Principles of data privacy
Data privacy refers to the protection of the personal information of individuals or organizations from unauthorized access, use, or disclosure. Regulations around the world are cognizant of data privacy laws, and it is important for the risk manager to understand these principles that guide data privacy. Laws such as General Data Protection Regulation (GDPR) that apply to data stored anywhere in the European Union (EU) also set limits on transfers to other jurisdictions of data associated with EU citizens. The California Privacy Rights Act (CPRA) has a similar structure to GDPR but is applicable only to California residents, and many other state laws require companies to put equal emphasis on privacy as much as security. The following are some key principles that are relevant to data privacy:
- Consent: Organizations should obtain individual consent before collecting, using, or sharing personal information. Consent should be obtained through clear and...