Why is it So Important to be Compliant, and How Can You be Compliant?
Recently, there has been a surge in the number of fines imposed on companies for violating privacy laws and regulations. Some notable incidents are the $888 million fine imposed on Amazon by the European Union (EU) in July 2021 and the $58.7 million fine on Google in 2019. Though these fines are considerably huge, they are essential to ensure our personal data is safe with companies.
What is Personal Data?
Personal data is any data that can identify an individual. Email addresses, phone numbers, credit card numbers, SSN, home addresses, etc., are examples of personal data. Personal data is also known as sensitive data or Personally Identifiable Information (PII).
The growing awareness of data rights has made it essential to safeguard these sensitive data. GDPR and CCPA are two of the largest privacy laws and regulations.
What are GDPR and CCPA?
The General Data Protection Regulation or GDPR is a regulation on data protection and privacy in the EU. Adopted in 2016, it applies to all companies dealing with EU citizen data worldwide. Its goal is to provide EU citizens more control over their data. These rights include the right to access, change, move, or delete data, know who’s collecting it, where it is, where it’s going, who has access to it, and for what purposes.
Similarly, the California Consumer Privacy Act (CCPA) is a state statute to enhance privacy rights and consumer protection for residents of California, United States. The Bill, passed in 2018, also gives consumers more control over the personal information businesses collect about them and provides guidance on implementing the law.
The key difference between them is that:
- GDPR protects data subjects who can be any person and not necessarily an EU resident or citizen.
- CCPA considers consumers as the citizens of the state of California, living in the state or outside.
Regardless, violating GDPR or CCPA rules can result in hefty fines and reputational damage for companies. Therefore, it is essential to be compliant.
However, being compliant is easier said than done. With the long list of laws and regulations, companies often struggle with the data they hold. Yet, the following best practices may assist in being compliant with the GDPR, CCPA, and other similar regulations.
Collect with Consent
Request consent from all your data subjects before collecting their personal data. Request for consent must be “clearly distinguishable from the other matters” and presented in “clear and plain language.” Document the response to the consent request as evidence.
Be Accountable
Once you have collected the data from your data subject with their consent, be accountable for it. Maintain detailed documentation of the data you collect, how it’s used, where it’s stored, which employee is responsible for it, etc. Have Data Processing Agreement contracts in place with third parties you contract to process data for you. This is essential because if you cannot show that you are GDPR compliant, you are not.
Secure the Data
Securing the data acquired from your data subjects is essential. Implement “appropriate technical and organizational measures” such as two-factor authentication, end-to-end encryption, data privacy policy, staff training, and limiting access to personal data.
Remediate Data
Regularly analyze and manage the data you have. Keep it for only as long as it is needed; then, delete it. Ensure you keep a record of what data you had and why you deleted it. Migrate the critical data into archives and control who has access to it strictly.
Follow the principles
- Lawfulness, fairness, and transparency — Process your data subjects’ data lawfully, fairly, and transparently.
- Purpose limitation — Process data only for the purposes specified to your data subjects during the data collection.
- Data minimization — Collect and store only as much data as absolutely necessary for the specified purposes.
- Accuracy — Keep personal data accurate and up to date.
- Storage limitation — Store PII only for as long as necessary or specified to the data subject.
- Integrity and confidentiality — Ensure data security, integrity, and confidentiality by means such as encryption.
- Accountability — Ensure the data controller can demonstrate GDPR compliance with all of these principles.
Additionally, you should:
- Report a data breach within the first 72 hours of becoming aware of it to avoid penalties.
- Seek parental permission when consent from under 13 is required.
- Appoint Data Protection Officers wherever feasible.
- Lastly, be respectful of individual privacy rights.
Conclusion
Complying with data privacy has neither been easy in the past, nor will it be in the future. Similarly, there is neither a shortcut for being compliant nor an escape from non-compliance penalties. Therefore, understand your data and the laws that apply to it, be accountable, secure the data, collect with consent and follow the principles. If all of that seems too much, seek support from your Data Protection Officer or deploy compliance management software solutions.
Comments
Post a Comment