National and Regional Framework Examples

Organizations handling and processing user data must comply with regional data privacy laws protecting data against inappropriate use.

5 slides · 4 min read · Domain 1

Slide 1

Businesses and government agencies throughout the Americas, and in many countries throughout the Asia-Pacific, have modified their web applications and other business processes to continue to do business in the European Union (EU) or across its e-borders. In some cases, these countries have modeled new information protection laws based on the General Data Protection Regulation (GDPR). In other cases, multinational businesses have made their sites GDPR-compliant because it is good business sense for them to do so. The following is a sampling of different national and regional frameworks and concepts regarding privacy and data protection.

The United States

The United States has many sector-specific privacy and data security laws, both at the federal and state levels. There is no official national privacy data protection law or authority that governs privacy protection. In fact, privacy in the United States is said be a sectorial concern. For example, the Federal Trade Commission (FTC) has jurisdiction over most commercial entities and, therefore, has the authority to issue and enforce privacy regulations in specific areas. In addition to the FTC, there are other industry-specific regulators, particularly those in the healthcare and financial services sectors, with authority to issue and enforce privacy regulations.

Privacy and E-discovery in U.S. Law

As the Fourth Amendment to the U.S.

the government, under any circumstances Constitution states, people are protected it deems fit, for example, at a request (but from unreasonable searches and seizures by not a subpoena or a court order) from the government. The Fourth Amendment, a law enforcement or national security however, is not a guarantee against all official. A question is raised as to how data searches and seizures but only those is controlled once an individual has left the deemed unreasonable under the law. organization retaining said data. Whether a particular type of search is The USA PATRIOT Act changed many longconsidered reasonable in the eyes of the held practices in e-discovery, search, and law is yet another example of the prudent seizure and information protection within man rule, and it balances two important the United States. This Act was signed into interests: the intrusion on an individual's law on October 26, 2001, shortly after the

Fourth Amendment rights and legitimate

September 11 terrorist attacks. The USA government interests such as public safety.

PATRIOT Act extended the government's powers of search and seizure by allowing

It is also important to

national security letters to be written and

recognize that this Fourth

served on any information owner, controller,

Amendment protection in

or custodian without the action of a court the United States restricts or the use of a subpoena or search warrant. what government can do in its This Act, along with laws pertaining to the detection, prevention, and disruption of efforts to obtain information;

money laundering activities, also prohibits it makes no restrictions an organization from disclosing to the

whatsoever on what private

data subjects that they have been served organizations can do with with a national security letter or other information that they own, such discovery motion. In many respects it transformed the dialogue about privacy by control, possess, or use.

shifting the balance toward greater security at the cost of personal privacy.

Private organizations can establish their own fair use policies that may define what data is owned by the organization, and what data (if any) is owned by the individual employee, customer, client, or other entity having a relationship with that organization. Private organizations are also free to voluntarily give a copy of that information to

In 2012, the U.S. government unveiled the Consumer Privacy Bill of Rights as part of a comprehensive blueprint to protect individual privacy rights and give users more control over how their information is handled by organizations that are collecting such information.

Asia-Pacific Economic Cooperation

The Asia-Pacific Economic Cooperation (APEC) has become the point of reference for the data protection and privacy regulations for the 21 countries that are APEC members throughout the Asia-Pacific region. The APEC countries have endorsed the APEC privacy framework, recognizing the importance of the development of effective privacy protections that avoid barriers to information flows and ensure continued trade and economic growth in the APEC region.

The APEC privacy framework promotes a flexible approach to information privacy protection across APEC member economies, while avoiding the creation of unnecessary barriers to information flows.

In 2017, APEC implemented its Cross Border Privacy Rules (CBPRs), which parallel those of GDPR.

Latin America

Argentina, Brazil, Chile, and Colombia all have various implementations of comprehensive data protection and privacy legislation, either already in force or under development.

Test this domain