Remove tag disclosure
article thumbnail

$10,000,000 civil penalty for disclosing personal data without consent

Data Protection Report

The claims related to the company’s sharing personal data without consumer consent and making it very difficult for consumers to cancel their subscriptions to this telehealth service. The complaint alleged that the company’s data handling practices also resulted in unauthorized disclosures of personal information.

article thumbnail

Newly Proposed SEC Cybersecurity Risk Management and Governance Rules and Amendments for Public Companies

Data Matters

Securities and Exchange Commission (SEC) proposed new cybersecurity rules to enhance and standardize disclosures regarding cybersecurity risk management, strategy, governance, and incident reporting by public companies. The proposed rules includes a nonexclusive list of cybersecurity events that may require disclosure, such as.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Doing Well By Doing The Right Thing: How The CCPA Is Good For Businesses And Consumers

Reltio

Noncompliance could carry a hefty price tag. CCPA compels companies to tell consumers what kind of personal data is being collected about them and if it is being sold to third parties. Companies that take action to protect data are not only acting in the interest of customers but themselves, too. It's ironic but true.

GDPR 78
article thumbnail

California Consumer Privacy Act: GDPR-like definition of personal information

Data Protection Report

By removing the name requirement and instead including specific data elements such as IP address, browser history and geolocation data as PI, the CCPA requires companies to reexamine how data is tagged and risks related to data is analyzed and mitigated. Article #2: CCPA Covered Entities.

GDPR 40
article thumbnail

California proposes rules for automated decision-making

Data Protection Report

The proposed regulations also include some provisions specifically relating to the use of automated decision-making technology in the employment context, including rebuttable presumptions relating to the use of alternative methods of processing personal data.

Access 64
article thumbnail

Identity and The Independent Web

John Battelle's Searchblog

As we roam the web, we are tracked, tagged, and profiled by third parties. If I alight on a post about a cool new mountain bike, for example, I might chose to reveal that I'm a fan of the Blur XC, a bike made by the Santa Cruz company. In this example, the Dependent Web does the revealing for me.

Marketing 111
article thumbnail

The Legitimisation of Have I Been Pwned

Troy Hunt

That harm extends all the way from those in data breaches feeling a sense of personal violation (that's certainly how I feel when I see my personal information exposed), all the way through to people literally killing themselves (there are many documented examples of this in the wake of the Ashley Madison breach).