9 ms·
On the other hand, they could have bankrupted them if they wanted to. Do we really want the government to have that much say in whether businesses live or die?
by stass 8y ago
On the other hand, they could have bankrupted them if they wanted to. Do we really want the government to have that much say in whether businesses live or die?
- StavrosK 8y agoIt's a worthwhile question, but remember that the alternative is companies that aren't accountable to anyone, and which are cavalier with their users' security.
- stass 8y agoThey are accountable to their users. If a company is negligent with user data and their customers actually do care about this issue, this company will either eventually improve or go out of business. And if customers don't deem this important, it's not a government's role to decide it is. To be clear, I'm not arguing for no control at all. However, fines should not be so egregious that it ends up being up to bureaucrats to decide whether a company lives or dies. This will easily lead to selective enforcement and corruption.
- krageon 8y ago> If a company is negligent with user data and their customers actually do care about this issue, this company will either eventually improve or go out of business. I think we've seen enough of how this theory works in practice (or how it doesn't) to be able to say that there is absolutely no good reason to rely on it.
- ninegunpi 8y ago1. The problem is that most population is terribly poor at defining and managing risk, by biological design and social selection - those who are good at it are usually not the best neighbors you want to have. 2. In many businesses, the actual customers are not the end-users, whose data is leaked (all the nice free services you're getting over this invisible thing called internet), they are the merchandise business is selling to somebody else (ads, etc.). 3. There are two ways of coping with this: 3.1 darwinian, where stupid users who choose to hand their data to dumb businesses all jump off the cliff holding hands 3.2 paternalistic, where we elect somebody competent to make choices for the rest of the community, which would prevent people's poor judgment to both hand data to insecure businesses and for businesses to be insecure in the first place. 4. We tried darwinian one since the day 1 in many fields. Reverting it comes at cost (antibiotics would be one good example to think of).
- summerdown2 8y agoThat's assuming the company explains in enough detail how it secures its product for consumers to tell the difference. More likely is that company A has a breach, and consumers who care about security move to company B, which is just as insecure but hasn't recently been hit by the risk realisation bat.
- TheSpiceIsLife 8y agoIt also requires the end users understanding the downstream consequences of multiple breaches of various online services over time. Even on breach could result in real damage to an individual, but that risk increases as more of that individuals data can be collated.
- dmitriid 8y agoTake this argument over to Facebook. How many breaches of trust have happened over the past year? Have they improved? Not a bit. If anything, they are becoming worse.
- mikojan 8y ago> If a company is negligent with user data and their customers actually do care about this issue, this company will either eventually improve or go out of business. 1. Knuddels is largely targeting minors 2. its customers are other companies not its users 3. in the real world there are externalities (like the network effect)
- watwut 8y agoThat is not even theoretically valid. Even if customer care, customer has no way to review security. Moreover, companies lie a lot about their systems security. All systems totally secure and there were no succesfull attacks until laws about mandatory announcements came around. It is only after publicly known exploit that small customer can know about issue.
- Angostura 8y agoSo you are saying, if a company negligently loses some important data about me; lets say enough to create a fake identity or access my medical records, my only recourse should be to stop using them? How does that work in a case like Equifax?
- mikeash 8y agoReplace "user data" with "toxic waste." Does it still work? History seems to indicate that it doesn't. Why would this be different?
- ahje 8y ago> Do we really want the government to have that much say in whether businesses live or die? Frankly, yes.
- bambataa 8y agoBy that logic, governments shouldn't be able to impose meaningful punishments on any business.
- stass 8y agoMy point is that it should not be discretionary. Either apply the law universally (without taking the viability of the company into account), or lower the fines to a meaningful level.
- fao_ 8y ago> My point is that it should not be discretionary. Right. But that won't work. We set the fines at say, 20% of the business. So a 'mom and pop' firm breaks it, gets reported. Ok, now they're out say, 20,000 EUR (scale to whatever is appropriate in your country for a small company). Then a big business breaks it for maybe, gets reported. Ok, now they're out $35.57bn. These might indeed be acceptable amounts. Now imagine that for example, instead of having a fair number of people affected, it is just two people. Or three people. And perhaps in this instance the people involved were only marginally affected by it, perhaps at worst they would have lost a couple of hundred $currency. Technically speaking, the companies still broke the law, but suddenly perhaps the punishment does not quite fit the crime!
- talltimtom 8y agoSo you want them to bankrupt small companies while letting large companies getting away with not even a slap on the wrists? That seems strange. The law as written has leeway in the amount to make it more fair than it would be if you applied it universally.
- SmellyGeekBoy 8y agoSo if Amazon were caught doing this they should be fined €20k too?
- ahje 8y agoOne would assume the same care would be taken not to drive Amazon out of business, but considering the difference in size of the two businesses, the fine would most likely be much larger.
- miemo 8y agoYes, society at large should shut down businesses in the same sense that we jail individuals who act improperly
- andy_ppp 8y agoIf your business operates outside of the law of course it should be shutdown. I think fines are a good way to cause compliance without causing more harm than necessary. Are you advocating government not be able to influence businesses to comply with the law at all? GDPR is actually a very well thought through piece of legislation and I've implemented compliant systems: best rule of thumb I heard - treat peoples personal information as if it is credit card data and you will comply in a fairly straight forward way.
- bayesian_horse 8y agoOne problem is that the law significantly changed right under their noses. I don't think that they have either a significant development team/effort for their platform, nor a very good revenue. It's basically a very old chat platform I used about 15 years ago...
- dmitriid 8y ago> law significantly changed right under their noses. You mean two years to comply before it went into effect. + over 10 years of similar local laws. "right under their noses" my ass
- TheSpiceIsLife 8y agoAh, the old a-planet-full-of-media-attention variety of right under their noses.
- ahje 8y agoEven if it had changed right under their noses, that would still be OK in my book. The Lawmakers are elected by the people (somewhat -- the EU could be more democratic, but that's a different topic), and they should therefore be able to change the laws on the behalf of the people.
- CathyWest 8y agoThat would have been a reasonable argument if they were found to have been using something like DES-based crypt(3) to hash their passwords. But they didn't, they were just plain text.
- fao_ 8y ago> Do we really want the government to have that much say in whether businesses live or die? The company broke the law in a way that could have potentially harmed* individuals (passwords are critical secrets, many users do not have more than one, and so could lose their entire identity and maybe several years worth of funds. Sure, you can say that is the fault of the user, but there is the assumption of security here that was given by the company and not fulfilled). If you rent a deposit box at a bank, with the assumption of safety, and it turns out they leave all the doors unlocked, don't hire guards, and someone came in and stole everyone's things and took them to the market, then closure of the bank is absolutely deserved. Conversely, if a prison gives the assumption of security, but doesn't hire guards, or bother locking cells, and all the inmates walk out and some people are killed, does the prison deserve to go bankrupt? These examples are exaggerated, yes, but roughly similar in circumstance. Hopefully enough to show that, yes, there are circumstances in which we want the government to have that hold over companies. Now, do we want governments to have restraint? Sure. But it seems clear to me that they very openly are acting in restraint in this case. 20k EUR is a pittance to what was potentially lost by the people involved in the breach. * - (Indeed, in America and a few other countries with weak to non-existent social welfare nets, loss of identity and money is likely to lead to homelessness and eventual death for the person, if they do not have family to rely on).
- thaumasiotes 8y ago> If you rent a deposit box at a bank, with the assumption of safety, and it turns out they leave all the doors unlocked, don't hire guards, and someone came in and stole everyone's things and took them to the market, then closure of the bank is absolutely deserved. OK, but I don't think any government action to close the bank would be necessary in that case. So how does giving the government a say help?
- orf 8y agoIn that example the goods stolen are tangible and have real, solid value that anybody can recognize. In the case of things covered by GDPR the value is opaque and intangible, and only valuable to certain people. Letting 'the free hand of the market, driven by the layman who doesn't understand this, is not effective. If you want proof, well, it's in the pudding. Edit: also, if banks wheew getting knocked over as much as sites and apps, the government would intervene
- DanBC 8y ago> the government It's not the government, it's the judiciary. The business can go to court to appeal any fines with the final court being outside the country.
- CathyWest 8y agoGiven the nature of the violation I think bankrupting them would have been perfectly warranted.
- SmellyGeekBoy 8y ago> Do we really want the government to have that much say in whether businesses live or die? GDPR is nothing new in this respect.
- ionised 8y agoIn this case yes, I'd be totally fine with them being shut the fuck down.
- raverbashing 8y ago> Do we really want the government to have that much say in whether businesses live or die? Sure, because before the GDPR businesses needed to follow no laws and never would have been closed by the government by not following laws and regulations.
- eksemplar 8y agoYes, but I suspect it’s a European truth. There is a fundamental difference between America and Europe, in that Americans distrust their government but trust corporations and the free market. Europe is the exact opposite. You can agree or disagree our world view, but that doesn’t change the fact that in average, more than 70% of Europeans trust the EU to have their best interests in mind, mich higher for GDPR. I don’t think it’s really start-up hostile either. I think there is a huge potential for disruption for privacy centric companies.
- vonmoltke 8y ago> Americans distrust their government but trust corporations and the free market I don't think that's true; that's a common European misinterpretation. I think, in general, Americans trust their government less than they trust corporations, but they are generally distrustful of any entity that wields or appears to wield significant power over them. Exceptions are made for entities that "agree" with a particular person (and these exceptions are not entirely rational).
- wild_preference 8y agoThere's the idea that a corporation has at least some economic incentive to do a decent job and government doesn't since it has zero competition. The classic example to the average person of the government's level of hustle being your local DMV.
- pjc50 8y agoNot the "government" the political unit, but the legal system: courts and regulatory bodies. Turn this statement around. Would you say that no matter what it does, no matter how many crimes are committed or citizens harmed, a business should be able to carry on without interference? That companies should be superior to people - entirely above the law? (It's not a very big harm in this case, but I don't see anyone arguing that e.g. companies should be able to dump unlimited amounts of toxic waste into rivers any more)
- isostatic 8y ago> On the other hand, they could have bankrupted them if they wanted to. Do we really want the government to have that much say in whether businesses live or die? "The government" have the ability to remove the freedom of people who have erred. In some backwards countries the government even has the ability to execute people.
- Nursie 8y ago> Do we really want the government to have that much say in whether businesses live or die? Businesses that break the law, yes! Do you really not want your government to be able to fine or even shut down repeat offenders?
- LyndsySimon 8y ago> Do we really want the government to have that much say in whether businesses live or die? I would say "no", but you have to understand that's coming from the perspective of an anarchist. Rationally, this power pales in comparison to the others that governments already possess. If a state wants a business to fail, it will fail. GDPR has zero impact whatsoever on that.