I would only apply it to business models that directly monetize consumer data though, because there are no technological means to guarantee complete security. A fact more people calling themselves computer scientists should make more clear in my opinion. But if you want to monetize data, you have the responsibility to keep it safe.
Would have severe consequences for funding of some sites, but I think it would seriously be worth it.
Also liability is interesting: According to [1] banks are not liable for contents of lockers. According to [2] banks might be liable for ATM robberies though, if there is not a resonable amount of security (camera, lighting, ...). It's quite an interesting topic.
There are also quite a few followup questions: Does a company that had a databreach have recourse against the software vendors? Are open source developers liable when there was a bug leading to a databreach? (I assume "no liability" licencese might be void in this case?) Is an social engineered or phished employee personally liable?
It might have far reaching consequences, and it's interesting to think about them.
[1] https://www.financialexpress.com/money/bank-locker-theft-rbi...
[2] https://www.hg.org/legal-articles/can-banks-be-held-liable-f...
This is entirely separate from strict liability, though. The main issue is damages. Even if a company is strictly liable, they are only liable for the dollar value of damages caused by the data breach. And your data privacy has a dollar value of zero dollars until a law like CCPA says otherwise.
Under current legal theory, if your data is stolen, you can sue a company for the cost of identity theft that is provably caused by that data breach. But if you are not the victim of identity theft (or if you are, but can't connect that to the data breach in a court of law), then you don't have damages. A company has nothing to fear from strict liability if they are liable for zero damages.
tl;dr CCPA addresses severe problem in the existing system.
> “a result of the business’s violation of the duty to implement and maintain reasonable security procedures and practices appropriate to the nature of the information.”
[1] https://www.natlawreview.com/article/data-breaches-and-damag...
Government will just leak more important info.
I think a shift toward identity as a service is underway for the market to solve this. Auth0 and the like are offering a solution.
How does auth0 solve this? This isn't about your email or passwords getting leaked. This is about your lab test results (eg. HIV, herpes, etc.) getting leaked.