SlideShare a Scribd company logo
1 of 19
WHEN BIG DATA IS
PERSONAL DATA - DATA
ANALYTICS IN THE AGE OF
PRIVACY LAWS
DATA BREACHES IN 2019
• Blur – 2.4 million users
• Town of Salem Video Game – 7.6 million users
• DiscountMugs.com – credit card skimming
• BenefitMall HR Services – number unknown
• Capital One – like, everybody
• Poshmark - last week
• 86 others
• It’s September
© Aaron | Sanders PLLC
Free photo 2069034 © Dejan Savic - Dreamstime.com
1970 1980 1990 2000 2010 2020
2001 ‘18
September
11th
Safe Harbor
Invalidated
EU
Directive on
Data
Protection
Safe
Harbo
r
’95
Cambridge
Analytica
‘16
GDPR
‘19‘96 ‘98‘99
CCPA
‘15
HIPA
A
Gramm-
Leach-
Bliley
COPP
A
First DP Law In
the World,
Hesse
Germany
How Did We Get Here?
Computer
Mainframes
PCs
Development of
Information
Technology
Concerns About Privacy
• EUROPEAN UNION
• UNITED STATES
• JAPAN
• SOUTH KOREA
• BRAZIL
• NIGERIA
• AUSTRALIA
• THAILAND
GENERAL DATA
PROTECTION
REGULATION
• Regulation (EU) 2016/679
— protection of natural
persons with regard to the
processing of personal
data and the free
movement of such data
GDPR IN A NUTSHELL
DATA PROCESSING must be lawful,
limited, accurate, secure and for an
explicit purpose
DATA SUBECTS have rights
DATA CONTROLLERS AND PROCESSORS
have obligations of security and
accountability
RECORD KEEPING IS
MANDATORY
licensed under CC BY-
SA
• Must be
• Lawful
• Done for “specified, explicit and
legitimate purposes”
• Limited to what is necessary
• Accurate and kept up to date
• Erased after storage is no longer
necessary
• Secure
• Subject to accountability
• 6 lawful bases for processing data
• Informed consent
• Performance of a contract
• Compliance with legal obligations
• Protection of the interests of a person
• Performance of a task in the public interest
• “Legitimate Interest of Processor”
Data
Processing
RIGHTS OF THE DATA SUBJECT
• Right to know who is processing their
information
• Right to have cost-free access
• Right to have information corrected
• Limited Right of Erasure (Right to be
Forgotten)
• If lawful bases was consent or
• If purpose is solely marketing
• Right of Portability
• Machine readable
• May mean porting data to a competitor
• Limited Right of Objection to Processing
• If processing was not lawful
© Aaron | Sanders PLLC
OBLIGATIONS OF CONTROLLERS
AND PROCESSORS
• Controllers – Responsible for “implementing
appropriate technical and organizational
measures which are designed to implement
data-protection principles”
• Security
• Pseudonymization
• Encryption
• Disaster and Breach Response Plans
• Regular Testing / Maintenance
• Impact Assessments
• Processors – those who process data on
behalf of Controllers
• Vendor (Data Protection) Agreements
• Compliance with Controller’s
Security Protocols
• Rapid Breach Notification
NOTICE REQUIREMENTS
& RECORD KEEPING
• Contact information of the organization,
and a responsible person inside the
organization
• Categories of personal data processed
• Any processing of children’s data
• Categories of recipients of data
• Purpose of processing, explained in detail
• Existence of any data transfers to other
countries
• Retention Periods
• Recipients of personal data
• Security and technical data
protection measures
EXEMPTIONS
• Anonymized Data
• Public access to official documents
• Employee data
• Obligations of secrecy
• Scientific and historical research
purposes or statistical purposes (in
the public interest)
• Archiving in the public interest
• Churches and religious associations
CALIFORNIA CONSUMER
PROTECTION ACT
• AB 375 (2018) – “The bill would
authorize a consumer to opt out
of the sale of personal
information by a business and
would prohibit the business from
discriminating against the
consumer for exercising this
right….”
© Aaron | Sanders PLLC
TIMING FOR
COMPLIANCE
• Effective Date – January 1, 2020
• Look-Back Period – 2019
• Rulemaking – Approximately July 2020
WHO HAS TO COMPLY?
• Businesses who:
• Collect information on more than
50,000 CA residents, “households” or
devices
• Have $25 million or more in annual
revenue
• Derive half or more of revenue from
selling Californian’s information
HEADLINE COMPLIANCE
POINTS
• Definition of “personal information” is
broad
• Like GDPR, consumers have rights
• If a company is collecting data, notice
to consumers is required:
• What was collected
• For what purpose
• To whom it was shared, and for what
purpose
• To whom it was sold
• A CONSUMER MAY OPT-OUT OF
HAVING THEIR INFORMATION SOLD,
AND CAN’T BE DISCRIMINATED
AGAINST
OTHER STATE LAWS
• Vermont – Data Brokers must register and pay a fee
• Nevada – Disclose whether third parties can collect information from a consumer-
facing website (“cookie notice”)
• Florida – In the event of a data breach, data breach policy must be in writing and
must be demonstrably followed
SO WHAT’S A DATA HOLDER TO DO?
• Create a Concise Privacy
Notice and Robust Internal
Policies
• Keep Good Records
• Comply with Data Subject
Requests
• Educate your team
• Don’t Keep Secrets
• Keep your Promises
HERE TO HELP!
• Tara Aaron, CIPP/US, CIPP/E
• Aaron | Sanders Law PLLC
• tara@aaronsanderslaw.com
• www.aaronsanderslaw.com

More Related Content

What's hot

Privacy and Data Security
Privacy and Data SecurityPrivacy and Data Security
Privacy and Data SecurityWilmerHale
 
California Consumer Privacy Act (CCPA): Countdown to Compliance
California Consumer Privacy Act (CCPA): Countdown to ComplianceCalifornia Consumer Privacy Act (CCPA): Countdown to Compliance
California Consumer Privacy Act (CCPA): Countdown to ComplianceTinuiti
 
Data Privacy Introduction
Data Privacy IntroductionData Privacy Introduction
Data Privacy IntroductionG Prachi
 
Data Privacy
Data PrivacyData Privacy
Data PrivacyHome
 
Consumer Privacy
Consumer PrivacyConsumer Privacy
Consumer PrivacyAshish Jain
 
What is the GDPR & What does it mean for YOUR business?
What is the GDPR & What does it mean for YOUR business?What is the GDPR & What does it mean for YOUR business?
What is the GDPR & What does it mean for YOUR business?Nexsen Pruet
 
Data Privacy for Information Security Professionals Part 1
Data Privacy for Information Security Professionals Part 1Data Privacy for Information Security Professionals Part 1
Data Privacy for Information Security Professionals Part 1Dione McBride, CISSP, CIPP/E
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsUlf Mattsson
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for DummiesAtif Ghauri
 
2019 10-23 ccpa survival guide
2019 10-23 ccpa survival guide2019 10-23 ccpa survival guide
2019 10-23 ccpa survival guideTrustArc
 
Big Data
Big DataBig Data
Big Datacadmef
 
Data Protection in India
Data Protection in IndiaData Protection in India
Data Protection in IndiaHome
 
Data protection ppt
Data protection pptData protection ppt
Data protection pptgrahamwell
 
Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...CILIPScotland
 

What's hot (18)

Privacy and Data Security
Privacy and Data SecurityPrivacy and Data Security
Privacy and Data Security
 
Online privacy
Online privacyOnline privacy
Online privacy
 
Balancing Privacy and Digitization
Balancing Privacy and DigitizationBalancing Privacy and Digitization
Balancing Privacy and Digitization
 
Privacy 101
Privacy 101Privacy 101
Privacy 101
 
California Consumer Privacy Act (CCPA): Countdown to Compliance
California Consumer Privacy Act (CCPA): Countdown to ComplianceCalifornia Consumer Privacy Act (CCPA): Countdown to Compliance
California Consumer Privacy Act (CCPA): Countdown to Compliance
 
Data Privacy Introduction
Data Privacy IntroductionData Privacy Introduction
Data Privacy Introduction
 
Data Privacy
Data PrivacyData Privacy
Data Privacy
 
Data Privacy
Data PrivacyData Privacy
Data Privacy
 
Consumer Privacy
Consumer PrivacyConsumer Privacy
Consumer Privacy
 
What is the GDPR & What does it mean for YOUR business?
What is the GDPR & What does it mean for YOUR business?What is the GDPR & What does it mean for YOUR business?
What is the GDPR & What does it mean for YOUR business?
 
Data Privacy for Information Security Professionals Part 1
Data Privacy for Information Security Professionals Part 1Data Privacy for Information Security Professionals Part 1
Data Privacy for Information Security Professionals Part 1
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulations
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
2019 10-23 ccpa survival guide
2019 10-23 ccpa survival guide2019 10-23 ccpa survival guide
2019 10-23 ccpa survival guide
 
Big Data
Big DataBig Data
Big Data
 
Data Protection in India
Data Protection in IndiaData Protection in India
Data Protection in India
 
Data protection ppt
Data protection pptData protection ppt
Data protection ppt
 
Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...
 

Similar to When Big Data is Personal Data - Data Analytics in The Age of Privacy Laws

Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...Quarles & Brady
 
Scotland legal update 25 sept
Scotland legal update   25 septScotland legal update   25 sept
Scotland legal update 25 septRachel Aldighieri
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulationJames Mulhern
 
Privacy issues in data analytics
Privacy issues in data analyticsPrivacy issues in data analytics
Privacy issues in data analyticsshekharkanodia
 
Online privacy; myth or reality?
Online privacy; myth or reality?Online privacy; myth or reality?
Online privacy; myth or reality?Swaleh Ahmed
 
Presentation on Information Privacy
Presentation on Information PrivacyPresentation on Information Privacy
Presentation on Information PrivacyPerry Slack
 
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)Symantec
 
74 x9019 bea legal slides short form ged12.12.16
74 x9019 bea legal slides short form ged12.12.1674 x9019 bea legal slides short form ged12.12.16
74 x9019 bea legal slides short form ged12.12.16Glenn E. Davis
 
Who ownes the customer? Privacy in the connected age.
Who ownes the customer? Privacy in the connected age.Who ownes the customer? Privacy in the connected age.
Who ownes the customer? Privacy in the connected age.jatharrison
 
Countdown to CCPA: 48 Days Until Your IBM i Data Needs to Be Secured
Countdown to CCPA: 48 Days Until Your IBM i Data Needs to Be SecuredCountdown to CCPA: 48 Days Until Your IBM i Data Needs to Be Secured
Countdown to CCPA: 48 Days Until Your IBM i Data Needs to Be SecuredPrecisely
 
Bridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and RetentionBridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and RetentionInfoGoTo
 
European GDPR for Good Technology Collective (GTC)
European GDPR for Good Technology Collective (GTC)European GDPR for Good Technology Collective (GTC)
European GDPR for Good Technology Collective (GTC)Dr. Mira Suleimenova, CIPPe
 
Domain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRDomain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRBartLieben
 
Are Your Data Ready for GDPR? (with MAPR and Talend)
Are Your Data Ready for GDPR? (with MAPR and Talend)Are Your Data Ready for GDPR? (with MAPR and Talend)
Are Your Data Ready for GDPR? (with MAPR and Talend)Jean-Michel Franco
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? SecurityScorecard
 
Introduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsIntroduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsFinancial Poise
 
Administrative and public law seminar
Administrative and public law seminarAdministrative and public law seminar
Administrative and public law seminarBrowne Jacobson LLP
 

Similar to When Big Data is Personal Data - Data Analytics in The Age of Privacy Laws (20)

Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
 
Scotland legal update 25 sept
Scotland legal update   25 septScotland legal update   25 sept
Scotland legal update 25 sept
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
13687562.ppt
13687562.ppt13687562.ppt
13687562.ppt
 
GDPR Part 1: Quick Facts
GDPR Part 1: Quick FactsGDPR Part 1: Quick Facts
GDPR Part 1: Quick Facts
 
Get you and your business GDPR ready
Get you and your business GDPR readyGet you and your business GDPR ready
Get you and your business GDPR ready
 
Privacy issues in data analytics
Privacy issues in data analyticsPrivacy issues in data analytics
Privacy issues in data analytics
 
Online privacy; myth or reality?
Online privacy; myth or reality?Online privacy; myth or reality?
Online privacy; myth or reality?
 
Presentation on Information Privacy
Presentation on Information PrivacyPresentation on Information Privacy
Presentation on Information Privacy
 
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)
 
74 x9019 bea legal slides short form ged12.12.16
74 x9019 bea legal slides short form ged12.12.1674 x9019 bea legal slides short form ged12.12.16
74 x9019 bea legal slides short form ged12.12.16
 
Who ownes the customer? Privacy in the connected age.
Who ownes the customer? Privacy in the connected age.Who ownes the customer? Privacy in the connected age.
Who ownes the customer? Privacy in the connected age.
 
Countdown to CCPA: 48 Days Until Your IBM i Data Needs to Be Secured
Countdown to CCPA: 48 Days Until Your IBM i Data Needs to Be SecuredCountdown to CCPA: 48 Days Until Your IBM i Data Needs to Be Secured
Countdown to CCPA: 48 Days Until Your IBM i Data Needs to Be Secured
 
Bridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and RetentionBridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and Retention
 
European GDPR for Good Technology Collective (GTC)
European GDPR for Good Technology Collective (GTC)European GDPR for Good Technology Collective (GTC)
European GDPR for Good Technology Collective (GTC)
 
Domain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRDomain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPR
 
Are Your Data Ready for GDPR? (with MAPR and Talend)
Are Your Data Ready for GDPR? (with MAPR and Talend)Are Your Data Ready for GDPR? (with MAPR and Talend)
Are Your Data Ready for GDPR? (with MAPR and Talend)
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
Introduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsIntroduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and Requirements
 
Administrative and public law seminar
Administrative and public law seminarAdministrative and public law seminar
Administrative and public law seminar
 

Recently uploaded

PowerPoint - Legal Citation Form 1 - Case Law.pptx
PowerPoint - Legal Citation Form 1 - Case Law.pptxPowerPoint - Legal Citation Form 1 - Case Law.pptx
PowerPoint - Legal Citation Form 1 - Case Law.pptxca2or2tx
 
Introduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusionIntroduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusionAnuragMishra811030
 
The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...James Watkins, III JD CFP®
 
CAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction FailsCAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction FailsAurora Consulting
 
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881mayurchatre90
 
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxIBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxRRR Chambers
 
Human Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptxHuman Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptxfilippoluciani9
 
Appeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdfAppeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdfPoojaGadiya1
 
The doctrine of harmonious construction under Interpretation of statute
The doctrine of harmonious construction under Interpretation of statuteThe doctrine of harmonious construction under Interpretation of statute
The doctrine of harmonious construction under Interpretation of statuteDeepikaK245113
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书SS A
 
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptx
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptxMOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptx
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptxRRR Chambers
 
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceanilsa9823
 
PPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptxPPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptxRRR Chambers
 
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxxAudience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxxMollyBrown86
 
Shubh_Burden of proof_Indian Evidence Act.pptx
Shubh_Burden of proof_Indian Evidence Act.pptxShubh_Burden of proof_Indian Evidence Act.pptx
Shubh_Burden of proof_Indian Evidence Act.pptxShubham Wadhonkar
 
THE FACTORIES ACT,1948 (2).pptx labour
THE FACTORIES ACT,1948 (2).pptx   labourTHE FACTORIES ACT,1948 (2).pptx   labour
THE FACTORIES ACT,1948 (2).pptx labourBhavikaGholap1
 
589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdfSUSHMITAPOTHAL
 
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptxKEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptxRRR Chambers
 

Recently uploaded (20)

PowerPoint - Legal Citation Form 1 - Case Law.pptx
PowerPoint - Legal Citation Form 1 - Case Law.pptxPowerPoint - Legal Citation Form 1 - Case Law.pptx
PowerPoint - Legal Citation Form 1 - Case Law.pptx
 
Introduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusionIntroduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusion
 
The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...
 
CAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction FailsCAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction Fails
 
Russian Call Girls Rohini Sector 6 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
Russian Call Girls Rohini Sector 6 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...Russian Call Girls Rohini Sector 6 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
Russian Call Girls Rohini Sector 6 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
 
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
 
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxIBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
 
Human Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptxHuman Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptx
 
Appeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdfAppeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdf
 
The doctrine of harmonious construction under Interpretation of statute
The doctrine of harmonious construction under Interpretation of statuteThe doctrine of harmonious construction under Interpretation of statute
The doctrine of harmonious construction under Interpretation of statute
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书
 
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptx
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptxMOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptx
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptx
 
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
 
PPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptxPPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptx
 
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxxAudience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
 
Shubh_Burden of proof_Indian Evidence Act.pptx
Shubh_Burden of proof_Indian Evidence Act.pptxShubh_Burden of proof_Indian Evidence Act.pptx
Shubh_Burden of proof_Indian Evidence Act.pptx
 
THE FACTORIES ACT,1948 (2).pptx labour
THE FACTORIES ACT,1948 (2).pptx   labourTHE FACTORIES ACT,1948 (2).pptx   labour
THE FACTORIES ACT,1948 (2).pptx labour
 
589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf
 
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptxKEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
 

When Big Data is Personal Data - Data Analytics in The Age of Privacy Laws

  • 1. WHEN BIG DATA IS PERSONAL DATA - DATA ANALYTICS IN THE AGE OF PRIVACY LAWS
  • 2. DATA BREACHES IN 2019 • Blur – 2.4 million users • Town of Salem Video Game – 7.6 million users • DiscountMugs.com – credit card skimming • BenefitMall HR Services – number unknown • Capital One – like, everybody • Poshmark - last week • 86 others • It’s September © Aaron | Sanders PLLC Free photo 2069034 © Dejan Savic - Dreamstime.com
  • 3.
  • 4.
  • 5. 1970 1980 1990 2000 2010 2020 2001 ‘18 September 11th Safe Harbor Invalidated EU Directive on Data Protection Safe Harbo r ’95 Cambridge Analytica ‘16 GDPR ‘19‘96 ‘98‘99 CCPA ‘15 HIPA A Gramm- Leach- Bliley COPP A First DP Law In the World, Hesse Germany How Did We Get Here? Computer Mainframes PCs Development of Information Technology Concerns About Privacy
  • 6. • EUROPEAN UNION • UNITED STATES • JAPAN • SOUTH KOREA • BRAZIL • NIGERIA • AUSTRALIA • THAILAND
  • 7. GENERAL DATA PROTECTION REGULATION • Regulation (EU) 2016/679 — protection of natural persons with regard to the processing of personal data and the free movement of such data
  • 8. GDPR IN A NUTSHELL DATA PROCESSING must be lawful, limited, accurate, secure and for an explicit purpose DATA SUBECTS have rights DATA CONTROLLERS AND PROCESSORS have obligations of security and accountability RECORD KEEPING IS MANDATORY licensed under CC BY- SA
  • 9. • Must be • Lawful • Done for “specified, explicit and legitimate purposes” • Limited to what is necessary • Accurate and kept up to date • Erased after storage is no longer necessary • Secure • Subject to accountability • 6 lawful bases for processing data • Informed consent • Performance of a contract • Compliance with legal obligations • Protection of the interests of a person • Performance of a task in the public interest • “Legitimate Interest of Processor” Data Processing
  • 10. RIGHTS OF THE DATA SUBJECT • Right to know who is processing their information • Right to have cost-free access • Right to have information corrected • Limited Right of Erasure (Right to be Forgotten) • If lawful bases was consent or • If purpose is solely marketing • Right of Portability • Machine readable • May mean porting data to a competitor • Limited Right of Objection to Processing • If processing was not lawful © Aaron | Sanders PLLC
  • 11. OBLIGATIONS OF CONTROLLERS AND PROCESSORS • Controllers – Responsible for “implementing appropriate technical and organizational measures which are designed to implement data-protection principles” • Security • Pseudonymization • Encryption • Disaster and Breach Response Plans • Regular Testing / Maintenance • Impact Assessments • Processors – those who process data on behalf of Controllers • Vendor (Data Protection) Agreements • Compliance with Controller’s Security Protocols • Rapid Breach Notification
  • 12. NOTICE REQUIREMENTS & RECORD KEEPING • Contact information of the organization, and a responsible person inside the organization • Categories of personal data processed • Any processing of children’s data • Categories of recipients of data • Purpose of processing, explained in detail • Existence of any data transfers to other countries • Retention Periods • Recipients of personal data • Security and technical data protection measures
  • 13. EXEMPTIONS • Anonymized Data • Public access to official documents • Employee data • Obligations of secrecy • Scientific and historical research purposes or statistical purposes (in the public interest) • Archiving in the public interest • Churches and religious associations
  • 14. CALIFORNIA CONSUMER PROTECTION ACT • AB 375 (2018) – “The bill would authorize a consumer to opt out of the sale of personal information by a business and would prohibit the business from discriminating against the consumer for exercising this right….” © Aaron | Sanders PLLC
  • 15. TIMING FOR COMPLIANCE • Effective Date – January 1, 2020 • Look-Back Period – 2019 • Rulemaking – Approximately July 2020 WHO HAS TO COMPLY? • Businesses who: • Collect information on more than 50,000 CA residents, “households” or devices • Have $25 million or more in annual revenue • Derive half or more of revenue from selling Californian’s information
  • 16. HEADLINE COMPLIANCE POINTS • Definition of “personal information” is broad • Like GDPR, consumers have rights • If a company is collecting data, notice to consumers is required: • What was collected • For what purpose • To whom it was shared, and for what purpose • To whom it was sold • A CONSUMER MAY OPT-OUT OF HAVING THEIR INFORMATION SOLD, AND CAN’T BE DISCRIMINATED AGAINST
  • 17. OTHER STATE LAWS • Vermont – Data Brokers must register and pay a fee • Nevada – Disclose whether third parties can collect information from a consumer- facing website (“cookie notice”) • Florida – In the event of a data breach, data breach policy must be in writing and must be demonstrably followed
  • 18. SO WHAT’S A DATA HOLDER TO DO? • Create a Concise Privacy Notice and Robust Internal Policies • Keep Good Records • Comply with Data Subject Requests • Educate your team • Don’t Keep Secrets • Keep your Promises
  • 19. HERE TO HELP! • Tara Aaron, CIPP/US, CIPP/E • Aaron | Sanders Law PLLC • tara@aaronsanderslaw.com • www.aaronsanderslaw.com

Editor's Notes

  1. What it doesn’t allow data subjects to do is opt out of lawful processing completely (except in a couple of circumstances)
  2. Vendor Agreements Lawfulness, fairness and transparency Purpose limitation Data minimisation Accuracy Storage limitation Integrity and confidentiality (This is the Data Security Principle) Basic Security Protocols are also going to include employee training, user authentication, access controls, firewalls, software updates, virus control. GDPR doesn’t spell it out, but for example, if you’re ISO 27000 compliant, or HIPAA compliant, it’s likely that your security protocols are sufficient.
  3. There are U.S. state laws that mean you should also have a written data breach policy as well, and we’ll get to those.
  4. Major difference between the GDPR and the California law – consumers can opt out of all sale of data
  5. These are collective numbers, so basically if you have the information of more than 16,666 Califorians, and that information includes IP addresses, this applies to you.
  6. Definition of “sale” is super broad. Any transfer for consideration, except to service providers (those who help with internal business). Determining if information is being sold to a service provider. -- May have to re-do contracts with service providers. Keep California separate? The ‘do not sell’ button is only required for California residents, but Bailey said many companies plan to offer it to all U.S. users. ”Will I selectively display this link? Am I going to show it to everyone who comes to my website?” Bailey said. “Or am I going to somehow try to fence off California citizens and only show them the link? … For this particular use case, it’s a hard thing to do.”Verify users’ identity. If companies do choose to keep California residents separate, they’ll need to identify which consumers are from the state, the privacy professionals said, and that can get complicated. Leipzig advised against collecting data such as uploaded driver’s license photos; it just adds to the data a company needs to protect. At a minimum, Bailey said websites should include CAPTCHA tests and emailed verification to prevent bots from spamming ‘do not sell’ links.
  7. If you’re in the business of collecting and selling information about data subjects that your company does not have a direct relationship with, and any of those subjects are from Vermont, you need to be registered in Vermont. Nevada’s law is more narrow – only applies to sites that sell goods and services to consumers. So it applies to Amazon, but not Twitter. We didn’t get to a lot about cookie notices today – the EU is pretty soon going to be making a new regulation that will require cookie controls to be available at the browser level. Florida’s fines are up to half a million dollars.