Data Privacy Laws
Lawful Basis for Processing
You must have a valid legal reason to collect and use personal data. Common lawful bases include:
• Consent
• Contractual necessity
• Legal obligation
• Legitimate interests
Data Subject Rights
You must enable individuals to exercise their rights under data protection laws, including:
• Right to access their data
• Right to rectification (correct inaccuracies)
• Right to redaction ("right to be forgotten")
• Right to restrict processing
• Right to data portability
• Right to object to data processing
• Rights related to automated decision-making and profiling
Transparency & Communication
• Provide clear privacy notices that explain how personal data is used.
• Ensure transparency in all communications with data subjects.
Data Minimization & Purpose Limitation
• Collect only the minimum data necessary.
• Use data only for the specific purposes stated at the time of collection.
Security Measures
• Implement appropriate technical and organizational measures to protect data, such as encryption and access controls.
• Conduct regular risk assessments and data protection impact assessments when needed.
The following materials contain additional information for end users to comply with data protection obligations:
1. CCPA: https://www.oag.ca.gov/privacy/ccp
2. CPRA: https://privacy.ca.gov/california-privacy-rights/rights-under-the-california-consumer-privacy-act/
3. GDPR: https://www.gdpreu.org/
4. CPPA: https://ised-isde.canada.ca/site/innovation-better-canada/en/consumer-privacy-protection-act
5. CPA: https://coag.gov/resources/colorado-privacy-act/
7. UCPA: http://dcp.utah.gov/ucpa/
8. CTDPA: https://portal.ct.gov/ag/sections/privacy/the-connecticut-data-privacy-act