CCPA (California Consumer Privacy Act, 2018)
The California Consumer Privacy Act, effective from January 1, 2020, is a landmark US state privacy law granting California residents comprehensive rights over their personal information. It applies to for-profit businesses that collect California residents’ personal information, meet specific thresholds (annual revenues over $25 million, data of 50,000+ consumers, or 50%+ revenue from selling data), […]
EU AI Act (Artificial Intelligence Act – Proposed, 2021)
The EU AI Act is the world’s first comprehensive AI regulation, proposed in 2021 and expected to be fully implemented by 2026. It establishes a risk-based approach categorizing AI systems into four levels: unacceptable risk (banned), high-risk, limited risk, and minimal risk. High-risk AI systems, including those used in biometric identification, critical infrastructure, and employment, […]
GDPR (General Data Protection Regulation, 2016)
The General Data Protection Regulation is the European Union’s comprehensive data protection law that came into force on May 25, 2018. It establishes strict rules for how organizations collect, process, store, and transfer personal data of EU residents. Key provisions include requiring explicit consent for data processing, mandatory data breach notifications within 72 hours, right […]
Information Technology Act, 2000 – Amended 2008)
The IT Act is based on the United Nations Model Law on Electronic Commerce and contains provisions on data protection and privacy, including Section 43A which provides for compensation in case of negligence in protecting sensitive personal data, and Section 72A which provides criminal punishment for unauthorized disclosure of personal information. The Act forms the foundation […]
Digital Personal Data Protection Act, 2023
This official document outlines India’s Digital Personal Data Protection Act, 2023, a comprehensive law enacted to regulate the processing of digital personal data. The Act aims to balance individual data protection rights with the necessity of processing such data for lawful purposes. It defines key terms like Data Fiduciary and Data Principal, establishes the Data Protection Board of India to oversee compliance, and […]