Data Privacy Laws | Cybersecurity Insights #12

preview_player
Показать описание

The most well-known is the EU’s General Data Protection Regulation (GDPR). Under GDPR, an organization must demonstrate that security safeguards are active, up-to-date, and working effectively. Or risk substantial fines.

GDPR has set the standard for other regulations around the world, but Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) comes pretty close. Most notable with PIPEDA is the need to prove your security posture was airtight when the incident happened, not just whether data was stolen.

What about data privacy laws in the US? Well, we find laws such as HIPAA (for health information) and S-P and S-ID statutes for financial records, enforced by the SEC. There is also the California Consumer Privacy Act (CCPA). But no national privacy standard. Yet.

Data Privacy is today's greatest challenge for IT and security teams, and with 35% of sensitive data out-of-sight on endpoints, there has never been a stronger need for persistent endpoint visibility and control.

----

----

Watch more episodes of the Cybersecurity Insights series:
Рекомендации по теме
Комментарии
Автор

Thanks for the video ! Brief and informative. I like that :)

sarahb.
Автор

Great insights into data privacy laws! It's clear GDPR has set a high bar globally. How do you see emerging technologies like AI impacting compliance efforts under these regulations?

JossOrtan
Автор

Interesting that you led with GDPR which is an EU regulation. Most US businesses would need even meet the threshold for GDPR.

techlaw
Автор

I'm a software developer. My job sometimes requires me to handle sensitive client data, although it is avoided as far as possible. As such I keep this information properly encrypted at all times. In the event of a data breach, can a client's auditor force me to give up the decryption keys? I sign nondisclosure agreements with clients, but is the auditor required to sign a similar agreement with me? Client A has no business accessing the data on my machine of Client B, nor the fact my employer is doing business with Client B in the first place. I'm fortunate enough that a data breach has not occurred but I'm not sure how to navigate this if it did. Also if I have personal data on my machine, can I refuse the auditor's access to this without incriminating myself?

pieterrossouw
Автор

Thank you, I needed to watch that video. I am a victim in Las Vegas Nevada of what I believe to be the biggest civil y

solomonzepeda