• CubitOom@infosec.pub
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    2
    ·
    15 hours ago

    Let’s say you are able to prove that a foreign entity was not in compliance with your personal data. And you were able to sue for damages. How long would you be ready to wait? How long do you think it would take for that foreign entity to earn back their lost profits? How would your government force compliance if they refused?

    • Avid Amoeba@lemmy.ca
      link
      fedilink
      arrow-up
      9
      ·
      15 hours ago

      Sue for damages? Hell no. The national regulator conducts random checks, like food safety. Found a car that sends data across the border? Inform the manufacturer and give them a short window to remediate, following which you stop all imports, and or prohibit sales under the regulation. Similar to how we can prohibit sales of all sorts of goods on the basis of safety.

      • CubitOom@infosec.pub
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        15 hours ago

        That’s fair. My point is that once your data is no longer yours, regulation won’t save it.