SlideShare a Scribd company logo
1 of 25
Download to read offline
1
1
© 2021 TrustArc Inc. Proprietary and Confidential Information.
So Many States, So Many Privacy Laws:
US State Privacy Law Update
April 14, 2020
2
2
Thank You for Joining “So Many States, So Many Privacy Laws: US State
Privacy Law Update”
● We will be starting a couple minutes after the hour
● This webinar will be recorded and the recording and slides sent out later today
● Please use the GoToWebinar control panel on the right hand side to submit any
questions for the speakers
3
3
Speakers
K Royal
Associate General Counsel
Privacy Intelligence
TrustArc
Christina Fratschko
Privacy Research Specialist
Privacy Intelligence
TrustArc
4
4
Agenda
● Recent developments in US state privacy laws
● US federal privacy law predictions
● Best practices and tips on how your company can keep up
5
5
CCPA vs. CPRA vs. VCDPA
6
6
California
California Privacy Rights Act (CPRA)
CCPA CPRA
Threshold Application Buy, receive, or sell the personal information of
50,000 or more California residents, households,
or devices.
Buy, sell, or share the personal information of
100,000 or more California residents or households.
Employee B2B
Exemption
Concludes January 1, 2021 Concludes January 1, 2023
Consumer Rights ● Right to Know/Access
● Right to Delete
● Right to Opt-out of Sale
● Right to Non-Discrimination
Same rights as the CCPA, and an addition of:
● Right to Rectification
● Right to Limit Use and Disclosure of Sensitive
Personal Information
Enforcement Enforcement by the State Attorney General. Creation of the California Privacy Protection Agency
for enforcement and guidance.
Sensitive Information Not defined under the CCPA It is defined as personal information, which includes a
consumer’s SSN, driver’s license, state ID card, etc.
7
7
Virginia
How it differs from CCPA/CPRA:
● Has an explicit definition of sensitive data
● Applicability to employees and B2B communications
● Designation of controllers and processors
● Data protection impact assessments
● Consumer Rights
Next steps:
● This law is effective January 1, 2023
Virginia Consumer Data Protection Act (VCDPA)
8
8
Current Consumer Privacy
Landscape
9
9
Oklahoma
Current status:
If passed, businesses that do business in Oklahoma or collect consumers' PI must comply with
consumers' requests for access and portability (within 45 days of receipt of request), cannot
discriminate against a consumer for exercising any consumer right (including denying goods or
services), and must provide notice to consumers that their information may be sold; violations
are liable for civil penalties between $2,500 and 7,500.
Next steps:
● If passed, this Act will take effect on January 1, 2023 due to the latest bill amendments.
Oklahoma Computer Data Privacy Act (OCDPA) / HB 1602
10
10
New York
Current status:
The Act is identical to the version introduced in the previous Senate sitting; if passed, covered
entities must comply with consumers' requests for disclosure, access, correction and deletion
of personal data, cessation of processing, and data portability, and will have a fiduciary
responsibility to exercise a duty of care and confidentiality over personal data in its possession;
consumers may bring a private right of action for damages, and the attorney general may
impose civil penalties for violations.
Next steps:
● If passed, the Act will take effect on the 180th day after it becomes law.
New York Privacy Act (NYPA or A680) + Multiple Bills
11
11
Washington
Current status:
If passed, consumers must be provided one or more secure and reliable means to submit a
consumer request (e.g., data portability, erasure, opt-out), risks assessments must be
conducted when processing personal data for purposes of targeted advertising, and covered
data must be deleted or deidentified when such data is no longer being used for such
purposes; the AG may may initiate an action and seek damages of up to $7,500 for each
violation of this Act.
Next steps:
● This bill covers both private sector management of consumer personal data and privacy
and public sector management of data processed for a public health emergency (i.e.,
COVID-19)
● Most sections of the bill would take effect July 31, 2022
Washington Privacy Act (WPA)
12
12
Florida
Current status:
If passed, businesses must comply with opt-out requests within 15 days (including requests received
from authorized persons), make available a notice that is reasonably accessible to all consumers
whose PI is collected, and comply with deletion, correction, and access requests (deletion and
correction requests must be responded to within 30 days); consumers can recover damages ranging
between $100 and $750 for violations of this Act.
Next steps:
● If passed, this Act will take effect July 1, 2022 due to the latest amendments made to the bill
● The revised bill has also removed the private right of action provision, and limited the amount of
businesses required to comply with the Act (i.e., the Act would only apply to businesses that
annually buy, sell or share the personal info from 100,000 or more users or that generate at
least 50% of its global annual revenue from selling or sharing personal information about
consumers).
SB 1734
13
13
Alaska
Current status:
SB 116 and HB 159 were both introduced on March 31, 2021 to the Alaska State Senate and
House. The Consumer Data Privacy Act contains 4 new rights, the right to know, disclosure,
delete, and opt-out. Businesses cannot disclose consumer’s PI for a business or commercial
purpose, or use the consumer’s precise geolocation data for a purpose other than to provide
goods or services if it has actual knowledge that the consumer is under the age of 18.
Next steps:
● If passed, this Act would take effect January 1, 2023.
Senate Bill 116 and House Bill 159
14
14
Consumer Privacy Heat Map
15
15
Commonalities & Differences
16
16
State by State Comparison
17
17
State by State Comparison
18
18
The Federal Scenario
19
19
Poll Question
What do you think the time frame is for getting a US federal privacy law in place?
● This year
● Within the next 4 years
● Not anytime in predictable future
● There shouldn't be one
20
20
Federal Regulation
● Several promising bills have been introduced in the past, with most disagreement
centering on private rights of action and federal preemption
● Once again, current proposed legislation seems promising
○ Information Transparency and Personal Data Control Act - Rep DelBene
■ HR 1816
○ Most bills target specific areas of privacy - contact tracing, research, etc.
● How many state laws will it take to encourage Congress to pass legislation?
○ Are the differences among the states operationally impactful?
○ Keep in mind, every state has a data breach notification law
● Would other federal laws simply be expanded and strengthened?
● Consider global implications and impact
What’s next?
21
21
How Do You Keep Up?
Managing an Up-to-Date Privacy
Program
22
22
US Consumer Privacy Laws Map and Chart
23
23
Frameworks Facilitate Better Comparisons
Framework Element GDPR LGPD CCPA HIPAA Security USSG C&E Program Virginia CDPA
Integrated Governance
Risk Assessment
Resource Allocation
Policies and Standards
Processes
Awareness and Training
Data Necessity
Use, Retention, and Disposal
Disclosures to 3rd Parties & Onward Transfer
Choice and Consent
Access and Individual Rights
Data Integrity and Quality
Security
Transparency
Monitoring and Assurance
Reporting and Certification
24
24
25
25
Thank You!
See http://www.trustarc.com/insightseries for the
2021 Privacy Insight Series and past webinar
recordings.
If you would like to learn more about how TrustArc can support you with
compliance, please reach out to sales@trustarc.com for a free demo.

More Related Content

What's hot

Fairness and Ethics in A
Fairness and Ethics in AFairness and Ethics in A
Fairness and Ethics in ADaniel Chan
 
Responsible AI
Responsible AIResponsible AI
Responsible AIAnand Rao
 
Geografia 8º ano aula 02
Geografia   8º ano aula 02Geografia   8º ano aula 02
Geografia 8º ano aula 02Eloy Souza
 
Aula Sobre GeopolÍtica E Conflitos Internacionais
Aula Sobre GeopolÍtica E Conflitos InternacionaisAula Sobre GeopolÍtica E Conflitos Internacionais
Aula Sobre GeopolÍtica E Conflitos InternacionaisProfMario De Mori
 
Regularização Urbanística e Fundiária da Vila Hípica do Cristal
Regularização Urbanística e Fundiária da  Vila Hípica do CristalRegularização Urbanística e Fundiária da  Vila Hípica do Cristal
Regularização Urbanística e Fundiária da Vila Hípica do CristalAssociação Cohabs
 
SPEAK with CHATGPT 24h in US Language
SPEAK with CHATGPT 24h in US LanguageSPEAK with CHATGPT 24h in US Language
SPEAK with CHATGPT 24h in US LanguageErol GIRAUDY
 
[Material de aula] região sudeste
[Material de aula] região sudeste[Material de aula] região sudeste
[Material de aula] região sudesteflaviocosac
 
Brasil territorio e fronteiras 7º ano
Brasil territorio e fronteiras   7º anoBrasil territorio e fronteiras   7º ano
Brasil territorio e fronteiras 7º anoProfessor
 
Informaatiovaikuttaminen somessa
Informaatiovaikuttaminen somessaInformaatiovaikuttaminen somessa
Informaatiovaikuttaminen somessaHarto Pönkä
 
Geografia humana da Europa - Etnias e religiões
Geografia humana da Europa - Etnias e religiõesGeografia humana da Europa - Etnias e religiões
Geografia humana da Europa - Etnias e religiõesCarlos Ribeiro Medeiros
 
BACIA HIDROGRÁFICA DO RIO PARAGUAI
BACIA HIDROGRÁFICA DO RIO PARAGUAIBACIA HIDROGRÁFICA DO RIO PARAGUAI
BACIA HIDROGRÁFICA DO RIO PARAGUAIConceição Fontolan
 
Bias in AI-systems: A multi-step approach
Bias in AI-systems: A multi-step approachBias in AI-systems: A multi-step approach
Bias in AI-systems: A multi-step approachEirini Ntoutsi
 
Região Centro-Oeste do Brasil
Região Centro-Oeste do BrasilRegião Centro-Oeste do Brasil
Região Centro-Oeste do BrasilJailson Lima
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationVicky Dallas
 

What's hot (20)

Fairness and Ethics in A
Fairness and Ethics in AFairness and Ethics in A
Fairness and Ethics in A
 
Gdpr in a nutshell
Gdpr in a nutshellGdpr in a nutshell
Gdpr in a nutshell
 
Região Nordeste.
Região Nordeste.Região Nordeste.
Região Nordeste.
 
Responsible AI
Responsible AIResponsible AI
Responsible AI
 
Geografia 8º ano aula 02
Geografia   8º ano aula 02Geografia   8º ano aula 02
Geografia 8º ano aula 02
 
Aula Sobre GeopolÍtica E Conflitos Internacionais
Aula Sobre GeopolÍtica E Conflitos InternacionaisAula Sobre GeopolÍtica E Conflitos Internacionais
Aula Sobre GeopolÍtica E Conflitos Internacionais
 
Regularização Urbanística e Fundiária da Vila Hípica do Cristal
Regularização Urbanística e Fundiária da  Vila Hípica do CristalRegularização Urbanística e Fundiária da  Vila Hípica do Cristal
Regularização Urbanística e Fundiária da Vila Hípica do Cristal
 
Nordeste.
Nordeste.Nordeste.
Nordeste.
 
SPEAK with CHATGPT 24h in US Language
SPEAK with CHATGPT 24h in US LanguageSPEAK with CHATGPT 24h in US Language
SPEAK with CHATGPT 24h in US Language
 
[Material de aula] região sudeste
[Material de aula] região sudeste[Material de aula] região sudeste
[Material de aula] região sudeste
 
Região sul.pptx
Região sul.pptxRegião sul.pptx
Região sul.pptx
 
Brasil territorio e fronteiras 7º ano
Brasil territorio e fronteiras   7º anoBrasil territorio e fronteiras   7º ano
Brasil territorio e fronteiras 7º ano
 
Informaatiovaikuttaminen somessa
Informaatiovaikuttaminen somessaInformaatiovaikuttaminen somessa
Informaatiovaikuttaminen somessa
 
Geografia humana da Europa - Etnias e religiões
Geografia humana da Europa - Etnias e religiõesGeografia humana da Europa - Etnias e religiões
Geografia humana da Europa - Etnias e religiões
 
BACIA HIDROGRÁFICA DO RIO PARAGUAI
BACIA HIDROGRÁFICA DO RIO PARAGUAIBACIA HIDROGRÁFICA DO RIO PARAGUAI
BACIA HIDROGRÁFICA DO RIO PARAGUAI
 
Bias in AI-systems: A multi-step approach
Bias in AI-systems: A multi-step approachBias in AI-systems: A multi-step approach
Bias in AI-systems: A multi-step approach
 
Região Centro-Oeste do Brasil
Região Centro-Oeste do BrasilRegião Centro-Oeste do Brasil
Região Centro-Oeste do Brasil
 
Model bias in AI
Model bias in AIModel bias in AI
Model bias in AI
 
O continente americano
O continente americanoO continente americano
O continente americano
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 

Similar to US State Privacy Law Update Webinar Summary

Post US Election Privacy Updates & Implications
Post US Election Privacy Updates & ImplicationsPost US Election Privacy Updates & Implications
Post US Election Privacy Updates & ImplicationsTrustArc
 
U.S. Quarterly Privacy Update
U.S. Quarterly Privacy UpdateU.S. Quarterly Privacy Update
U.S. Quarterly Privacy UpdateTrustArc
 
Wb 2020-03-25-us-quarterly-privacy-update
Wb 2020-03-25-us-quarterly-privacy-updateWb 2020-03-25-us-quarterly-privacy-update
Wb 2020-03-25-us-quarterly-privacy-updateTrustArc
 
CCPA Update: What You Need to Know about CPRA & July 1st Enforcement
CCPA Update: What You Need to Know about CPRA & July 1st EnforcementCCPA Update: What You Need to Know about CPRA & July 1st Enforcement
CCPA Update: What You Need to Know about CPRA & July 1st EnforcementTrustArc
 
SECTOR-SPECIFIC-REGULATIONS-AND-A-FEW-HICCUPS-MORE-U.S.A-AND-ITS-PRIVACY-LAWS...
SECTOR-SPECIFIC-REGULATIONS-AND-A-FEW-HICCUPS-MORE-U.S.A-AND-ITS-PRIVACY-LAWS...SECTOR-SPECIFIC-REGULATIONS-AND-A-FEW-HICCUPS-MORE-U.S.A-AND-ITS-PRIVACY-LAWS...
SECTOR-SPECIFIC-REGULATIONS-AND-A-FEW-HICCUPS-MORE-U.S.A-AND-ITS-PRIVACY-LAWS...DaviesParker
 
California Consumer Privacy Act (CCPA) - Kloudlearn
California Consumer Privacy Act (CCPA) - KloudlearnCalifornia Consumer Privacy Act (CCPA) - Kloudlearn
California Consumer Privacy Act (CCPA) - KloudlearnKloudLearn
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsPECB
 
What are the new laws under Canada Digital Privacy Act.pdf
What are the new laws under Canada Digital Privacy Act.pdfWhat are the new laws under Canada Digital Privacy Act.pdf
What are the new laws under Canada Digital Privacy Act.pdfRiley Claire
 
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Financial Poise
 
Introduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsIntroduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsFinancial Poise
 
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...Kenneth Riley
 
CSR PII White Paper
CSR PII White PaperCSR PII White Paper
CSR PII White PaperDmcenter
 
China's PIPL: How to Comply in Under 60 Days
China's PIPL: How to Comply in Under 60 DaysChina's PIPL: How to Comply in Under 60 Days
China's PIPL: How to Comply in Under 60 DaysTrustArc
 
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...TrustArc
 
Privacy issues in data analytics
Privacy issues in data analyticsPrivacy issues in data analytics
Privacy issues in data analyticsshekharkanodia
 
California Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act: What your brand needs to knowCalifornia Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act: What your brand needs to knowOgilvy Health
 
What to expect from the New York Privacy Act
What to expect from the New York Privacy ActWhat to expect from the New York Privacy Act
What to expect from the New York Privacy ActVISTA InfoSec
 
DATA SAFEGUARD INC.- WHITE PAPER
DATA SAFEGUARD INC.- WHITE PAPERDATA SAFEGUARD INC.- WHITE PAPER
DATA SAFEGUARD INC.- WHITE PAPERYashiVaidya
 

Similar to US State Privacy Law Update Webinar Summary (20)

Post US Election Privacy Updates & Implications
Post US Election Privacy Updates & ImplicationsPost US Election Privacy Updates & Implications
Post US Election Privacy Updates & Implications
 
U.S. Quarterly Privacy Update
U.S. Quarterly Privacy UpdateU.S. Quarterly Privacy Update
U.S. Quarterly Privacy Update
 
Wb 2020-03-25-us-quarterly-privacy-update
Wb 2020-03-25-us-quarterly-privacy-updateWb 2020-03-25-us-quarterly-privacy-update
Wb 2020-03-25-us-quarterly-privacy-update
 
CCPA Update: What You Need to Know about CPRA & July 1st Enforcement
CCPA Update: What You Need to Know about CPRA & July 1st EnforcementCCPA Update: What You Need to Know about CPRA & July 1st Enforcement
CCPA Update: What You Need to Know about CPRA & July 1st Enforcement
 
SECTOR-SPECIFIC-REGULATIONS-AND-A-FEW-HICCUPS-MORE-U.S.A-AND-ITS-PRIVACY-LAWS...
SECTOR-SPECIFIC-REGULATIONS-AND-A-FEW-HICCUPS-MORE-U.S.A-AND-ITS-PRIVACY-LAWS...SECTOR-SPECIFIC-REGULATIONS-AND-A-FEW-HICCUPS-MORE-U.S.A-AND-ITS-PRIVACY-LAWS...
SECTOR-SPECIFIC-REGULATIONS-AND-A-FEW-HICCUPS-MORE-U.S.A-AND-ITS-PRIVACY-LAWS...
 
Cybersecurity and Data Privacy Whistleblower Protections
Cybersecurity and Data Privacy Whistleblower ProtectionsCybersecurity and Data Privacy Whistleblower Protections
Cybersecurity and Data Privacy Whistleblower Protections
 
California Consumer Privacy Act (CCPA) - Kloudlearn
California Consumer Privacy Act (CCPA) - KloudlearnCalifornia Consumer Privacy Act (CCPA) - Kloudlearn
California Consumer Privacy Act (CCPA) - Kloudlearn
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
 
What are the new laws under Canada Digital Privacy Act.pdf
What are the new laws under Canada Digital Privacy Act.pdfWhat are the new laws under Canada Digital Privacy Act.pdf
What are the new laws under Canada Digital Privacy Act.pdf
 
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
 
Cybersecurity & data privacy whistleblower incentives and protections
Cybersecurity & data privacy whistleblower incentives and protectionsCybersecurity & data privacy whistleblower incentives and protections
Cybersecurity & data privacy whistleblower incentives and protections
 
Introduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsIntroduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and Requirements
 
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...
 
CSR PII White Paper
CSR PII White PaperCSR PII White Paper
CSR PII White Paper
 
China's PIPL: How to Comply in Under 60 Days
China's PIPL: How to Comply in Under 60 DaysChina's PIPL: How to Comply in Under 60 Days
China's PIPL: How to Comply in Under 60 Days
 
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
 
Privacy issues in data analytics
Privacy issues in data analyticsPrivacy issues in data analytics
Privacy issues in data analytics
 
California Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act: What your brand needs to knowCalifornia Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act: What your brand needs to know
 
What to expect from the New York Privacy Act
What to expect from the New York Privacy ActWhat to expect from the New York Privacy Act
What to expect from the New York Privacy Act
 
DATA SAFEGUARD INC.- WHITE PAPER
DATA SAFEGUARD INC.- WHITE PAPERDATA SAFEGUARD INC.- WHITE PAPER
DATA SAFEGUARD INC.- WHITE PAPER
 

More from TrustArc

TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc
 
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc
 
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc
 
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...TrustArc
 
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...TrustArc
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesTrustArc
 
CBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceCBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceTrustArc
 
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfEverything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfTrustArc
 
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...TrustArc
 
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsPrivacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsTrustArc
 
Building Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsBuilding Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsTrustArc
 
The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...TrustArc
 
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdfTrustArc
 
Artificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceArtificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceTrustArc
 
How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023TrustArc
 
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act:  Using Consumer Data and Maintaining TrustThe Ultimate Balancing Act:  Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act: Using Consumer Data and Maintaining TrustTrustArc
 
The Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To KnowThe Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To KnowTrustArc
 
TrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdf
TrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdfTrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdf
TrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdfTrustArc
 

More from TrustArc (20)

TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
 
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI Innovations
 
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
 
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
 
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 States
 
CBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceCBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy Compliance
 
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfEverything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
 
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
 
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsPrivacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
 
Building Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsBuilding Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy Certifications
 
The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...
 
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
 
Artificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceArtificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI Governance
 
How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023
 
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act:  Using Consumer Data and Maintaining TrustThe Ultimate Balancing Act:  Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
 
The Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To KnowThe Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To Know
 
TrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdf
TrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdfTrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdf
TrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdf
 

Recently uploaded

Key Features Of Token Development (1).pptx
Key  Features Of Token  Development (1).pptxKey  Features Of Token  Development (1).pptx
Key Features Of Token Development (1).pptxLBM Solutions
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Alan Dix
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Patryk Bandurski
 
Artificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraArtificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraDeakin University
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024Scott Keck-Warren
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphSIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphNeo4j
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationSafe Software
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr LapshynFwdays
 
Unlocking the Potential of the Cloud for IBM Power Systems
Unlocking the Potential of the Cloud for IBM Power SystemsUnlocking the Potential of the Cloud for IBM Power Systems
Unlocking the Potential of the Cloud for IBM Power SystemsPrecisely
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersThousandEyes
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhisoniya singh
 

Recently uploaded (20)

Key Features Of Token Development (1).pptx
Key  Features Of Token  Development (1).pptxKey  Features Of Token  Development (1).pptx
Key Features Of Token Development (1).pptx
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
 
Artificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraArtificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning era
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
Vulnerability_Management_GRC_by Sohang Sengupta.pptx
Vulnerability_Management_GRC_by Sohang Sengupta.pptxVulnerability_Management_GRC_by Sohang Sengupta.pptx
Vulnerability_Management_GRC_by Sohang Sengupta.pptx
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphSIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
 
Unlocking the Potential of the Cloud for IBM Power Systems
Unlocking the Potential of the Cloud for IBM Power SystemsUnlocking the Potential of the Cloud for IBM Power Systems
Unlocking the Potential of the Cloud for IBM Power Systems
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
 
The transition to renewables in India.pdf
The transition to renewables in India.pdfThe transition to renewables in India.pdf
The transition to renewables in India.pdf
 

US State Privacy Law Update Webinar Summary

  • 1. 1 1 © 2021 TrustArc Inc. Proprietary and Confidential Information. So Many States, So Many Privacy Laws: US State Privacy Law Update April 14, 2020
  • 2. 2 2 Thank You for Joining “So Many States, So Many Privacy Laws: US State Privacy Law Update” ● We will be starting a couple minutes after the hour ● This webinar will be recorded and the recording and slides sent out later today ● Please use the GoToWebinar control panel on the right hand side to submit any questions for the speakers
  • 3. 3 3 Speakers K Royal Associate General Counsel Privacy Intelligence TrustArc Christina Fratschko Privacy Research Specialist Privacy Intelligence TrustArc
  • 4. 4 4 Agenda ● Recent developments in US state privacy laws ● US federal privacy law predictions ● Best practices and tips on how your company can keep up
  • 5. 5 5 CCPA vs. CPRA vs. VCDPA
  • 6. 6 6 California California Privacy Rights Act (CPRA) CCPA CPRA Threshold Application Buy, receive, or sell the personal information of 50,000 or more California residents, households, or devices. Buy, sell, or share the personal information of 100,000 or more California residents or households. Employee B2B Exemption Concludes January 1, 2021 Concludes January 1, 2023 Consumer Rights ● Right to Know/Access ● Right to Delete ● Right to Opt-out of Sale ● Right to Non-Discrimination Same rights as the CCPA, and an addition of: ● Right to Rectification ● Right to Limit Use and Disclosure of Sensitive Personal Information Enforcement Enforcement by the State Attorney General. Creation of the California Privacy Protection Agency for enforcement and guidance. Sensitive Information Not defined under the CCPA It is defined as personal information, which includes a consumer’s SSN, driver’s license, state ID card, etc.
  • 7. 7 7 Virginia How it differs from CCPA/CPRA: ● Has an explicit definition of sensitive data ● Applicability to employees and B2B communications ● Designation of controllers and processors ● Data protection impact assessments ● Consumer Rights Next steps: ● This law is effective January 1, 2023 Virginia Consumer Data Protection Act (VCDPA)
  • 9. 9 9 Oklahoma Current status: If passed, businesses that do business in Oklahoma or collect consumers' PI must comply with consumers' requests for access and portability (within 45 days of receipt of request), cannot discriminate against a consumer for exercising any consumer right (including denying goods or services), and must provide notice to consumers that their information may be sold; violations are liable for civil penalties between $2,500 and 7,500. Next steps: ● If passed, this Act will take effect on January 1, 2023 due to the latest bill amendments. Oklahoma Computer Data Privacy Act (OCDPA) / HB 1602
  • 10. 10 10 New York Current status: The Act is identical to the version introduced in the previous Senate sitting; if passed, covered entities must comply with consumers' requests for disclosure, access, correction and deletion of personal data, cessation of processing, and data portability, and will have a fiduciary responsibility to exercise a duty of care and confidentiality over personal data in its possession; consumers may bring a private right of action for damages, and the attorney general may impose civil penalties for violations. Next steps: ● If passed, the Act will take effect on the 180th day after it becomes law. New York Privacy Act (NYPA or A680) + Multiple Bills
  • 11. 11 11 Washington Current status: If passed, consumers must be provided one or more secure and reliable means to submit a consumer request (e.g., data portability, erasure, opt-out), risks assessments must be conducted when processing personal data for purposes of targeted advertising, and covered data must be deleted or deidentified when such data is no longer being used for such purposes; the AG may may initiate an action and seek damages of up to $7,500 for each violation of this Act. Next steps: ● This bill covers both private sector management of consumer personal data and privacy and public sector management of data processed for a public health emergency (i.e., COVID-19) ● Most sections of the bill would take effect July 31, 2022 Washington Privacy Act (WPA)
  • 12. 12 12 Florida Current status: If passed, businesses must comply with opt-out requests within 15 days (including requests received from authorized persons), make available a notice that is reasonably accessible to all consumers whose PI is collected, and comply with deletion, correction, and access requests (deletion and correction requests must be responded to within 30 days); consumers can recover damages ranging between $100 and $750 for violations of this Act. Next steps: ● If passed, this Act will take effect July 1, 2022 due to the latest amendments made to the bill ● The revised bill has also removed the private right of action provision, and limited the amount of businesses required to comply with the Act (i.e., the Act would only apply to businesses that annually buy, sell or share the personal info from 100,000 or more users or that generate at least 50% of its global annual revenue from selling or sharing personal information about consumers). SB 1734
  • 13. 13 13 Alaska Current status: SB 116 and HB 159 were both introduced on March 31, 2021 to the Alaska State Senate and House. The Consumer Data Privacy Act contains 4 new rights, the right to know, disclosure, delete, and opt-out. Businesses cannot disclose consumer’s PI for a business or commercial purpose, or use the consumer’s precise geolocation data for a purpose other than to provide goods or services if it has actual knowledge that the consumer is under the age of 18. Next steps: ● If passed, this Act would take effect January 1, 2023. Senate Bill 116 and House Bill 159
  • 16. 16 16 State by State Comparison
  • 17. 17 17 State by State Comparison
  • 19. 19 19 Poll Question What do you think the time frame is for getting a US federal privacy law in place? ● This year ● Within the next 4 years ● Not anytime in predictable future ● There shouldn't be one
  • 20. 20 20 Federal Regulation ● Several promising bills have been introduced in the past, with most disagreement centering on private rights of action and federal preemption ● Once again, current proposed legislation seems promising ○ Information Transparency and Personal Data Control Act - Rep DelBene ■ HR 1816 ○ Most bills target specific areas of privacy - contact tracing, research, etc. ● How many state laws will it take to encourage Congress to pass legislation? ○ Are the differences among the states operationally impactful? ○ Keep in mind, every state has a data breach notification law ● Would other federal laws simply be expanded and strengthened? ● Consider global implications and impact What’s next?
  • 21. 21 21 How Do You Keep Up? Managing an Up-to-Date Privacy Program
  • 22. 22 22 US Consumer Privacy Laws Map and Chart
  • 23. 23 23 Frameworks Facilitate Better Comparisons Framework Element GDPR LGPD CCPA HIPAA Security USSG C&E Program Virginia CDPA Integrated Governance Risk Assessment Resource Allocation Policies and Standards Processes Awareness and Training Data Necessity Use, Retention, and Disposal Disclosures to 3rd Parties & Onward Transfer Choice and Consent Access and Individual Rights Data Integrity and Quality Security Transparency Monitoring and Assurance Reporting and Certification
  • 24. 24 24
  • 25. 25 25 Thank You! See http://www.trustarc.com/insightseries for the 2021 Privacy Insight Series and past webinar recordings. If you would like to learn more about how TrustArc can support you with compliance, please reach out to sales@trustarc.com for a free demo.