- While the legislation landscape is constantly changing, organizations are struggling to stay abreast of the new obligations and understand what the laws and regulations entail.
- Companies, especially for-profit companies, are driven by sales and revenues. Data is considered a commodity. There is a long way to go with respect to changing the mindset and culture of data protection.
- It is not uncommon that privacy programs are underfunded, de-prioritized, and understaffed due to the disconnection between business strategy and privacy program.
Our Advice
Critical Insight
The privacy legislation landscape is constantly changing in the U.S. and privacy protection will become more complicated before it is simplified. Your organization should implement an integrated and holistic privacy program to simplify and streamline the compliance effort.
Impact and Result
- Organizations need to employ a systematic approach in establishing and operationalizing risk-based and right-sized privacy programs.
- Building a strong foundation is key to success by focusing on fulfilling core obligations such as establishing a data inventory, performing DPIAs, responding to DSAR requests, etc.
- Privacy and data protection can’t stand alone. Engaging with your stakeholder and getting buy-in as early as you can. Privacy principles should be embedded into business processes.
Comply With 2023 US Privacy Laws
(Virginia, Colorado, Connecticut, and Utah)
Establish an integrated and holistic program to streamline your data protection compliance efforts.
Analyst Perspective
Be accountable, be proactive, be diligent.
The development and usage of information technologies have drastically increased the collection and processing of personal information by organizations. With the rise of the internet and digital devices, personal information such as names, addresses, contact, geolocation, and financial information is being collected and stored by various entities.
The increasing amount of personal data being collected has made privacy and data protection a significant concern for individuals. For organizations, the implications of a data breach can be severe, including damage to reputation, loss of customer trust, and legal and financial penalties.
Although there’s limited protection for consumer data nationally, some states are taking the matter into their own hands. The Virginia Consumer Data Protection Act came into effect on January 1, 2023. The Colorado Privacy Act and Connecticut Data Privacy Act will be effective on July 1, 2023. The Utah Consumer Privacy Act will come into effect on December 31, 2023.
Compliance with privacy laws and regulations is essential for protecting personal information and maintaining the trust of customers and stakeholders. Organizations that are subject to those privacy laws should take proactive perspectives to implement a holistic privacy framework and stay away from a fragmented, inconsistent, and ineffective approach. Collaborating with business stakeholders and embedding privacy by design into business processes are imperative to drive compliance initiatives and programs.
Alan Tang
Principal Research Director, Security & Privacy
Info-Tech Research Group
Executive Summary
Your Challenge
|
Common Obstacles
|
Info-Tech's Approach
|
Info-Tech Insight
The privacy legislation landscape is constantly changing in the US and privacy protection will become more complicated before it is simplified. Your organization should implement an integrated and holistic privacy program to simplify and streamline the compliance effort.
Current landscape and effective dates
As of Feb. 6, 2023, five US states have enacted comprehensive privacy laws. Aside from that, 11 US states are working on 26 active privacy Bills.[1] At the federal level, 51 active privacy-related Bills have been proposed and 18 of them are consumer privacy laws.[2] Eighty-nine percent of companies surveyed have increased their budgets to prepare to meet the obligations set forth by the new consumer privacy laws.[3] This research will mainly focus on the following four privacy laws.
Effective Dates of the Four Privacy Laws
Compliance Budget Increased in Complying With New US State Privacy Laws[3]
Forty-five percent of surveyed organizations increased their compliance budgets by 10%-20%, and nearly a quarter of respondents (24%) have increased them by 20% or more. Only 11% have not increased their compliance budgets.
[1] US State Privacy Legislation Tracker, IAPP, Feb. 3, 2023.
[2] US Federal Privacy Legislation Tracker, IAPP, December 2022.
[3] State of US Data Privacy Law Compliance Survey Report, Womble Bond Dickinson, Jun 22, 2022.
Info-Tech Insight
A privacy program is not a one-and-done effort. The effective date is the start date not the end date of your privacy program. Don’t ask for a budget to barely get yourself across the effective date. You need the resources to operationalize and maintain the processes.
Applicability and exemptions
The four US state privacy laws provide quite a range of exemptions from both entity and data levels in addition to the traditional threshold approach. In general, the privacy laws aim to exempt the entities who are subject to other existing privacy laws such as HIPAA, GLBA, or FCRA.
Although there are options for some exemptions, it is important to note that each organization needs to do an analysis on each of their business areas to determine if they can qualify for any of the exemptions.