The terms “deidentified” and “deidentification” are commonly used in modern privacy statutes and are functionally exempt from most privacy and security-related requirements. As indicated in the chart below, differences exist between how the term was defined in the California Consumer Privacy Act (CCPA) and how it was defined in later state privacy statutes that are
More Posts
Comparing and Contrasting the State Laws: Does Pseudonymized Data Exempt Organizations from Complying with Privacy Rights?
Comparing and Contrasting the State Laws: What is Pseudonymized Data?
Data transfers that are exempt from the definition of ‘sale’
How do state statutes differ in terms of how they define the term ‘selling’?
What exactly is a “Transfer Impact Assessment” (TIA), and where the heck did it come from?
Transfers from a European Data Subject: Data Subject → Controller (US) → Processor (non-EEA)
Transfers from a European Data Subject: Data Subject→Controller (US)→Processor (US)
Transfers from a European Data Subject: Data Subject→Controller (US)→Controller (non-EEA)
Transfers from a European Data Subject: Data Subject→Controller (US)→Controller (US)
Subscribe: Subscribe via RSS
Blogs
Firm/Org