17.3.1 Privacy Laws and Regulations


In the digital age, data is often referred to as the “new oil,” highlighting its value and importance. As technological advancements have enabled unprecedented levels of data collection, processing, and transfer, the protection of personal data has become a pressing concern. Various jurisdictions have responded by enacting privacy laws and regulations to protect individuals’ rights and regulate entities handling personal data. Let’s delve into some key privacy laws and their core tenets:

1. General Data Protection Regulation (GDPR) – European Union

Core Tenets:

  • Data Subject RightsIndividuals have the right to access, rectify, and erase their personal data, among others.
  • ConsentClear, informed, and explicit consent is required for data processing.
  • Data Protection Officers (DPO)Certain organizations must appoint a DPO to ensure compliance.
  • Data Breach NotificationsOrganizations must report breaches within 72 hours.
  • International Data TransfersTransfers outside the EU must ensure an adequate level of protection.

2. California Consumer Privacy Act (CCPA) – California, USA

Core Tenets:

  • Right to KnowConsumers can request businesses to disclose the data collected about them.
  • Right to DeleteConsumers can ask businesses to delete their personal data.
  • Opt-Out RightConsumers can opt-out of the sale of their personal data.
  • Non-DiscriminationBusinesses can’t discriminate against consumers for exercising their rights.

3. Personal Data Protection Act (PDPA) – Singapore

Core Tenets:

  • Consent ObligationOrganizations must obtain an individual’s consent before collecting, using, or disclosing their personal data.
  • Notification ObligationIndividuals must be informed of the purposes for which their data will be collected, used, or disclosed.
  • Access and CorrectionIndividuals have the right to access and correct their personal data.

4. Lei Geral de Proteção de Dados (LGPD) – Brazil

Core Tenets:

  • Legal BasisData processing must have a legal basis, such as consent, contractual necessity, or legal obligation.
  • Rights of the Data SubjectSimilar to GDPR, it includes rights of access, rectification, deletion, and more.
  • Data Protection OfficerCertain organizations need to appoint a DPO.

5. Data Protection Act – United Kingdom

Core Tenets:

  • Data Processing Principles: Data must be processed lawfully, transparently, and for a specific purpose. It must be accurate, kept no longer than necessary, and secured.
  • Individual Rights: Individuals have rights over their data, including the right to be informed and rights of access, rectification, and erasure.

6. Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules – India

Core Tenets:

  • Consent for CollectionRequires companies to obtain written consent before collecting sensitive personal data.
  • DisclosureInformation can’t be shared without the individual’s consent or legal necessity.
  • Reasonable Security PracticesEntities must have security practices and standards in place to protect the data.

Conclusion

These privacy laws and regulations exemplify the global commitment to ensuring the privacy and protection of personal data. Given their variations and nuances, organizations operating across borders must be particularly vigilant to remain compliant. As technology evolves and data becomes even more integrated into daily life, these regulations will likely undergo revisions and updates, making it essential for businesses to stay informed and adaptable.



Key terms in plain language

Open a term for a concise explanation of language used on this page.

Cybersecurity

The practices and controls used to protect identities, devices, networks, applications, and data from unauthorized access, disruption, or manipulation.

Zero Trust

A security model that does not automatically trust a user or device because of its location. Access is continuously verified and limited to what is necessary.

SASE

Secure Access Service Edge combines networking and security capabilities in a cloud-delivered architecture so users and locations can receive consistent policy wherever they connect.

Identity and Access Management (IAM)

The systems and policies that determine who a user is, what resources they may access, and how that access is authenticated and reviewed.

Multi-Factor Authentication (MFA)

A login control requiring more than one form of verification, such as a password plus an authenticator app, security key, or biometric factor.

MDR / XDR

Security services and tools that monitor activity, investigate suspicious behavior, and help contain threats. MDR is managed detection and response; XDR correlates signals across multiple security layers.