Published: 02 August 2023
Summary
The North American regulatory landscape for privacy continues to fracture by state and province, and is fragmenting further by sector and data type. This research tracks the impact of this storm and provides recommendations to help security and risk management leaders insulate their data strategy.
Included in Full Research
Overview
Impacts
Federal privacy laws are either absent or outdated as neither U.S. or Canadian legislatures have pushed through new countrywide mandates. This has resulted in an increasingly fragmented regulatory landscape with a patchwork of potentially conflicting laws.
Passed and proposed laws focus almost exclusively on consumer privacy rights, with many aspects of comprehensive privacy legislation missing.
Recommendations
Security and risk management leaders with privacy responsibilities should:
Address inconsistencies by consolidating the key requirements and adopting a structured privacy program to provide a unified approach to personal data handling.
Focus privacy programs by starting with a scalable approach to individual privacy rights, then expanding
To view the entire document, log
in or purchase