SlideShare a Scribd company logo
Today’s Data Privacy
Landscape
A High Level Comparison of the
GDPR and CCPA
Data Privacy is
Not New
Many specific industries have
their own acts governing data
compliance.
Medical
Financial
Educational
Telecommunications
Workplace
FTC Enforcement
Recent Events
Now consumer rights and
protections are demanded due
to rise in breachs.
2013 - Yahoo - 3 billion accounts
2014 - eBay - 145 million accounts -
using corporate employee logins
2017 - Equifax - SSN of 143 million -
credit card numbers of 209,000
2018 - Marriott - 500 million
customers - Chinese intelligence
group had access for 5 years
without detection
What is the
Solution?
European Union and California
lead the way to create uniform
laws in data protection.
General Data Protection Regulation
in European Union - (GDPR)
California Consumer Privacy Act -
CCPA
No Federal Legislation to Date
Who Must Comply?
GDPR
● Businesses in the EU (regardless of where processing occurs)
● Businesses outside the EU
○ That offer free or paid goods or services to EU customers; or
○ That monitor behavior of EU customers.
Who Must Comply?
CCPA -
● All businesses that collect personal information from California residents.
● A business under the act is defined as:
○ Businesses that earn $25,000,000 or more a year in revenue
○ Businesses that annually buy, receive, sell or share personal information of 50,000 or more
consumers, households or devices for commercial purposes
○ Business that derive 50% or more of its annual revenue from selling consumer personal
information
What is Personal Information?
GDPR
Personal data means any information relating to an identified or identifiable
natural person.
CCPA
Any information that identifies, relates to, describes, is capable of being
associated with, or could reasonably be linked, directly or indirectly, with a
particular consumer or household.
Unique Examples: IP Address, Search History, Biometric Data, Geolocation
Requirement to Inform (Before Collection)
GDPR
● Must inform customers:
○ The data that is being collected
○ How the customer’s data being used
CCPA
● Same as GDPR plus:
○ Categories of PI that businesses have collected, sold or otherwise disclosed during
preceding 12 months must be in the online privacy policy.
Consumer Opt-Out v. Opt-In
CCPA
● Need to give option to “Opt-Out”
○ If customer does opt-out cannot request to opt-back in for 12 months.
● Cannot sell data if consumer requests; or
● If consumer is a minor (unless minor has opted-in); and
● Cannot discriminate for opting out
GDPR
● Consent is required at the onset of collection of information
● Need to implement “Opt-In” methods
Unique Issue Arises
GDPR
● Requires privacy notices that inform customer of rights
FTC
● Cause of Action for Unfair and Deceptive Business Practices
○ If you have a privacy policy that you do not comply with
Consumer Access to PI
GDPR
● A free copy of the personal data
● Purpose of processing
● Categories of data processed (e.g., name, address, etc.)
● Any third party recipients
● Where the data came from (directly from consumer or not)
● How long such personal data would be stored
● Any automated decision making based on data
Consumer Access to PI
CCPA
● Information collected;
● Categories of information collected;
● Categories of third parties with whom the information is shared;
● Categories of sources of the information;
● Business or commercial purpose for collecting or selling personal
information.
GDPR is Broader i.e right to retention period and automated decision making
Required Security Protocols
Both the CCPA and GDPR require “reasonable” security measures.
GDPR
If handling sensitive information:
● Must appoint data protection officer;
● Implement privacy by design; and
● Undertake data protection impact assessments for new technologies
implemented.
Right to be Forgotten
CCPA
● Only applies to data collected from consumer
GDPR
● Applies to all data regardless of source
● Should be deleted if no longer needed (i.e. data minimization)
Liability
GDPR
● You may be fined for up to €20mm or 4% of your worldwide turnover
(revenue), whichever is greater.
● You may also be subject to lawsuits by affected data subjects.
Liability
CCPA
● If brought as a civil action by persons violated:
○ Not less than one hundred dollars ($100) and not greater than seven hundred and fifty
($750) per consumer per incident or actual damages, whichever is greater.
○ (Marriott would have been Three Billion Seven Hundred and Fifty Million Dollars)
● If brought by Attorney General:
○ Any person, business, or service provider that intentionally violates this title may be liable for
a civil penalty of up to seven thousand five hundred dollars ($7,500) for each violation; or
○ Two thousand five hundred dollars $2,500 for unintentional violations if a business fails to
cure unintentional violations within 30 days of notice of alleged non-compliance.
Conclusion
Consumer Rights:
● Right to know what information is being collected
● Right to know if information is being sold
● Right to say no to sale of personal information
● Right to access personal information
● Right to not be discriminated against if exercise rights

More Related Content

PDF
California Consumer Privacy Act - What You Need To Know
PPTX
California Consumer Privacy Act: What your brand needs to know
PDF
California Consumer Privacy Act (CCPA): Countdown to Compliance
PDF
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)
PPTX
*Webinar* CCPA: Get Your Business Ready
PDF
CMR - GDPR - general introduction for marketeers
PPT
California's Tough New Privacy Law is Here. Are You Ready?
PPTX
Second Verse, Different from the First.
California Consumer Privacy Act - What You Need To Know
California Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act (CCPA): Countdown to Compliance
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)
*Webinar* CCPA: Get Your Business Ready
CMR - GDPR - general introduction for marketeers
California's Tough New Privacy Law is Here. Are You Ready?
Second Verse, Different from the First.

What's hot (11)

PPTX
California Consumer Privacy Act (CCPA) - Kloudlearn
PDF
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
PPT
Personal Data Privacy and Information Security
PPT
Consumer Privacy
PPTX
Preparing for GDPR: What Every B2B Marketer Must Know
PDF
Gdpr in a nutshell
PPT
GDPR FAQ'S
PPT
Privacy and Data Security: Risk Management and Avoidance
PPTX
Getting Ready for GDPR
PPTX
GDPR Is Coming – Are Search Marketers Ready?
PPTX
General Data Protection Regulation for Ops
California Consumer Privacy Act (CCPA) - Kloudlearn
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Personal Data Privacy and Information Security
Consumer Privacy
Preparing for GDPR: What Every B2B Marketer Must Know
Gdpr in a nutshell
GDPR FAQ'S
Privacy and Data Security: Risk Management and Avoidance
Getting Ready for GDPR
GDPR Is Coming – Are Search Marketers Ready?
General Data Protection Regulation for Ops
Ad

Similar to Data privacy presentation (20)

PDF
California Consumer Privacy Act and the Role of IAM
PDF
GDPR vs CCPA - Chicago Oracle Eloqua User Group - November 2019
PPTX
Comparing California's Consumer Protection Act with the European Union's GDPR
PPTX
Privacy Needs to be Personal
PDF
Top Questions Asked About the CCPA
PDF
Driving change
PDF
The California Consumer Privacy Act (CCPA)
PDF
The california consumer privacy act (ccpa) is in effect starting on january 1...
PDF
California Consumer Protection Act - Insight from Sia Partners
PDF
Sia Partners_CCPA 2018_The American GDPR
PDF
3 Steps to Turning CCPA & Data Privacy into Personalized Customer Experiences
PDF
California Consumer Protection Act - Insight from Sia Partners
PDF
Eic munich-2019-ripple effect of gdpr in na- cx pa-rev20190430
PDF
Magento checklist AVG / GDPR - Algemene Verordering Gegevensbescherming
PPTX
When Big Data is Personal Data - Data Analytics in The Age of Privacy Laws
PDF
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
PDF
TrustArc Webinar - Cross-Contextual-Advertising: Rethinking How Consumer Data...
PPTX
GDPR - A Concise Treatise
PDF
Privacy by Design and by Default + General Data Protection Regulation with Si...
PPT
The Countdown is on: Key Things to Know About the GDPR
California Consumer Privacy Act and the Role of IAM
GDPR vs CCPA - Chicago Oracle Eloqua User Group - November 2019
Comparing California's Consumer Protection Act with the European Union's GDPR
Privacy Needs to be Personal
Top Questions Asked About the CCPA
Driving change
The California Consumer Privacy Act (CCPA)
The california consumer privacy act (ccpa) is in effect starting on january 1...
California Consumer Protection Act - Insight from Sia Partners
Sia Partners_CCPA 2018_The American GDPR
3 Steps to Turning CCPA & Data Privacy into Personalized Customer Experiences
California Consumer Protection Act - Insight from Sia Partners
Eic munich-2019-ripple effect of gdpr in na- cx pa-rev20190430
Magento checklist AVG / GDPR - Algemene Verordering Gegevensbescherming
When Big Data is Personal Data - Data Analytics in The Age of Privacy Laws
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
TrustArc Webinar - Cross-Contextual-Advertising: Rethinking How Consumer Data...
GDPR - A Concise Treatise
Privacy by Design and by Default + General Data Protection Regulation with Si...
The Countdown is on: Key Things to Know About the GDPR
Ad

Recently uploaded (20)

PPTX
Income under income Tax Act..pptx Introduction
DOCX
FOE Reviewer 2022.docxhgvgvhghhghyjhghggg
PPTX
Sexual Harassment Prevention training class
PPT
wipo: IP _smes_kul_06_www_6899913 (1).ppt
PDF
The Advocate, Vol. 34 No. 1 Fall 2024
PDF
NRL_Legal Regulation of Forests and Wildlife.pdf
PDF
APPELLANT'S AMENDED BRIEF – DPW ENTERPRISES LLC & MOUNTAIN PRIME 2018 LLC v. ...
PDF
The AI & LegalTech Surge Reshaping the Indian Legal Landscape
PDF
Analysis Childrens act Kenya for the year 2022
PDF
A SEP and FRAND Overview 13 Aug 2024.pdf
PPTX
Peter Maatouk Is Redefining What It Means To Be A Local Lawyer Who Truly List...
PDF
AHRP LB - Quick Look of the Newly-initiated Koperasi Merah Putih (KMP).pdf
PDF
Notes to accompany the TMT and FRAND Overview Slides
PDF
TRAFFIC-MANAGEMENT-AND-ACCIDENT-INVESTIGATION-WITH-DRIVING-PDF-FILE.pdf
PPTX
FFFFFFFFFFFFFFFFFFFFFFTA_012425_PPT.pptx
PPT
Cyber-Crime-in- India at Present day and Laws
PDF
algor mortis or cooling of body after death THANATOLOGY
PPT
Over view on IPR and its components :ppt
PDF
Vinayaka Mission Law School Courses and Infrastructure.pdf
PPTX
PART-3-FILIPINO-ADMINISTRATIVE-CULTURE.pptx
Income under income Tax Act..pptx Introduction
FOE Reviewer 2022.docxhgvgvhghhghyjhghggg
Sexual Harassment Prevention training class
wipo: IP _smes_kul_06_www_6899913 (1).ppt
The Advocate, Vol. 34 No. 1 Fall 2024
NRL_Legal Regulation of Forests and Wildlife.pdf
APPELLANT'S AMENDED BRIEF – DPW ENTERPRISES LLC & MOUNTAIN PRIME 2018 LLC v. ...
The AI & LegalTech Surge Reshaping the Indian Legal Landscape
Analysis Childrens act Kenya for the year 2022
A SEP and FRAND Overview 13 Aug 2024.pdf
Peter Maatouk Is Redefining What It Means To Be A Local Lawyer Who Truly List...
AHRP LB - Quick Look of the Newly-initiated Koperasi Merah Putih (KMP).pdf
Notes to accompany the TMT and FRAND Overview Slides
TRAFFIC-MANAGEMENT-AND-ACCIDENT-INVESTIGATION-WITH-DRIVING-PDF-FILE.pdf
FFFFFFFFFFFFFFFFFFFFFFTA_012425_PPT.pptx
Cyber-Crime-in- India at Present day and Laws
algor mortis or cooling of body after death THANATOLOGY
Over view on IPR and its components :ppt
Vinayaka Mission Law School Courses and Infrastructure.pdf
PART-3-FILIPINO-ADMINISTRATIVE-CULTURE.pptx

Data privacy presentation

  • 1. Today’s Data Privacy Landscape A High Level Comparison of the GDPR and CCPA
  • 2. Data Privacy is Not New Many specific industries have their own acts governing data compliance. Medical Financial Educational Telecommunications Workplace FTC Enforcement
  • 3. Recent Events Now consumer rights and protections are demanded due to rise in breachs. 2013 - Yahoo - 3 billion accounts 2014 - eBay - 145 million accounts - using corporate employee logins 2017 - Equifax - SSN of 143 million - credit card numbers of 209,000 2018 - Marriott - 500 million customers - Chinese intelligence group had access for 5 years without detection
  • 4. What is the Solution? European Union and California lead the way to create uniform laws in data protection. General Data Protection Regulation in European Union - (GDPR) California Consumer Privacy Act - CCPA No Federal Legislation to Date
  • 5. Who Must Comply? GDPR ● Businesses in the EU (regardless of where processing occurs) ● Businesses outside the EU ○ That offer free or paid goods or services to EU customers; or ○ That monitor behavior of EU customers.
  • 6. Who Must Comply? CCPA - ● All businesses that collect personal information from California residents. ● A business under the act is defined as: ○ Businesses that earn $25,000,000 or more a year in revenue ○ Businesses that annually buy, receive, sell or share personal information of 50,000 or more consumers, households or devices for commercial purposes ○ Business that derive 50% or more of its annual revenue from selling consumer personal information
  • 7. What is Personal Information? GDPR Personal data means any information relating to an identified or identifiable natural person. CCPA Any information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. Unique Examples: IP Address, Search History, Biometric Data, Geolocation
  • 8. Requirement to Inform (Before Collection) GDPR ● Must inform customers: ○ The data that is being collected ○ How the customer’s data being used CCPA ● Same as GDPR plus: ○ Categories of PI that businesses have collected, sold or otherwise disclosed during preceding 12 months must be in the online privacy policy.
  • 9. Consumer Opt-Out v. Opt-In CCPA ● Need to give option to “Opt-Out” ○ If customer does opt-out cannot request to opt-back in for 12 months. ● Cannot sell data if consumer requests; or ● If consumer is a minor (unless minor has opted-in); and ● Cannot discriminate for opting out GDPR ● Consent is required at the onset of collection of information ● Need to implement “Opt-In” methods
  • 10. Unique Issue Arises GDPR ● Requires privacy notices that inform customer of rights FTC ● Cause of Action for Unfair and Deceptive Business Practices ○ If you have a privacy policy that you do not comply with
  • 11. Consumer Access to PI GDPR ● A free copy of the personal data ● Purpose of processing ● Categories of data processed (e.g., name, address, etc.) ● Any third party recipients ● Where the data came from (directly from consumer or not) ● How long such personal data would be stored ● Any automated decision making based on data
  • 12. Consumer Access to PI CCPA ● Information collected; ● Categories of information collected; ● Categories of third parties with whom the information is shared; ● Categories of sources of the information; ● Business or commercial purpose for collecting or selling personal information. GDPR is Broader i.e right to retention period and automated decision making
  • 13. Required Security Protocols Both the CCPA and GDPR require “reasonable” security measures. GDPR If handling sensitive information: ● Must appoint data protection officer; ● Implement privacy by design; and ● Undertake data protection impact assessments for new technologies implemented.
  • 14. Right to be Forgotten CCPA ● Only applies to data collected from consumer GDPR ● Applies to all data regardless of source ● Should be deleted if no longer needed (i.e. data minimization)
  • 15. Liability GDPR ● You may be fined for up to €20mm or 4% of your worldwide turnover (revenue), whichever is greater. ● You may also be subject to lawsuits by affected data subjects.
  • 16. Liability CCPA ● If brought as a civil action by persons violated: ○ Not less than one hundred dollars ($100) and not greater than seven hundred and fifty ($750) per consumer per incident or actual damages, whichever is greater. ○ (Marriott would have been Three Billion Seven Hundred and Fifty Million Dollars) ● If brought by Attorney General: ○ Any person, business, or service provider that intentionally violates this title may be liable for a civil penalty of up to seven thousand five hundred dollars ($7,500) for each violation; or ○ Two thousand five hundred dollars $2,500 for unintentional violations if a business fails to cure unintentional violations within 30 days of notice of alleged non-compliance.
  • 17. Conclusion Consumer Rights: ● Right to know what information is being collected ● Right to know if information is being sold ● Right to say no to sale of personal information ● Right to access personal information ● Right to not be discriminated against if exercise rights