Similarly, if a food truck uses a point of sale service, the food truck owner should not also have to be knowledgeable about evaluating the point of sale’s database security. Their job is to make food.
If the government wants to protect people’s data, then it should set the standards or certifications for the vendors (and/or go after the people who misuse the data), not lay that liability on the vendor’s customers.
EDIT Sorry, misread the comment. I removed the part of my response related to my confusion.
It's not like we're turning up to the house of the CEO to burn it down.
If a company knowingly keeps data about users, they should be liable. You're right that this data liability might discourage companies from hoarding lots of data about users; mission accomplished, I want companies to be discouraged from keeping lots of data about me.
People bought tickets to things in the 90’s. It isn’t very difficult. The only thing Ticketmaster does is make that more convenient by keeping track of everybody’s payment info. If they can’t do that safely, they don’t even satisfy their reason for being, they don’t need to exist.
for better or worse, the industry as we know it today could not exist without ticketmaster and companies like it.
And charge exorbitant service and "delivery" fees.
In the US only 1% of all companies are public.