Personal data needs to be much more of a liability than it currently is for anything to change. Business will respond when the bottom line is affected.
In the case of a university like the head of this thread, it isn’t going to be easy to avoid collecting and retaining data.
for instance, how many companies (including universities) store their own cash on prem? what if we treated PII like cash? limit amount and time kept outside the data "bank" (which would be a third party specialized for security and authenticating access).
I might suggest a construct like this too.
What do you think how much it cost to do it perfect?
It’s the difference between being a professional and an amateur (or worse, a ‘cowboy’).
There is no capitalist incentive for the latter, and you will lose market share to firms that can undercut you because of their lower costs.
One assumes the rest of the world won’t be far behind, apart from the the corrupt land of the USA which is going backwards right now.
If (4% of your revenue * risk_of_breach_with_your_security < cost of outsourcing storage to a 3rd party cloud) {
Roll your own security solution
} Else {
Outsource to 3rd party
}
In my experience, putting proper compliance procedures in place, following industry best practice in relation to data management and data security actually leads to a more effective organisation, because it professionalises.
It’s the first step out of the ad-hoc phase of a startup and into the real world of creating a business with value. It also means as you scale up the personnel in the organisation, there are proper checks and balances in place.
When you come to sell your business, if it has a ton of existential risks attached to it, it will be worth less and may even not be sellable at all. So even from a cynical “all I care about is money” point-of-view, you want a business that is sound and isn’t storage for future law suits or fines.
Also, the cost of a fine due to a data breach isn’t the only thing to be concerned about. Gross negligence could lead loss of life, loss of property, loss of earnings, etc. and the buck stops with the executives — don’t think you can’t be completely fucked by the good ol’ law as it stands today.
Some businesses are more vulnerable than others, but that’s also why you scale the compliance architecture to the business.
As for the buck stopping with the executives: can you apply this to a case I've heard of? We have multiple data breaches of companies that scan IDs. We have the Experian breach. We have multiple LastPass breaches. Is there any executive at any of these companies that has been held accountable?
I've actually done the legwork on the ones I just mentioned and the answer is there have been no criminal or civil penalties to any individual in an executive role at any of those companies as a result of the data breaches. Maybe I'm missing one?
With my last company, managing medical records, I was always conscious that if we didn’t take our responsibility of managing medical data correctly it could lead to the death of one of my customer’s patients; or some other extreme circumstance that the executives could be held liable for.
That was my point about being professional, if you have proper processes in place and audits to prove it, you have protection. And only the most egregious cases would land.
It’s good business to protect yourself from a gross negligence or corporate manslaughter claim. It just so happens that it’s good for your customer too.
Presumably, the reason you don’t hear much about executives in the dock for these crimes is because most professional organisations put these processes in place.
Again, I was just stating that it isn’t just data-breach fines that should encourage executives to professionalise.
As far as I know, it was considered an act of god not something that resulted in punishment. Oh sure, they punished the hacker, but how about the people who were supposed to keep the data secure?
I’m not sure where I stand on punishing companies for getting hacked. I guess like the thread says, was it gross negligence? Back to searching the internet to find out…
Edit: definitely gross negligence.
> one of the first things he noticed was how lax security had been. “It was definitely unfit for purpose for storing this kind of information,” he says. He tells me that the patient records database was accessible via the internet; there was no firewall and, perhaps most egregiously, it was secured with a blank password, so anyone could just press enter and open it [2]
Edit: accountability? Maybe.
> the board announced that it had let the CEO, Ville Tapio, go. In April 2023, Tapio was found guilty of criminal negligence in his handling of patient data. His conviction was overturned on appeal in December 2025 [2]
[1]: https://www.bbc.com/news/articles/c62nzxqw45eo [2]: https://www.theguardian.com/technology/2026/jan/17/vastaamo-...
This is the default business mindset. Push every rule and regulation to the limit in the name of profit, if you can break a rule with minimal concequsnces then pay the fine and move on.
Stellantis has a recall out for >1M vehicles because they catch fire even when turned off. Unless that kind of fuckup is met with business threatening fines it will happen again.
It isn’t, it is how some people approach business. Not all.
Again, in my opinion this is just cynical and constantly - almost psychopathically - propagated here as though it’s some kind of virtue of business or the only way a business can be ‘pure’ and succeed.
It just isn’t.
And, if you want to sell B2B, you have to sort out your compliance, or you’re gonna sell nothing. So, for a very large number of businesses, this levelling up is non-negotiable if you want to succeed.
To rephrase the comment you replied to, if being a cowboy is more profitable (by whatever shady means) then that will generally be preferred by the market. Despite whatever sensibilities you or I might have there is no escaping that simple truth of capitalism.
https://www.dw.com/en/cyberattack-in-berlin-14-million-files...
This is literally the point of data breach laws like this. To provide a financial incentive to take this stuff seriously.
If you are hacked and you are seen to have not given a shit about compliance, or independent penetration tests, or proper documentation of process, with good internal controls enforcing your processes. Then you’re almost certainly vulnerable to a negligence claim.
However, if you have all that in place, and somehow something slipped through the net. And once aware you put in new controls to make sure it doesn’t happen again, then you’re very unlikely to have the book thrown at you.
You may still get a fine, but it would be much reduced.
It’s not hard to do this. Yes, compliance can be overdone, so you need key stakeholders to make sure it doesn’t turn into jobsworth heaven; but the actual implementation isn’t hard to do, and if done well, will improve the processes within the business.
It’s very much like an insurance policy. It has some ongoing cost, but it saves you from the one big cost.
This measure add similar incentive for data breaches.
Lets say these are paper records, behind a locked door, with a security guard that they check id for it. If someone then breaks in at night time, cuts the cameras and knocks out the security guard and steals a filing cabinet, should that university then be fined 10% of revenue, which could mean the entire university shuts down because most businesses cannot survive that? We have to remember who is the original criminal here.
But to your point, the article doesn’t define what that means.
They can try:
* various education campaigns
* force users/customers to adopt passkeys or other phishing resistant mfa
* add various alarms and alerts for unusual activity, resulting in lockout
The problem is that even after adopting all of the above, it's still not too hard to breach virtually all companies, and there is massive user opposition to the last two.
To defend against the threat OP talks about (intentionally under capitalized corporate entity to avoided liability), insurance should be required, and your cyber insurance underwriter will perform an audit as part of underwriting. It's effectively a bond against fuckery in this context.
(cyber consultant and practitioner)
I've worked with very profitable firms who care very little (and it shows in their systems and how they operate in this regard), and barely profitable firms who do everything right. What's the difference? Their culture, people, and internal incentives.
TLDR Security failures and data breach fines must be more expensive than the happy path and doing the right things. This encourages the happy path and doing the right thing, while discouraging doing not enough or nothing.
I think that still aligns the incentives, and University in this case has interest to make sure the data is stored properly.
If this is not possible no cloud storage would ever be possible to be liable for anything. Your Google drive got hacked? Your responsibility.
It certainly feels much better being an proactive member of society rather than a self-serving arsehole though.
So, there is that.
Hmm, this is perhaps why we get socially-negative businesses that often have very friendly (and driven, and hard-working, and intelligent) internal cultures. Competency becomes a fault line. When it becomes obvious that a large fraction of humanity just doesn't give a shit, a small group of people who are competent and driven turn their efforts to taking advantage of people who don't give a shit. Thus creating industries like market-makers, cryptocurrency, advertising, and AI.
Not sure who “everybody else” is in your statement, but as someone who founded a healthcare tech platform (since sold) [1], I spent 20 years caring about the many millions of patient medical records we held and making sure my team cared too. In my mind it wasn’t optional.
I did it because:
* it’s the right thing to do
* for professional pride
* and so I could sleep at night
And, at least at the beginning, I believed a data breach could be the death knell of the company. Over time the laissez faire attitude to data protection, by the industry as a whole, made it seem like a breach would be survivable, but luckily we never tested that theory.
I still walked away from it a wealthy man. Being competent and caring about your customers (and being able to sleep at night) doesn’t have to mean failure like it seems everyone here thinks.
We're moving from a high trust society to a low trust society, I fear. It's a tough transition.