Hacker News new | ask | show | jobs
by tyingq 2768 days ago
They should, though assuming a bloated org structure and process, fixing it now is probably more expensive than the €20000 fine.
3 comments

Note that the actual cost to Knuddels is much higher, because you also have to include the cost of implementing proper security measures. The Data Protection Officer's statement (https://www.baden-wuerttemberg.datenschutz.de/lfdi-baden-wue..., in German) states that the total cost to Knuddels is a six figure sum.
For a larger company, should be considerably higher.

Also, the ruling mentioned a reduced fine for cooperation and quick remediation. This probably wouldn't play out so well with a bloated structure and process, as you mentioned.

But the fine would have been more if they had refused to fix it. So the calculus isn’t straightforward.