Skip to content
NGTEdu Logo

NGTEdu

A PRODUCT OF NGTECH.CO.IN

NGTEdu Logo

NGTEdu

  • Home
  • Cyber Attacks
  • Malware
  • Vulnerabilities
  • Data Breach
  • Home
  • Cyber Attacks
  • Privacy in Q2 2022: US, Canada, and the UK
  • Cyber Attacks
  • Data Breach

Privacy in Q2 2022: US, Canada, and the UK

3 years ago Tripwire Guest Authors
Privacy in Q2 2022: US, Canada, and the UK

The second quarter of 2022 offered plenty of positing on privacy, both in the U.S. and internationally. In the U.S., we saw the addition of another state privacy law, and a spark of hope in privacy professionals’ eyes with the introduction of tangible federal legislation. Plus, the Federal Trade Commission (FTC) is positioned to act on rulemaking like never before. In the EU, the GDPR’s fourth anniversary served as a chance for real reflection on its successes and failings, while criticism of the current enforcement approach continues to roll in. Lastly, Canada tried again to introduce legislation to revamp its outdated privacy law, and the country’s long-standing privacy commissioner passed the baton.

Looking at the US

Connecticut kicked off Q2 in style, becoming the fifth state to enact a privacy law. Adding to the ever-expanding patchwork of U.S. privacy laws, An Act Concerning Personal Data Privacy and Online Monitoring, also known as the Connecticut Data Privacy Act (CTDPA), provides consumers with access, deletion, rectification and certain opt-out rights; includes provisions prohibiting “dark patterns”; and requires companies to honor a global opt-out mechanism. Effective July 1, 2023, CTDPA is considered to be operable with other state laws, following trends presented in previously enacted state laws and offering little divergence.

The second quarter has offered the most exciting time for federal privacy in recent history. While lawmakers have filed countless bills in the past years, none have captured the attention of the privacy community quite like the bipartisan, bicameral proposal called the American Data Privacy and Protection Act (ADPPA). Offered by three of the four committee leaders that handle privacy matters, the ADPPA presents a compromise on two intractable obstacles to passing legislation in the US — preemption of state laws and the private right of action.

The success of the bill will rest in the fourth and final committee leader, Senate Committee Chair Maria Cantwell (D-Wash), who has signaled at the end of June that she is not close to supporting the bill due to enforcement gaps and, in her view, its inability to adequately address preemption. On June 23, ADPPA advanced from the House Energy and Commerce subcommittee markup and now goes to the full Committee.

Should ADPPA fail to progress, it seems there is a second option for privacy in the U.S. — the FTC has once again initiated rulemaking. The FTC refiled an Advanced Notice of Proposed Rulemaking with the Office of Management and Budget for a potential rulemaking on privacy and artificial intelligence this June. The key difference between the filing from December and the current filing is that Chair Lina Khan now has a Democratic majority — thanks to Alvaro Bedoya’s long-awaited confirmation as FTC commissioner on May 11 — meaning a rulemaking package could succeed despite Republican opposition.

The EU’s reflection phase

In Europe, the second quarter marks the end of the French Presidency of the Council of the European Union. As leadership transfers to the Czech Republic on July 1, the Council can chalk up many achievements in France’s six-month reign — most notably the Digital Services Act and the Digital Markets Act. With text now being finalized, it is expected that the two will be adopted in the coming months. Together, the sister acts will advance the EU’s digital strategy, putting the EU ahead of the curve yet again.

Also noteworthy is the European Data Protection Supervisor’s (EDPS) conference “The Future of Data Protection: Effective enforcement in the digital world.” Exploring a longstanding criticism that enforcement of the GDPR is lacking and misguided, the conference identified three main issues: the unequal burden-sharing of enforcement, a lack of cooperation due to differences in procedural law, and the fact that the European Data Protection Board is often involved too little and too late.

EDPS Wojciech Wiewiórowski said enforcement of the GDPR had failed to rein in data protection abuses by big companies, focusing too often on smaller grievances, and said that he would like to go one step further on cooperation among regulators and move towards centralization of enforcement.

Meanwhile, the UK continued to move forward with anticipated changes to its data protection scheme. On May 11, the UK government declared its intentions to reform the country’s data protection regime by way of the Data Reform Bill announced during the Queen’s Speech. The government is expected to issue draft legislation in July.

What we are looking forward to in the third quarter:

  • Next steps for the EU-U.S. data sharing agreement.
  • Will ADPPA get consensus before the August Recess?
  • What happens with FTC rulemaking should ADPPA fail.
  • The UK’s new, business-friendly approach to privacy.

About the Authors: Molly Hulefeld is a Privacy Content Analyst with Ethos Privacy. Molly entered the world of privacy through the International Association of Privacy Professionals (IAPP), where she worked as Associate Editor for the publications team. Now she works to develop Sentinel’s privacy program management technology, Ethos, making it easier for businesses to meet their obligations and develop a culture of privacy.

Emily Leach

Emily Leach is the privacy content director at Ethos Privacy, overseeing framework analysis and creation for the company’s privacy program management technology. Emily has been working in data privacy for 14 years, spending 11 years at the IAPP as manager of its online resource center and editor of the Privacy Tracker, among other responsibilities. Emily holds both CIPP/US and CIPP/E certifications from the IAPP.

Editor’s Note: The opinions expressed in this guest author article are solely those of the contributor, and do not necessarily reflect those of Tripwire, Inc.

Previous Roundups

2022 Q1 Privacy Update — A new year sparks new initiatives

Privacy in 2021: A Year Worth Reviewing

A Look Back at Privacy in Q3 2021: Summertime and the Livin’ Was Easy

Privacy in Q2: In Like a Lion, Out Like a … Lion

A quick round up of privacy highlights for Q1 of 2021

Privacy in 2020 and What to Expect for the Year Ahead

The post ” Privacy in Q2 2022: US, Canada, and the UK” appeared first on TripWire

Source:TripWire – Tripwire Guest Authors

Tags: Compliance, Encryption, Goverment, Privacy, TripWire

Continue Reading

Previous 5 Things We Learned from The Definitive Guide to Data Loss Prevention (DLP)
Next GitLab Issues Patch for Critical Flaw in its Community and Enterprise Software

More Stories

  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

China-Linked DKnife AitM Framework Targets Routers for Traffic Hijacking, Malware Delivery

7 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

CISA Orders Removal of Unsupported Edge Devices to Reduce Federal Network Risk

8 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure Entities

10 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach

How Samsung Knox Helps Stop Your Network Security Breach

11 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware

13 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Data Breach
  • Vulnerabilities

Claude Opus 4.6 Finds 500+ High-Severity Flaws Across Major Open-Source Libraries

16 hours ago [email protected] (The Hacker News)

Recent Posts

  • China-Linked DKnife AitM Framework Targets Routers for Traffic Hijacking, Malware Delivery
  • CISA Orders Removal of Unsupported Edge Devices to Reduce Federal Network Risk
  • Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure Entities
  • How Samsung Knox Helps Stop Your Network Security Breach
  • Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware

Tags

Android APT Bug CERT Cloud Compliance Coronavirus COVID-19 Critical Severity Encryption Exploit Facebook Finance Google Google Chrome Goverment Hacker Hacker News High Severity Instagram iPhone Java Linux Low Severity Malware Medium Severity Microsoft Moderate Severity Mozzila Firefox Oracle Patch Tuesday Phishing Privacy QuickHeal Ransomware RAT Sim The Hacker News Threatpost TikTok TripWire VMWARE Vulnerability Whatsapp Zoom
Copyright © 2020 All rights reserved | NGTEdu.com
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Read More here.Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT