4% of revenue in the EU, 4% of revenue in the UK, and 10% of revenue in Korea should be enough of an incentive to start caring about how you deal with your customer’s privacy and personal data.
One assumes the rest of the world won’t be far behind, apart from the the corrupt land of the USA which is going backwards right now.
I want to see how much be the fine will for this data leak.
https://www.dw.com/en/cyberattack-in-berlin-14-million-files...
It's only an incentive to start caring if it's cheaper than circumventing the law. In other words it won't work unless the aforementioned liability loophole is closed.
To rephrase the comment you replied to, if being a cowboy is more profitable (by whatever shady means) then that will generally be preferred by the market. Despite whatever sensibilities you or I might have there is no escaping that simple truth of capitalism.
So we get to a very easy formula for companies to do in the EU and UK:
If (4% of your revenue * risk_of_breach_with_your_security < cost of outsourcing storage to a 3rd party cloud) {
Roll your own security solution
} Else {
Outsource to 3rd party
}