{"id":42834,"date":"2021-11-10T04:51:31","date_gmt":"2021-11-10T09:51:31","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?post_type=emagazine&#038;p=42834"},"modified":"2023-07-06T04:24:24","modified_gmt":"2023-07-06T08:24:24","slug":"privacy-global-regulations-new","status":"publish","type":"emagazine","link":"https:\/\/www.kaspersky.com\/blog\/secure-futures-magazine\/privacy-global-regulations-new\/42834\/","title":{"rendered":"INFOGRAPHIC: How GDPR changed the world, and privacy regulation&#8217;s future"},"content":{"rendered":"<p>One piece of regulation has never before had such global impact as the EU Global Data Protection Regulation (GDPR.) It\u2019s firmly established data privacy in the public mind, giving extensive and unassailable rights and affecting behavior well beyond the EU\u2019s borders.<br>\n<img decoding=\"async\" class=\"aligncenter wp-image-42839\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2021\/11\/08043535\/global_regulations_infographic-1-scaled.jpg\" alt=\"\" width=\"507\" height=\"2350\"><br>\nGDPR legislation was a pioneer that <a href=\"https:\/\/www.dlapiperdataprotection.com\/index.html?t=world-map&amp;c=US\" target=\"_blank\" rel=\"noopener nofollow\">other regions followed<\/a>. The California Consumer Privacy Act (CCPA) came into force in 2020. The more expansive California Privacy Rights Act (CPRA) will replace it in 2023. While there is no federal nationwide data protection law in the US, all fifty states have regulated data safeguarding, disposal and breach disclosure. US data privacy is pointing towards giving consumers more rights.<\/p>\n<p>Africa and Asia, with few exceptions, have a way to go in privacy regulation. It may be fair to say data protection regulation follows economic and political development. But China has a different focus. Having enacted strong privacy regulation, it\u2019s regaining control of local Big Tech, starting with <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2021-04-11\/china-s-record-alibaba-fine-shows-big-tech-can-t-fight-back\" target=\"_blank\" rel=\"noopener nofollow\">corporate dismemberment of Alibaba<\/a>. It aims to control the massive amounts of data held by <a href=\"https:\/\/apnews.com\/article\/technology-business-china-media-beijing-1600c373da85fb26517e8c7224d8ca80#:~:text=BEIJING%20(AP)%20%E2%80%94%20Companies%20in,disrupt%20operations%20for%20international%20corporations.\" target=\"_blank\" rel=\"noopener nofollow\">Chinese companies that may list overseas<\/a>.<\/p>\n\t\t\t<div class=\"c-promo-product\">\n\t\t\t\t\t\t<article class=\"c-card c-card--link c-card--medium@sm c-card--aside-hor@lg\">\n\t\t\t\t<div class=\"c-card__body  \">\n\t\t\t\t\t<header class=\"c-card__header\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<p class=\"c-card__headline\">Brittany Kaiser's data privacy solution<\/p>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h3 class=\"c-card__title \"><span>Whistleblower's wisdom<\/span><\/h3>\n\t\t\t\t\t\t\t\t\t\t\t<\/header>\n\t\t\t\t\t\t\t\t\t\t\t<div class=\"c-card__desc \">\n\t\t\t\t\t\t\t<p>After Cambridge Analytica, Brittany Kaiser knows what should happen<\/p>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"c-card__aside\">\n\t\t\t\t\t<a href=\"https:\/\/www.kaspersky.com\/blog\/secure-futures-magazine\/brittany-kaiser-data-privacy\/38362\/\" class=\"c-button c-card__link\" target=\"_blank\" rel=\"noopener nofollow\">Read the interview<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<\/article>\n\t\t<\/div>\n\t\n<h2>New consumer expectations of data privacy<\/h2>\n<p>GDPR and other regulations worldwide have raised awareness of privacy issues.<\/p>\n<blockquote><p>Organizations need to focus on disclosure and incident response best practice or risk consumers seeing them as not transparent and losing trust.<\/p>\n<\/blockquote>\n<p>There\u2019s a <a href=\"https:\/\/www.cybersource.com\/content\/dam\/documents\/en\/global-digital-shopping-index-2020-uk.pdf\" target=\"_blank\" rel=\"noopener nofollow\">gap between what customers want and what businesses <\/a><a href=\"https:\/\/www.cybersource.com\/content\/dam\/documents\/en\/global-digital-shopping-index-2020-uk.pdf\" target=\"_blank\" rel=\"noopener nofollow\"><em>think <\/em><\/a><a href=\"https:\/\/www.cybersource.com\/content\/dam\/documents\/en\/global-digital-shopping-index-2020-uk.pdf\" target=\"_blank\" rel=\"noopener nofollow\">customers want<\/a> in their digital experience. Businesses think it\u2019s profiles (for example, offering relevant suggestions,) live help and price-matching. But consumers prioritize rewards, free shipping and data protection.<\/p>\n<h2>Forced innovation is also good innovation<\/h2>\n<p>Data protection is now front of mind for everyone. Many once saw security regulations as an innovation inhibitor adding friction to the customer experience, but now they\u2019re customer experience\u2019s new best friend.<\/p>\n<p>With today\u2019s cybercrime landscape, data protection has never had so much focus, driving the need for strong authentication. <a href=\"https:\/\/en.wikipedia.org\/wiki\/3-D_Secure\" target=\"_blank\" rel=\"noopener nofollow\">3-D Secure<\/a> is a great example. Ecommerce businesses saw the first version of 3-D Secure as an important tool for tackling fraud, but also the main culprit for customers not completing checkout. But the same businesses are finding the latest version, which includes new security features like biometrics, highly attractive for easier authentication across the whole customer experience. 3-D Secure\u2019s latest iteration links with new EU regulation\u2019s authentication requirements.<\/p>\n<h2>Privacy expectations impact on cybercrime<\/h2>\n<p>The COVID-19 pandemic has sped up changes in digital consumer behavior like never before. Security and fraud risk increased, triggering more stringent regulation.<\/p>\n<blockquote><p>But stricter regulation has also seen cybercriminals weaponize data protection against those it\u2019s supposed to protect. <\/p>\n<\/blockquote>\n<p>Ransomware gangs try to extort money from victims by encrypting their data, but also releasing it if the ransom isn\u2019t paid, adding data privacy insult to injury.<\/p>\n<p>Nations are stepping up to address <a href=\"https:\/\/www.zdnet.com\/article\/ransomware-attacks-are-the-biggest-global-cyber-threat-and-still-evolving-warns-cybersecurity-chief\/\" target=\"_blank\" rel=\"noopener nofollow\">ransomware, now the world\u2019s biggest cyberthreat<\/a>. But it\u2019s early days. Attempts to reduce ransomware risk are sometimes surprising with little consensus on how to address it, like US proposals to <a href=\"https:\/\/www.cbsnews.com\/news\/ransomware-payments-may-be-tax-deductible\/\" target=\"_blank\" rel=\"noopener nofollow\">make ransomware payments tax-deductible<\/a> or, conversely, <a href=\"https:\/\/home.treasury.gov\/system\/files\/126\/ofac_ransomware_advisory_10012020_1.pdf\" target=\"_blank\" rel=\"noopener nofollow\">making paying a ransom illegal<\/a>. Once a profitable niche, <a href=\"https:\/\/www.protocol.com\/fintech\/ransomware-cyber-insurance-premiums\" target=\"_blank\" rel=\"noopener nofollow\">cyber insurance now struggles to stay afloat<\/a> with increasing ransomware and skyrocketing demands.<\/p>\n<h2>Emerging trends in data regulation and oversight<\/h2>\n<p>Data protection and privacy regulations are now part of life. We also see several emerging trends. For example, increased data protection and privacy oversight; in the three years since GDPR, <a href=\"https:\/\/www.netimperative.com\/2021\/07\/20\/gdpr-3-years-on-43-of-uk-organisations-reported-to-the-ico-for-a-data-breach\/\" target=\"_blank\" rel=\"noopener nofollow\">nearly half of UK businesses have been reported to the Information Commissioner\u2019s Office over breaches<\/a>. With longstanding data breach disclosure laws in the US, a <a href=\"https:\/\/www.tripwire.com\/state-of-security\/government\/new-bill-could-force-u-s-businesses-to-report-data-breaches-quicker\/\" target=\"_blank\" rel=\"noopener nofollow\">new bill could force businesses to report breaches faster<\/a>. India has long deliberated its <a href=\"https:\/\/www.datacenterdynamics.com\/en\/opinions\/why-india-has-introduced-the-new-personal-data-protection-bill\/\" target=\"_blank\" rel=\"noopener nofollow\">Personal Data Protection Bill (PDP.)<\/a><\/p>\n<p>We\u2019re also seeing financial and security regulations aligning. Financial services regulations now include extensive obligations overlapping with security. Penalties are no longer the sole domain of national data protection authorities but could come from any regulator. <a href=\"https:\/\/www.theguardian.com\/business\/2018\/oct\/01\/tesco-bank-fined-cyber-attack-fca\" target=\"_blank\" rel=\"noopener nofollow\">UK\u2019s Financial Conduct Authority fined Tesco Bank 16.4 million pounds sterling<\/a> for failing to protect customers\u2019 accounts and not doing enough to prevent financial crime.<\/p>\n<p>And we see increased desire to control Big Tech. The most notable example started in China with Alibaba in 2019. <a href=\"https:\/\/techcrunch.com\/2021\/09\/09\/what-chinas-new-data-privacy-law-means-for-us-tech-firms\" target=\"_blank\" rel=\"noopener nofollow\">New Chinese data protection regulation<\/a> has more scope for oversight, as we saw with the <a href=\"https:\/\/www.aljazeera.com\/economy\/2021\/8\/6\/china-tech-crackdown-didi-mulls-ceding-control-of-valuable-da\" target=\"_blank\" rel=\"noopener nofollow\">crackdown on ride-hailing service Didi<\/a> and others.<\/p>\n<p>China perhaps sees its companies listed overseas as a national security risk because foreign governments could scrutinize the massive amounts of data they hold. But there are other risks: Several <a href=\"https:\/\/www.bbc.com\/news\/business-57744983\" target=\"_blank\" rel=\"noopener nofollow\">shareholders sued Didi since their share price fell after regulatory crackdown<\/a>.<\/p>\n<p>It\u2019s not just China wanting to rein in Big Tech and their data \u2013 security concerns led to <a href=\"https:\/\/iapp.org\/news\/a\/german-dpa-tells-government-organizations-to-shut-down-facebook-pages\/\" target=\"_blank\" rel=\"noopener nofollow\">Germany\u2019s data protection commissioner telling government organizations to shut down their Facebook pages<\/a>. UK\u2019s draft Online Safety Bill proposes a <a href=\"https:\/\/techcrunch.com\/2021\/05\/12\/uk-publishes-draft-online-safety-bill\/\" target=\"_blank\" rel=\"noopener nofollow\">new Big Tech oversight body<\/a> to help tackle illegal and harmful online content.<\/p>\n<p>Another trend is increasing regulatory oversight of start-ups, especially in fintech. Stock trading app <a href=\"https:\/\/finance.yahoo.com\/news\/robinhood-crypto-expects-pay-30m-221025280.html\" target=\"_blank\" rel=\"noopener nofollow\">Robinhood must pay 30 million US dollars to the New York State regulatory body for cybersecurity and anti-money laundering failures<\/a>. The Swedish financial regulator is <a href=\"https:\/\/www.finextra.com\/newsarticle\/38398\/klarna-faces-data-privacy-investigation-in-sweden\" target=\"_blank\" rel=\"noopener nofollow\">investigating buy-now-pay-later firm Klarna for data privacy breaches<\/a>.<\/p>\n<h2>Coming soon: The data regulation to prepare for<\/h2>\n<p>Data regulation laws are often challenged. In Europe in 2020, the <a href=\"https:\/\/www.osano.com\/articles\/privacy-shield-invalidated\" target=\"_blank\" rel=\"noopener nofollow\">Schrems II judgment invalidated Privacy Shield, the data-sharing mechanism<\/a> between the EU and the US. Austrian activist Max Schrems scored a major win as his <a href=\"https:\/\/www.reuters.com\/technology\/austrian-activist-schrems-facebook-complaint-referred-eu-court-2021-07-20\/\" target=\"_blank\" rel=\"noopener nofollow\">case questioning Facebook\u2019s legal basis to collect data<\/a> was referred to the EU Court of Justice.<\/p>\n<p>Trump\u2019s <a href=\"https:\/\/www.theguardian.com\/technology\/2020\/sep\/29\/trump-tiktok-wechat-china-us-explainer\" target=\"_blank\" rel=\"noopener nofollow\">US attempt to ban TikTok and WeChat<\/a> shows this isn\u2019t confined to the EU. India\u2019s Reserve Bank <a href=\"https:\/\/techcrunch.com\/2021\/07\/14\/india-bans-mastercard-from-adding-new-customers\/\" target=\"_blank\" rel=\"noopener nofollow\">banned Mastercard from issuing new credit and debit cards<\/a> for not keeping to local data storage rules.<\/p>\n<p>Three years since GDPR came into force, regulators aren\u2019t standing still. In April 2021, the <a href=\"https:\/\/www.mccannfitzgerald.com\/knowledge\/gdpr\/european-commission-publishes-proposal-on-ai-regulation\" target=\"_blank\" rel=\"noopener nofollow\">EU Commission published a draft proposal to regulate artificial intelligence<\/a> in line with GDPR. With increased automation globally, this is one area to watch.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Three years since GDPR, there\u2019s much to learn from what\u2019s happened since. We can also predict what\u2019s next in privacy regulation.<\/p>\n","protected":false},"author":2690,"featured_media":42835,"template":"","coauthors":[4251],"class_list":{"0":"post-42834","1":"emagazine","2":"type-emagazine","3":"status-publish","4":"has-post-thumbnail","6":"emagazine-category-data-and-privacy","7":"emagazine-category-digital-transformation","8":"emagazine-category-opinions","9":"emagazine-tag-gdpr","10":"emagazine-tag-predictions","11":"emagazine-tag-regulation"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/secure-futures-magazine\/privacy-global-regulations-new\/42834\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/secure-futures-magazine\/privacy-global-regulations-new\/25678\/"}],"acf":[],"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/emagazine\/42834","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/emagazine"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/emagazine"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2690"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/42835"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=42834"}],"wp:term":[{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/coauthors?post=42834"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}