Skip to content
NGTEdu Logo

NGTEdu

A PRODUCT OF NGTECH.CO.IN

NGTEdu Logo

NGTEdu

  • Home
  • Cyber Attacks
  • Malware
  • Vulnerabilities
  • Data Breach
  • Home
  • Data Breach
  • Privacy in Q2: In Like a Lion, Out Like a … Lion
  • Data Breach

Privacy in Q2: In Like a Lion, Out Like a … Lion

5 years ago Tripwire Guest Authors
Privacy in Q2: In Like a Lion, Out Like a … Lion

For a while, privacy in Q2 was looking like it would follow the season’s idiomatic rule: in like a lion, out like a lamb. But it came roaring back in June with a new U.S. state law, EU adequacy decisions, a new EU data transfer mechanism, and more. As we look back over the second quarter of 2021, several important developments are worth noting.

U.S. State Privacy

Overall, the short legislative season proved to be as much an obstacle to passing comprehensive privacy laws as the private right of action has been. By the end of the second quarter, with a total of 26 states having introduced comprehensive privacy bills since the start of 2021, only Colorado and Virginia crossed the finish line by the end of their legislative calendar. Massachusetts, New Jersey, and Pennsylvania remained in session with privacy bills on the agenda.

Much as Virginia did last quarter, Colorado stole the show this quarter as legislators worked quietly and diligently to become the third state in the U.S. to pass comprehensive privacy legislation. Drawing from laws in California and Virginia, and generally seen as striking a balance between consumer privacy and enabling business, the Colorado Privacy Act positions itself as an example for other states to follow.

Signed into law by Gov. Jared Polis, the CPA provides consumers with what have come to be seen as the standard data subject rights in the U.S. — access, rectification, deletion, and portability. Similar to California and Nevada, it provides the ability for consumers to opt-out of the sale of personal information and, like Virginia, includes an opt-out option for targeted advertising and profiling.   

The CPA will take effect July 1, 2023. Enforcement of the CPA rests with the Attorney General’s Office, which has also been tasked with creating clarifying regulations. The bill does not include the private right of action — a common deal-breaker for privacy laws — and, for clarity, states this multiple times.   

Polis has acknowledged that the CPA is a work in progress, remarking in his signing statement that, “in the haste to pass this bill, several issues remain outstanding … SB 21-190 will require clean-up legislation next year.” 

U.S. Federal Privacy

A U.S. federal privacy law seemed inevitable at the start of 2021. Lawmakers on both sides of the aisle generally support and agree on how to provide protections for consumers. The proof can be found in the various bills introduced, which show overwhelming agreement in the details of how to construct a federal standard. Despite this, proposals continue to be met with resistance and delays, and toward the end of the quarter, congressional attention on privacy seemed to practically disappear.

Discussions on federal privacy are rumored to begin later this summer. Until then, we will be watching to see how the Federal Trade Commission handles it in the near term. With Lina Khan now confirmed and appointed Chairwoman, the FTC is well-positioned to explore its rule-making capabilities as a solution for federal regulation. We are even seeing previously reluctant FTC members acquiesce to the idea in the absence of a federal law.

International Considerations

In contrast to the United States, Europe continues working to develop more nuanced areas of focus in privacy and data protection matters as it continues its digital transformation. Work on reforming the ePrivacy Directive into a regulation continues, for instance, while the European Commission released new Standard Contractual Clauses, issued adequacy to the U.K. and a draft adequacy decision to South Korea, as well as released guidance on artificial intelligence.

The Court of Justice of the European Union issued a judgment that will change the EU’s one-stop-shop mechanism and is likely to de-congest an enforcement bottleneck. The CJEU’s judgement gives supervisory authorities other than the lead authority the power to bring cases of alleged GDPR violations to their national courts in certain circumstances, specifically cross-border cases. With myriad big tech firms headquartered in Ireland, this decision is likely to lessen the burden placed on the Irish authority, which has been criticized for failing to properly enforce GDPR matters in a timely fashion.

China recently released the second draft of its Personal Information Protection Law, which adds clarification to the first draft and expands data subject rights. It is expected that the draft will be reviewed once more before adoption later this year. 

South Africa’s Protection of Personal Information Act (POPIA) became enforceable on July 1. POPIA protects personal information processed by public and private bodies, provides data subjects rights, regulates the cross-border flow of personal information, introduces mandatory obligations to report and notify of data breach incidents, and imposes statutory penalties for violations of the law. 

Looking ahead

Looking ahead to the third quarter, here is what we will be watching:

  • Remaining active state privacy bills: New Jersey, Massachusetts, and Pennsylvania
  • How will federal privacy discussions play out this summer?
  • How will the FTC navigate rule-making for privacy regulations?
  • Will we see increased enforcement action across Europe as one-stop-shop is clarified?
  • Will the ePrivacy Regulation finally get passed?

About the Authors: Molly Hulefeld is a Privacy Content Analyst with Sentinel. Molly entered the world of privacy through the International Association of Privacy Professionals (IAPP), where she worked as Associate Editor for the publications team. Now she works to develop Sentinel’s privacy program management technology, Ethos, making it easier for businesses to meet their privacy obligations and develop a culture of privacy.

Emily LeachEmily Leach is the privacy content director at Sentinel LLC, overseeing privacy framework analysis and creation for Ethos, Sentinel’s privacy program management technology. Emily has been working in data privacy for 14 years, spending 11 years at the IAPP as manager of its online resource center and editor of the Privacy Tracker, among other responsibilities. Emily holds both CIPP/US and CIPP/E certifications from the IAPP.

Editor’s Note: The opinions expressed in this guest author article are solely those of the contributor, and do not necessarily reflect those of Tripwire, Inc.

The post ” Privacy in Q2: In Like a Lion, Out Like a … Lion” appeared first on TripWire

Source:TripWire – Tripwire Guest Authors

Tags: Compliance, Encryption, Goverment, Privacy, TripWire

Continue Reading

Previous Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets
Next Phishing Costs Nearly Quadrupled Over 6 Years

More Stories

  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks

2 days ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager

2 days ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026

2 days ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Malware

Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages

2 days ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets

3 days ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure

3 days ago [email protected] (The Hacker News)

Recent Posts

  • FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks
  • Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
  • CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026
  • Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages
  • Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets

Tags

Android APT Bug CERT Cloud Compliance Coronavirus COVID-19 Critical Severity Encryption Exploit Facebook Finance Google Google Chrome Goverment Hacker Hacker News High Severity Instagram iPhone Java Linux Low Severity Malware Medium Severity Microsoft Moderate Severity Mozzila Firefox Oracle Patch Tuesday Phishing Privacy QuickHeal Ransomware RAT Sim The Hacker News Threatpost TikTok TripWire VMWARE Vulnerability Whatsapp Zoom
Copyright © 2020 All rights reserved | NGTEdu.com
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Read More here.Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT