3: Privacy Prog Framework: Applicable Privacy Laws and Regs Flashcards
What is a major driver for compliance?
data protection laws and regulations. The laws and regs often overlap, so consult legal to make sure all the relevant areas are covered
Global Privacy Laws
enforcing how PI is collected and how data subjects are informed and have a right to decide how their PI is used.
New areas of data protection? (4)
AI
ML
Data security measures and controls on new tech, like quantum computing
handing data during pandemics
Omnibus laws (wrt other countries)
you have to abide by the laws of the country you are trying to do business in (not the country you are based in).
2 important privacy frameworks that many countries have based their data protection laws on?
- Organisation for Economic Co-operation and Development (OECD) guidelines on the protection of privacy and transborder flows of personal data & Asia-Pacific Economic Cooperation (APEC) privacy framework.
What concepts do the OECD and APEC cover?
- colleciton limitation
data quality
purpose specification
use limitation
security safeguards
openness
individual participation
accountability
Commonalities btwn global privacy & data protection laws, regulations and standards
requirements for ensuring individual rights (access, correction and deletion) and obligations (safeguarding data).
also, contractual requirements, audit protocol, self-regulatory regimes, and market place expectaiton
EU General Data Protection Regulation
GDPR - framework for data protection with increased accountability for organizations.
Has become the global standard for data protection
General Provisions of the GDPR (3)
Subject-matter and Objectives
- protection of people wrt processing, protection and movement of personal data
Material scope
- processing of personal data
Territorial Scope
- processor or controller in the Union, whether the processing takes place in the Union or not
CCPA
California Consumer Privacy Act
-privacy rights for Californians and significant new data protection obligations for businesses
Other PI and Data Protection law examples (2)
Brazil LGPD
China PIPL Personal Information Protection Law
for businesses it resembles the GDPR, does not prevent the PRC (People Republic of China) from accessing data
Sectoral Privacy Laws
Privacy and data protection addressed through laws that apply to market sectors and industries, like:
Health care (Protected Health Information in the US, special categories of data in the EU)
Financial
Telecom - includes communication, metadata and location information
Online
Government
Education
Video - including online streaming
Marketing
Energy
HR/Employment
Self-Regulation
Industry standards and codes of conduct
Voluntary and contractual initiatives
i.e. PCI DSS, Verisign, CARU (children’s advertising review unity)
Cross-Border Data Transfers
Protective measures required when data is crossing borders
EU has the strictest requirements, transfers outside EEA (European Economic Area) are ok if the countries are deemed to have adequate levels of data protection
Cross-Border Data Transfers with countries not deems to have adequate data protection…
SCC - Standard contractual clauses - valid method of data transfer
- assess on a case by case basis using a DTIA or TIA (Data transfer impact assessment or transfer impact assessment)