3 ms·
Legislation when it comes to PII data in the U.S is notoriously weak. Without that it's the only place to prosecute these companies is in the court of public op
by mtanski 9y ago
Legislation when it comes to PII data in the U.S is notoriously weak. Without that it's the only place to prosecute these companies is in the court of public opinion (better then nothing).
We have some laws for PII when it comes to health care data. Even those are comically bad... where hospitals, insurers, medical providers routine lose data (paper or electronic) and get away with small fines. On the other hand legitimate research doesn't have access to this data. It's even hard on an opt in basis.
On the other hand some industries do a lot of security/compliance theater. You have a bunch of accountants that figure out they can do compliance shake downs (SAS 70, SSAE 16, SOC, ...). A lot of times you're required to have these to be able to do business with other large businesses. Most of the time it's a checkbox more so then any kind of business processes.
My wife's old employer worked in a HIPAA required insutry, did all their SAS 70, SSAE 16, SOC, ... Then the next tax season after she left she got a letter in the mail saying that an employee got phished (real dumb phish too) for all their payroll data. My wife got 2 years of credit card monitoring and "please be vigilant this tax season" communication.
TL;DR: Laws are weak, enforcement is weak, fines are low.