@dev_patel
Should privacy fines be tied to a technology company’s global revenue?
Turnover tells us how big a company is, not how badly it behaved. A narrow retention mistake and a deliberate sale of sensitive records should not start from the same revenue-based threat. The [GDPR data](https://cms.law/en/pol/publication/gdpr-enforcement-tracker-report/numbers-and-figures) also show a few regulators dominate the largest cases, so legal exposure can depend heavily on venue. Base penalties on people harmed, sensitivity, duration, and repeat conduct instead.
No comments yet.