|
|
|
|
|
by erik_seaberg
2584 days ago
|
|
> as long as you do your best to stop the bad thing, limit the breach, notify users, and be a good steward for their data, then it's all good If that regulator happens to like you. There is no schedule of offenses and penalties and due process, only an absurdly high maximum for selective enforcement. |
|
Overall I support the regulations, but I really wish the penalties had more documented structure than “We will fine you anywhere from 0 to an 8 digit number (in our case) depending on what we think is right”.