Data Privacy in the Age of GenAI

vtqhtr413

Level 27
Thread author
Verified
Top Poster
Well-known
Forum Veteran
Aug 17, 2017
1,273
17,246
2,568
Consumer data is still a prime target for threat actors, and organizational consumption of data must be aligned to protect it. The new rights act seeks to do some of this, but it still needs tweaking.

COMMENTARY

The American Privacy Rights Act of 2024 (APRA) is the most comprehensive proposed national legislation defining privacy for Americans to date — something that historically has meant difficulties in federal approval. We're looking at legislation that holds organizations accountable at a level we've not yet seen. With APRA, these companies will need:
  • Annual CEO-signed certification of compliance
  • Mandated reporting lines for privacy and security officers (You can't have a figurehead chief privacy officer with no reports or budget.)
  • To conduct biennial audits and Privacy Impact Assessments (PIAs)
  • To publish the privacy policies for the past 10 years and deliver annual reports on consumer requests related to privacy
There's a reason why the United States has not passed any comprehensive data privacy laws in recent history: Companies largely monetize consumer data. Data is profitable, and restricting that cash flow would have economic ripple effects. However, while well-intentioned, APRA does warrant some scrutiny. Notably, its Civil Rights and Algorithm section lacks concern about transparency and ethics.
 
Agree it is poorly written but this is really just an op ed, I posted it to spur a conversation or even just some thoughts on the subject :)
 
Reading your post again I would say that you are too into the fight, don't crawl into the ditch with them, we have to moderate as rational people otherwise irrational will win the day oldschool, I know you know this #####, I think you are lounging poolside, no offense intended.
 

You may also like...