Remove category enforcement
article thumbnail

How to implement the General Data Protection Regulation (GDPR)

IBM Big Data Hub

Think: an online retailer that stores customers’ email addresses to send order updates. The only processing operations exempt from the GDPR are national security and law enforcement activities and purely personal uses of data. Organizations usually need a user’s explicit consent to process special category data.

GDPR 78
article thumbnail

CCPA: “Attorney General Amendment” Likely Dead

Data Protection Report

It would have deleted the 30-day cure period that enables a company to remedy an issue prior to Attorney General enforcement. Excludes “employees” from definition of “consumer”. Clarifies non-discrimination provision to allow retail loyalty programs. Narrows disclosure requirement relating to categories of third parties.

Retail 40
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

California passes major legislation, expanding consumer privacy rights and legal exposure for US and global companies

Data Protection Report

The law is enforceable in California and applies to California users, but given the nature of data processing, most companies will need to consider whether to apply the rules to all users. It also requires a description of consumers’ rights and the categories of personal information the business has sold in the preceding 12 months.

Privacy 40
article thumbnail

California Passes Major Legislation, Expanding Consumer Privacy Rights and Legal Exposure for US and Global Companies

Data Protection Report

The law is enforceable in California and applies to California users, but given the nature of data processing, most companies will need to consider whether to apply the rules to all users. It also requires a description of consumers’ rights and the categories of personal information the business has sold in the preceding 12 months.

Privacy 40
article thumbnail

The Good, Bad, And The Ugly: Key Takeaways From California’s New Privacy Law

Privacy and Cybersecurity Law

California law also requires businesses that suffer a breach of security to disclose the breach to consumers, and in some instances law enforcement, if sensitive information is compromised. The CCPA’s definition of “consumer” is equally broad. This definition therefore not only encompasses a “consumer” in the traditional sense (i.e.,

Privacy 58
article thumbnail

The Good, Bad, And The Ugly: Key Takeaways From California’s New Privacy Law

Privacy and Cybersecurity Law

California law also requires businesses that suffer a breach of security to disclose the breach to consumers, and in some instances law enforcement, if sensitive information is compromised. The CCPA’s definition of “consumer” is equally broad. This definition therefore not only encompasses a “consumer” in the traditional sense (i.e.,

Privacy 58
article thumbnail

Regulatory Update: NAIC Summer 2020 National Meeting

Data Matters

The Annuity Suitability Working Group (ASWG) led the NAIC’s multi-year efforts to develop revisions to the Suitability in Annuity Transactions Model Regulation (SAT) to incorporate a requirement for producers to act in the “best interest” of a retail customer when making a recommendation of an annuity. Proposed revisions to SSAP No.