You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function.
Minimizes money usage and does not require any security investments
Followed by deleting data once you've used it for its stated purpose.
Personal data needs to be much more of a liability than it currently is for anything to change. Business will respond when the bottom line is affected.
that's the odd thing: we simply don't ask whether there's an alternative.
for instance, how many companies (including universities) store their own cash on prem? what if we treated PII like cash? limit amount and time kept outside the data "bank" (which would be a third party specialized for security and authenticating access).
Funny you say that without even knowing the school’s use case for the data. And most certainly in the abstract, companies have even less reason to collect PII than they are currently doing.
augment_me · · focus · HN ↗
Minimizes money usage and does not require any security investments
louthy · · focus · HN ↗
m132 · · focus · HN ↗
SoftTalker · · focus · HN ↗
Personal data needs to be much more of a liability than it currently is for anything to change. Business will respond when the bottom line is affected.
gregglain · · focus · HN ↗
fn-mote · · focus · HN ↗
In the case of a university like the head of this thread, it isn’t going to be easy to avoid collecting and retaining data.
markhahn · · focus · HN ↗
for instance, how many companies (including universities) store their own cash on prem? what if we treated PII like cash? limit amount and time kept outside the data "bank" (which would be a third party specialized for security and authenticating access).
rTX5CMRXIfFG · · focus · HN ↗