RSI Security

Webinar Recap: How To Prepare Your Business for the Future of Data Privacy

risk

RSI Security recently partnered with Trustifi to discuss some significant considerations for the future of data privacy and security. Panelists discussed companies’ pain points concerning various, overlapping compliance frameworks and how RSI Security and Trustifi can help address them. Read on for a comprehensive recap of the data privacy webinar.

 

Webinar Recap: How To Prepare for the Future of Data Privacy

At the beginning of the webinar, Security Associate Nicole Fredrich noted an animating point from a recent poll. Of all participants asked about whether their company is ready for the future of data privacy, only 47% indicated they felt they were “over halfway prepared.” So, if the majority feels less than halfway prepared, what are some of the big reasons?

One major obstacle is data mapping—or identifying relevant data that needs protecting. Another is meeting data protection requirements, which differ by country. Then, there is the data privacy landscape here in the US, which differs by state. Other significant considerations involve trends impacting data privacy at present, such as a shift in cybercrime toward medical data rather than credit cards. The last important point of discussion involved enforcement. Companies that fail to comply with data regulations may incur penalties, which differ by framework and severity.

 

The Biggest Obstacle to Data Privacy: Mapping Sensitive Data

Peter Phaneuf, Senior Security and Privacy Advisor at RSI Security, established that the biggest obstacle to data privacy and security is mapping. Successful mapping requires identifying several critical factors:

Peter then noted that the other major factor impacting data protection for most companies is adjusting to regulatory policies that stipulate how data is supposed to be protected. Nicole then asked about how data protection officers can help address policies, leading to the next point.

 

Data Protection Policies, and How Data Protection Officers Help

RSI Security’s Director of Information Security and Compliance, Mohan Shamachar, led the following section with an overview of data protection policies that companies must be aware of when business activities involve other countries’ citizens’ data. He began by outlining some notable differences between regulations for data protection officers (DPO) across countries.

The European Union (EU) General Data Protection Regulation (GDPR) explicitly requires a DPO for companies processing EU member states’ citizens’ data. However, companies operating in or processing data from countries not covered by the GDPR may still require DPOs, or similar officials, for other legal adherences.

Beyond these distinctions, Mohan also covered some critical differences in the severity of data processing laws, and the reasons behind them, by country.

 

Request a Free Consultation

 

Differences and Similarities in DPO Requirements, By Country

Major differences exist in the scope of DPO requirements and stakeholder notification. Mohan categorized these in a visual aid as Scope and Registration / Notification:

Aside from these differences, the required tasks and training were identical for all countries detailed by Mohan. Namely, DPOs require knowledge of all applicable laws and practices, as their responsibilities include

 

Strictness and Focus of Data Privacy Laws by Country

Shifting focus, Nicole posed a question about which companies have the strictest data privacy laws. Mohan noted that it depends on what kind of data a company needs to protect. There are major differences between the priorities of the GDPR, similar regulations in the UK, and the laws applicable to companies working with data that belongs to Californians—from in the US or not.

Mohan explained that all the applicable regulations in these places define sensitive data in their own ways, leading to differences in how (and why) data must be protected. Consider:

At this point, Trustifi CEO Rom Hendler stepped in to note that the GDPR is considered the gold standard for general data privacy at present. This is similar to how, for a long time, the Payment Card Industry (PCI) Data Security Standard (DSS) has been the standard for credit card data.

 

Another Obstacle: Data Protection Requirements in the US

Next up, Nicole asked Peter to talk about privacy rights and business obligations within the US, or trends related to them, all of which are loosely based on the EU GDPR rules. Peter began by looking into acts already signed into law in two US states: California and Virginia.

In California, the pertinent acts are the California Consumer Privacy Act of 2018 (CCPA), which went into effect in 2020, and the California Privacy Rights Act of 2020 (CPRA), effective in 2023. Virginia signed into law one pertinent act, the Consumer Data Protection Act (CDPA), earlier in 2021, which also takes effect in 2023.

Then, Peter provided an overview of other bills currently in the works across several other US states, along with a proposed federal bill. He noted that many companies have trouble keeping up with and acclimating to the rapidly changing landscape all across the country.

 

Consumer Data Protection Rights in California and Virginia

Peter’s breakdown of rights guaranteed by the two states’ current and future laws included:

Note that, until the CPRA, Virginia’s CDPA offered more rights. But moving forward, California covers all data privacy rights of the CDPA, plus the additional consumer right to data restriction.

The other right guaranteed in California but not Virginia pertains to security, not privacy proper: the private right of action. This allows consumers to bring private legal suits against businesses that fail to protect their personal information adequately, including violating other rights above.

 

Data Privacy Business Obligations in California and Virginia

Peter’s breakdown of business obligations in the current and future laws included:

The only significant difference between the two states’ requirements is the opt-in requirement age: 16 for California (as of the CCPA) and 13 for Virginia. Beyond that one exception, California’s data privacy requirement laws had been more lenient than Virginia’s until the CPRA made them near-identical. Both are similar, now, to the EU GDPR.

 

New Data Privacy Laws in the Works Across Other US States

Per Peter’s overview of other data privacy laws being considered across various US states: 

At the time of the webinar, numerous dead bills had already failed to pass their state legislatures, including:

 

New Comprehensive Federal Data Privacy Law Being Considered

Finally, Peter noted that there are also federal privacy bills bubbling up at present, such as the Consumer Data Privacy and Security Act, proposed by Senator Moran (Kansas) in 2021, which would:

Peter noted that, if passed, the legislation’s strictness is likely subject to current political parties’ philosophies and ongoing debate, but that it may meet or exceed CA’s and VA’s existing laws. Regardless, Peter reaffirmed that all businesses must prepare for strict regulations soon.

 

Software Solutions to Trending Challenges in Data Protection 

Moving forward, Nicole posed a question about how these new developments impact Trustifi’s solutions and clients. Zack Schwartz, Vice President of Business Development at Trustifi, noted that the primary goal of all Trustifi tools and services is to find a happy medium between locking down users’ data and giving users the ability to use their data as needed. Encryption is the key (no pun intended) to striking this balance, per Zack. His answer led Nicole into querying all panelists about what cross-industry trends they see on the horizon.

Peter noted that cybercriminals used to target credit cards; now, they are stealing health data.

(At a later point in the conversation, Zac circled back to note that the main reason for hackers targeting healthcare data is that they have found they can use it for insurance fraud schemes.)

Rom then explained that COVID has had a significant impact on this shift, increasing the volume and variety of health data. Unfortunately, it’s easier than ever to use this data for illegitimate financial ends, and there is more of it available for exploitation than ever.

 

How Exactly Trustify Helps Ensure and Optimize Data Privacy

Moving into a more pointed discussion of how Trustifi addresses these trends, Rom highlighted the applicability of Trustifi across various industries. For example, a recent case involved a client dealing with issues related to online gaming and location-based restrictions on a reservation.

One of the primary solutions for this client (and others) is the innovative “one-click compliance” solution Trusifi has developed. The primary technology behind it is outbound encryption, which allows the end-user ultimate control over the extent to which their data is shared or kept private. 

Rom noted that Trustify is designed to maximize security without compromising productivity. He used a metaphor of adding locks to a house—doing so makes it more difficult for any unwanted intruders to enter, but it also makes it harder for you to enter and exit your own home, which is far from ideal. This is precisely the kind of compromise the team at Trustifi is trying to avoid. 

Circling back later, Zack explained how one-click compliance helps users prevent data leakage through outbound email, which he identified as the primary cause of data privacy violations.

 

Final Major Obstacle: Penalties for Non-compliance

The last segment began with a quick overview of general stakes companies should consider with respect to non-compliance, along with principles to help them mitigate various risks:

Then, presenters offered individual analyses of specific consequences and considerations for individual data privacy frameworks—namely, GDPR penalties and HIPAA penalties in the US.

 

Variations in Applicable GDPR Fines Based on Severity

Peter began this segment with further analysis of applicable GDPR fines. He noted that the penalties depend on the severity of an infraction. A less severe incident could incur fines of up to 10 million euros or 2 percent of a company’s worldwide revenue—whichever is higher. Top cases from countries highlighted in an infographic Peter shared included the following:

Multiple panelists agreed that EU Member States are using these enforcements as a revenue generator—almost as a tax. In practice, this means that states are motivated to seek out and enforce non-compliance penalties occurring within their borders or impacting their citizens. In addition, Zack noted that these fines are assessed pre-breach—unlike fines for HIPAA.

 

Multiple Factors Impacting HIPAA Non-Compliance Fines 

Moran then quickly turned his attention to HIPAA, the Health Insurance Portability and Accountability Act of 1996. HIPAA still applies within the US to companies processing patients’ medical and billing information, whether or not the companies are healthcare providers.

Moran identified some of the primary factors that determine HIPAA non-compliance penalties:

Moran noted that the Office for Civil Rights (OCR) assesses a wide range of penalties. For example, a company may be on the hook for just $100 or up to millions of dollars per infraction.

 

Final Questions and Remarks on Data Privacy and Security

Closing out the webinar, one final question from the crowd was addressed. All panelists were asked whether CCPA and CPRA restrictions apply to a company operating out of Arizona with client data from California. Multiple panelists agreed that it does, as CCPA applicability depends upon the data subjects’ location, not the company processing the data. The same goes for GDPR applicability. Nicole then opened the floor for the panelists’ closing thoughts. All agreed that data privacy regulations are here to stay—and won’t loosen any time soon.

At present, unless your company plans on avoiding all data from residents of California, it needs to be CCPA compliant. If EU citizens’ data is in your sights, you need to comply with the GDPR.

In the future, there will likely be more data privacy regulatory frameworks you need to follow.

 

RSI Security’s Advisory and Education

RSI Security is here to help all companies navigate compliance and other concerns about personal data privacy and security. In addition to our advisory services, you can find past and future webinars providing education across numerous cybersecurity and compliance topics on our Events page.

To build out your program, contact RSI Security today!

 

 

Exit mobile version