyond, than for simply complying with rules.
That's what the GDPR does.
Requiring people to lawyer up to make the company responsible is far weaker.
Me too! But not at any cost. This discussion involves thinking about scope (both in who and what is regulated), penalties (both in frequency and magnitude) and pre-emptive enforcement, if any. The trade-offs are far-reaching. A conservative approach is prudent. (It's also politically resilient.)
> GDPR is quite broad and open to interpretation by both sides
That's a sin and a virtue.
> Requiring people to lawyer up to make the company responsible is far weaker
This, too, is a sin and a virtue. The sin is it may allow bad deeds to go unpunished. But presently, everything is going unpunished. The virtue is in its prudence. It's unlikely to cause systemic harm, and we can observe its case law to more-precisely draft the next wave of rules.
And what is this "any cost" rubbish?
Using fines to fund public services creates perverse incentives though, especially where the fines go directly to the agency that brings the case.
> Well they do. Our government takes money through fines and taxes and uses it to build infrastructure and provide services.
That's only true if you consider the public at large to be equivalent to any individual member of the public, or if you believe only the government is "injured" by a data breach.
If I stole all your money and repaid it in fines to the government instead of directly to you, would you consider the matter settled?
Nonsense.
> If I stole all your money and repaid it in fines to the government instead of directly to you, would you consider the matter settled?
I mean, that's typically how it works.
People get robbed by people who don't have the ability to directly restore what they've taken, so the state takes them into custody and makes them a productive member of society.
Would I consider the matter settled? Gee, I've seen some really stupid arguments on the Internet that have made me wish I could punch someone over TCP/IP, but while I'm wishing I'm not going to wish for that either.
Can you please detail why paying a fine to the government is the same thing as paying a fine to the people injured by a crime?
Replace EU by "the data/privacy regulator of the country in question"
Of course, "responsible" and "data aggregation company" rarely belong in the same sentence...
Reporting requirements. If you find out you're breached, you have to notify everyone involved--plus their states' attorneys general--within N days. If you find out you're breached and fail to notify at least one attorney general, that becomes a criminal liability for those who knew but didn't act.
I was working with Albany on a law in this form (notice only) after the Equifax breach. It was tabled due to lack of Equifax-related outreach from voters.
I suspect this is because the very people who would be the most vocal about this issue are also the most politically cynical, and would never think to reach out to their representatives. That's a damn shame, if true.
For example, Europe was first on texting on the mobile network while the US (single country) took years to come to a standard.
I think it will be the same with regards to GDPR. You (US) will discuss this for years and come up with a different law.
But after going several answers deep you still haven't listed any specific complaints and instead complain that nobody discuss them. This really make no sense.
So, feel free to explain what specific things you dislike, why, and how else you would have done it, and then people would be able to discuss them with you and exchange opinion.
Saying "it's not possible to talk about x" when you don't even try to really isn't the way.
The work sucked, but I was more than happy to help our customers get their data from us.