| ▲ | Korea raises data breach fines to 10% of revenue(koreajoongangdaily.com) |
| 268 points by throw7 5 hours ago | 87 comments |
| |
|
| ▲ | augment_me 4 hours ago | parent | next [-] |
| You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function. Minimizes money usage and does not require any security investments |
| |
| ▲ | killingtime74 23 minutes ago | parent | next [-] | | There are specific laws called Piercing the Veil that can easily be passed to close this type of loophole. Courts are run by people, not AI, so judges can easily ignore the corporate entity once these laws are passed. | |
| ▲ | louthy 4 hours ago | parent | prev | next [-] | | Or … and hear me out on this one … care? | | |
| ▲ | m132 3 hours ago | parent | next [-] | | Some hard to swallow pills for tech companies in 2026: data not collected in the first place cannot leak. | | |
| ▲ | fn-mote an hour ago | parent | next [-] | | In the abstract, yes. In the case of a university like the head of this thread, it isn’t going to be easy to avoid collecting and retaining data. | | |
| ▲ | markhahn 16 minutes ago | parent [-] | | that's the odd thing: we simply don't ask whether there's an alternative. for instance, how many companies (including universities) store their own cash on prem? what if we treated PII like cash? limit amount and time kept outside the data "bank" (which would be a third party specialized for security and authenticating access). |
| |
| ▲ | SoftTalker 3 hours ago | parent | prev | next [-] | | Followed by deleting data once you've used it for its stated purpose. Personal data needs to be much more of a liability than it currently is for anything to change. Business will respond when the bottom line is affected. | |
| ▲ | gregglain an hour ago | parent | prev [-] | | Not collect data? Heresy! |
| |
| ▲ | novok 41 minutes ago | parent | prev | next [-] | | How much to care is reasonable? Do you live in a windowless underground security bunker? Should most businesses be held to that standard? Lets say these are paper records, behind a locked door, with a security guard that they check id for it. If someone then breaks in at night time, cuts the cameras and knocks out the security guard and steals a filing cabinet, should that university then be fined 10% of revenue, which could mean the entire university shuts down because most businesses cannot survive that? We have to remember who is the original criminal here. | | |
| ▲ | asp_hornet 35 minutes ago | parent [-] | | > to have leaked the personal data of 10 million or more people through intent or gross negligence But to your point, the article doesn’t define what that means. |
| |
| ▲ | AIiscoming 4 hours ago | parent | prev | next [-] | | Lets be honest here, this is a business risk which is crazy high. As stupid as this is, I care but i can't guarantee it. I might suggest a construct like this too. What do you think how much it cost to do it perfect? | | |
| ▲ | louthy 4 hours ago | parent | next [-] | | Perfect isn’t required. The bar is “gross negligence”. Perfect is impossible, but proper compliance procedures, proper process, and a commitment to following industry best practice will always see you on the right side of the negligence bar, even if something slipped through the net. It’s the difference between being a professional and an amateur (or worse, a ‘cowboy’). | | |
| ▲ | augment_me 4 hours ago | parent [-] | | Again this is not priced in. Every rational(in terms of revenue) business would rather be a highly profitable "amateur" compared to a barely profitable "professional". There is no capitalist incentive for the latter, and you will lose market share to firms that can undercut you because of their lower costs. | | |
| ▲ | louthy 4 hours ago | parent | next [-] | | 4% of revenue in the EU, 4% of revenue in the UK, and 10% of revenue in Korea should be enough of an incentive to start caring about how you deal with your customer’s privacy and personal data. One assumes the rest of the world won’t be far behind, apart from the the corrupt land of the USA which is going backwards right now. | | |
| ▲ | augment_me 3 hours ago | parent | next [-] | | So we get to a very easy formula for companies to do in the EU and UK: If (4% of your revenue * risk_of_breach_with_your_security < cost of outsourcing storage to a 3rd party cloud) { Roll your own security solution } Else { Outsource to 3rd party } | | |
| ▲ | louthy 3 hours ago | parent [-] | | Your replies here suggest a level of cynicism that is, well, … , it ain’t pretty. In my experience, putting proper compliance procedures in place, following industry best practice in relation to data management and data security actually leads to a more effective organisation, because it professionalises. It’s the first step out of the ad-hoc phase of a startup and into the real world of creating a business with value. It also means as you scale up the personnel in the organisation, there are proper checks and balances in place. When you come to sell your business, if it has a ton of existential risks attached to it, it will be worth less and may even not be sellable at all. So even from a cynical “all I care about is money” point-of-view, you want a business that is sound and isn’t storage for future law suits or fines. Also, the cost of a fine due to a data breach isn’t the only thing to be concerned about. Gross negligence could lead loss of life, loss of property, loss of earnings, etc. and the buck stops with the executives — don’t think you can’t be completely fucked by the good ol’ law as it stands today. Some businesses are more vulnerable than others, but that’s also why you scale the compliance architecture to the business. | | |
| ▲ | rpdillon 2 hours ago | parent | next [-] | | The person you're replying to is citing the incentives that are created. That's not cynicism, it's analyzing motives to help model outcomes. As for the buck stopping with the executives: can you apply this to a case I've heard of? We have multiple data breaches of companies that scan IDs. We have the Experian breach. We have multiple LastPass breaches. Is there any executive at any of these companies that has been held accountable? I've actually done the legwork on the ones I just mentioned and the answer is there have been no criminal or civil penalties to any individual in an executive role at any of those companies as a result of the data breaches. Maybe I'm missing one? | | |
| ▲ | louthy 2 hours ago | parent [-] | | Maybe I wasn’t clear in my message. But the buck stopping with the executives is when ‘the company’ breaks law. Usually because of gross negligence or corporate manslaughter. With my last company, managing medical records, I was always conscious that if we didn’t take our responsibility of managing medical data correctly it could lead to the death of one of my customer’s patients; or some other extreme circumstance that the executives could be held liable for. That was my point about being professional, if you have proper processes in place and audits to prove it, you have protection. And only the most egregious cases would land. It’s good business to protect yourself from a gross negligence or corporate manslaughter claim. It just so happens that it’s good for your customer too. Presumably, the reason you don’t hear much about executives in the dock for these crimes is because most professional organisations put these processes in place. Again, I was just stating that it isn’t just data-breach fines that should encourage executives to professionalise. | | |
| ▲ | fn-mote 40 minutes ago | parent [-] | | Wondering where the accountability was in the hack of this Finish psychotherapy organization (Vastaamo).[1] As far as I know, it was considered an act of god not something that resulted in punishment. Oh sure, they punished the hacker, but how about the people who were supposed to keep the data secure? I’m not sure where I stand on punishing companies for getting hacked. I guess like the thread says, was it gross negligence? Back to searching the internet to find out… Edit: definitely gross negligence. > one of the first things he noticed was how lax security had been. “It was definitely unfit for purpose for storing this kind of information,” he says. He tells me that the patient records database was accessible via the internet; there was no firewall and, perhaps most egregiously, it was secured with a blank password, so anyone could just press enter and open it [2] Edit: accountability? Maybe. > the board announced that it had let the CEO, Ville Tapio, go. In April 2023, Tapio was found guilty of criminal negligence in his handling of patient data. His conviction was overturned on appeal in December 2025 [2] [1]: https://www.bbc.com/news/articles/c62nzxqw45eo
[2]: https://www.theguardian.com/technology/2026/jan/17/vastaamo-... |
|
| |
| ▲ | nik282000 2 hours ago | parent | prev [-] | | > Your replies here suggest a level of cynicism that is, well, … , it ain’t pretty. It seems you think “fuck the human cost as long as I’m making money”. I’d suggest changing your outlook on life if I didn’t feel like it wasn’t such a lost cause. This is the default business mindset. Push every rule and regulation to the limit in the name of profit, if you can break a rule with minimal concequsnces then pay the fine and move on. Stellantis has a recall out for >1M vehicles because they catch fire even when turned off. Unless that kind of fuckup is met with business threatening fines it will happen again. | | |
| ▲ | louthy 2 hours ago | parent [-] | | > This is the default business mindset. It isn’t, it is how some people approach business. Not all. Again, in my opinion this is just cynical and constantly - almost psychopathically - propagated here as though it’s some kind of virtue of business or the only way a business can be ‘pure’ and succeed. It just isn’t. And, if you want to sell B2B, you have to sort out your compliance, or you’re gonna sell nothing. So, for a very large number of businesses, this levelling up is non-negotiable if you want to succeed. |
|
|
| |
| ▲ | pkaye 3 hours ago | parent | prev | next [-] | | I want to see how much be the fine will for this data leak. https://www.dw.com/en/cyberattack-in-berlin-14-million-files... | |
| ▲ | fc417fc802 3 hours ago | parent | prev [-] | | It's only an incentive to start caring if it's cheaper than circumventing the law. In other words it won't work unless the aforementioned liability loophole is closed. To rephrase the comment you replied to, if being a cowboy is more profitable (by whatever shady means) then that will generally be preferred by the market. Despite whatever sensibilities you or I might have there is no escaping that simple truth of capitalism. |
| |
| ▲ | josephg 3 hours ago | parent | prev [-] | | > There is no capitalist incentive for the latter This is literally the point of data breach laws like this. To provide a financial incentive to take this stuff seriously. |
|
| |
| ▲ | deepsun 2 hours ago | parent | prev [-] | | But it does create an incentive to not keep data that a company doesn't really need. And that incentive already works with GDPR for PII. This measure add similar incentive for data breaches. |
| |
| ▲ | pluc 4 hours ago | parent | prev | next [-] | | Every single tool being released since like 2024 is pushing everyone to care less and less and to let agents handle more and more. We are not trending towards increased quality, resilience and reliability - even though we've been obsessing over these things for the past 20 years. | |
| ▲ | carefree-bob an hour ago | parent | prev | next [-] | | Problem is that most breaches are social engineering attacks where employees or customers are phished for their credentials or even to approve/install some malicious code. It's very hard for businesses to defend against this. They can try: * various education campaigns * force users/customers to adopt passkeys or other phishing resistant mfa * add various alarms and alerts for unusual activity, resulting in lockout The problem is that even after adopting all of the above, it's still not too hard to breach virtually all companies, and there is massive user opposition to the last two. | |
| ▲ | ortusdux 3 hours ago | parent | prev | next [-] | | That's more expensive. | |
| ▲ | augment_me 4 hours ago | parent | prev | next [-] | | Sounds like something that costs money, if a university doesn't care I don't think most companies will. | | |
| ▲ | louthy 4 hours ago | parent | next [-] | | Yes, being competent requires effort. It certainly feels much better being an proactive member of society rather than a self-serving arsehole though. So, there is that. | | |
| ▲ | nostrademons 4 hours ago | parent [-] | | It feels better only as long as everybody else cares too. Being the only one competent in a room of imbeciles is a terrible feeling. Hmm, this is perhaps why we get socially-negative businesses that often have very friendly (and driven, and hard-working, and intelligent) internal cultures. Competency becomes a fault line. When it becomes obvious that a large fraction of humanity just doesn't give a shit, a small group of people who are competent and driven turn their efforts to taking advantage of people who don't give a shit. Thus creating industries like market-makers, cryptocurrency, advertising, and AI. | | |
| ▲ | louthy 4 hours ago | parent [-] | | > It feels better only as long as everybody else cares too. Not sure who “everybody else” is in your statement, but as someone who founded a healthcare tech platform (since sold) [1], I spent 20 years caring about the many millions of patient medical records we held and making sure my team cared too. In my mind it wasn’t optional. I did it because: * it’s the right thing to do * for professional pride * and so I could sleep at night And, at least at the beginning, I believed a data breach could be the death knell of the company. Over time the laissez faire attitude to data protection, by the industry as a whole, made it seem like a breach would be survivable, but luckily we never tested that theory. I still walked away from it a wealthy man. Being competent and caring about your customers (and being able to sleep at night) doesn’t have to mean failure like it seems everyone here thinks. [1] https://www.meddbase.com/ | | |
| ▲ | rpdillon 2 hours ago | parent [-] | | People don't think caring about your customers leads to failure, but it's a lot harder than not caring, and it does seem to be the case that it is mandatory to not care if you're going to be chasing massive valuations. We're moving from a high trust society to a low trust society, I fear. It's a tough transition. | | |
| ▲ | louthy 2 hours ago | parent [-] | | I realise I’m a sample size of 1, but for me caring was good for business: caring means you can empathise, if you can empathise you can understand, if you can understand you can build a better product. |
|
|
|
| |
| ▲ | zelphirkalt 3 hours ago | parent | prev [-] | | A university which doesn't care to protect its students, deserves to get its whatever-license/accredited status checked/audited. |
| |
| ▲ | toomuchtodo 4 hours ago | parent | prev [-] | | Caring is orthogonal to profits and shareholder value. The one who cares the least wins unless economic incentives change this math, which is what these financial penalties work towards. Humans are tricky. To defend against the threat OP talks about (intentionally under capitalized corporate entity to avoided liability), insurance should be required, and your cyber insurance underwriter will perform an audit as part of underwriting. It's effectively a bond against fuckery in this context. (cyber consultant and practitioner) | | |
| ▲ | my-huge-pony 4 hours ago | parent | next [-] | | Why the middle man? Can't we make the law so that the University is still liable for the data beach because it's "their" data (collected/stored on their behalf) that is breached? I think that still aligns the incentives, and University in this case has interest to make sure the data is stored properly. | | |
| ▲ | augment_me 4 hours ago | parent | next [-] | | This is already the law, but the shell company signs the ownership of the data and the security responsility. The university in this case is just using APIs to load and store stuff to someone else's servers. If this is not possible no cloud storage would ever be possible to be liable for anything. Your Google drive got hacked? Your responsibility. | |
| ▲ | SoftTalker 4 hours ago | parent | prev [-] | | Insurance only pays for damages, up to the limit of coverage. It does not do anything to remove liability. |
| |
| ▲ | x3n0ph3n3 4 hours ago | parent | prev [-] | | That's not what orthogonal means. Saying they are orthogonal means that you can care and be profitable. | | |
| ▲ | toomuchtodo 4 hours ago | parent [-] | | You can care and be profitable, but it is usually cheaper to not unless regulatory mechanisms exist to internalize this potential externality. Can't rely on humans to do the right thing, some will not unless they feel pain for doing the wrong thing. Ergo, we build systems (legal, regulatory, technical, people) to encourage the desired target outcome(s). I've worked with very profitable firms who care very little (and it shows in their systems and how they operate in this regard), and barely profitable firms who do everything right. What's the difference? Their culture, people, and internal incentives. TLDR Security failures and data breach fines must be more expensive than the happy path and doing the right things. This encourages the happy path and doing the right thing, while discouraging doing not enough or nothing. | | |
| ▲ | bluGill 4 hours ago | parent [-] | | There is a lot more than regulations. Reputation is important as well. While you can give up a reputation fairly quickly, it is very hard to get/keep. Many companies are well aware of the value of their reputation - they call it the value of the brand. |
|
|
|
| |
| ▲ | amelius 4 hours ago | parent | prev | next [-] | | That's like blaming Seagate when your harddisk fails. No judge will fall for that. You should have made backups. And you are responsible for the data of your clients. | | |
| ▲ | augment_me 4 hours ago | parent [-] | | Not really, the shell company is the owner of the data and is responsible for the security of it by contract, that's the whole point. Seagate will not in a million years sign anything like this when you buy a HDD. | | |
| ▲ | louthy 4 hours ago | parent | next [-] | | That’s not how it works. Especially with compliance schemes like ISO27001, Hippa, etc. they require an audit chain through the supply line. Obviously it depends on what data you’re managing to whether your customers care about whether you’re audited, or not, but if you’re selling enterprise software then this is all part of your compliance process. You can’t offload that responsibility, you have to make sure your suppliers comply too. | | |
| ▲ | augment_me 3 hours ago | parent [-] | | Maybe it's different in the US, but in the EU you can get certified to be able to handle certain data securely, for example getting SOC/ISO/ESC certifications. When you then are looking for storage solutions you can in practice absolve yourself from liability/gross negligence if you choose a provider that has these certifications. So when an org needs cheap solutions, they find the cheapest compliant provider and hands are clean. | | |
| ▲ | louthy 3 hours ago | parent [-] | | If you want to be certified for SOC or ISO in the US you have to check all your suppliers too. You can’t outsource your responsibility if you want to comply. I know this because I have been through it in the US, EU, and UK. If your supplier has these compliance audits in place and has the documentation to prove it, this isn’t “absolving”, it’s literally the diligence process. But a “shell company”, as per your original comment, is not going to reach a compliance threshold to allow the diligence chain to succeed. Just from a business continuity point of view they would fail, but there are plenty of other areas that would be problematic from a compliance standpoint. |
|
| |
| ▲ | xboxnolifes 4 hours ago | parent | prev | next [-] | | You can't just absolve yourself of responsibility by saying "I hired a contractor". You are still responsible for doing your due diligence in picking your contractor. | |
| ▲ | SoftTalker 4 hours ago | parent | prev [-] | | It's not that easy. Companies are required to do due diligence on stuff like this. If they know (or should have known) that they are outsourcing something to an incompetent provider, they could still be liable. |
|
| |
| ▲ | dmos62 4 hours ago | parent | prev | next [-] | | That's legal? | | |
| ▲ | EA-3167 4 hours ago | parent | next [-] | | Sure, but the real question is, "Will a judge not immediately see through this and punish them accordingly in any realistic case?" Sort of like EULA's a lot of the "value" is incredibly theoretical. | |
| ▲ | miohtama 2 hours ago | parent | prev | next [-] | | It’s Hollywood accounting | |
| ▲ | micromacrofoot 4 hours ago | parent | prev [-] | | similarly, most AI datacenters aren't directly owned by the frontier labs guess who holds the bag if capacity needs collapse |
| |
| ▲ | Barrin92 16 minutes ago | parent | prev | next [-] | | >You can just do what my university did, hire a small shell firm with 3 employees to hold all your data except you can't in South Korea because PIPA (their data privacy/compliance framework) is as strict if not stricter than GDPR and comes with criminal liability in case you violate consent rules, so you can't just send other people's data to some third party shell company either why do people always make these completely generic comments as if they've just on the toilet figured out the one simple trick every data framework covered over a decade ago | |
| ▲ | ranger_danger 4 hours ago | parent | prev | next [-] | | Perhaps they should read https://en.wikipedia.org/wiki/Piercing_the_corporate_veil | | |
| ▲ | makeitdouble 29 minutes ago | parent [-] | | Parent isn't talking about shareholders or ownership, but full delegation of a process to a contracting company. Calling "shell company" makes it sound like the University is the shareholder, but that's usually not what's happening IMHO. In general the entities are clearly defined and nothing crosses the client/contractor frame, the university just happens to be the sole client and the contractor will have the uni pay for their whole operation. |
| |
| ▲ | imnotr0b0t 4 hours ago | parent | prev | next [-] | | That sounds risky | |
| ▲ | bdangubic 3 hours ago | parent | prev [-] | | Anyone that hires such a company deserves the treatment you are proposing |
|
|
| ▲ | prologic 4 hours ago | parent | prev | next [-] |
| Wow! :O Finally, a legislator with enough balls to put up something that _might_ (just might) make corporations _actually_ care about security and privacy! I can't wait for this to start being adopted in other countries. It's about time! |
|
| ▲ | SoftTalker 4 hours ago | parent | prev | next [-] |
| "through intent or gross negligence" I'm not familiar with Korean law but that seems a rather high bar. I don't think we'll see many fines actually levied. |
| |
| ▲ | bluGill 4 hours ago | parent [-] | | The hope is they levy few fines. When you want to make money you set the fines such that they are "a cost of doing business". Most often you don't even call them fines, you call them a permit/license fee (though fines are also common). When you want to prevent a behavior you make the costs high enough that it is worth the effort to not pay them in the first place. (I'm assuming here that 10% is high enough that nobody would call it a cost of doing business - I could be wrong) |
|
|
| ▲ | _the_inflator an hour ago | parent | prev | next [-] |
| And what about the governments like Berlin for example? Massive data breach, and guess what happens? Nothing to those who are responsible for the breach. So even though this is Korea, it is modern hypocrisy. Companies have to comply to more and more complicated regulation, while those who govern the states get a free pass. If the Berlin incident remotely had happened to any private company - hell would have been loose. Berlin reduced the IT budget especially regarding maintenance and security massively over the years. In fact, what came to light - CCC talk as a reference besides others - sounds so embarrassing, that all companies should get a bonus payment whenever they get hacked. |
|
| ▲ | markhahn an hour ago | parent | prev | next [-] |
| This is wonderful, though a little low. Basing it on revenue is sensible, since the goal is to make it hurt. But that would argue for a higher fraction. But the main thing is to introduce an incentive to take security more seriously. |
|
| ▲ | hn_submit 2 hours ago | parent | prev | next [-] |
| This is exactly what we need in the West! I have a strong suspicion that nobody here actually cares about security or customer data being spilled into the streets. Security costs money and as long as there aren't any penalties for negligence management will make the calculation to prioritize increased profitability over securing company data. |
|
| ▲ | roundup 3 hours ago | parent | prev | next [-] |
| Assuming global adoption, this would also have the side effect of increasing bug bounty payouts. Consider the recent OpenAI compromise: an attack RCE, an SSO configuration flaw, and subsequent employee account takeover, for a mere $6500 bounty for a trillion-dollar company. |
|
| ▲ | guillybarres 2 hours ago | parent | prev | next [-] |
| Will they uphold this law when DPRK threat actors use it as a form of economic sabotage? |
|
| ▲ | xp84 3 hours ago | parent | prev | next [-] |
| I'm assuming the intent is to protect customers. Tying the fine to intent or gross negligence doesn't work for me, as a customer doesn't care why, they only care that the harm happened. Doesn't matter to me if you train everyone really well and one guy forgot his training just one time, or if you don't train at all. I'm thinking: (The following example is in "American" terms, I assume some other countries have similar ideas as SSN though) - Name and address or name and phone number leak: $100 per customer affected. - Email: $50 per customer affected, or $100 if tied to any other data. - Social Security numbers: $2000 per customer affected - Unsalted or plaintext passwords: $500 per customer affected. - Cap is the greater of 200% of annual EBITDA, or 20% of revenue Money goes to the government to be distributed DIRECTLY (tax-free) to the affected users. This might bankrupt a couple of companies in particularly bad breaches, while companies are still getting used to it. Good! I hope it does and that business textbooks highlight those disasters, the way they do the Enron collapse. My goals for this system are for businesses to properly price in the risk of holding (or even momentarily touching) sensitive data. SSNs, for instance should already (in a sane world) be radioactive for any business to even CONSIDER touching. To the extent any business feels the need to collect or hold it, frankly I'd say, think again. Credit reporting agencies are the worst offenders (and under my rules Equifax would already be gone), as they maintain databases with that as primary key, and force all their customers to deal in that key, instead of taking advantage of some 1990s technology like one-way hashing, or better yet, coming up with their own identifiers that could be replaced responsibly in the case of breaches. |
|
| ▲ | jmclnx 4 hours ago | parent | prev | next [-] |
| Sounds great if all the following is true. * Before Tax Revenue * If the company is owned by another company, the revenue is the total of all companies owned by the highest level parent. * Includes Worldwide Revenue * Includes companies based in all other Countries. I would have went for 20%, but if he above applies I wish the US would do the same. |
| |
| ▲ | zelphirkalt 3 hours ago | parent [-] | | The US is probably among the countries, where the lobbying against such a law or policy would be very severe, because multiple of their tech giants are built on the foundation of abusing people and considering fines to be cost of business. |
|
|
| ▲ | __natty__ 4 hours ago | parent | prev | next [-] |
| Huge fines but reasonable. Especially now with all the people doing blind vibe coding |
|
| ▲ | ggarnhart 4 hours ago | parent | prev | next [-] |
| This feels like a really odd way to incentivize data breaches and/or not reporting data breaches. |
| |
| ▲ | Retro_Dev 4 hours ago | parent [-] | | Um, I think it does the opposite of what you are suggesting - this aims to reduce data breaches and incentivize people to prevent these breaches. | | |
| ▲ | amelius an hour ago | parent [-] | | If 10% of revenue is still cheaper than building secure systems ... Perhaps what would help is a progressive system, where you'd pay 20% the next time. |
|
|
|
| ▲ | rectang 4 hours ago | parent | prev | next [-] |
| It's childish of me I know, but if this actually goes through I will feel a twinge of delight at the refutation of all the HN commenters who have argued that such enforcement is unrealistic. |
| |
| ▲ | esafak 4 hours ago | parent [-] | | The EU AI Act already levies 7% global annual turnover penalties for prohibited AI practices. |
|
|
| ▲ | quickthrowman 5 hours ago | parent | prev | next [-] |
| I would like to make a wager on this law being ignored the first time Samsung or another chaebol violates it and is facing a fine equal to 10% of revenue. I can almost guarantee it, it’s a high enough fine to turn some low-margin businesses from profitable to unprofitable for the year and there’s no such thing as a secure computer system. The only way to guarantee compliance is to not store any data which isn’t exactly reasonable for some business models. |
| |
| ▲ | Retro_Dev 4 hours ago | parent | next [-] | | > there’s no such thing as a secure computer system Where is your source for this? It is entirely possible to make a secure computer system, though it does require effort. The article specifically mentions "up to" 10% and the fines applying to companies leaking data on purpose or through negligence. I doubt the fines will be nearly as high for a company that tries to secure a system (and thus prevents more leaks) rather than a company that does not try to secure a system (assuming that leaks will occur), if the same breach happens. Computers are deterministic (excluding cases where practically impossible cosmic ray events occur), so while we have the power to ensure system security, we should ensure system security. Heck, even just encrypting consumer information and protecting just the keys to this data would already decrease the effectiveness of many data breaches. | | |
| ▲ | aucisson_masque 2 hours ago | parent [-] | | > Where is your source for this? It is entirely possible to make a secure computer system You can’t. You don’t need source for that, just common sense. Exploits are discovered every day, bugs happen, bad actors. You can do the best system, shit still happen. BTW you want a source ? Remember when the freaking CIA data got leaked ? Edward Snowden, ring a bell ? If the cia couldn’t prevent it, I bet you can’t. |
| |
| ▲ | bigfatkitten 38 minutes ago | parent | prev | next [-] | | The South Korean privacy regulator is the most diligent that I’ve ever seen in terms of slapping companies with fines when they screw up. | |
| ▲ | buellerbueller 4 hours ago | parent | prev | next [-] | | Maybe those specific business models shouldn't exist, if they consistently risk harm to 3rd parties. | | |
| ▲ | google234123 4 hours ago | parent [-] | | You legally have to hold transactions for years yk as a business | | |
| ▲ | josephg 3 hours ago | parent [-] | | Then secure your database? This stuff isn’t rocket science. You don’t even have to hold historical transactions online. It’s quite difficult for hackers to access a hard drive sitting in a drawer. |
|
| |
| ▲ | google234123 4 hours ago | parent | prev [-] | | Probably a law targeted at foreign companies | | |
| ▲ | Retro_Dev 4 hours ago | parent [-] | | I especially hope this holds true, because I don't want my information being leaked by anyone. |
|
|
|
| ▲ | aucisson_masque 3 hours ago | parent | prev | next [-] |
| GDPR in Europe puts it at 4%, and yet we are seeing leaks every week. 10% maximum mean nothing if it’s not enforced, you got to make examples. |
|
| ▲ | happytoexplain 4 hours ago | parent | prev | next [-] |
| Higher. |
|
| ▲ | nosmokewhereiam 4 hours ago | parent | prev [-] |
| Imagine 10% of Samsung! Edit: "That'll be $23B. Cash or card?" |