Section 5 Flashcards
Which city banned employment based on credit history in 2015?
New York City
When was the California Financial Information Privacy Act passed and what is the other name by which it is known?
2004 and known as SB-1
How does the CFIPA (CA Financial Info Privacy Act) add to GLBA?
- Shifts the requirement for financial institution data sharing from an opt-out under GLBA to an OPT-IN under CFIPA.
- requires that financial institutions provide a SEPARATE DOCUMENT that is prominently titled “Important Privacy Choices for Consumers.”
In what two days does the Cal ECPA (Electronic Communications Privacy Act) restrict law enforcement in access to electronic comms?
- Service Provider Records
- criminal: search warrant or court order
- non-criminal: subpoena - Electronic Devices
- search warrant, wiretap order, consent of the customer or certification of an emergency situation
What rights does the CCPA (CA Consumer Privacy Act) of 2018 provide?
Right to: KKHOORD
- know what information is collected
- know how the information is shared
- opt out of information sharing
- review information
- request deletion of information
Does the CCPA include a private right of action?
Yes
How does the CA Privacy Rights Act update the CCPA?
- Creates a new category of information: Sensitive PI
- Adds new rights like:
- correct inaccurate information
- limit use and disclosure of SPI
- access information on automated decision-making
- to opt out of that automated decision-making
What law created the California Privacy Protection Agency?
CPRA (2023)
When did CA pass the CA Data Broker Law?
2019
What does the CA Data Broker Law require?
- annual registration with the AG
- AG publishes list of registered broker on its website
When does the CA Age Appropriate Design Code go into effect?
was set to go into effect July 2024 but was litigated
What does the CAADCA (California Age Appropriate Design Code Act) require that companies do?
- Annual Data Protection Impact Assessment (DPIA)
- Document risks and develop remediation plans
- Comply with AG requests
- Estimate age of child visitors
- Use strong default privacy settings
- Write privacy notices that children can understand
- Notify children they may be tracked
- Provide tools + info that parents and children can use to enforce privacy rights
What websites does the CAADCA apply to?
Those that are already subject to the CCPA AND
- are directed at children (as defined by COPPA)
- are routinely accessed by children
- are similar to another website directed at children
- have advertisements marketed to children
- have design elements interesting to children
- a significant amount of the audience is children
What are the possible fines under the CAADCA?
Negligent: $2500 per child
Intentional: $7500 per child
Is there a private right of action under the CAADCA?
No
What entities does the Colorado Privacy Act apply to?
If the business handles PI of 100K or more CO residents or handles PI of 25K or more residents and earns revenue from sharing that info
Does not apply to PI for your own employees
Does the CO law apply to non-profits?
Yes. CA does not.
Does CO Privacy Law have a private right of action?
No
What companies does the Connecticut Data Privacy Act (CTDPA) apply to?
If the business handles PI of 100K or more CT residents or derives over 25% of revenue from selling data AND control or process data of 25K or more CT residents annually
What does the CTDPA not apply to?
governments, non-profits, higher education or entities regulated by GLBA, HIPAA and FCRA
What rights does the CTDPA provide?
access, correction and deletion of data
data portability
opt out
appeal denial of requests
designate an authorized agent
Does the CTDPA have a private right of action?
No
When did the Delaware Online Privacy and Protection Act (DOPPA) go into effect?
2016
What are the three main categories of DOPPA?
Privacy policies
Protections for children (expands to under 18)
Protections for the privacy of users’ reading habits
How does the DOPPA definition of website operators affect a service like Amazon Web Servies?
It does not include web hosting services that have nothing to do with operating the actual site so AWS would be excluded
What are the Nevada SB 538 requirements?
Disclose clear privacy policies
What is the subject matter of the New Jersey Personal Information and Privacy Protection Act?
Customer identity/customer ID cards
What are the eight purposes that the NJ law allows retailers to collect customer IDs?
Validate customer identities for refunds
Verify customer age if needed
Prevent fraud in product returns
Prevent identity fraud in retain credit accounts
Creating and continuing customer contracts
Comply with laws that compel collection or disclosure
Disclose records to financial regulation
Compliance with HIPAA
What kinds of data does the WA Biometric law exclude?
Photographs, videos and audio recordings
What does the WA Biometric law require for biometric data?
Notice and consent before data can be “enrolled” in a database for commercial purposes with an exception for data needed to complete a transaction or to comply with other legal obligations
What does the NYDFS Cybersecurity Regulation do?
Makes financial institutions operating in NY follow cybersecurity infrastructure under NIST