The California Consumer Privacy Act (CCPA) offers wide protection for the personal information of California residents, including rights to be informed of business privacy practices, to access, to delete personal information, and to deny third parties’ use of personal information. Compliance violations are punishable by fines of up to $7,500 per record plus the potential for class-action litigation.
Organizations conducting business in California collecting personal information must:
- publish their privacy practices,
- disclose to consumers what personal information has been collected in the preceding 12 months,
- honor requests for deletion,
- and enable consumers to direct third parties not to use their personal information.
Spirion advances compliance with the CCPA by:
- precisely locating personal information wherever it resides across the enterprise
- providing data classification capabilities that offer complete protection for data at rest,
- including options for data encryption, deletion, or quarantine
- offering a management dashboard that provides insightful reports on the state of the business’s data protection program.
The GDPR regulates the collection and processing of EU personal data. Rights of EU data subjects include transparent data collection and processing practices, access to collected data, and correction and deletion of personal data. Transferring personal data outside of the EU is subject to multiple requirements. Violations of the regulation can result in fines of up to the greater of 4% of the offender’s gross revenue or €20M.
The GDPR requires organizations to
- accurately identify all personal data under their control,
- give data subjects access to their personal data,
- maintain data security,
- notify authorities of data breaches,
- police third-party processing of personal information,
- and keep timely and accurate records of data protection activities.
Spirion advances organizations’ compliance with GDPR by:
- identifying personal data wherever it resides across the enterprise
- assisting in the development of a comprehensive data inventory
- using Spirion’s data classification capability it promotes data-at-rest security,
- and provides a management dashboard that enables organizations to execute their data protection programs.
The Health Insurance Portability and Accountability Act (HIPAA) was enacted in 1996 to, in part, protect patients’ protected health information (PHI). A follow-up law, the Health Information Technology for Economic and Clinical Health Act (HITECH) was passed in 2009. The Act extends HIPAA requirements to business associates of healthcare providers. The Confidentiality of Medical Information Act (CMIA) is California’s extension of HIPAA to individually identifiable medical information held by employers. HIPAA penalties are assessed on four tiers, ranging from $100 to a maximum of $1.5 million per violation per year.
HIPAA/HITECH requires organizations to implement safeguards for electronic personal healthcare information (ePHI), including:
- access controls,
- risk management,
- along with reporting breaches of unsecured PHI.
Spirion provides security and privacy officials and their staffs with the ability to:
- rapidly develop precise, timely inventories of ePHI
- create inventories that assist in protecting patient confidentiality, policing and meeting the mandates of business associate agreements,
- conduct privacy impact assessments (PIAs),
- implement breach notification plans.
- using the data classification technology, transform paper policies into dynamic programs for executing technical safeguards.
The Payment Card Industry Data Security Standard (PCI-DSS) is the information security standard mandated by the payment card brands (Visa, Mastercard, etc.) for use by any entity that processes payment cards. Failure to protect payment card data can result in fines as high as $500,000 per incident as well as losing the ability to continue processing payments.
PCI-DSS compliance requires:
- the execution of 12 security controls,
- including protecting cardholder data,
- tracking and monitoring all access to network resources and cardholder data,
- and maintaining an information security policy.
Spirion provides security leaders and their staffs with:
- the ability to identify the location and map the flows of cardholder data,
- encrypt data at rest,
- establish an early-warning system for potential policy violations,
- and support the terms of agreements with payment processors and financial institutions.
ADDITIONAL COMPLIANCE CAPABILITIES
In addition to CCPA, GDPR, HIPAA/HITECH/CMIA, and PCI-DSS, the Spirion data discovery, classification, and protection capabilities also help organizations meet these compliance regulations.
- Gramm-Leach-Bliley Act (GLB Act or GLBA)
- Family Educational Rights and Privacy Act (FERPA)
- Defense Federal Acquisition Regulation Supplement 7012 (DFARS)
- New York State Department of Financial Services Part 500 (NYDFS)
- NAIC Insurance Data Security Model Law
- Privacy Act of 1974
- State Data Protection Laws