There was a lot of noise a few years back about Meta getting billion-euro fines over GDPR violations.
I looked it up: they paid almost none of the fines.
If you get a ticket from a speed camera, the government will garnish your wages if you don’t pay the fine. For trillion dollar organisations payment is apparently optional.
The EU seems to live in a world all on its own. They can’t fine enough to actually change the behavior of big companies, but they can fine enough to kill their own startup culture.
I don’t feel bad for them anymore. Their voters seem to be fine with this status quo. And I get why other countries see these fines as trying to raise taxes by other means because it hasn’t and won’t change anything.
> They can’t fine enough to actually change the behavior of big companies
Of course they can fine enough. They just don't, which is why you see companies get fined again and again profiting from each violation.
The real issue is that fines are hard to set against companies with more money than they could ever need. What we need is for more CEOs to go to prison, but that's hard to do when the company's CEO is a citizen of another country.
They should multiple by 100 and then by another 100 with each violation. The real solution is to lock executives behind bars, but if the CEO is a citizen of another country you're kind of stuck with fines and bans
They just need to ban these companies from operating in their countries. They are fundamentally burdens on society run by bad people.
Your best case scenario with fines is getting them into the narrow definition of compliance just until a new "innovation" gives them a different way to conduct the same abuse while evading the letter of previous judgments.
This is a judgement from the DPC in Ireland, which has a history of reluctance [0] when it comes to enforcing the GDPR on US corporations, e.g. in [1] they even had to be ordered by a court to start investigating. I don't see the Irish DPC voluntarily choosing to take on more oversight here.
https://www.enforcementtracker.com/ETid-3171 Yangoo. UAE.
https://www.enforcementtracker.com/ETid-1912 Criteo. French.
https://www.enforcementtracker.com/ETid-3162 Intesa Sanpaolo. Italian.
https://www.enforcementtracker.com/ETid-2864 Shein. Chinese.
https://www.enforcementtracker.com/ETid-2306 Enel Energia. Italian.
American companies fines tend to be highest since they are biggest and revenue affects the fine amount.
I looked it up: they paid almost none of the fines.
If you get a ticket from a speed camera, the government will garnish your wages if you don’t pay the fine. For trillion dollar organisations payment is apparently optional.
Source?
So far they’ve paid something like €20 million out of €4.0 billion in GDPR fines.
The justice system is slow, that's why the fines are slow to be collected, that's all.
I don’t feel bad for them anymore. Their voters seem to be fine with this status quo. And I get why other countries see these fines as trying to raise taxes by other means because it hasn’t and won’t change anything.
Of course they can fine enough. They just don't, which is why you see companies get fined again and again profiting from each violation.
The real issue is that fines are hard to set against companies with more money than they could ever need. What we need is for more CEOs to go to prison, but that's hard to do when the company's CEO is a citizen of another country.
Your best case scenario with fines is getting them into the narrow definition of compliance just until a new "innovation" gives them a different way to conduct the same abuse while evading the letter of previous judgments.
[0] https://arstechnica.com/tech-policy/2021/09/ireland-fails-to...
[1] https://cooltechzone.com/news/court-irish-dpa-must-investiga...