- Philippines – Data Privacy Act of 2012
- Singapore – Personal Data Protection Act 2012 (PDPA)
- Europe – General Data Protection Regulation (GDPR)
- UK – Data Protection Act
- US – HIPAA
- India – Personal Data Protection Bill 2019 (not a law yet)
- Accept and Store the information only which is mandatorily required for completion of the respective business operations. Avoid taking unnecessary additional personal information.
- Ensure that the data privacy system’s architecture and implementation are finalized after engaging Subject Matter Experts to identify the best approach for respective organizations. Approach for every organization may vary based on the number of records, the extent of exposure, the likelihood of attacks, etc.
- Ensure Consumer consent is acquired prior to the storage of any personal or sensitive information.
- Ensure procedures are in place to remove all the data of any consumer who choose their “Right to Forget”
- Ensure that site has a section that describes the control posture utilized and regulations adhered to protect personal data as a consumer assurance.
- Run a company-wide data discovery scan to identify known and unknown locations where sensitive/personal data is stored.
- Ensure encryption controls are present for transmission and storage of sensitive or personal information with strong key management methods.
- Security best-practices like role-based access control, two-factor authentication to access production systems, IDS/IPS monitoring, system hardening & updating latest patches, removing obsolete system components, etc. should be followed.
- Conduct annual third-party assessments/audits with SME audit companies like ControlCase, to validate the data privacy and security posture of the organization against the applicable data privacy regulations, to confirm its adherence.
- In case of gaps or vulnerabilities take assistance from the SME’s to come up with a Corrective Action Plan.
- Bad Press & Loss of Reputation to the Organization
- Litigations
- Heavy Sanctions ranging to approximately millions of dollars.
