Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
ManagementSecurity ServicesSecurity Leadership and ManagementSecurity & Business Resilience

Comply with the new data privacy regulations now

By Jeff Sizemore
data privacy

Image via Unsplash

March 13, 2023

Data privacy will continue to be a big focus for businesses in 2023. The U.S. states of Virginia, California, Colorado, Connecticut and Utah have already enacted or plan to enact legislation this year. We have also seen positive momentum around federal legislation with the American Data Privacy and Protection Act (ADPPA) and more government and regulatory agencies are getting involved, like with personal financial data rights.

Business-impacting regulations will keep coming and they will not be going away. So security professionals must be prepared, no matter the size of the organization. Company trust is also going to have a more significant impact on customers’ buying decisions. While these major changes can be overwhelming, there are several steps that businesses can take now to help comply with rapidly-evolving data privacy regulations and maintain trust with consumers.

Map company data

A good first step is to map company data in order to understand where consumer and employment data lives, how it’s used, who has access to it and potential risks that it might pose. It's important to gain visibility into structured and unstructured data, especially in today’s hybrid work environment. This can include anything from addresses and employee records to emails, photos and videos.

Several U.S. state privacy regulations, including the Virginia Consumer Data Protection Act and the Colorado Privacy Act, and international laws, such as the European Union’s General Data Protection Regulation (GDPR), also require data protection and privacy impact assessments. In a nutshell, assessments are designed to identify and minimize data risks.

Review data privacy policy

Updating of an organization’s data privacy policy is critical as well. Typically, a privacy policy is a document that details how a company handles customer, client or employee information. The privacy policy is prominently displayed, often on the company’s website. Because an organization's privacy policy is important to key stakeholders, it’s always best to keep it updated.

All five of the U.S. state regulations that will go into effect in 2023 have consumer notification requirements that could impact a company’s data privacy policy, particularly if it has not been reviewed recently. Similarly, Quebec’s Private Sector Privacy Act contains strict requirements for affected businesses. Up-to-date privacy policies will help organizations conform with new and changing regulations.

One aspect that is often overlooked when updating a privacy policy is that it’s a consumer-friendly business practice. With consumers taking their personal privacy more seriously, reviewing an organization's privacy policy shows that this is also top of mind for the organization. According to Cisco’s 2020 Consumer Privacy Survey, one-third of consumers are “privacy actives,” meaning they have stopped conducting business with an organization due to data privacy concerns.

Children's privacy is another area that is also getting more attention. The Children’s Online Privacy Protection Act (COPPA) from the U.S. Federal Trade Commission (FTC) imposes certain requirements on “operators” of websites or other online services that relate to the activities of children under the age of 13. Specifically, under the COPPA, these operators must receive verifiable parental consent before personal information is collected, used or disclosed from those under 13 years old. It’s important to note that state regulations may include special data privacy requirements for minors, such as the California Age-Appropriate Design Code Act.

Anticipate strict enforcement

Government entities and regulatory bodies are taking a closer look at how organizations handle their data. For example, the California Attorney General’s office announced in August 2022 that well-known retailer Sephora would have to pay $1.2 million in fines due to violations of the California Consumer Privacy Act (CCPA). Sephora failed to disclose that it was selling customers’ personal data and the company also neglected to process requests from users opting out of the sale of their data. In addition, Sephora did not resolve their CCPA violations within the required 30-day time period.

More recently, in December 2022, the FTC announced that video game maker Epic Games would have to pay $275 million in fines for violating the COPPA — and $245 million for tricking users into making unwanted purchases. The fines for violating the children’s privacy law were reported to be the largest penalty to date for violating one of the FTC’s rules. Outside of the U.S., Ireland's data privacy board determined earlier in 2023 that Facebook and Instagram owner Meta had violated GDPR because of the company’s advertising and data handling practices.

Take action now

No matter where an organization operates, being aware of ever-changing data privacy regulations and how they specifically apply to a business is crucial. And as a business continues to evolve, so should it's data privacy practices — entry into a new business market, for instance, could expose an organization to privacy regulations that may not have affected it previously. At a time when there’s a growing need to respect data privacy — and enforcement is becoming more strict — understanding the short- and long-term benefits of compliance and heeding the best practices outlined above is imperative.

KEYWORDS: data privacy federal security requirements government regulation policy state government

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jeff sizemore

Jeff Sizemore, Vice President of Governance and Compliance at Egnyte, is responsible for the strategy and execution of the Egnyte Protect content governance solution. Jeff has an extensive background in data protection, specifically in encryption, key management, data loss prevention, and identity and access management. Jeff has helped define the market by contributing to several start-ups, including PGP (now part of Symantec), Ionic Security, and Port Authority (now ForcePoint DLP). 

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • SEC0820-Data-Feat-slide1_900px.jpg

    Compliance regulators don’t stop working when companies go remote

    See More
  • 5mw Grewal

    5 minutes with Steve Grewal - Preparing for new data privacy regulations

    See More
  • red and green digital graphic

    Navigating the new US data privacy regulations

    See More

Related Products

See More Products
  • 9780367030407.jpg

    National Security, Personal Privacy and the Law

  • s and the law.jpg

    Surveillance and the Law: Language, Power and Privacy

  • 9780367667887.jpg

    Surveillance, Privacy and Security

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing