1.No consistent federal laws/directives in the US.
2.Laws vary based on location of stored data and pathways that data travels.
3.European Union sees privacy as a human rights.
4.Laws and standards such as GLBA,HIPAA and PCI DSS have requirements for protecting the privacy of information.These responsibilities are not transferred to the CSP.
5.Privacy vs. confidentiality
Privacy - Owner's right to determine to whom information is disclosed.
Security - Controller (processor) must provide security controls to enforce privacy.
0 Comments