Is there any kind of legal standard of liability when a victim of a data breach suffers from someone exploiting their data? If you are only breached once, obviously it’s easy to point the finger to whoever leaked your data.

But I’ve been hit 3 times now. So all those shitty corps who sloppily handled my data can point the finger to each other. Would a court say the most recent sloppy custodian is responsible if my data is used against me? Or would it be the most reckless custodian? Or would it be equal blame? Or does everyone get off the hook when a victim cannot prove which leak leads to an exploit?

It’s a hypothetical question. Not saying my data was exploited after the breaches, but I wonder about the overall trend. What I’m getting at is there may be little incentive to actually invest in good data security because when a breach happens amid so many other breaches there is perhaps a diffusion responsibility.

4 points

Yes, always blame the companies who steal and sell your information and have crap security.

permalink
report
reply
2 points

It was always hard to point the finger. Basically the problem stems from the idea that for breaches there just are no significant repercussions for the parties involved. They pay for (or set up) some form of credit monitoring and then just go on about their merry way. In the event that they are held accountable at all it’s usually something like a fine, which to the vast majority of these companies is less than a slap on the wrist. These corps consider it the price of doing business.

As someone who’s data has been exploited (and who’s data was actually leaked by breaching the federal government), I’m gonna say there’s just not a lot to be done except doing your due diligence to change the PII you can change (locking your credit, monitoring credit reports, changing PII like your SSN or other ID number etc).

But I doubt even a class action suit would do much in most of these cases.

permalink
report
reply
1 point
Deleted by creator
permalink
report
parent
reply
1 point

That’s not what I meant. I was specifically talking in the legal context because in America we have so few privacy protections for things like this.

permalink
report
parent
reply

US Law (local/state/federal)

!law_us@lemmy.sdf.org

Create post

This is the only decentralized venue for chatter about law in the US. Federal law and law of various states and territories is on topic here.

Loosely related:

Community stats

  • 34

    Monthly active users

  • 9

    Posts

  • 41

    Comments

Community moderators