Companies behind major negligent data leaks can now face fines of up to 10 percent of annual revenue under revised privacy rules.

339 points•throw7•12 days ago•115 comments•

115 comments

augment_me12 days ago
You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function.

Minimizes money usage and does not require any security investments

killingtime7412 days ago
There are specific laws called Piercing the Veil that can easily be passed to close this type of loophole.

Courts are run by people, not AI, so judges can easily ignore the corporate entity once these laws are passed.

laughing_man12 days ago
Piercing the corporate veil is difficult to do in practice unless they've gotten very sloppy.
dubeye12 days ago
Sounds good in theory, what's the practical reality in your experience?
rat998812 days ago
Doesn't seem out of reach of AI. Not sure why you think so.
louthy12 days ago
Or … and hear me out on this one … care?
m13212 days ago
Some hard to swallow pills for tech companies in 2026: data not collected in the first place cannot leak.
AIiscoming12 days ago
Lets be honest here, this is a business risk which is crazy high. As stupid as this is, I care but i can't guarantee it.

I might suggest a construct like this too.

What do you think how much it cost to do it perfect?

pluc12 days ago
Every single tool being released since like 2024 is pushing everyone to care less and less and to let agents handle more and more. We are not trending towards increased quality, resilience and reliability - even though we've been obsessing over these things for the past 20 years.
novok12 days ago
How much to care is reasonable? Do you live in a windowless underground security bunker? Should most businesses be held to that standard?

Lets say these are paper records, behind a locked door, with a security guard that they check id for it. If someone then breaks in at night time, cuts the cameras and knocks out the security guard and steals a filing cabinet, should that university then be fined 10% of revenue, which could mean the entire university shuts down because most businesses cannot survive that? We have to remember who is the original criminal here.

carefree-bob12 days ago
Problem is that most breaches are social engineering attacks where employees or customers are phished for their credentials or even to approve/install some malicious code. It's very hard for businesses to defend against this.

They can try:

* various education campaigns

* force users/customers to adopt passkeys or other phishing resistant mfa

* add various alarms and alerts for unusual activity, resulting in lockout

The problem is that even after adopting all of the above, it's still not too hard to breach virtually all companies, and there is massive user opposition to the last two.

ranger_danger12 days ago
makeitdouble12 days ago
Parent isn't talking about shareholders or ownership, but full delegation of a process to a contracting company.

Calling "shell company" makes it sound like the University is the shareholder, but that's usually not what's happening IMHO. In general the entities are clearly defined and nothing crosses the client/contractor frame, the university just happens to be the sole client and the contractor will have the uni pay for their whole operation.

amelius12 days ago
That's like blaming Seagate when your harddisk fails.

No judge will fall for that. You should have made backups. And you are responsible for the data of your clients.

augment_me12 days ago
Not really, the shell company is the owner of the data and is responsible for the security of it by contract, that's the whole point.

Seagate will not in a million years sign anything like this when you buy a HDD.

dmos6212 days ago
That's legal?
EA-316712 days ago
Sure, but the real question is, "Will a judge not immediately see through this and punish them accordingly in any realistic case?"

Sort of like EULA's a lot of the "value" is incredibly theoretical.

miohtama12 days ago
It’s Hollywood accounting
micromacrofoot12 days ago
similarly, most AI datacenters aren't directly owned by the frontier labs

guess who holds the bag if capacity needs collapse

prologic12 days ago
Wow! :O Finally, a legislator with enough balls to put up something that _might_ (just might) make corporations _actually_ care about security and privacy! I can't wait for this to start being adopted in other countries. It's about time!
SoftTalker12 days ago
"through intent or gross negligence"

I'm not familiar with Korean law but that seems a rather high bar. I don't think we'll see many fines actually levied.

bluGill12 days ago
The hope is they levy few fines. When you want to make money you set the fines such that they are "a cost of doing business". Most often you don't even call them fines, you call them a permit/license fee (though fines are also common). When you want to prevent a behavior you make the costs high enough that it is worth the effort to not pay them in the first place.

(I'm assuming here that 10% is high enough that nobody would call it a cost of doing business - I could be wrong)

someguynamedq12 days ago
Yeah neither intent nor gross negligence is the reason most data breaches occur
xtajv12 days ago
Hopefully, this raises the bar then.
quickthrowman12 days ago
I would like to make a wager on this law being ignored the first time Samsung or another chaebol violates it and is facing a fine equal to 10% of revenue. I can almost guarantee it, it’s a high enough fine to turn some low-margin businesses from profitable to unprofitable for the year and there’s no such thing as a secure computer system. The only way to guarantee compliance is to not store any data which isn’t exactly reasonable for some business models.
Retro_Dev12 days ago
> there’s no such thing as a secure computer system

Where is your source for this? It is entirely possible to make a secure computer system, though it does require effort. The article specifically mentions "up to" 10% and the fines applying to companies leaking data on purpose or through negligence. I doubt the fines will be nearly as high for a company that tries to secure a system (and thus prevents more leaks) rather than a company that does not try to secure a system (assuming that leaks will occur), if the same breach happens.

Computers are deterministic (excluding cases where practically impossible cosmic ray events occur), so while we have the power to ensure system security, we should ensure system security. Heck, even just encrypting consumer information and protecting just the keys to this data would already decrease the effectiveness of many data breaches.

aucisson_masque12 days ago
> Where is your source for this? It is entirely possible to make a secure computer system

You can’t. You don’t need source for that, just common sense.

Exploits are discovered every day, bugs happen, bad actors.

You can do the best system, shit still happen.

BTW you want a source ? Remember when the freaking CIA data got leaked ? Edward Snowden, ring a bell ?

If the cia couldn’t prevent it, I bet you can’t.

someguynamedq12 days ago
It is not possible to make a secure computer system that is also usable. There is ultimately no way to avoid the tradeoff between convenience and security.

You can make a system "more" secure than other systems, but you cannot make it truly secure.

quickthrowman11 days ago
> Where is your source for this?

For one, the lack of any secure computing systems.

bigfatkitten12 days ago
The South Korean privacy regulator is the most diligent that I’ve ever seen in terms of slapping companies with fines when they screw up.
buellerbueller12 days ago
Maybe those specific business models shouldn't exist, if they consistently risk harm to 3rd parties.
google23412312 days ago
You legally have to hold transactions for years yk as a business
google23412312 days ago
Probably a law targeted at foreign companies
Retro_Dev12 days ago
I especially hope this holds true, because I don't want my information being leaked by anyone.
hn_submit12 days ago
This is exactly what we need in the West! I have a strong suspicion that nobody here actually cares about security or customer data being spilled into the streets.

Security costs money and as long as there aren't any penalties for negligence management will make the calculation to prioritize increased profitability over securing company data.

tstenner10 days ago
This is exactly what the GDPR does (except it's 4%, not 10%).

Read the full thread on Hacker News →

Related stories