CIO News Hubb
Advertisement
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact
No Result
View All Result
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact
No Result
View All Result
CIO News Hubb
No Result
View All Result
Home Information Security

Newest State Data Privacy Legislation

admin by admin
April 25, 2022
in Information Security
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter


The latest legislation provides consumers with the right to access and delete some of their personal data and opt out of data collection under certain circumstances.

When we wrote about state privacy laws earlier this year, Virginia, California, and Colorado were the only states with laws in place to protect consumers’ privacy. (Nevada has also had a more limited law since 2019.) Since then, Utah Governor Spencer Cox signed the Utah Consumer Privacy Act (SB 227) on March 24, 2022, and Virginia has enacted three additional laws amending its Consumer Data Protection Act.

Utah’s law ⁠— which goes into effect at the end of 2023 ⁠— provides consumers with the right to access and delete some of their personal data, opt out of data collection under certain circumstances, and provide consumers with what data is collected on their behalf. It doesn’t contain any provision to provide consumers with any legal action in the case of a violation or to correct any inaccuracies or a right to opt out of personal profiling (as can be found with other states).

The reason why I’ve mentioned that consumers will have the right to delete some of their data is because Utah’s law only places limits on data supplied by the consumer to a particular entity, which will be interesting to see how that works out. The law applies to anyone who conducts business in the state and has an annual revenue of at least $25M. There are various exemptions in terms of who needs to comply with this law that are similar to Virginia’s law. For example,  higher education and non-profit organizations don’t have to comply. 

How Utah’s legislation differs from other state data privacy laws

One big difference between Utah and other states is that consumers don’t give prior consent before sensitive data can be collected. This is the opposite of what the other states have enacted, which requires this consent. In Utah, consumers can opt out prior to its collection. Another difference is that Utah doesn’t require businesses to perform data protection assessments, making it “more business friendly”.

Each of these four states has subtle differences in how they handle requests from consumers, which means there a fair amount of confusion can be expected when it comes to understanding these differences and interacting with state governments to address and resolve privacy problems.


Further reading: Protecting your personal data online


Moving on to Virginia, the various amendments will go into effect July 1, 2022, although the main Consumer Data Protection Act takes effect in January 2023 as mentioned above. The amendments were the result of a working group to refine what was previously passed and focus on three areas:

  1. A narrowing of the “right to delete” that excludes data not directly provided by consumers (this is similar to the legislation passed by Utah)
  2. Replacing the Consumer Privacy Fund with a new collections entity for any fines
  3. Modification of non-profit exemptions to include all 501(c)(4) organizations and other political entities.

Data privacy legislation updates in other states

Finally, several other states are considering their own privacy laws, as Husch Blackwell catalogs here, including bills under consideration in Iowa, Connecticut, Maryland, and other states that are holding hearings during this year’s legislative sessions.

We will continue to watch this space and provide future updates once these efforts result in enacted legislation. To continuously keep up on the latest updates, the US State Privacy Legislation Tracker is a great resource that provides a comprehensive overview of data privacy legislative activities on a state level.



Source link

Previous Post

3 Problems with Just-in-Time Planning and Solving Them with Agile Planning

Next Post

AWS welcomes new Trans-Atlantic Data Privacy Framework

Related Posts

Information Security

Cisco Issues Patch for New IOS XR Zero-Day Vulnerability Exploited in the Wild

by admin
May 23, 2022
Information Security

APTs Overwhelmingly Share Known Vulnerabilities Rather Than Attack O-Days

by admin
May 22, 2022
Information Security

Researchers Find Backdoor in School Management Plugin for WordPress

by admin
May 21, 2022
Information Security

380K Kubernetes API Servers Exposed to Public Internet

by admin
May 21, 2022
Information Security

Virtual product placements revealed by streaming platforms

by admin
May 21, 2022
Next Post

AWS welcomes new Trans-Atlantic Data Privacy Framework

Leave Comment

Recommended

Reimagining the cities of the future in Finland

May 23, 2022

The longlist of the UK’s influential tech leaders

May 23, 2022

Did the Conti ransomware crew orchestrate its own demise?

May 23, 2022

Understanding attack paths is a question of training

May 23, 2022

How large companies can be ‘sharks’ that devour startups in their way – I-CIO

May 23, 2022

Cisco Issues Patch for New IOS XR Zero-Day Vulnerability Exploited in the Wild

May 23, 2022

© 2022 CIO News Hubb All rights reserved.

Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Privacy Policy.

Navigate Site

  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact

Newsletter Sign Up

No Result
View All Result
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact

© 2022 JNews - Premium WordPress news & magazine theme by Jegtheme.