Best practices to prepare for new data U.S. protection regulations

Data privacy protection was taken to a whole new level when the General Data Protection Regulation was implemented by European lawmakers in May 2018. Under GDPR, vendors are required to be fully transparent with customer data belonging to European residents and comply with stringent data management requirements. It gives businesses legal incentive to properly manage and protect customer data and gives customers the opportunity to opt-out at any point.
While businesses scrambled to meet these compliance requirements, their customers welcomed the added security of their data. Not surprisingly, other governments took notice of GDPR’s success.
Not long after GDPR went into effect, a group of California legislators voted unanimously to pass the California Consumer Privacy Act (CCPA), a law inspired by GDPR to ensure that residents’ data is well protected. It can be expected that government bodies around the globe may begin to pass similar laws that protect their constituents’ data.
Although GDPR only applies to European consumers, global businesses with European customers are responsible for ensuring their privacy practices are compliant with GDPR. The same will be true for businesses under the CCPA; any customer that resides in California will be protected under the act regardless of the location of the business they are purchasing from.
Most businesses in the US already ran a rigorous gamut to meet compliance requirements for GDPR. In theory, complying with new US regulations should be a simple matter with a few nuances added here and there.
But in today’s data-driven economy, businesses must not only understand how they should be compliant, they should also understand their customers’ concerns about data privacy and what they are looking for in a data privacy agreement.
A recent study from Veritas found that over 60 percent of consumers would stop buying from a business that fails to protect their data. Additionally, 48 percent of respondents said they would switch loyalties and begin purchasing from a competitor while 81 percent would encourage friends and family members to boycott the company.
Compliance for its own sake isn’t enough. To achieve true compliance, everyone involved in data management must understand its importance. Organizations must strike the perfect balance between the right technology and employee training.


