For example, you could run NPM update that installs a malicious package that is somehow able to connect to your MySQLD and access all the tables (that contain geolocation information on children) and execute a cronjob to perform a query to backup the .sql data and upload it to a remote server.
There would be 0 consequences legally for such an action (or development would cease to function entirely).
Besides, how is knowingly storing GPS information on children acceptable? They can't consent, so maybe it's time to apply that to things like geolocation as well.
Code has no consequences, because law makers likely don't "get" what that means. You may think it's just $GPSOfALLChildrenInTheDatabase but that variable can cause actual, real harm to humans.
There's totally a disconnect.