Building a Privacy Compliance Program: Governance Data Mapping and the Legal Patchwork
36 questions
36 questions on building a privacy compliance program, answered and cited by the UpLaw editorial team.
- Can the FTC bring an enforcement action over weak cybersecurity?
- Does a small company need a privacy compliance program?
- Does the GDPR apply to a company with no European offices?
- How can a company lawfully transfer personal data from the EU to the United States?
- How does a company prove its privacy program actually works?
- How does the FTC regulate privacy without a privacy statute?
- How long does a company have to respond to a data-rights request?
- How many states have comprehensive privacy laws, and how do they differ?
- How should a company handle conflicting state privacy laws?
- How should a company handle consumer data-rights requests?
- How should a privacy compliance roadmap be prioritized?
- Is there a comprehensive federal privacy law in the United States?
- Should privacy be run by a chief privacy officer or a committee?
- What are the Fair Information Practice Principles?
- What are the GDPR's core principles?
- What are the penalties under the CCPA, and can consumers sue directly?
- What contracts are required with vendors that handle personal data?
- What extra exposure does a facial-recognition feature create?
- What is a data protection impact assessment, and when is one required?
- What is a record of processing activities?
- What is data mapping, and why does it come before everything else?
- What is the difference between a privacy policy and a privacy compliance program?
- What is the NIST Privacy Framework, and why use it?
- What must a privacy notice contain, and how many does a company need?
- What pressures push a company to build a privacy program?
- What questions must a data inventory answer?
- What rights does the CCPA give California consumers?
- What sector-specific privacy laws might apply to a business?
- What should a data breach response plan include?
- When is a Data Protection Officer legally required?
- Where should a company start building a privacy program?
- Which businesses are covered by the CCPA?
- Which departments does a privacy program need to work with?
- Who should be accountable for privacy inside a company?
- Why do data retention schedules matter for privacy compliance?
- Why does privacy training matter if the policies are well drafted?