3 ms·
They did: the Finnish CEO was criminally charged and convicted (under GDPR); that never happens in the US. (I wasn't aware it was overturned on appeal in 12/202
by smcin 5mo ago
They did: the Finnish CEO was criminally charged and convicted (under GDPR); that never happens in the US. (I wasn't aware it was overturned on appeal in 12/2025, neither is Wikipedia currently).
They did face consequences. That ex-CEO (and CTO) also essentially had their reputations shredded, and their behavior was publicly scrutinized (have you ever seen the Comcast CEO grilled by Congress? I haven't). Sure, it would be better if they had actually gone to prison. But my point is GDPR has teeth, unlike US state digital privacy laws.
- applfanboysbgon 5mo ago> have you ever seen the Comcast CEO grilled by Congress? I seem to recall some media circuses here and there about CEOs being subpoenad by Congress, for example Zuckerberg. I don't really consider that a consequence in any meaningful sense. Apparently the appeals court also released the hacker, even though his extortion led directly to the suicide of two people, and damage to thousands of others. Maybe the GDPR was meant to have teeth, but I can't help but wonder if the Helsinki Court of Appeals is for sale.
- ryanlol 5mo ago> Apparently the appeals court also released the hacker The court of appeals found me guilty, despite the evidence clearly not supporting that conclusion. I rather doubt it's because they're for sale, rather it would have been too damaging for the government to admit that they had framed me.
- smcin 5mo agoI share your outrage about companies abusing users' data, but we're mixing up several different things: - the Vastaamo ex-CEO was in fact criminally tried and convicted (even if that conviction was overturned on eventual appeal) and had his reputation destroyed. That compares well for GDPR vs US state privacy laws, which is what I was saying to you. That was my point by saying the US Comcast CEO hasn't been grilled by Congress on those (he has on media mergers, but not his company's business practices). I'm agreeing with you that Congressional grillings aren't consequences in any meaningful sense. - the Vastaamo hacker was not charged under GDPR, they were charged with criminal offenses: aggravated data breach, aggravated attempted extortion, aggravated distribution of information infringing private life, blackmail, breach of confidentiality and falsification of evidence. - I was not aware the Vastaamo hacker had been freed after serving part of his sentence (although his conviction was not overturned), but it seems [0] it might have been for implicating other people in the cyberextortion/ransomware ring. And since those people were operating in countries without much rule of law, we'd expect actions were taken that didn't involved courts or journalists. I can't find any press coverage of that part. [0]: https://www.bitdefender.com/en-us/blog/hotforsecurity/vastaamo-psychotherapy-hack-us-citizen-charged-in-latest-twist-of-notorious-data-breach https://www.bitdefender.com/en-us/blog/hotforsecurity/vastaa...
- smcin 5mo agoOk, with the current huge Canvas breach 5/1/2026 [0], you're going to be able to compare the responses from Canvas, education systems and individual colleges across US, Canada, Australia, UK, Sweden, etc. Specifically, what, if anything, do Canvas or the colleges disclose about the breach (which users were affected, and how severely), and how soon? And then subsequently you'll see govt inquiries, and there will be cyberinsurance claims. So you'll be able to compare the effectiveness of privacy laws of each jurisdiction. [0]: https://news.ycombinator.com/item?id=48055913#48059071 https://news.ycombinator.com/item?id=48055913#48059071