Privacy Concepts Continually and Rapidly Evolve
5 slides · 3 min read · Domain 1
Privacy Concepts Continually and Rapidly Evolve
Privacy regulations and expectations shift frequently, driven by technological advances, legal challenges, and changing views on how personal data should be handled and safeguarded.
At its heart, General Data Protection Regulation (GDPR) consists of rules, regulations, and penalties that provide anyone in the European Union (EU) or European Economic Area (EEA) with more control over their own personal data. However, each member state within the EU has their own set of legislation for privacy and data protection. Currently, there are more than 50 areas where individual member states may use their own legislation instead of GDPR.
GDPR not only applies to any organization operating (based) within the EU but also to all organizations providing goods and services to individuals or organizations within the EU.
This effectively means that every corporation globally must have a strategy in place that provides a GDPR compliance-like solution for data transfer to and from the EU.
The problem arises from the fact that many countries do not have the same expectation for data protection. Within the United States, Health Insurance Portability and Accountability Act (HIPAA) protects healthcare records while the GrammLeach-Bliley Act protects financial records. However, more general data may not be protected to the same degree. The issue is further complicated because state and federal law may be different.
The figure lists 11 countries and one U.S. state that have GDPR-like legislation.
Legislation, Year
Notes (if applicable)
Country The Privacy Amendment (Notifiable Data | Where there is a risk of harm, any organizaBreaches) Act, 2017 tion with an annual turnover over AU $3 million
Australia must disclose data breaches within 30 days. (An amendment to the Privacy Act 1988) Compliance required within 18 months. Lei Geral de Proteção de Dados (LGPD), Brazil Based directly on GDPR. While it doesn't quite align, there are many overlaps. This is the strongest protection withCalifornia, United California Consumer Privacy Act (CCPA), in the United States.
States Not ruled to be adequate for GDPR. Digital Charter Implementation Act, 2020; Personal Information Protection Canada and Electronic Documents Act (PIPEDA), Chile
China
India
Japan
New Zealand
South Africa
South Korea
Thailand Constitutional change, 2018
Personal Data Protection Law (PDPL), Chile amended its constitution to declare data privacy a human right.
Personal Data Protection Bill (PDPB), drafted in 2019 Act on the Protection of Personal InforApplies to both domestic and foreign compamation (APPI), amended in 2017 nies. Privacy Act, 1993 Misses some key GDPR elements. Protection of Personal Information Act (POPIA), 2020 Personal Information Protection Act, 2011
Personal Data Protection Act (PDPA), Figure: Countries with GDPR-like legislation
Major forces continue to drive the ways that information systems must deal with privacyrelated information. One force is frequent legislative change, such as privacy laws in India, China, Brazil, and California that were passed or became effective in the past few years.
The CCPA demonstrates the power of a second force: when consumercitizens feel threatened, they can speak with power to authorities and cause significant changes in legislative and regulatory landscapes.
A third force is this: as markets become more demanding, entrepreneurs see the opportunity to provide a better, safer, more secure, and more private product or service.
