<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Privacy Laws - Vinod Sebastian - B.Tech, M.Com, PGCBM, PGCPM, PGDBIO</title>
	<atom:link href="https://vinodsebastian.com/category/it-made-easy-cat/privacy-laws/feed/" rel="self" type="application/rss+xml" />
	<link>https://vinodsebastian.com</link>
	<description>Hi I&#039;m a Web Architect by Profession and an Artist by nature. I love empowering People, aligning to Processes and delivering Projects.</description>
	<lastBuildDate>Sat, 06 Dec 2025 14:31:18 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://vinodsebastian.com/wp-content/uploads/2020/12/cropped-Me-32x32.jpg</url>
	<title>Privacy Laws - Vinod Sebastian - B.Tech, M.Com, PGCBM, PGCPM, PGDBIO</title>
	<link>https://vinodsebastian.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Major Privacy Laws</title>
		<link>https://vinodsebastian.com/major-privacy-laws/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=major-privacy-laws</link>
		
		<dc:creator><![CDATA[vinodsebastian]]></dc:creator>
		<pubDate>Sat, 06 Dec 2025 14:22:45 +0000</pubDate>
				<category><![CDATA[Privacy Laws]]></category>
		<category><![CDATA[IT Made Easy]]></category>
		<guid isPermaLink="false">https://vinodsebastian.com/?page_id=4048</guid>

					<description><![CDATA[<p>Major Privacy Laws General Data Protection Regulation (GDPR) &#8211; EU &#38; UK Scope: The GDPR applies globally to any organization processing personal data of EU/UK residents, covering both online and offline data. Key Features: Explicit consent required for data collection. Rights include access, rectification, erasure (&#8220;right to be forgotten&#8221;), and portability. Mandatory breach notification within [&#8230;]</p>
<p>The post <a href="https://vinodsebastian.com/major-privacy-laws/">Major Privacy Laws</a> first appeared on <a href="https://vinodsebastian.com">Vinod Sebastian - B.Tech, M.Com, PGCBM, PGCPM, PGDBIO</a>.</p>]]></description>
										<content:encoded><![CDATA[<article>
<h1>Major Privacy Laws</h1>
<h2>General Data Protection Regulation (GDPR) &#8211; EU &amp; UK</h2>
<p><strong>Scope:</strong> The GDPR applies globally to any organization processing personal data of EU/UK residents, covering both online and offline data.</p>
<p><strong>Key Features:</strong></p>
<ul>
<li>Explicit consent required for data collection.</li>
<li>Rights include access, rectification, erasure (&#8220;right to be forgotten&#8221;), and portability.</li>
<li>Mandatory breach notification within 72 hours.</li>
<li>Non-compliance can result in heavy fines, up to €20 million or 4% of global turnover.</li>
</ul>
<h2>California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA) &#8211; California, USA</h2>
<p><strong>Scope:</strong> These laws apply to for-profit businesses handling data of California residents, with thresholds based on revenue or number of consumers.</p>
<p><strong>Key Features:</strong></p>
<ul>
<li>Right to know what data is collected.</li>
<li>Right to delete personal data.</li>
<li>Right to opt-out of data sales.</li>
<li>CPRA introduces correction rights and sensitive data protections.</li>
<li>Penalties range from $2,500 to $7,500 per violation.</li>
</ul>
<h2>Personal Information Protection and Electronic Documents Act (PIPEDA) &#8211; Canada</h2>
<p><strong>Scope:</strong> PIPEDA applies to private-sector organizations across Canada, with exceptions for provinces with their own equivalent laws.</p>
<p><strong>Key Features:</strong></p>
<ul>
<li>Requires informed or implied consent for data processing.</li>
<li>Principles include accountability, limiting collection, and safeguarding data.</li>
<li>Individuals have the right to access and challenge the accuracy of their data.</li>
</ul>
<h2>Brazilian General Data Protection Law (LGPD) &#8211; Brazil</h2>
<p><strong>Scope:</strong> LGPD applies to any entity processing personal data in Brazil, including both domestic and international companies.</p>
<p><strong>Key Features:</strong></p>
<ul>
<li>Consent-based processing with transparency obligations.</li>
<li>Rights include access, correction, and deletion of personal data.</li>
<li>Requires the appointment of a Data Protection Officer (DPO).</li>
<li>Penalties can reach up to 2% of revenue, capped at 50 million BRL.</li>
</ul>
<h2>Personal Data Protection Act (PDPA) &#8211; Singapore</h2>
<p><strong>Scope:</strong> PDPA governs the collection, use, and disclosure of personal data in Singapore, applicable to both digital and physical records.</p>
<p><strong>Key Features:</strong></p>
<ul>
<li>Consent is required for the collection and use of personal data.</li>
<li>Organizations have accountability obligations for data protection.</li>
<li>Mandatory breach notification requirements.</li>
<li>Penalties can go up to SGD 1 million for non-compliance.</li>
</ul>
<h2>Protection of Personal Information Act (POPIA) &#8211; South Africa</h2>
<p><strong>Scope:</strong> POPIA applies to all public and private bodies processing personal information in South Africa.</p>
<p><strong>Key Features:</strong></p>
<ul>
<li>Requires lawful processing of personal information.</li>
<li>Individuals have rights to access, correct, and object to the processing of their data.</li>
<li>Non-compliance can lead to severe penalties, including fines or imprisonment for up to 10 years.</li>
</ul>
<h2>Personal Information Protection Law (PIPL) &#8211; China</h2>
<p><strong>Scope:</strong> PIPL applies to the processing of personal data of individuals in China, with strict rules for cross-border data transfers.</p>
<p><strong>Key Features:</strong></p>
<ul>
<li>Consent-based processing of personal data.</li>
<li>Strict restrictions on international data transfers.</li>
<li>Penalties for violations can be as high as RMB 50 million or 5% of annual revenue.</li>
</ul>
<h2>Data Protection Bill (DPDP Act) &#8211; India</h2>
<p><strong>Scope:</strong> The DPDP Act applies to the processing of digital personal data in India and extends to data related to Indian citizens processed abroad.</p>
<p><strong>Key Features:</strong></p>
<ul>
<li>Consent-based processing of personal data.</li>
<li>Rights provided include access, correction, erasure, and grievance redressal.</li>
<li>Establishes the Data Protection Board of India for oversight and enforcement.</li>
</ul>
<h2><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4dc.png" alt="📜" class="wp-smiley" style="height: 1em; max-height: 1em;" /> HIPAA (USA – Healthcare)</h2>
<p><strong>Scope</strong></p>
<ul>
<li>Applies to healthcare providers, insurers, and business associates handling <em>protected health information (PHI)</em> in the United States.</li>
<li>Covers electronic, paper, and oral health information.</li>
</ul>
<p><strong>Key Features</strong></p>
<ul>
<li>Privacy Rule: limits use/disclosure of PHI, grants patients rights to access and amend records.</li>
<li>Security Rule: requires safeguards for electronic PHI (encryption, access controls, audit trails).</li>
<li>Breach Notification Rule: mandates notifying affected individuals and regulators of breaches.</li>
<li>Enforcement Rule: civil and criminal penalties, fines up to $1.5M per year per violation category.</li>
</ul>
<h2><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f511.png" alt="🔑" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Big Picture</h2>
<ul>
<li><strong>GDPR, LGPD, PIPL, DPDP Act</strong> → broad, cross-sector, consent-driven frameworks.</li>
<li><strong>CCPA/CPRA, PIPEDA, PDPA, POPIA</strong> → regional laws with varying strength, often modeled after GDPR.</li>
<li><strong>HIPAA</strong> → sector-specific, focused entirely on healthcare data, with strict technical safeguards.</li>
</ul>
</article><p>The post <a href="https://vinodsebastian.com/major-privacy-laws/">Major Privacy Laws</a> first appeared on <a href="https://vinodsebastian.com">Vinod Sebastian - B.Tech, M.Com, PGCBM, PGCPM, PGDBIO</a>.</p>]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
