I know the human tendency is to think in extremes, but I would prefer to have a system that is as balanced as possible, or at least one that affords adecuate protections to all parties involved.
The issue I have with the “just don’t do anything illegal” argument is that depending on how the illegality is defined, it can be used as a tool for bad actors. Take for instance something like the afformentioned 50% penalty with mandatory jail time for repeat offenders, if I decided that jim’s furniture store shouldn’t exist anymore, I would only need to find some tiny thing wrong with their data handling, like for instance, assuming this specific hole exists, that they asked for contact info before it’s needed for purchase verification. Now they may lose on this minor infraction, and pretty much any small business will die a horrible death without half their revenue. Meanwhile the mega corps will likely find some workaround do to their high priced lawyers, but even assuming we make a rock solid definition, they still just cycle the ceo immediately, because no one will want to be an active ceo when they are one court case from jail.
hddsx@lemmy.ca 9 months ago
IIRC there were hospitals in the US that violated HIPAA by accident because they used the Meta Pixel to aggregate useful information on their website, but which was also sending more information than they knew to Meta. So, it does “just happen”.
Meta is doing it knowingly though so….
themurphy@lemmy.ml 9 months ago
If these laws came into place, you would ofc create a grace periode, resulting in løser punishments.
It will give corps a window to really check wtf they are doing, and take it seriously.
Szyler@lemmy.world 9 months ago
And a few fines to popular websites and news reports about it and people will start to learn what the law is and don’t implement meta haphazardly. “just happen” will quickly turn to “rarely happens” once it becomes enforced.
ayyy@sh.itjust.works 9 months ago
Only an absolute brain dead moron would think using a Meta tracking pixel wasn’t going to exfiltrate information to Meta. Thats the level of negligence with important data that should be punished. If people are scared to collect data, then the correct goal has been achieved.
hddsx@lemmy.ca 9 months ago
They didn’t think that using Meta pixel would send absolutely no information to Meta. They were on board with that. They just didn’t think it would send sensitive medical information to Meta.
While I do agree with you, sometimes you have to wonder, “Do these places have anyone in IT at all?”
ayyy@sh.itjust.works 9 months ago
IT experts do nothing except reduce profit margins. You wouldn’t want a lower profit margin, would you?