logoalt Hacker News

DrewADesigntoday at 1:09 AM2 repliesview on HN

Maybe there should be some kind of annual ISO privacy certification for companies that resell any customer data in any form. Then make data customers (e.g. marketing agencies, major retailers) and data collectors (e.g. those that collect telemetry data from libraries included in their app, auto manufacturers, wireless providers) civilly liable for any privacy violations dealing with uncertified brokers, making sure there’s an uncapped modifier based on the company’s annual revenue. That seems like it puts the bulk of the compliance responsibility on the parties that can do the most wide-scale damage with unethical and dodgy practices, while leaving some out there for others that need incentive to not ignore the rules.

Haven’t really thought this through and I’m not a policy wonk… just spitballin’.


Replies

dredmorbiustoday at 1:48 AM

Bonding and/or insurance.

Make this cost and practices will change.

show 1 reply
JumpCrisscrosstoday at 1:42 AM

> Maybe there should be some kind of annual ISO privacy certification for companies that resell any customer data in any form

Why is this better than requiring deletion?

show 2 replies