article thumbnail

Big California Privacy News: Legislative and Enforcement Updates

Data Matters

As a provider subject to CMIA, mental health apps would be subject to HIPAA-like constraints on their ability to use and share data collected and will have increased litigation exposure, as CMIA includes a private right of action. New CCPA Enforcement Case Examples – Opt Outs, GPC, Clarity & Functionality Are Top of Mind.

Privacy 197
article thumbnail

Colorado AG Publishes Draft Colorado Privacy Act Rules

Hunton Privacy

Below are key examples of topics addressed by the proposed regulations. Right to Request to Exercise Personal Data Rights (Rule 4.02 – Rule 4.07; 6.11). of the proposed regulation requires “controllers” to establish “reasonable methods” to authenticate consumers who submit data rights requests.

Privacy 78
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Off to the Races: Comment Period for CPRA Proposed Regulations Begins

Data Matters

They include several real world examples informed by the California Office of the Attorney General’s (OAG) enforcement experiences over the last two years; indeed two of the most senior attorneys in charge of CCPA enforcement at the OAG—Stacey Schesser and Lisa Kim—played a significant role in drafting these regulations. 11 CCR § 7012(e)(6).

Privacy 88
article thumbnail

ICO Releases COVID-19 Guidance for Re-Opening Workplaces

Hunton Privacy

If the same result could be achieved without collecting personal information, further collection should be avoided. Data collection should be kept to a minimum and permanent records should not be created unless necessary. Employers should be transparent with staff as to how the data is going to be used.

article thumbnail

How to implement the General Data Protection Regulation (GDPR)

IBM Big Data Hub

The GDPR applies to any organization that processes the personal data of European residents, regardless of where that organization is based. First, knowing what data the company has and how it is processed helps the organization better understand its compliance burdens. Consents cannot be bundled, either.

GDPR 80
article thumbnail

Belgian Data Protection Authority Releases Direct Marketing Recommendation

Hunton Privacy

With this Recommendation, the Belgian DPA aims to clarify the complex rules relating to the processing of personal data for direct marketing purposes, including by providing practical examples and guidelines to the different stakeholders involved in direct marketing activities. Purchase , Rental and Enrichment of Personal Data.

Marketing 109
article thumbnail

How to prepare for the California Consumer Privacy Act

Thales Cloud Protection & Licensing

For example, data collected by an entity may not be associated with an individual but could identify a household. Also, entities under the CCPA must post a “Do Not Sell My Personal Information” link on their websites allowing consumers to easily exercise their right of opting-out. (4)

Privacy 92