3 ms·
I disagree. "You can't use the collected data anymore" is a million times harder to enforce than "pay us ten billion dollars." > otherwise it will just be risk
by nathan_long 9y ago
I disagree. "You can't use the collected data anymore" is a million times harder to enforce than "pay us ten billion dollars."
> otherwise it will just be risk-assessed.
The key is to make the cost so large that the risk isn't worth it.
What's my geolocation history worth to Google? $20? $200? Make them pay $2,000 if they lose or misuse it.
Sure, maybe they'll buy "data loss insurance". But even then, there will be motivation to do things better. Eg, the insurer will refuse to cover claims where proper encryption wasn't used, will prorate policies based on data collected, etc.
- tankenmate 9y agoFrom May 2018 in the EU the maximum fine for a data breach is €20m or 4% of global annual revenue. This is due to the GDPR.[0] [0] https://en.wikipedia.org/wiki/General_Data_Protection_Regulation https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
- isostatic 9y agoSo after a certain point, the bigger the company the lower the fine? 20 million is 0.01% of Apple's turnover.
- patmcc 9y ago>>>I disagree. "You can't use the collected data anymore" is a million times harder to enforce than "pay us ten billion dollars." Not especially hard; you send in auditors to delete the collected data from all servers. Oh, that kills the company? Too bad.
- nathan_long 9y agoIt wouldn't fly. And the data may have been "laundered" intentionally or not - used to send emails, get new customers and social media contacts, etc. It may be hard to even trace anymore.
- overhang 9y agoDefine 'misuse'. If they sell ad space based on your geolocation, is that a misuse? If they sell your geolocation, ip address, and search history together, is that a misuse?