Corporate Data Breach Liability

This cluster focuses on calls for holding companies accountable for data breaches through fines, lawsuits, and regulations due to negligence in securing user data like PII. Commenters criticize minimal current consequences and advocate for stronger incentives to improve security practices.

➡️ Stable 0.5x Security
4,761
Comments
20
Years Active
5
Top Authors
#1659
Topic ID

Activity Over Time

2007
2
2008
6
2009
17
2010
31
2011
112
2012
87
2013
135
2014
127
2015
203
2016
188
2017
503
2018
578
2019
470
2020
390
2021
390
2022
284
2023
405
2024
470
2025
343
2026
20

Keywords

e.g mobinspire.com US CREDIT FREE AT MONITORING PII GDPR data breach companies security breaches company user data personal information consequences sensitive data

Sample Comments

bawolff Jul 25, 2025 View on HN

Make company liable for damages when breached.If you want companies to care about security then you need to make it affect their bottom line.This wasn't the work of some super hacker. They literally just posted the info in public.

thatguy0900 Jan 26, 2021 View on HN

I would assume the companies working on those accounts care more about security than the company working for average citizens. They can actually go out of business and see consequences after being hacked as opposed to, say, experian.

quantified Jul 13, 2024 View on HN

Which implies that the company is negligent in hoarding the data in the first place. If you admit that there is no effective security for sensitive data, you admit that holding the sensitive data in the first place is negligent. Create real sanctions for the loss of the data, follow through on them, and then companies will do better.Mind you, Snowflake is the problem here, not AT&T, if it was their leak. AT&T is big enough that no meaningful sanctions will fall on them. It's not

lawl Feb 12, 2018 View on HN

Start fining companies when user data is lost. News would report on companies getting fined for shitty security practices, which also makes it clear that the problem isn't hackers. Plus companies have an incentive to spend money on securing their data.

pier25 Oct 27, 2019 View on HN

Shouldn't companies be penalized for exposing its users' private data?

pharke Apr 3, 2021 View on HN

Think of it like a class action lawsuit on behalf of investors. Instead of entrusting their savings to a company, people are entrusting them with their personal information. If there is gross negligence on part of the company leading to that data being leaked then all of the people whose data was stolen should be able to claim monetary damages. If a legal precedent is established so that these claims can be pursued whenever this happens it should provide enough motivation for these companies to

AlexandrB Jan 6, 2021 View on HN

In my opinion, this is a symptom of weak/ineffective regulation in the personal information space. The consequences for data breaches to the guilty parties have been minimal at best. Meanwhile responsibility for fraud has been pushed onto individuals via concepts like "identity theft". Even if the company in question was indeed reputable and well-known, most people don't have the technical expertise to evaluate any claims about security or privacy. Who would take that risk kn

josefritzishere Jul 16, 2024 View on HN

Maybe not a popular take but This is kind of a victimless crime. They mishandled private data but so did Experian (for example) and she never had a breach! On all the other charges I'd argue the tech companies poor security processes were by design because it generated more revenue.

game-of-throws Jul 30, 2022 View on HN

Strongly agree.We've already seen shades of this in banking. After chips were added to credit cards, people started having their chargebacks denied because "our records show the card was physically present" (even if the charge originated in another country)How long until companies try to deny responsibility for data leaks because "our records show Windows was fully up-to-date and secure"

Porthos9K Oct 8, 2019 View on HN

This is what you get for giving corporations PII they don't actually need.