April 2023

Data Privacy Frontline Report

April 2023

Here are key highlights from April 2023 detailing global news and regulatory updates.

US & Canada

  • Canada’s Bill C-27, the Digital Charter Implementation Act, passes second reading and is referred to a standing committee before going to third reading in the House of Commons
  • Indiana becomes seventh US state to pass a comprehensive privacy law, one that closely tracks the laws in Connecticut and Virginia
  • Montana and Tennessee comprehensive privacy bills clear legislatures on the same day, joining Indiana and Iowa among states to pass such bills this year. See also this article for more details on Montana’s law
  • Nevada Senate passes Bill 370, a health data privacy bill that would bar healthcare companies from collecting or sharing patient health information without consumer consent
  • Texas proposes a strong data privacy law that includes definitions of both de-identified and pseudonymous data
  • US state privacy laws and whether they fill the void in US privacy law with respect to the protection of health information
  • US health industry responds to privacy crackdown by cutting back significantly on targeted Facebook and Google ads
  • US BBB National Programs to turn the Consumer Privacy Framework for Health Data into an accountability program for companies collecting and using non-HIPAA-covered consumer health data
  • US FTC Chair and other departments release a joint statement on AI, pledging to uphold America’s commitment to the core principles of fairness, equality, and justice
  • Washington state’s My Health My Data Act receives final approval in the House, establishing consumer rights, consent requirements for data practices concerning personal health care information, and a private right of action

EMEA

  • EU and Japan complete the first review of their mutual adequacy agreement, demonstrating that the convergence between their frameworks has increased since 2019 (also in APAC)
  • Finnish district court gives 3-month suspended jail sentence to therapy center ex-CEO for not pseudonymizing and encrypting patient data
  • Tanzania’s Personal Information Protection Act—signed into law on November 27, 2022—is examined in detail
  • UK data protection reforms and their impact in comparison to the GDPR

APAC

  • Australian telecommunication giant Optus hit with class action over cybersecurity breach for failing to adequately protect customer data and destroy or de-identify the data of former customers
  • China’s standard contractual clauses translated
  • Japan and the EU complete the first review of their mutual adequacy agreement, demonstrating that the convergence between their frameworks has increased since 2019 (also in EMEA)
  • Vietnam’s government published a Decree on Protection of Personal Data, effective July 1, which implements principles around data collection, processing and storage

LATAM

  • Brazil’s data protection authority releases guidance on proper procedures for data protection impact assessments (DPIA)

Archiving / Destroying

Are you unleashing the full value of data you retain?

Your Challenges

Do you need help...

OUR SOLUTION

Value Retention

Client Success

Client: Comcast

Situation: California’s Consumer Privacy Act inspired Comcast to evolve the way in which they protect the privacy of customers who consent to share personal information with them.

Evaluating

Are you achieving intended outcomes from data?

Your Challenge

Do you need help...

OUR SOLUTION

Unbiased Results

Client Success

Client: Integrate.ai

Situation: Integrate.ai’s AI-powered tech helps clients improve their online experience by sharing signals about website visitor intent. They wanted to ensure privacy remained fully protected within the machine learning / AI context that produces these signals.

Accessing

Do the right people have the right data?

Your Challenges

Do you need help...

OUR SOLUTION

Usable and Reusable Data

Client Success

Client: Novartis

Situation: Novartis’ digital transformation in drug R&D drives their need to maximize value from vast stores of clinical study data for critical internal research enabled by their data42 platform.

 

Maintaining

Are you empowering people to safely leverage trusted data?

Your Challenges

Do you need help...

OUR SOLUTION

Security / compliance efficiency

CLIENT SUCCESS

Client: ASCO’s CancerLinQ

Situation: CancerLinQ™, a subsidiary of American Society of Clinical Oncology, is a rapid learning healthcare system that helps oncologists aggregate and analyze data on cancer patients to improve care. To achieve this goal, they must de-identify patient data provided by subscribing practices across the U.S.

 

Acquiring / Collecting

Are you acquiring the right data? Do you have appropriate consent?

Your Challenge

Do you need help...

OUR SOLUTIONS

Consent / Contracting strategy

Client Success

Client: IQVIA

Situation: Needed to ensure the primary market research process was fully compliant with internal policies and regulations such as GDPR. 

 

Planning

Are You Effectively Planning for Success?

Your Challenges

Do you need help...

OUR SOLUTION

Build privacy in by design

Client Success

Client: Nuance

Situation: Needed to enable AI-driven product innovation with a defensible governance program for the safe and responsible use
of voice-to-text data under Shrems II.

 

Join the next 5 Safes Data Privacy webinar

This course runs on the 2nd Wednesday of every month, at 11 a.m. ET (45 mins). Click the button to register and select the date that works best for you.