3. Framework: Applicable Privacy Laws and Regulations Flashcards
What elements of data protection laws overlap?
- Notice
- Choice and consent
- Purpose limitation
- Individual rights
- Retention limits
- Transfers
What is the responsibility of data regulators?
Regulators enforce how personal information is collected and how data subjects are informed and have a right to decide how their personal data is used.
Many laws have penalties for noncompliance or allow for private right of action.
What do new laws focus on?
The application of new technologies:
- Artificial intelligence
- Machine learning
- Data security measures and controls on new technologies such as quantum computing and AI/ML
- Handling personal data during pandemics
What are omnibus laws?
Omnibus laws cover the collection and use of personal data in general with perhaps increased protection and sensitivity required for certain categories of data such as health or sexual orientation data.
Who is subject of foreign data protection laws?
Anyone actively trying to solicit business in a country
What are the commonalities among provisions among global privacy and data protection laws?
- Ensuring individual rights (access, correction, and deletion)
AND - Obligations (safeguarding data)
Other: contractual requirements, audit protocol, self-regulatory regimes, and marketplace expectations.
When did the EU General Data Protection Regulation come into effect?
The EU Parliament and council agreed upon the GDPR in December 2016 and is enforceable as of May, 2018.
The GDPR was first proposed in 2012.
What does the GDPR offer?
A framework for data protection with increased accountability for organizations, and it’s reach is extraterritorial.
What is the first comprehensive privacy law introduced in the United States?
The California Consumer Privacy Act (CCPA) was signed into laws in June 2018 and went into effect in January 2020.
What does the CCPA achieve?
New privacy laws for Californians and significant new data protection obligations for businesses.
How is the CCPA enforced?
The Office of the Attorney General.
What was the intent of the California ballot initiative?
To provide additional protection to consumers through the California Privacy Rights Act (CPRA).
The CPRA will come into force on January 1, 2023 with a one year look back to January 2022.
What is Brazil’s general data protection law?
Lei Geral de Protecao Dados Pessoias (LGPD)
When was the LGPD passed?
It was passed in August, 2018 and went into effect September, 2020, though administrative sanctions could not be issued August, 2021
What is China’s first comprehensive information protection law?
The People’s Republic of China Personal Information Protection Law (PIPL)