Data Protection
79 items tagged with "data-protection"
Standards12
ISO/IEC 9075:2003 (SQL:2003)
Adhering to ISO/IEC standards during software migrations is essential for ensuring quality, security, and compliance. By following best practices outlined in these standards, teams can mitigate risks, improve stakeholder confidence, and enhance the overall success of their migration projects.
ISO/IEC 27018:2019 (Cloud PII)
Adhering to ISO/IEC standards during software migrations is essential for ensuring compliance, mitigating risks, and enhancing system quality. This comprehensive guide outlines the key requirements, practical steps, and tools necessary for teams to navigate the complexities of migration projects successfully, ensuring a smooth transition while maintaining compliance with industry standards.
NIST SP 800-171 Rev 3
Adhering to NIST standards during software migrations is crucial for maintaining data integrity, enhancing security, and ensuring compliance with regulations. This guide outlines the key requirements, compliance considerations, and practical strategies for effectively managing migration projects while aligning with NIST frameworks.
UK GDPR 2021
Adhering to compliance standards during software migrations is crucial for protecting sensitive data, maintaining stakeholder confidence, and ensuring seamless transitions. This guide outlines the key requirements, practical steps for adherence, and tools to help teams navigate compliance challenges effectively.
CCPA (AB 375)
Understanding compliance standards is essential for successful software migrations. By adhering to legal and regulatory requirements, teams can protect sensitive data, uphold privacy rights, and ensure operational continuity. This guide outlines key requirements, practical strategies, and tools to help organizations navigate compliance challenges during their migration processes.
OCI Image Spec 1.1
Understanding and adhering to compliance standards is essential for successful software migrations. By implementing best practices, utilizing the right tools, and addressing common challenges, organizations can streamline their migration processes while ensuring security and transparency, ultimately building trust with stakeholders and mitigating risks.
PKCS #12 v1.1
This content details the RSA standard for software migrations, emphasizing the importance of compliance for data protection and operational continuity. It offers actionable guidance on ensuring adherence, tools to maintain compliance, and strategies to overcome common challenges during migration projects.
Erlang/OTP 26
Understanding and adhering to Ericsson's technical standards is essential for successful software migrations. These standards provide a framework for ensuring data protection, interoperability, and performance, thereby mitigating risks and enhancing efficiency. By following best practices and leveraging appropriate tools, teams can navigate the complexities of migration while maintaining compliance with industry standards.
ISO/IEC TR 24772-2:2023 (Safer Programming)
Adhering to ISO/IEC standards during software migrations is essential for ensuring quality, safety, and compliance. These standards provide critical guidance that helps mitigate risks, enhance operational efficiency, and build trust with stakeholders. By implementing best practices and utilizing the right tools, teams can navigate migration challenges with confidence.
Matter 1.3
Adhering to compliance standards during software migrations is crucial for mitigating risks, ensuring legal obligations are met, and maintaining stakeholder trust. This guide outlines the key requirements, practical steps for adherence, and tools to help teams navigate the complexities of compliance in migration projects.
ISO/IEC 7816-4:2020 (Smart Cards)
Adhering to ISO/IEC standards during software migrations is essential for risk mitigation, quality assurance, and stakeholder confidence. This guide outlines key requirements, compliance strategies, and practical tools to help teams navigate migration projects effectively while ensuring adherence to these important standards.
MITRE ATT&CK v14
Adhering to MITRE standards during software migrations enhances security, interoperability, and compliance. This comprehensive guide outlines key requirements, practical implementation strategies, and tools to navigate challenges effectively, ensuring a smooth transition from legacy systems to modern architectures.
Best Practices3
Privacy by Design 7 Principles
Framework embedding privacy into systems engineering from the outset.
SOC 2 Compliance
SOC 2 is an AICPA auditing framework that assesses how a service organization protects customer data against five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.
GDPR Compliance Engineering
GDPR compliance engineering turns the EU General Data Protection Regulation's legal principles into concrete technical controls: lawful processing, data minimization, consent, and data-subject rights.
Anti-Patterns2
Publicly Exposed Storage Buckets
Leaving cloud object storage open to anonymous read or write, a leading cause of large-scale data leaks from simple misconfiguration.
Logging Sensitive Data
Writing passwords, tokens, PII, or payment data into logs, where it spreads to aggregators and backups far beyond its intended access controls.
Reference Architectures1
Checklists1
Regulations54
General Data Protection Regulation
European Union regulation on data protection and privacy for individuals within the EU and EEA
Lei Geral de Proteção de Dados
Brazil's General Data Protection Law regulating personal data processing
United Kingdom General Data Protection Regulation
The UK's retained and amended version of the EU GDPR governing the processing of personal data of individuals in the United Kingdom.
Virginia Consumer Data Protection Act
Virginia's comprehensive consumer privacy law granting residents data rights and imposing controller and processor obligations.
Colorado Privacy Act
Colorado's comprehensive consumer privacy law granting data rights and requiring recognition of universal opt-out mechanisms.
Connecticut Data Privacy Act
Connecticut's comprehensive consumer privacy law granting data rights and requiring opt-out preference signal recognition.
Utah Consumer Privacy Act
Utah's comprehensive consumer privacy law granting limited data rights with a business-friendly, opt-out-based design.
Texas Data Privacy and Security Act
Texas's comprehensive consumer privacy law applying to most businesses regardless of revenue, with broad data rights and opt-out signals.
Lei Geral de Proteção de Dados Pessoais
Brazil's general data protection law governing the processing of personal data, modeled closely on the EU GDPR.
Personal Information Protection and Electronic Documents Act
Canada's federal private-sector privacy law governing the collection, use, and disclosure of personal information in commercial activity.
Quebec Act to Modernize Legislative Provisions Respecting the Protection of Personal Information
Quebec's privacy reform law (formerly Bill 64) overhauling personal information protection in the public and private sectors.
Protection of Personal Information Act
South Africa's data protection law regulating the processing of personal information by public and private bodies.
Personal Data Protection Act 2012 (Singapore)
Singapore's data protection law governing the collection, use, and disclosure of personal data by private-sector organizations.
Personal Data Protection Act B.E. 2562 (Thailand)
Thailand's comprehensive data protection law governing the collection, use, and disclosure of personal data, modeled on the GDPR.
Act on the Protection of Personal Information (Japan)
Japan's national data protection law governing how businesses handle personal information, overseen by the PPC.
Digital Personal Data Protection Act, 2023 (India)
India's first comprehensive data protection law governing the processing of digital personal data with consent at its core.
Privacy Act 1988 (Australia)
Australia's principal privacy law regulating handling of personal information through the Australian Privacy Principles.
Law on the Protection of Personal Data No. 6698 (Turkey)
Turkey's data protection law regulating the processing of personal data, modeled on the EU Data Protection Directive.
Federal Act on Data Protection (Switzerland)
Switzerland's revised federal data protection law modernizing privacy rules and aligning them more closely with the GDPR.
Personal Data Protection Law (Saudi Arabia)
Saudi Arabia's first comprehensive data protection law governing the processing of personal data, supervised by the SDAIA.
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE)
The United Arab Emirates' first federal data protection law governing the processing of personal data across the country.
Nigeria Data Protection Act 2023
Nigeria's comprehensive data protection law governing the processing of personal data and establishing a national data protection commission.
Data Protection Act 2019 (Kenya)
Kenya's comprehensive data protection law governing the processing of personal data and establishing the Office of the Data Protection Commissioner.
Privacy Act 2020 (New Zealand)
New Zealand's principal privacy law regulating the handling of personal information through 13 Information Privacy Principles.
Oregon Consumer Privacy Act
Oregon's comprehensive consumer privacy law granting residents rights over their personal data and imposing duties on businesses that process it.
Montana Consumer Data Privacy Act
Montana's comprehensive privacy law giving residents data rights and requiring controllers to honor opt-outs and protect sensitive data.
Iowa Consumer Data Protection Act
Iowa's consumer privacy law giving residents access, deletion, and opt-out rights with comparatively limited controller obligations.
Delaware Personal Data Privacy Act
Delaware's comprehensive privacy law granting residents broad data rights with low applicability thresholds and coverage of many nonprofits.
New Jersey Data Privacy Act
New Jersey's comprehensive privacy law giving residents data rights and requiring consent for sensitive data and certain processing of minors.
Tennessee Information Protection Act
Tennessee's comprehensive privacy law granting consumer data rights and offering an affirmative defense for documented privacy programs.
Indiana Consumer Data Protection Act
Indiana's comprehensive privacy law granting residents data rights, with one of the latest effective dates among state privacy statutes.
Florida Digital Bill of Rights
Florida's privacy law targeting large technology companies, with rights for consumers and rules on data sales, profiling, and children's data.
Nebraska Data Privacy Act
Nebraska's comprehensive privacy law modeled on Texas, applying to most businesses except small businesses regardless of data volume.
New Hampshire Privacy Act
New Hampshire's comprehensive privacy law granting residents data rights with low applicability thresholds and rulemaking by the Department of Justice.
Kentucky Consumer Data Protection Act
Kentucky's comprehensive privacy law modeled on Virginia, granting residents data rights and requiring consent for sensitive data.
Maryland Online Data Privacy Act
Maryland's strict privacy law imposing strong data minimization limits and broad protections, especially for sensitive data and minors.
Minnesota Consumer Data Privacy Act
Minnesota's comprehensive privacy law with novel rights including the right to question profiling decisions and to review a data inventory.
Rhode Island Data Transparency and Privacy Protection Act
Rhode Island's comprehensive privacy law granting consumer data rights with distinctive third-party disclosure transparency requirements.
Illinois Biometric Information Privacy Act
Illinois law regulating the collection and handling of biometric identifiers such as fingerprints and facial geometry, with a private right of action.
Personal Information Protection Act (South Korea)
South Korea's comprehensive data protection law, one of the strictest globally, governing the processing of personal information by public and private entities.
Argentina Personal Data Protection Act (Law 25.326)
Argentina's foundational data protection law, recognized as EU-adequate, governing processing of personal data and habeas data rights.
Federal Law on Protection of Personal Data Held by Private Parties (Mexico)
Mexico's federal privacy law governing how private-sector entities collect and process personal data, centered on the privacy notice and ARCO rights.
Colombia General Data Protection Law (Law 1581 of 2012)
Colombia's general data protection law governing the processing of personal data, requiring database registration and authorization from data subjects.
Chile Law 19.628 on the Protection of Private Life
Chile's data protection law on the processing of personal data, recently overhauled by Law 21.719 to align with modern GDPR-style standards.
Philippines Data Privacy Act of 2012 (Republic Act 10173)
The Philippines' comprehensive data privacy law protecting personal information in government and private systems, enforced by the National Privacy Commission.
Indonesia Personal Data Protection Law (Law No. 27 of 2022)
Indonesia's first comprehensive personal data protection law, modeled on the GDPR, governing data controllers and processors across all sectors.
Vietnam Personal Data Protection Decree (Decree 13/2023/ND-CP)
Vietnam's foundational personal data protection regulation establishing consent, data subject rights, and cross-border transfer impact assessments.
Malaysia Personal Data Protection Act 2010
Malaysia's data protection law regulating the processing of personal data in commercial transactions, recently amended to add breach notification and a DPO duty.
Israel Protection of Privacy Law, 5741-1981
Israel's foundational privacy law governing databases of personal information, recognized as EU-adequate and modernized by Amendment 13.
Egypt Personal Data Protection Law (Law No. 151 of 2020)
Egypt's first comprehensive data protection law governing electronic personal data, requiring licensing, consent, and a data protection officer.
Ghana Data Protection Act, 2012 (Act 843)
Ghana's data protection law regulating the processing of personal data and requiring registration of data controllers with the Data Protection Commission.
California Age-Appropriate Design Code Act
California law requiring online services likely accessed by children to prioritize their privacy and safety by design and default.
UK Age Appropriate Design Code (Children's Code)
UK statutory code requiring online services likely accessed by children to follow data protection standards that put children's best interests first.
FTC Safeguards Rule (Gramm-Leach-Bliley Act)
U.S. FTC rule requiring financial institutions to implement a documented information security program to protect customer data.
FAQs3
What is encryption at rest versus encryption in transit?
Encryption at rest protects stored data on disks, databases, and backups so that someone who obtains the physical media or storage volume cannot read ...
What is GDPR in a nutshell?
The General Data Protection Regulation (GDPR) is an EU law that governs how organizations collect, process, and store the personal data of people in t...
What is PII (personally identifiable information)?
PII is any data that can identify a specific individual, either on its own or when combined with other information. Direct identifiers include name, e...
Glossaries2
Encryption at Rest
Encryption at rest is the protection of stored data by encrypting it on disk or in a database, so that the data is unreadable without the correct decryption keys.
Encryption in Transit
Encryption in transit protects data as it travels across a network by encrypting the communication channel, preventing eavesdropping and tampering.