36 karma · joined February 5, 2013
The scale of damage when occurring is what worries me.
Eg. in old times when someone wanted to eavesdrop someones phone they needed ratio of 1:1 in person count, one keeping up the conversation and another one transcripting it up. Then some more people to intrepret that transcript an make conclusions, maybe even decisions what comes next. That is not the reality we leave in today. Today's scale of data processing and storage capabilities makes the ratio of 1:8298979488 (AI:everyone). I don't want us to ever have AI decision making over those transcripts with the same ratio. Possibility seems clearly to be there soon.
Another eg. in old times when someone wanted to dig into vulnerable system they needed ratio of 1:1 in count, one person having time to dig in one system at a time. I don't want to know how many critical and vulnerable systems we have running today in this planet connected to the same network these AI agents are run. Yes, over time you can use AI to find and patch those vulnerabilities but the scale and speed to do harm (exploiting every system at once) is the problem here.
After Windows XP/7 family originated support requests have declined like 95% being only 1-2 per year for past years. I don't give all credit to Linux/Mint/Mate/apps but to the fact installing any unnecessary bloat to an average Linux requires a bit more than just clicking "Install me" button on any web page and then (generously instructed by the browser) run that .exe in admin privileges.
Yes there are Flatpak and friends and I'm already a bit scared they will evolve easy enough to install bloat increasing family originated support requests to Windows days.
I don't take this yet as an argument that he is back.
So the main scope is with IPR and 3rd party licensing matters and GDPR is just another additional side track.
Not commenting about first two. Let me know if still some concerns in GDPR scope as I've been working too heavily with it within last months.
are you referring on to a case where you have not met the regulations (from the perspective of the information and options you give to your end-users) and authoritative entity comes to you with warning which you are not going to notice
-OR-
are you referring on to a case where personal user data is stored and used without end-user explicit consent and/or knowledge and/or that data "leakage" has caused/will probably cause in the future real damage to this user
Note that I'm certainly NOT a lawyer.
..but still here in European Union the preference has been (at least pre-GDPR era) to first give a written warning to service provider about not being inline with the regulations. This has also included a period during which the provider can fix it's behavior. If regulations are not met after given period only then (usually progressively and aligned with the extent of the business and real damages caused) monetary penalties will arrive. This is EU not US.
When looking here from Finland GDPR is not that big change as we have had quite strict national regulations in place since 1999. The biggest change here is that user should really be able to get all it's data removed permanently from whatever service she/he has previously used (usually referred with terms right-to-be-forgotten). Another big change is that it is not anymore up to only the actual end-user to raise a lawsuit about personal data losses but to give also for an authoritative entity possibility to raise that lawsuit without prior actions of the original end-user.