PII Leak Liability

Discussions center on a company's exposure of sensitive personal data (PII), highlighting privacy violations, legal liabilities, compliance failures, negligence, and potential repercussions.

➡️ Stable 0.7x Security
3,195
Comments
20
Years Active
5
Top Authors
#4566
Topic ID

Activity Over Time

2007
3
2008
6
2009
24
2010
53
2011
67
2012
99
2013
155
2014
110
2015
118
2016
123
2017
195
2018
329
2019
284
2020
257
2021
285
2022
233
2023
274
2024
222
2025
339
2026
19

Keywords

MS e.g DPA AWS PR HIPAA PA DHS CEO MIT data pii sensitive data confidential sensitive unauthorized information security disclosure company

Sample Comments

XCSme Jun 2, 2020 View on HN

A bit weird to have a company working with such sensitive data not care about privacy.

bediger4000 Jan 21, 2026 View on HN

Throw the book at them. This is highly confidential data, with massive misuse potential. Don't do the crime if you can't do the time, and this sounds deliberate, not accidental or momentary lapse type of thing.

yjftsjthsd-h Aug 16, 2021 View on HN

From the customer's perspective, does it matter how their data got out?

sfjailbird Nov 7, 2024 View on HN

Sounds like a potential compliance issue too, if you work with sensitive data.

e40 Dec 20, 2025 View on HN

Are there privacy issues with the data being exfiltrated?

Mountain_Skies Sep 26, 2021 View on HN

It's rather lengthy and contains lots of repeated verbiage but I didn't see anywhere in it penalties for unauthorized access or leaking of the PII collected. It lists the purpose for collecting the data, what they intend to use it for, and states it cannot be used for purposes other than those listed in the bill but without consequences for violating those provisions, there's little reason for the organizations who are given access to this data to treat it with respect and secure

pixl97 Oct 26, 2025 View on HN

Depending on what jurisdiction you're in, it still could be a legal risk due to PII leaking.

Phlarp May 23, 2014 View on HN

>Perhaps they dont want any inadvertent leaks of the data to a third party?Little late for this.

criddell Jun 3, 2019 View on HN

What liability is there for not providing data you don't have?

duped Feb 28, 2022 View on HN

There may be liability attached. But this reads more like "a lot of data that we assumed to be private, and legally must be kept private appeared on a website. Here's everything we know and the steps we have taken." Essentially what happens when there's a screw up and lawyers get consulted about how to disclose it.