• demesisx@infosec.pub
    link
    fedilink
    English
    arrow-up
    9
    ·
    10 months ago

    Disagree if you add the three different factors that I added to account for this in my original comment:

    As I wrote in my edit, I think the size of fine should be dependent on:

    • size of company

    • the reasonable expectation of security (which would partially attempt to decrease fines for unfixable breaches)

    • the number of unique users affected