2 ms·
A big problem with slapping huge statutory damages / fines onto data breaches is that only the "suckers" will ever pay or even own up to it. Recently in Washin
by rlucas 7y ago
A big problem with slapping huge statutory damages / fines onto data breaches is that only the "suckers" will ever pay or even own up to it.
Recently in Washington State, a small research group at WSU lost a couple of hard drives that had PII data on them on order of 1 M people. They even had them in a safe; the safe was stolen and no real evidence of the data being the target of the theft was found.
Nonetheless, being good civil servants they scrupulously reported what happened and carried out required notification procedures to the million folks.
Their reward was to be sued for basically the maximum that their insurance would pay out.
How many thousands of times per year do similar things happen in private industry? Nobody knows. You don't even have to posit malice or a coverup; just think about how many times a year a hard drive backup of a database with a mere million records gets accidentally thrown away or sold off with surplus.
- rhizome 7y agoThe stolen hard drive story appears to be a bit different than you portray: https://healthitsecurity.com/news/washington-state-university-settles-4.7m-data-breach-lawsuit https://healthitsecurity.com/news/washington-state-universit... If the liability had been $50MM or $500MM, you can bet their storage practices would reflect it (not to mention actually telling people you're collecting their data). "Eh, whaddya gonna do?" is absolutely a normalization and a devaluing well out of proportion to the damage that is done.