Remove tag
article thumbnail

$10,000,000 civil penalty for disclosing personal data without consent

Data Protection Report

The claims related to the company’s sharing personal data without consumer consent and making it very difficult for consumers to cancel their subscriptions to this telehealth service. The order also, in Section IX, set forth data destruction requirements and a data retention policy.

article thumbnail

CHINA: uncertainties helpfully clarified on various key data compliance activities

DLA Piper Privacy Matters

The Draft Measures propose to introduce or flesh out other compliance requirements contained in the PIPL. This will, therefore, require more in-depth privacy notices than businesses may be used to providing in China. All these indicate that DPO should be a relatively senior position within an organization.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Guest Post -- GDPR Compliance starts with Data Discovery

AIIM

Implicit in this is the requirement that organizations must institute policies, processes and systems that: Establish a central personal data register and record of processing activities ; Implement technical and organizational measures that enable organizations to demonstrate compliance; and.

GDPR 102
article thumbnail

China: Navigating China episode 16: New data lifecycle guidelines for financial institutions in China – detailed assessments, additional security measures and some data localisation introduced

DLA Piper Privacy Matters

This introduces a data lifecycle security framework, and represents the key guideline for handling personal and other financial information by financial institutions (i.e. Key compliance obligations include: Classification of financial data: the data lifecycle framework introduces five levels of financial data, namely: .

article thumbnail

Work Remotely Without Compromising Your Data

AIIM

And once you know where your high-risk issues are, you can start doing something about it: locking down access, cleaning up permissions, and removing stale data that’s outlived its value. The sheer volume of data regulations is impossible for end-users to keep track up. As IT leaders, it’s our job to care for this data.

article thumbnail

How Data Governance Protects Sensitive Data

erwin

When an organization knows what data it has, it can define that data’s business purpose. And knowing the business purpose translates into actively governing personal data against potential privacy and security violations. Do You Know Where Your Sensitive Data Is? erwin Data Intelligence.

article thumbnail

Doing Well By Doing The Right Thing: How The CCPA Is Good For Businesses And Consumers

Reltio

How is it that many companies doing business in California are still not compliance-ready? Noncompliance could carry a hefty price tag. The "carrot" is that taking steps to ensure compliance can have very positive effects on businesses. Appoint someone on your staff to manage the compliance processes.

GDPR 78