Privacy Program Frameworks: Chapter 3 Flashcards
Argentina
Personal Data Protection Law No 25,326 (PDPL)
Agency for Access to Public Information (AAPI)
Australia
Privacy act of 1988
Office of the Australian Information Commissioner (OAIC)
Brazil
Lei Geral de Proteção de Dados (LGPD), Law No. 13.709/20183
Autoridade Nacional de Proteção de Dados (ANPD)
Canada
Personal Information Protection and Electronic Documents Act (PIPEDA)4
Office of the Privacy Commissioner of Canada (OPC)
Note: Canadian provinces have their own, often stricter, privacy laws
China
Cybersecurity Law of the People’s Republic of China
Cyberspace Administration of China (CAC
Data Security Law of the PRC
Personal Information Protection Law of PRC
European Union
General Data Protection Regulations (GDPR)
Member state supervisory authorities
Hong Kong
Personal Data (Privacy) Ordinance
Office of the Privacy Commissioner for Personal Data (PCPD)
India
Information Technology Act 2000
Ministry of Electronics and Information Technology (MeitY)
Israel
Protection of Privacy Law 5741-1981
Privacy Protection Authority
Japan
Act on the Protection of Personal Information (APPI)
Personal Information Protection Commission (PIPC)
GDPR
Passed: 12/2016. Effective: 05/25/2018
Art 1: Subject matter and objectives
1. Natural persons
2. Fundamental freedoms
3. Free movement of personal data in the Union shall not be restricted
Art 2: Material Scope
1. automated or manual data
2. Not apply in certain issues
3. all member states
4. also directive 2000
Art 3: Territorial Scope
1. All controllers or processors in the union
2. Individuals in the union
3. Anywhere else where member state laws apply
Penalty: 4% of revenue, or 20m euros
GDPR Data subject rights
- withdraw consent
- request a copy of their data
- request to move their data to another org
- request to delete all their data
- object to automated decision making, profiling
CCPA
Passed: June 2018. Effective Jan 1, 2020
Consumers:
- request a record for the type of data and how it is used / shared
- request erasure
- opt out of sale of data
Orgs:
- verification for consumers
- respond to DSARs within 45 days
- provide methods for receiving requests
- disclose to whom they sell their data, all do not sell
- non-discrimination for exercising these rights
- Children optin (13-16 by child, under 13 by parent)
30 days to address
Penalty: $7500 fine (intentional) or $2500 fine (unintentional)
GDPR Org reqs
- Implement PbD&D
- Maintain appropriate safeguards
- Notify DPA within 72 hours of breach
- Collect consent and provide notification of processing activities
- Parental consent for under 16
- Keep records of all processing
- Appoint a DPO
- Responsibility for security and processing by vendors
- DPIA for new or high-risk processing activities
- Safeguard cross-border data transfers
- Consult regulators when necessary
- Demonstrate compliance
- Provide training for those with access
LGPD
Passed Aug 2018. Effective Aug 1, 2021
Penalty: 2% of revenue in Brazil, max of 50m reals
China Personal Info Protection Law
Passed Aug 2021. Effective Nov 1, 2021
Penalty: $7.7m or up to 5% of previous year revenue
FTC Act (Section 5) of 1914
Unfair and deceptive practices
Fair Credit Reporting Act (FCRA) of 1970
Accuracy and fairness of data with consumer reporting agencies
FERPA of 1974
Protect students data
Fed Privacy Act of 1974
fair information practices for fed collected PII
Electronic Communications Privacy Act of 1986
fed wiretapping limits
Video Privacy Protection Act of 1988
vcr rental records
Telephone Consumer Protection Act of 1991
limits auto-dialing systems
Drivers Privacy Protection Act of 1994
privacy for DMV collected PII
HIPAA of 1996
protects PHI
Children’s Online Privacy Protection Act of 1998 (COPPA)
Protects the PII of minors, specifically 12 and under
Gramm-Leach-Bliley Act of 1999
consumer financial services must explain sensitive data sharing
CAN-SPAM Act of 2003
controls unsolicited commercial email
Fair and Accurate Credit Transaction Act of 2003
consumer protection to prevent identity theft
National Do Not Call Registry
no telemarketing for numbers on the list
Health Info Tech for Economic and Clinical Health Act of 2009
HHS has authority to set higher system requirements
Self Regulations
PCI DSS: payment processing
DMA: data-driven marketing
Verasign, TrustArc, PaPal trust marks: vendor validation
Childrens Advertising Review Unit: target ads
Network Ad Initiative: privacy and data governance
EU Code of Conduct: B2B Cloud Serv
GDPR Article 45
Adequacy for countries
GDPR Article 46
Non-adequate country transfer
BCRs or SCCs