Enterprise Risk management

profileA_User1
Week5Enterprise.txt

Answer the Below Question. APA format. 300 words. Textbook : Information Governance: Concepts, Strategies and Best Practices; John R.S. Fraser, Betty J. Simkins, Kristina Narvaez; Copyright © 2015 by John R.S. Fraser, Betty J. Simkins, Kristina Narvaez (ISBN 978-1-118-69196-0) Beasley, M. S. (2016). What is Enterprise Risk Management? Retrieved from https://erm.ncsu.edu/az/erm/i/chan/library/What_is_Enterprise_Risk_Management.pdf Question : You are requested to write an essay highlighting key commonalities and key differences between GDPR and CCPA. Select one of the key differences and elaborate further on which you think is more effective. Write Response to below two Discussions seperately.APA format. 100 words each. DISCUSSION 1: CCPA is a law that provides consumers the right to personal details to be gathered, shared, or sold by a company. GDPR is also a privacy law that disallows the gathering and processing of personal information by organizations. The similarity between these laws is that they oblige organizations to adhere to specific guidelines when handling personal data of people. Both of them have the disclosure of transparency requirements (Hammarling, 2019). They protect consumers or data subjects, no matter where they are at the given time. Both of them protect the same categories and kinds of information of natural people. The first difference among these laws is the type of business that should comply. CCPA has applied to primary business that their sale is of personal information or to companies based in California that its revenues are above twenty-five million dollars. GDPR is for all businesses that process information of EU individuals no matter their size and location. GDPR needs websites, organizations, and businesses to have a legal basis for processing data in the European, whereas CCPA does not require prior consent from the consumer (Blanke, 2020). They differ in their financial penalties as GDPR sanction for non-compliance and data breach. In CCPA, a sanction is only done when there is a breach and enables customers to sue an organization for violation (Buresh, 2019). CCPA considers both the consumer and household as entities and can consider the information given by the customer while GDPR focuses on all the data associated with the EU consumer. The most effective difference is the right to prior consent in GDPR versus to opt-out in CCPA. They are incomparable as the right to opt-out goes hand in hand with the right to withdraw consent while that of prior consent has no equivalent in CCPA. The right to prior consent creates all the difference when comparing the rights in these laws as it provides a legal framework grounded on privacy first through user control. References: Blanke, Jordan M. (2020), Protection for 'Inferences Drawn:' A Comparison between the General Data Protection Rule and the California Consumer Privacy Act (January 12, 2020). Available at SSRN: https://ssrn.com/abstract=3518164. Buresh, D. L. (2019), A Comparison between the European and the American Approaches to Privacy. Indon. J. Int'l & Comp. L., 6, 257. Hammarling, J. (2019), A comparative study on “the Right of Access” under the GDPR and the CCPA. Retrieved from http://lup.lub.lu.se/student-papers/record/9000026 DISCUSSION 2: The GDPR as specific aspects would not be generally applicable with reference to the context that has been purely personal or even related with the household. CCPA on the other hand would be completely applicable for the non commercial activities as well. Exemption in this context with reference to GDP are would only be referring to the individuals while the other ccpa would be recovering the business aspects as well which has been processed with the personal data (cookiebot, 2020). CCPA will be tracking down the emergency applications that have been associated with the benefits of the on information while the agenda would be associated with the encouragement of strong privacy as well as greater transparency. Proper management of consumers and ownership on the other hand with reference to personal information would also help in bringing down the ability required. The context of each and every conditions which has been associated with the business disclosure in the personal information would also help in management of connectivity which has been required as far as a data has not been sold to parties. Third party management would also help in knowing down the personal information which has been collected and the access ability of personal information that has to be collected based on request. We should also make sure that whatever has been known in terms of the personal information should not be opt out but however equal service and price should be given to the privacy rights (varonis, 2020). The California consumer privacy act would also define the business as far as a profit entity which would collect the personal data which has been related to the consumer as well. Therefore, the business related contact which has been associated with the threshold would also be subjected to compliance because there are annual exemptions (varonis, 2020). References Cookiebot. (2020). CCPA vs GDPR. Retrieved from, https://www.cookiebot.com/en/ccpa-vs-gdpr/ varonis. (2020). California consumer privacy act. Retrieved from, https://www.varonis.com/blog/ccpa-vs-gdpr/