What a Week. Lots to Unpack.
Hello all, and thanks for reading today.
Read NowGet an overview of the simple, all-in-one data privacy platform
Manage consent for data privacy laws in 50+ countries
Streamline and automate the DSAR workflow
Efficiently manage assessment workflows using custom or pre-built templates
Streamline consent, utilize non-cookie data, and enhance customer trust
Automate and visualize data store discovery and classification
Ensure your customers’ data is in good hands
Key Features & Integrations
Discover how Osano supports CPRA compliance
Learn about the CCPA and how Osano can help
Achieve compliance with one of the world’s most comprehensive data privacy laws
Key resources on all things data privacy
Expert insights on all things privacy
Key resources to further your data privacy education
Meet some of the 5,000+ leaders using Osano to transform their privacy programs
A guide to data privacy in the U.S.
What's the latest from Osano?
Data privacy is complex but you're not alone
Join our weekly newsletter with over 35,000 subscribers
Global experts share insights and compelling personal stories about the critical importance of data privacy
Osano CEO, Arlo Gilbert, covers the history of data privacy and how companies can start a privacy program
Upcoming webinars and in-person events designed for privacy professionals
The Osano story
Become an Osanian and help us build the future of privacy!
We’re eager to hear from you
Published: February 22, 2024
Hello all, and happy Thursday!
There are lots of interesting stories in this week’s newsletter that I’d love to dig into, but in the interest of your time, I’ll limit myself to just one. Given the recent update to the CPRA enforcement timeline, it seems best to turn our attention to the Golden State.
Lawyers and privacy experts met at the California Lawyers Association Privacy Summit a few weeks ago. Notably, the summit included several panels hosted by privacy regulators (including California Privacy Protection Agency [CPPA] Deputy Director Macko)—and anytime a regulator speaks, it’s worth listening. Here are some of the takeaways that stood out to the Osano team in the event coverage:
All in all, CPRA regulators seemed intent on showing that they are serious about enforcement. This can all seem pretty intimidating, but it’s important to remember: CPRA enforcement isn’t about generating revenue for the state of California; it’s about protecting Californian consumers. Regulators can and will look favorably at businesses that are doing their best effort to get compliant.
Best,
Arlo
A new privacy regulation is to come into force in Oman, adding to the growing wave of privacy laws in the Middle East (including Saudi Arabia and Jordan). Among other characteristics, the new law appears to align with GDPR in regard to RoPAs, policies, SRRs, breach notifications, and other requirements.
Lawyers and privacy regulators gathered in Los Angeles last week for the second annual California Lawyers Association Privacy Summit. Notable takeaways included that 2024 is anticipated to be a major year for privacy enforcement; fines will be “significant” and accompanied by other, non-financial remedies; major enforcement focus will be paid to privacy notices, Do Not Sell/Share rights, children's privacy; and much more.
Privacy rights campaigner Max Schrems secured the High Court’s permission to participate in Meta’s challenge to a decision requiring the suspension of the transfer and storage of user data from Europe to the US. Schrems sought to be joined as a notice party in both cases, which both Meta and Ireland’s Data Protection Commission (DPC) opposed. However, Schrems argued he has a “clear vital and direct interest” in the proceedings, as the entire inquiry into data transfers came into existence because of an original complaint he made to the DPC in 2013.
A new category of AI chatbots serving as fantasy girlfriends fails many privacy and security standards, according to Mozilla research. Mozilla looked at AI chatbots such as iGirl: AI Girlfriend, Romantic AI, Genesia, Replika, and others, finding that many are intentionally vague about the AI training behind the bot, where their data comes from, how they protect information, and their responsibilities in case of a data breach.
Dr. Des Hogan and Mr. Dale Sunderland have been appointed to Ireland’s Data Protection Commission (DPC), taking effect February 20, 2024, for a five-year term. The appointment is significant, as 85% of the fines issued across Europe last year, including the EU, EEA, and UK, were issued by the DPC on foot of detailed and comprehensive investigations. Ireland’s DPC as a whole carries significant weight in terms of GDPR enforcement across the EU.
With the early arrival of CPRA enforcement, we’re fielding a lot of questions about what this means for businesses, how to interpret CPRA requirements, and more. Check out our blog post to review answers to some of the most frequently asked questions on CPRA enforcement.
If you’re interested in working at Osano, check out our Careers page! Right now, we’re looking for a Lead Privacy Architect—check out the job description here to see if you’d be a good fit.
Arlo Gilbert is the CEO & co-founder of Osano. An Austin, Texas native, he has been building software companies for more than 25 years in categories including telecom, payments, procurement, and compliance. In 2005 Arlo invented voice commerce, he has testified before congress on technology issues, and is a frequent speaker on data privacy rights.
Osano is used by the world's most innovative and forward-thinking companies to easily manage and monitor their privacy compliance.
With Osano, building, managing, and scaling your privacy program becomes simple. Schedule a demo or try a free 30-day trial today.