123ArticleOnline Logo
Welcome to 123ArticleOnline.com!
ALL >> General >> View Article

Gdpr And Ccpa Compliance – A Cheat Sheet For Data Privacy

Profile Picture
By Author: Syntelli Marketing
Total Articles: 29
Comment this article
Facebook ShareTwitter ShareGoogle+ ShareTwitter Share

What penalties are imposed by CCPA v. GDPR?
Both CCPA and GDPR provide for remedies in the case of non-compliance.

GDPR – Data Protection Authorities may impose an administrative fine “of up to €20 million or 4% of the business’s total annual worldwide turnover.”

CCPA – Violations are subject to civil penalties of up to $2,500 for each violation or $7,500 for each intentional violation.

In addition to these penalties, companies may be missing an opportunity to gain a competitive advantage.

Who is regulated by CCPA v. GDPR?
Both CCPA and GDPR have broad definitions of entities that are subject to data privacy regulations. In general, it’s best for any business to begin implementing data privacy policies with CCPA and GDPR in mind, as both laws have a broad territorial scope (see below). Also, these laws will not be the only data privacy protections on the books. New state and national laws are anticipated, as are expansions of CCPA and GDPR.

GDPR – First, it’s important to understand the difference between “data controllers” and “data processors” ...
... according to GDPR. Controllers are typically the businesses that determine what data is captured and how it is used. An online business that collects customer data for ecommerce is an example. A processor is another entity that processes data on behalf of a controller. Google – through its online tracking services – may be a processor for the online business. The obligations are different for each type of business. It’s important to note that controllers need to be support requests from individuals to comply with data privacy rights, including managing their processors to comply with these requests.

Data controllers and data processers are subject to GDPR if: the company that processes personal data of individuals in the EU has a branch in the EU, or the company is established outside of the EU and “goods/services (paid or for free) or is monitoring the behaviour of individuals in the EU.” Your company does not need to be a European company or you may not realize that your company has any interaction with people in the EU, and yet you may still be subject to GDPR.

CCPA – This data privacy law covers any for-profit entity doing business in California that collects and directs the use of personal information and meets certain thresholds:

- Annual gross revenues greater than $25 million
- Receives, sells, or shares personal information of 50,000 or more consumers, households, or devices
- Derives 50% or more of revenues from selling consumers’ personal information

Who and what information is protected by CCPA v. GDPR?

Both laws seek to protect actual people rather than legal persons that are not natural individuals.

GDPR – Data privacy protections apply to an identified or identifiable living individuals who live in the EU, regardless of whether the individual is currently in the EU or not.

It’s important to note that the inclusion of “identified or identifiable” in the definition of “personal identifiable data” means that any encrypted, de-identified, or “pseudonymized” data that can be used to re-identify an individual is covered by GDPR. Purely anonymous data, that cannot be reversed, is not covered by the law.

Also, personal identifiable data is not restricted to names and addresses that people typically use to identify individuals. Protected data also includes data typically used by software, like an IP address or a cookie ID.

CCPA – CCPA has similar categories of personal identifiable data, but excludes data used for certain legal, medical, financial, and employment-related purposes. Also, CCPA compliance does not include de-identified or aggregated data.

What consumer rights are established or protected by CCPA v. GDPR?
Both laws define acceptable business practices involving personal identifiable data and outline specific protections for individuals.

GDPR – GDPR provides grounds for processing personal data, including individual consent and in other specific situations.

In addition, covered individuals are afforded rights to:

- information about the processing of your personal data;

- obtain access to the personal data held about you;

- ask for incorrect, inaccurate or incomplete personal data to be corrected;

- request that personal data be erased when it’s no longer needed or if processing it is unlawful;

- object to the processing of your personal data for marketing purposes or on grounds relating to your particular situation;

- request the restriction of the processing of your personal data in specific cases;

- receive your personal data in a machine-readable format and send it to another controller (‘data portability’);

- request that decisions based on automated processing concerning you or significantly affecting you and based on your personal data are made by natural persons, not only by computers. You also have the right in this case to express your point of view and to contest the decision.

(The bulleted list above is an excerpt from this European Union website page.)

It’s important to note that these rights include the right not to profiled or subject to a decision based solely on automated means. That means that the interest rate for a loan, for example, cannot be only determined by an algorithm if the individual does not consent to an automated decision without human review.

CCPA – CCPA has similar but different data privacy protections. CCPA compliance requires the protection of specified data privacy rights, including:

- The right to know what personal information is collected, used, shared, or sold;

- The right to delete personal information by a business including - service providers;

- The right to opt-out of sale of personal information;

- The right to non-discrimination in price or service when an individual exercises her or his CCPA rights.

Note: The CCPA covers identifiable households and devices in addition to individuals; this distinction requires additional consideration to protect rights established by the CCPA.

What data privacy practices should be in place for GDPR and CCPA compliance?

Good data privacy practices – that include careful consideration of GDPR and CCPA requirements – will minimize the disruption of a rushed implementation due to a consumer request or a notice of violation. A solid data privacy regime must identify the types of personal identifiable data that you collect or process and provide means to comply with all requests within the time allotted for requests or remediation.

Syntelli Solutions can help. Contact us to discuss preparing for data privacy compliance.

Total Views: 139Word Count: 1017See All articles From Author

Add Comment

General Articles

1. Enhancing Your Online Presence: The Synergy Of Website Design And Seo Packages
Author: Shaganasaral

2. Why Invest In An Uber Clone App For Your Startup
Author: Smith Joe

3. Unleashing The Power Of White Label Crypto Exchange Software For Startups
Author: white label

4. Buy Led Light Therapy For Skin For Radiant And Healthy Skin
Author: Zuzusales LLC

5. Hip Kits And Dining Aids – Improving The Quality Of Life Everyday
Author: Zuzusales LLC

6. 30w 24v Solidrive Electronic Non-dimmable Constant Voltage Driver By Magnitude
Author: David Hessen

7. Navigating Your Journey With Pratham Motors: Maruti Suzuki Driving School In Hsr Layout
Author: Pratham Motors

8. Best Accounting Software For Petrol Pump
Author: sidharthh08877

9. How To Create An Arbitrum Crypto Wallet & Evaluate Its Cost
Author: JohnJames

10. Can An Exchange Traded Fund Give You Good Returns Over The Long Term?
Author: SURAAJ

11. How Should You Plan For Your Retirement?
Author: SURAAJ

12. Harnessing Biological Odour Control Systems For Electronics Corrosion Monitoring
Author: Aqozz

13. Induce More Happiness By Not Searching How To Remove Glance From Lock Screen In Mi!
Author: Jaykant P

14. Choosing The Right Statistical Consultancy Services Africa For Better Results
Author: Stat Consul

15. Global Bottled Water Processing Market: Key Trends And Insights By 2028
Author: sonal

Login To Account
Login Email:
Password:
Forgot Password?
New User?
Sign Up Newsletter
Email Address: