Skip to content
NGTEdu Logo

NGTEdu

A PRODUCT OF NGTECH.CO.IN

NGTEdu Logo

NGTEdu

  • Home
  • Cyber Attacks
  • Malware
  • Vulnerabilities
  • Data Breach
  • Home
  • Data Breach
  • A quick round up of privacy highlights for Q1 of 2021
  • Data Breach

A quick round up of privacy highlights for Q1 of 2021

5 years ago Tripwire Guest Authors
A quick round up of privacy highlights for Q1 of 2021

As expected, the start of 2021 has seen unprecedented movement in the U.S. with 22 states introducing comprehensive privacy legislation and even more introducing specific-use legislation. To date, hundreds of privacy bills were introduced across the states; to give some perspective, more than 50 privacy bills were introduced in New York alone. Undoubtedly a hot topic, it seemed anyone with an idea for a privacy bill put it in writing and introduced it to their legislature.

Most state legislatures are still working their way through the bills, but even so there are trends emerging that can help us understand how privacy is shaping up in the U.S. For example, many bills extend the standard consumer privacy rights of access, deletion and correction; the opt-out model for the sale of personal information is also popular. And bills that do these things while protecting businesses from the private right to action seem to advance with much less fanfare — and opposition.

Virginia’s Consumer Data Protection Act

Virginia is the only state to pass a comprehensive privacy bill into law so far this year. Modeled after the proposed Washington Privacy Act, Virginia’s Consumer Data Protection Act gives consumers the right to access, correction, deletion, and portability and obligations for data processors are fairly straightforward. One unique element of CDPA among U.S. proposals is that it requires data protection assessments for certain processing activities, reminiscent of requirements under the EU General Data Protection Regulation.

While Virginia deserves credit for crossing the finish line first, its law is underwhelming in terms of privacy protections on the global stage. With its opt-out model for targeted advertising, selling personal information and profiling and its lack of a private right of action, it lags behind many omnibus privacy and data protection laws.

Additionally, the scope of information covered by the law falls short of the standard fare. CPDA provides an exception for publicly available information that includes information for which organizations have a “reasonable basis to believe is lawfully made available to the general public through widely distributed media, by the consumer, or by a person to whom the consumer has disclosed the information unless the consumer has restricted the information to a specific audience.” This exception eliminates a huge amount of personal information from the law’s protections, and differs from CCPA, GDPR and Washington’s proposed bill.

Federal action

With so many states introducing a hodgepodge of comprehensive legislation and legislation targeted at genetic data, biometric data, data breaches, etc., requirements are quickly becoming even more cumbersome for organizations to navigate. In terms of compliance, the only thing more confusing than a patchwork of comprehensive privacy legislation is a patchwork of comprehensive privacy legislation intertwined with targeted privacy legislation. If this quarter is any indication, this is what the U.S. has coming down the pike.

So, the big question is: Has the start of 2021 provided enough movement for Congress to seriously consider federal legislation? The answer is anyone’s guess. A number of bills have been introduced, and the most likely candidate seems to be the Information Transparency and Personal Data Control Act, introduced by U.S. Rep. Suzan DelBene, D-Wash., which has garnered attention for its approach and support. Backed by 100 centrist lawmakers via The New Democrats Coalition caucus and endorsed by the U.S. Chamber of Commerce, the bill would require companies to obtain consumer opt-in for selling or sharing sensitive information and would allow consumers to opt-out for non-sensitive information.

The bill would preempt state privacy laws (CCPA and CDPA) and does not include a private right of action. Originally introduced in 2019, the current version reflects changes made based on stakeholder feedback. For instance, it now has a broader definition of sensitive information and significantly increased resources for the FTC, which would be tasked with enforcement. The proposed 2021 bill would give the FTC 500 new full-time employees dedicated to privacy and security matters (with 50 having technology expertise) and would increase enforcement funding from $35 million in the 2019 version to $350 million.

International considerations

While the bombardment of state privacy bills kept interested parties on their toes during the first quarter of 2021, there has also been movement in other interesting and important areas of privacy. Taking a quick look at the international privacy community, progress inches along in negotiations concerning an enhanced EU-U.S. Privacy Shield agreement with President Biden announcing on day one that Christopher Hoff would lead the Privacy Shield negotiations; the EU issued a draft decision on U.K. adequacy; and the EU ePrivacy Regulation is the closest it’s been to passing since its first draft was introduced in 2017.   

With so much happening in the privacy space, it’s hard to keep track of it all. Here’s what we’ll be watching:

  • Washington: The state is inches away from passing the Washington Privacy Act — but we’ve been here before. More than once.
  • The U.K adequacy decision: Will it suffer a similar fate to that of the EU-U.S. Privacy Shield agreement due to the country’s appetite for surveillance?
  • India: We’ve been hearing for months that their much-anticipated privacy bill will arrive any day.
  • Enforcement on big tech: Big tech remains the focus of privacy advocates and regulators worldwide.
  • U.S. federal law: Have we finally reached the tipping point where a federal law will happen?

About the Authors: Molly Hulefeld is a Privacy Content Analyst with Sentinel. Molly entered the world of privacy through the International Association of Privacy Professionals (IAPP), where she worked as Associate Editor for the publications team. Now she works to develop Sentinel’s Culture of PrivacyTM services and Ethos, the company’s privacy program management technology designed to help businesses meet their privacy obligations. Molly’s BA is from the University of Vermont and her MA in International Development from the University of Denver.

Emily LeachEmily Leach is the privacy content director at Sentinel LLC, overseeing privacy framework analysis and creation for Ethos, Sentinel’s privacy program management technology. Emily has been working in data privacy for 14 years, spending 11 years at the IAPP as manager of its online resource center and editor of the Privacy Tracker among other responsibilities. Emily holds both CIPP/US and CIPP/E certifications from the IAPP.

Editor’s Note: The opinions expressed in this guest author article are solely those of the contributor, and do not necessarily reflect those of Tripwire, Inc.

The post ” A quick round up of privacy highlights for Q1 of 2021″ appeared first on TripWire

Source:TripWire – Tripwire Guest Authors

Tags: Compliance, Encryption, Goverment, Privacy, TripWire

Continue Reading

Previous Biden Races to Shore Up Power Grid Against Hacks
Next Severe Bugs Reported in EtherNet/IP Stack for Industrial Systems

More Stories

  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

China-Linked DKnife AitM Framework Targets Routers for Traffic Hijacking, Malware Delivery

6 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

CISA Orders Removal of Unsupported Edge Devices to Reduce Federal Network Risk

7 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure Entities

8 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach

How Samsung Knox Helps Stop Your Network Security Breach

10 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware

12 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Data Breach
  • Vulnerabilities

Claude Opus 4.6 Finds 500+ High-Severity Flaws Across Major Open-Source Libraries

15 hours ago [email protected] (The Hacker News)

Recent Posts

  • China-Linked DKnife AitM Framework Targets Routers for Traffic Hijacking, Malware Delivery
  • CISA Orders Removal of Unsupported Edge Devices to Reduce Federal Network Risk
  • Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure Entities
  • How Samsung Knox Helps Stop Your Network Security Breach
  • Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware

Tags

Android APT Bug CERT Cloud Compliance Coronavirus COVID-19 Critical Severity Encryption Exploit Facebook Finance Google Google Chrome Goverment Hacker Hacker News High Severity Instagram iPhone Java Linux Low Severity Malware Medium Severity Microsoft Moderate Severity Mozzila Firefox Oracle Patch Tuesday Phishing Privacy QuickHeal Ransomware RAT Sim The Hacker News Threatpost TikTok TripWire VMWARE Vulnerability Whatsapp Zoom
Copyright © 2020 All rights reserved | NGTEdu.com
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Read More here.Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT