4 ms·
Something like Europe's GDPR should be enough. And of course product certifications.
by MrQuimico 6y ago
Something like Europe's GDPR should be enough. And of course product certifications.
- henryfjordan 6y agoI disagree. The GDPR and CCPA only have teeth against corporations. You will lose some money but nobody is going to jail over a GDPR violation. The investors will be sad but they aren't even really responsible, the employees who built the data-systems are. At the same time, you can ruin someone's life through a data-breach. Imagine you are on one of these dating apps and your boss takes a gander at the leaks and fires you because of your private life. Or worse, some bigots show up at your house and burn a cross in your yard. So how do we fix a situation where the person responsible for securing your data has no skin in the game? Put their head on the block. Other engineering disciplines hold the PE liable for mistakes because they recognize the stakes involved. I think that assigning liability is absolutely appropriate for building systems with PII. Product certifications would be great too, although that would be done by a PE so you'd kill two birds with one stone by licensing Data Engineers.
- MrQuimico 6y agoHow do you enforce that when the service is provided by a company in another country? GDPR solves that because if you want to do business with European citizens you must comply with it no matter where you are. GDPR is not only about the fines, it stablishes protocols to communicate breaches, makes somebody responsible for it (the DPO) and makes distinctions between the different types of data and the requirements to handle it. Also, enforcing GDPR is no joke, and we are still learning its consequences (http://www.london-registrars.co.uk/first-prison-sentence-arising-from-the-gdpr-should-remind-firms-of-their-responsibilities/ http://www.london-registrars.co.uk/first-prison-sentence-ari...). As I see it, Licensed Data Engineers won't make companies more careful with our data, since all they need to do is to sue them and fire them when there is a problem. We need laws that make data hard to use, so companies will only ask for what they really need, will use the data with a purpose and will store it only while it's useful. Software is more similar to a car than it is to a bridge. Companies build and sell them all over the world. Cars are certified at each country as needed, but it doesn't matter who is building them, as long as they meet all the requirements. Software should be similar.
- henryfjordan 6y agoI didn't realize the gdpr had such teeth. I was wrong, the gdpr will help solve data breaches.
- ntsplnkv2 6y ago> So how do we fix a situation where the person responsible for securing your data has no skin in the game? Put their head on the block. This implies there is a perfect scenario of security, but even the best security experts can still have breaches, it's unfair to punish people acting in good faith.