Shadow AI is already using your data. Get the complimentary Gartner® report. Read the report

Leveraging Core Privacy Rights to Build a Global Data Compliance Plan

PKWARE

By PKWAREProductivity Protected

Share on social media

While privacy laws are certainly not new, ever since the European Union’s General Data Protection Regulation (GDPR) went into effect in 2018, global data protection regulation and privacy laws have continued to boom. There is a continuing upward trajectory in the passing of privacy laws, and even older laws are up for review and modernization based on the foundational elements of GDPR. No business can afford to ignore the growing and evolving data protection regulation landscape.

How Fast the Landscape Is Moving

The numbers make the trend hard to argue with. UNCTAD data put 107 countries with data protection legislation in place by the first quarter of 2020. By early 2021 it was 128 of the world’s 197 countries. That is rapid growth over a single year, and it compounds: as more countries and states adopt or adapt privacy laws, others have to match them to keep sending and sharing data across borders.

The recent arrivals show the same pattern. Brazil’s Lei Geral de Protecao de Dados and the California Consumer Privacy Act both landed in 2020. Virginia’s Consumer Data Protection Act was adopted in 2021 ahead of enforcement in 2023. Even long-standing law is being revisited: Canada’s PIPEDA, originally instated in 1983, is up for review and modernization against the foundations GDPR established.

What Non-Compliance Costs

On the financial side alone the range runs from as little as 750 US dollars to as much as 4 percent of global revenue, before any class-action suit is counted. The enforcement record gives that shape. Google was fined 7,000,000 in Sweden in March 2020 for failing to remove individuals from search results. Wind Tre was fined 16,729,600 in Italy in July 2020 for failing to capture consent for data usage, and for not holding proper contracts with the partners it shared data with. CaixaBank was fined 6,000,000 in Spain in 2021, split between unlawfully processing client personal data and failing to give sufficient information about that processing.

The financial penalty is rarely the whole cost. There is the brand and press impact, what negative headlines do to the share price, and how many customers simply go elsewhere. Trust is difficult to earn and expensive to rebuild, and it is not an abstraction here: processing personal data requires express consent. Without trust there is no consent, and without consent there is no data to run marketing and sales on at all.

Why Transparency Is the Practical Answer

Privacy and identity-centric governance does two jobs at once. It builds the trusted relationships with users, customers, and vendors that lead to stronger partnerships and higher revenue, and it keeps the organization compliant with GDPR and the growing set of identity-centric regulations that followed it. Those are the same piece of work, not two competing ones.

Download this free whitepaper to learn more about how leveraging privacy and identity-centric governance will not only help global businesses form trusted relationships, but also help ensure that they remain compliant with the slew of identity-centric regulations. You’ll also learn more about:

  • What the layout of the growing data protection regulation landscape looks like
  • How to use Privacy by Design and Default
  • The key building blocks for global compliance

Download The Whitepaper

PKWARE

PKWARE

Productivity Protected

PKWARE has been securing sensitive data for over 40 years. We’ve earned the trust of 21 of the 25 largest banks in the U.S. Our team delivers modern, data-centric security solutions organizations can rely on.