Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That sounds like something fairly trivially avoided by having the punishment be proportional to revenue. And I believe this is already the case for GDPR?

A quick search indicates "Up to €20 million, or 4% of the worldwide annual revenue of the prior financial year, whichever is higher" https://www.gdpreu.org/compliance/fines-and-penalties/



EU have shown that it's willing to scale up the fines all the way if the company in question keep on violating the law. Alphabet global revenue 2018 was $136.8 billion, so the maximum fine is $5.5 billion which is in the vicinity of fines they've already received. It's a separate post in their yearly financial report. The gain must be significant if they continually keep violating the laws.


This is being quoted in every comment but if you have enough lawyers anything is possible.

Google has come out of antitrust cases relatively unscathed. They've even violated GDPR itself once before explicitly, and got out with a 57MM$ fine. This case won't be any different than all the other times that Google has blatantly violated laws and walked away with a slap on the wrist.

I would be very very very shocked if the EU actually managed to touch Google. I welcome and hope to be proved wrong.


I mean, that's an entirely different class of problem.

If the law literally doesn't work because of reasons, then that's just systemic corruption.


I would argue that it's the same problem and the reason GDPR is privacy theater.

It's a lot of regulations that can be worked around and the fines are hard to and rarely enforced. There are a bunch of poster children of GDPR fines that make it seem like it's doing a lot but the principal abusers (i.e. Google) just walk away with a light slap.

It needs the ability to be enforced, and I think this much should be obvious to lawmakers -- a law that can't be enforced well is useless.

That's why I'm calling it privacy theater. It's the EU saying "look what we did!" but in practice it doesn't really do much without enforcement that still does not exist both at a national and global scale.


As far as I know, GDPR fines are purely regulatory and never go to court. So I am not sure how the lawyers are relevant.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: