Data & Legal: What are the data regulations around the world?
# 1. General Data Protection Regulation (GDPR)
GDPR is a European regulation that aims to protect the personal data of individuals within the European Union (EU). Adopted in 2016 and implemented in May 2018, GDPR establishes a legal framework for the processing of personal data, by imposing strict obligations on companies that collect, process and store such data. The main provisions of GDPR include the explicit consent of individuals for the processing of their data, the right to erasure of data ("right to be forgotten"), and severe penalties in case of non-compliance with the rules.
2. California Consumer Privacy Act (CCPA)
The CCPA is a Californian law that aims to protect the personal data of consumers in California. Entered into application in January 2020, this law grants California consumers certain rights regarding their personal data, such as the right to access their data, the right to delete it, and the right to prohibit its sale to third parties. The CCPA applies to companies that conduct business in California and that meet certain size or revenue criteria.
3. Personal Data Protection Act (LGPD)
The LGPD is a Brazilian law that regulates the collection, processing and storage of personal data in Brazil. Implemented in September 2020, this law is largely inspired by the European GDPR and aims to strengthen the protection of individuals' data in Brazil. The LGPD requires Brazilian companies to comply with fundamental principles regarding data processing, such as transparency, purpose, data minimization and security.
4. New Data Protection Act (nLPD)
Switzerland is adopting new legislation to better protect personal data. Companies in the country must comply with it from September 1, 2023. Companies that had already complied with the EU General Data Protection Regulation (GDPR) will have few changes to undertake.
5. Other Data Protection Laws in the United States
- The CPRA (California Privacy Rights Act) strengthens the CCPA by adding the right to limit the use of personal data, the right to rectification, the right of access and the right to opt-out. The CPRA created a new regulatory body, the CPPA (California Privacy Protection Agency), responsible for enforcing the data protection rights of California residents.
- The VCDPA (Virginia Consumer Data Privacy Act) came into effect on January 1, 2023. This law applies to public and private organizations that control and process specific volumes of personal data.
- The CPA (Colorado Privacy Act) will take effect on July 1, 2023, providing Colorado residents with the option to refuse the processing of their personal data for targeted advertising or sale purposes.
- The CDPA (Connecticut Data Privacy Act) will be effective starting July 1, 2023. It gives Connecticut consumers options regarding the collection of their personal data by businesses operating in the state.
- The UCPA (Utah Consumer Privacy Act) will come into effect on December 31, 2023. This law adopts a more business-friendly approach, applying only to businesses with annual revenue of at least $25 million and imposing less stringent requirements, such as no obligation for data protection assessments for certain types of processing.
- Last year, legislators in nearly 30 other states examined legislative proposals offering various levels of consumer privacy protection. Some of these bills could be reintroduced during the 2023 legislative sessions, in addition to new bills in preparation.
6. Other data protection laws around the world
- PIPEDA (Personal Information Protection and Electronic Documents Act) is the Canadian federal privacy law that regulates how private sector organizations collect, use, and disclose personal information in the course of commercial activities.
- Bill C-27 (Digital Charter Implementation Act) was introduced by the Canadian federal government in June 2022. It includes three proposed laws: the CPPA (Consumer Privacy Protection Act), the PIDPTA (Personal Information and Data Protection Tribunal Act), and the AIDA (Artificial Intelligence and Data Act), covering consumer privacy, data protection, and AI systems.
- The PIPL (Personal Information Protection Law) is China's first comprehensive law aimed at regulating online data and protecting the personal information of Chinese consumers. Enacted in November 2021, the PIPL requires consent as the primary basis for data collection and processing, restricts cross-border data transfers, and imposes severe revenue-based fines for non-compliance.
- The POPIA (Protection of Personal Information Act) is South Africa's data protection law, aimed at protecting the personally identifiable information (PII) of South African citizens.
Conclusion
Data protection has become a major concern for businesses worldwide, due to the growing importance of personal data in the digital economy. Data regulations aim to protect the privacy and rights of individuals by regulating the collection, processing, and protection of personal data. It is essential for businesses to comply with these regulations to avoid penalties and risks related to violations of individuals' privacy.