3 ms·
I agree with the idea that fines based on the number of users affected makes a lot of sense. One question I have is how would you propose that number be calcula
by number-sequence 8y ago
I agree with the idea that fines based on the number of users affected makes a lot of sense. One question I have is how would you propose that number be calculated? In truth, I think the company whose data has been leaked should know exactly how many records have been leaked, but per-individual based fines create an incentive for them to underreport this number. Do you think that’s a problem, and if so, is there a good answer for how society could get an honest answer as to how many individuals are affected in a breach?
- cobbzilla 8y agoIdea: Create an incentive to overestimate — if the leaked data shows up online (pastebin/etc), and the volume of affected users is x% greater than the publicly disclosed figure, then fines are doubled (or go up by 3*x% or whatever).
- mike00632 8y agoWe might already have an example in HIPAA.
- jacques_chester 8y ago> One question I have is how would you propose that number be calculated? As a percentage of worldwide revenue on a sliding scale. > In truth, I think the company whose data has been leaked should know exactly how many records have been leaked, but per-individual based fines create an incentive for them to underreport this number. Very true, so triple damages for wilful underreporting and/or criminal sanctions for individuals.