To be clear, I'm not arguing for no control at all. However, fines should not be so egregious that it ends up being up to bureaucrats to decide whether a company lives or dies. This will easily lead to selective enforcement and corruption.
To be clear, I'm not arguing for no control at all. However, fines should not be so egregious that it ends up being up to bureaucrats to decide whether a company lives or dies. This will easily lead to selective enforcement and corruption.
I think we've seen enough of how this theory works in practice (or how it doesn't) to be able to say that there is absolutely no good reason to rely on it.
2. In many businesses, the actual customers are not the end-users, whose data is leaked (all the nice free services you're getting over this invisible thing called internet), they are the merchandise business is selling to somebody else (ads, etc.).
3. There are two ways of coping with this:
3.1 darwinian, where stupid users who choose to hand their data to dumb businesses all jump off the cliff holding hands
3.2 paternalistic, where we elect somebody competent to make choices for the rest of the community, which would prevent people's poor judgment to both hand data to insecure businesses and for businesses to be insecure in the first place.
4. We tried darwinian one since the day 1 in many fields. Reverting it comes at cost (antibiotics would be one good example to think of).
How does that work in a case like Equifax?
1. Knuddels is largely targeting minors
2. its customers are other companies not its users
3. in the real world there are externalities (like the network effect)
Even on breach could result in real damage to an individual, but that risk increases as more of that individuals data can be collated.
It is only after publicly known exploit that small customer can know about issue.