The California Privacy Rights Act, approved by voters in November 2020 and effective from January 1, 2023, significantly expands and strengthens the CCPA. It creates new consumer rights including the right to correct inaccurate information, right to limit use of sensitive personal information, and extends the “look-back” period for data access requests to 12 months. The CPRA establishes the California Privacy Protection Agency as an independent enforcement authority with rulemaking powers. It introduces the concept of “sharing” personal information for cross-context behavioral advertising and requires opt-out mechanisms. The law mandates privacy by design, annual cybersecurity audits for high-risk processors, and risk assessments. It also extends employee and B2B exemptions and introduces stricter requirements for processing minors’ data. Penalties remain similar to CCPA but with enhanced enforcement capabilities.
Health Data Management Policy (under Ayushman Bharat Digital Mission)
ABDM participants must comply with the Health Data Management Policy. Healthcare laws include the Clinical Establishments Act, National Medical Commission Act provisions requiring physician confidentiality,