Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Some hard to swallow pills for tech companies in 2026: data not collected in the first place cannot leak.


Followed by deleting data once you've used it for its stated purpose.

Personal data needs to be much more of a liability than it currently is for anything to change. Business will respond when the bottom line is affected.


In the abstract, yes.

In the case of a university like the head of this thread, it isn’t going to be easy to avoid collecting and retaining data.


Funny you say that without even knowing the school’s use case for the data. And most certainly in the abstract, companies have even less reason to collect PII than they are currently doing.


that's the odd thing: we simply don't ask whether there's an alternative.

for instance, how many companies (including universities) store their own cash on prem? what if we treated PII like cash? limit amount and time kept outside the data "bank" (which would be a third party specialized for security and authenticating access).


Not collect data? Heresy!




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: