Does a suicide potentially move this from willful civil negligence into the realm of criminal negligence? Nonfeasance?
Leaving my doors and windows open is stupid but not an invitation to go rummaging thru my stuff.
Your friends pay you money to permanently dispose of the evidence of their marital affair
You just leave the evidence at your house instead
You leave your doors and windows open
Now its still not your fault that people came in and rummaged through your stuff; but surely its you who are to blame for never disposing of the evidence as you promised (and accepted payment for)?
Its an interesting component to what is otherwise extremely simple.
If i paid a document shredding company to shred my documents and months later that company gets broken into and all my documents are released...
Surely i blame the shredding company as much, if not more, than i blame the thieves.
I don't really have a position or idea on what this all makes ashley madison guilty of from a criminal or civil law perspective - but i certainly feel that there are punishable actions taken by ashley madison in this whole mess
Both of those are separate issues from leaving the information laying about.
In the original case, I might be stupid, but the interlopers are wrong to assume that they had an invitation to stuff laying about. They are, in fact, burglars.
Even with your addition, they are still burglars. However, I am liable for either 1) failing to destroy said information/stuff and/or 2) failing to do so within the specified timeframe, if the burglary happened after that timeframe.
The blame to the burglars remains the same in either case.
Honestly, I'm sort of enjoying a fat cuppa shadenfreude tempered by the knowledge that it is, for the most part, really none of my damn business what someone else does with their naughty bits.
It'd be hard to argue that it conduct that disregarded human life, though.
You may be right that many companies behave this way, but they at least pretend that they don't. The companies I've worked for have always been extremely conscientious about honoring data-related terms, even if no user would ever know. The fear of getting sued is strong.
In any case: when I say that Avid Life is nowhere near the bottom quartile for companies when it comes to security, you can take that to the bank. Or, don't, if you're worried about taking things to places that won't lose your data in a breach. I guess you can take your data to Facebook in that case.
Given backups and billing records and stored message histories and so on, its not really a question of 'deleting an account'. More like 'making an account no longer visible/available to the current interface'. Nobody thought they'd wipe any disks or anything, in anticipation of a big data breach, right?
Whilst that is true, we equally don't want to be completely ruling it out. An investigation should be conducted regarding the actual attack, and perhaps their handling of the leak. Did they even notify all users?
edit: also, as others have implied, 2 suicides out of 40 million is not that high (I don't mean to downplay the tragedy - all suicides are horrible) - but IMO you'd have a hard time proving the Ashley Madison hack was really the only cause, and not the final straw for somebody who was already in a bad place mentally. If I were to tell someone that their spouse was cheating, and their spouse commits suicide, would I be criminally negligent?
Note that I'm not playing with people's identities, but even then, you have to ask whether they were paying to delete the availability of their user data or the actual database records (somewhere in the contract?).
http://krebsonsecurity.com/2015/08/leaked-ashleymadison-emai...