Remove tag record-retention-2
article thumbnail

$10,000,000 civil penalty for disclosing personal data without consent

Data Protection Report

The claims related to the company’s sharing personal data without consumer consent and making it very difficult for consumers to cancel their subscriptions to this telehealth service. The complaint alleged that the company’s data handling practices also resulted in unauthorized disclosures of personal information.

article thumbnail

California Consumer Privacy Act: GDPR-like definition of personal information

Data Protection Report

By removing the name requirement and instead including specific data elements such as IP address, browser history and geolocation data as PI, the CCPA requires companies to reexamine how data is tagged and risks related to data is analyzed and mitigated. Article #2: CCPA Covered Entities.

GDPR 40