Site icon Privacy Desk

Americas Implementation Programs

Click on the blocks available below to check out our privacy programs based on your requirements and jurisdiction

USA

Canada

Mexico

California

California Consumer Privacy Act (CCPA)

The California Consumer Privacy Act (CCPA), the first of comprehensive data-privacy legislation
in the US, was introduced in 2018 and has been enforced from January 1 2020, by the State of
California. The legislation seeks to establish the procedure for identifying, managing, securing,
tracking, producing and deleting consumer privacy information so as to protect the privacy
rights of the users. CCPA includes within its ambit the entities that do for-profit business in the territory of California involving the personal data of the Californian resident where the business meets one of the thresholds:

This legislation operates for the protection of person data entailing a broad interpretation, including items such as phone numbers, social security numbers, biometric information, and Internet Protocol (IP) addresses.

Rights of Consumers

CCPA seeks to provide a strong legal protective cover to consumers through their enumerated rights. Firstly, the consumers have the

Compliance Obligations

CCPA puts various obligations on the business entities to ensure protection of personal information from unrestrained transfers and processing.

Basis for Processing of Data under CCPA

Under CCPA, data maybe processed for either business purposes or commercial. The general rule is that consent of the consumer is not required for collecting or using their personal information. The exception is that consent of the consumer is required when the business entity intends to sell the personal information of the consumer to a third party. In case of minors who are consumers less than 16 years of age, the guardian of the individual must grant an affirmative authorization for the sale by way of opting-in.

Penalties

Corresponding to the obligations laid down under CCPA, there is a provision for the imposition of penalties for accountability and compliance under the regulation. The strictness of the penalties varies with the intent, frequency and severity of the non-compliance by the entity. CCPA mandates maximum civil penalties of $7,500 for intentional violations of the CCPA whereas maximum civil penalties of $2,500 can be ordered for unintentional violations of CCPA.

Enforcement Mechanism

Under CCPA, the Office of the Attorney General of California has been granted exclusive authorization to bring civil actions against entities not complying with the obligations laid under CCPA such as failure to maintain CCPA compliant privacy policy or address Consumer requests etc. Alternatively, consumers also have the private right to action to pursue a civil claim within the jurisdiction of a Court only when their unencrypted or un-redacted personal information is breached.

California Privacy Rights Act (CPRA)

The California Privacy Rights Act which shall be enforced on 1st of January 2023 gives the control of Data to the Data Subjects. These Rights those are conferred by the Act would play a major role in the data subject knowing the amount of data being processed, for the reason it is being processed and for the period they would be retaining it, as well as the extent to which it will be used. The key element to this is CPRA does not apply to Non-Profit Entities and other small businesses. CPRA also regulates 3rd parties who collect data from the entities that function in California. This act is also applicable on those entities that don’t function inside California but collect data of the citizens of California.

The CPRA applies to:-

Rights of Consumers

Compliance Obligations

Basis of processing data

Consent is the key factor under CPRA for processing of Data. CPRA establishes that consent should be undisputed and clear. The company should clearly mention the purpose of processing such data. Also the company needs to take special consent when it comes to processing special data.  In case a service provider engages another person to process the personal data for the service provider, the existence of such engagement shall be notified. For the fulfillment of legal compliance obligation or in matters of special concerns such data can be processed.

Penalties

Any business, service provider, contractor, or other person that violates this title shall be subject to an injunction and liable for a civil penalty of not more than two thousand five hundred dollars ($2,500) for each violation or seven thousand five hundred dollars ($7,500) for each intentional violation and each violation involving the personal information of minor consumers.


Connecticut

Connecticut Data Breach Law (CDBL)

The Connecticut Data Breach Law is set to be enforced on 1st of October, 2021. This law provides the same kind of protection of data and rights as that of the California Privacy Rights Act. This Law applies to Non-Profit Organization as well, thus giving wider jurisdiction to the law.

The Personal Information that have been included under the ambit of this Act are:-

Rights of Data Consumers

Compliance Obligations

Basis of Processing of Data

The basis of Processing Data is consent. The controller has to collect data from user only after an affirmative consent in written form. The controller shall not process any sensitive data without the consent of the user.  The processing of data between the processor and controller shall be governed by a contract. The data can be processed without consent for fulfillment of any legal obligation or in case there is a necessity to protect someone’s interest. However while processing such data; it needs to take care that there is no damage to be caused by the processing of such data to the interest of the consumer.

Enforcement Obligations

The law shall be enforced by the Attorney General of Connecticut. Civil Penalties shall be imposed for Unfair Trade Practices and Private Right of Action granted to Data Subjects.

Penalties

Any controller or processor shall be liable for a civil penalty of not more than $7500 for each violation.


Virginia

Virginia Consumer Data Protection Act (VCDPA)

The State of Virginia has enacted their Data Protection Law- Consumer Data Protection Act on the date of March 2, 2021.  The Act shall be enforced from 1st of January, 2023.  The legislation is on the framework of the General Data Protection Regulation (GDPR) and California Consumer Privacy Act of 2018 (CCPA). The law provides the individuals of the state with certain rights when their data is being collected. Such rights ensure a control over the processing of their data. 

The legislation applies to those entities that conducts business in Virginia or produces products or services that are targeted to Virginia residents, and those which:-

Rights of the Consumers

Compliance Obligations

Basis of processing of Data

The Basis of Processing Data is consent. The controller has to collect data from user only after an affirmative consent in written form. The controller shall not process any sensitive data without the consent of the user.

Penalties

This law gives special focus on data mapping the procedures that are being followed to sell or share the data and also exclusively provides the Right to opt-out to the data subject unlike the CPRA and CDBL. For any violation of this act, fines upto 7500$ for each violation can be imposed.


Colorado

Colorado Privacy Act (CPA)

The Colorado Privacy Act was passed on June 8, 2021 and will be enforced on July 1, 2023. The scope of the Colorado Privacy Act (CPA) is reminiscent of the CDPA and CCPA but includes a few notable differences.

The CPA applies to any controller that:

Rights of Consumers

Compliance Obligations

Basis for processing of data

The Basis of Processing Data is consent. The controller has to collect data from user only after an affirmative consent in written form. The controller shall not process any sensitive data without the consent of the user.  The data being processed by the processor for the controller shall be governed by a contract. The data processing can be allowed without consent for reasons of public interest in the areas of public health but solely to that extent. The data cannot be transferred to a third party without the consent of consumer. In case of a contractual obligation, such must be notified to the consumer.

Enforcement Obligations

The Attorney General and District Attorneys have the exclusive authority to enforce this Act. The party would be held liable for any of the breach that happens.


Utah

Utah Consumer Privacy Act

The Utah Consumer Privacy Act (“UCPA”) was introduced on February 17, 2022 ad was signed into law on March 24, 2022. The UCPA will take effect on December 31, 2023.

It applies to businesses with annual revenue of $25,000,000 or more that conduct business in Utah or produce products or services that target Utah residents and that:

The UCPA does not apply to:

Under the law personal information has been defined as “information that is linked or reasonably linked to an identified individual or an identifiable individual ” and consumer as “an individual who is a resident of Utah acting in an individual or household context and only applies to the personal data of consumers”.

The act however provides an exception for de-identified data, aggregated data and publicly available information. Entities subject to the UCPA are not required to re-identify de-identified or pseudonymous data to comply with the statute’s obligations.

Rights of Consumers

The act has extended rights to its consumers relating to their personal data which is to be processed by controllers and processors. These rights can be exercised by consumers upon their request as per the methods specified by the controller in the required privacy notice. These consumer rights include:

Compliance Obligations

UCPA requires the parties to enter into a contract establishing the details of the processing, along with the parties’ rights and obligations. Such a contract must set forth the instructions for processing, the nature and purpose of the processing, the type of data being processed and the duration of processing

For Controllers:

For Processors:

Enforcement

There is no right of private action under the act however, it does provide for a bifurcated enforcement scheme. This includes the Utah Department of Commerce Division which is required to investigate companies based on consumer complaints, and it then sends cases it deems legitimate to the Attorney General’s office. Subsequently, the Attorney-General must first provide the business with written notice 30 days before and an opportunity to cure within 30 days of receipt of the notice before taking any action.

Penalties

The UCPA allows penalties to include the cost of actual damages and statutory penalties of up to $7,500 per violation of the statute


Oklahoma

Oklahoma Computer Data Privacy Act of 2022

The Oklahoma Computer Data Privacy Act of 2022 (“Bill”) would apply to for-profit businesses that do business in the state, collect the personal information of Oklahoma residents,  determine the purposes for and means of the processing, and that satisfies one or more of the following thresholds:

Rights of Data Subjects

Compliance Obligations

Legal Basis for Processing

Any eligible business will be required to “only collect and/or share information with third parties that is reasonably necessary to provide a good or service to a consumer who has requested the same or is reasonably necessary for security purposes or fraud detection.”

It is also explicitly provided that the monetization of personal information shall never be considered reasonably necessary for any purpose.

Enforcement

The enforcement authority under the Bill is the Oklahoma Attorney General who is entitled to recover reasonable expenses, including reasonable attorney fees, court costs and investigatory costs, incurred in obtaining injunctive relief or civil penalties, or both, under this section. Amounts collected under this section shall be deposited in a dedicated account in the General Revenue Fund and shall be appropriated only for the purposes of the administration and enforcement of this act.

Penalties

Any person, business, or service provider that violates this act may be liable for a civil penalty of up to seven thousand five hundred dollars ($7,500) for each intentional violation and up to two thousand five hundred dollars ($2,500) for each unintentional violation.


Canada

Personal Information Protection and Electronic Documents Act (‘PIPEDA’)

The Act applies to private-sector organizations across Canada that collect, use or disclose personal information during commercial activity. The act doesn’t apply to:

Rights of Data Subjects

Compliance Obligations

Legal Basis for Processing

Enforcement

The Office of the Privacy Commissioner of Canada provides advice and information for individuals about protecting personal information. We also enforce two federal privacy laws that set the rules for how federal government institutions and certain businesses must handle personal information. The privacy commissioner has the authority to audit, and publish information about personal information-handling practices in the public and private sector, conduct research into privacy issues and promote awareness and understanding of privacy issues from the public.

Penalties

Up to $10,000 (summary conviction) or $100,000 (indictable offense) when an individual obstructs the investigation of a complaint or an audit or fails to comply with breach notification provisions


Alberta

Personal Information Protection Act (PIPA Alberta)

The act protects personal information that is collected, used or disclosed by private-sector organizations in the province. Balances the rights of individuals and the needs of organizations to collect, use and disclose personal information for reasonable purposes. It applies to any organization that collects, uses or discloses personal information. It doesn’t apply to Health Information, which comes under the purview of (the Health Information Act) and personal information to which the Freedom of Information and Protection of Privacy Act (Alberta) applies. It also doesn’t apply to a public body or any personal information that is in the custody of or under the control of a public body.

Rights of Data Subjects

Compliance Obligations

Legal Basis for Processing

Enforcement

Alberta’s Information and Privacy Commissioner is an independent officer of the Legislature who works independently of the government to protect the information access and privacy rights of all Albertans. The OIPC is the regulator responsible for ensuring compliance with the Freedom of Information and Protection of Privacy (FOIP) Act, Health Information Act and Personal Information and Protection of Privacy Act.

Penalties

Up to $10,000 for individuals and up to $100,000 for persons other than individuals if the authority determines the offense


British Colombia

Personal Information Protection Act (PIPA BC)

The purpose of this Act is to govern the collection, use and disclosure of personal information by organizations in a manner that recognizes both the right of individuals to protect their personal information and the need of organizations to collect, use or disclose personal information for purposes that a reasonable person would consider appropriate in the circumstances. It applies to any organization that collects, uses, or discloses personal information except the information to which PIPEDA applies and personal information to which the Freedom of Information and Protection of Privacy Act (BC) applies to.

Rights of Data Subjects

Compliance Obligations

Legal Basis for Processing

Enforcement

The Information and Privacy Commissioner is independent of government and promotes and protects the information and privacy rights of British Columbians. The Commissioner shall investigate, mediate and resolve appeals concerning access to information disputes, including issuing binding orders; investigate and resolve privacy complaints and educate and inform the public about their access and privacy rights and the relevant laws.

Penalties

Liability up to $10,000 for individuals and up to $100,000 for persons other than individuals if the authority determines offence.


Quebec

Protection of Personal Information in the Private Sector (Quebec Privacy Act)

The purpose of this Act is to establish, for the exercise of the rights concerning the protection of personal information, particular rules with respect to personal information relating to other persons which a person collects, holds, uses or communicates to third persons in the course of carrying on an enterprise. The Act applies to such information whatever the nature of its medium and whatever the form in which it is accessible, whether written, graphic, taped, filmed, computerized, or other. This Act does not apply to journalistic, historical or genealogical material collected, held, used or communicated for the legitimate information of the public.

Rights of Data Subjects

Compliance Obligations

Legal Basis for Processing

Enforcement

Chapter IV of the Access Act establishes the Commission d’accès à l’information (CAI), which has two sections, namely the monitoring section and the jurisdictional section. It sets out the various functions of the CAI and the powers attributed to it in order to allow them to be exercised, in addition to establishing the rules relating to its constitution and organization. Several articles contained in this chapter have been modified, in particular those related to the constitution and organization of the CAI, as well as the functions and powers of its two sections.

Penalties


Mexico

Ley Federal de Protección de Datos Personales en Posesión de los Particulares

The Federal Law on the Protection of Personal Data held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares) entered into force on July 6, 2010. The law is applicable to the parties regulated under this law are private parties, whether individuals or private legal entities, that process personal data, with the exception of:

Rights of Data Subjects

Compliance Obligations

Legal Basis for Processing

Under the Mexico data protection law, there is a general principle that prohibits the processing of personal data without the consent of the data subject. However, the requirement for consent does not apply if the personal data is being processed for:

Enforcement

Información y Protección de Datos Personales) (INAI) and the Ministry of Economy (Secretaría de Economía) serve as Mexico’s data protection authorities. The National Institute for Transparency, Access to Information and Personal Data Protection (INAI) is an autonomous constitutional body responsible for upholding the right to access to public information held by any authority, entity, body or agency belonging to the executive, legislative and judicial branches, as well as by any individual, moral person or labour union that receives and spends public money or performs acts of authority at the federal level. The INAI is also in charge of upholding the right to protection of personal data held by the public and the private sectors.

Penalties

Fines range from 100 to 320,000 days of the current Mexico City minimum wage.


Our Services

We offer the following services to our clients as a part of our Implementation Programs:

Benefits of the America Compliance Program

As part of our USA compliance program, we help you to:

Get in touch with us

← Back

Thank you for your response. ✨

Thank you for submitting your request ! We will get in touch with you shortly.


Exit mobile version