GDPR vs Australian Privacy Principles
Both Europe's GDPR and Australia's Privacy Act are based around explicitly stated principles for personal data privacy. These principles affect what businesses can and can't do with personal data, as...
GDPR's Anonymization vs CCPA/CPRA's De-identification
Privacy laws such as the GDPR and CPRA are less demanding when you change personal data to make it harder or impossible to link it to a specific individual. The...
Do You Need a Consent Log?
Getting consent for cookies or data processing isn't enough by itself: you need a reliable way to prove you have the consent. A consent log is the best way to...
Retention Policies: How Long Can You Keep Customer Data?
Many businesses handle all manner of data and don't have a clear method for deciding when to keep it and when to delete it. This can cause practical problems and...
User Consent vs. Legitimate Interest: Which Legal Basis Should You Use?
The GDPR only lets you process personal data for specific reasons. The most relevant for businesses involve either your "legitimate interests" or the consent of the person in question. You...