They are accountable to their users. If a company is negligent with user data and their customers actually do care about this issue, this company will either eventually improve or go out of business. And if customers don't deem this important, it's not a government's role to decide it is.
To be clear, I'm not arguing for no control at all. However, fines should not be so egregious that it ends up being up to bureaucrats to decide whether a company lives or dies. This will easily lead to selective enforcement and corruption.
> If a company is negligent with user data and their customers actually do care about this issue, this company will either eventually improve or go out of business.
I think we've seen enough of how this theory works in practice (or how it doesn't) to be able to say that there is absolutely no good reason to rely on it.
1. The problem is that most population is terribly poor at defining and managing risk, by biological design and social selection - those who are good at it are usually not the best neighbors you want to have.
2. In many businesses, the actual customers are not the end-users, whose data is leaked (all the nice free services you're getting over this invisible thing called internet), they are the merchandise business is selling to somebody else (ads, etc.).
3. There are two ways of coping with this:
3.1 darwinian, where stupid users who choose to hand their data to dumb businesses all jump off the cliff holding hands
3.2 paternalistic, where we elect somebody competent to make choices for the rest of the community, which would prevent people's poor judgment to both hand data to insecure businesses and for businesses to be insecure in the first place.
4. We tried darwinian one since the day 1 in many fields. Reverting it comes at cost (antibiotics would be one good example to think of).
So you are saying, if a company negligently loses some important data about me; lets say enough to create a fake identity or access my medical records, my only recourse should be to stop using them?
> If a company is negligent with user data and their customers actually do care about this issue, this company will either eventually improve or go out of business.
1. Knuddels is largely targeting minors
2. its customers are other companies not its users
3. in the real world there are externalities (like the network effect)
That's assuming the company explains in enough detail how it secures its product for consumers to tell the difference. More likely is that company A has a breach, and consumers who care about security move to company B, which is just as insecure but hasn't recently been hit by the risk realisation bat.
Take this argument over to Facebook. How many breaches of trust have happened over the past year? Have they improved? Not a bit. If anything, they are becoming worse.
That is not even theoretically valid. Even if customer care, customer has no way to review security. Moreover, companies lie a lot about their systems security. All systems totally secure and there were no succesfull attacks until laws about mandatory announcements came around.
It is only after publicly known exploit that small customer can know about issue.
To be clear, I'm not arguing for no control at all. However, fines should not be so egregious that it ends up being up to bureaucrats to decide whether a company lives or dies. This will easily lead to selective enforcement and corruption.