Other meanings of Privacy law
LAW AND TECHNOLOGY
Privacy law is the body of laws governing the collection, use, storage, and disclosure of personal information. It balances individual control, dignity, and security against legitimate activities such as health care, commerce, public administration, research, and law enforcement.
Privacy law regulates information about identifiable or identifiable households, consumers, employees, patients, and citizens. Its central questions are what may be collected, why it may be collected, how long it may be retained, who may receive it, and what safeguards apply. The OECD guidelines helped establish widely used principles of collection limitation, data quality, purpose specification, use limitation, security, openness, participation, and accountability.2
The legal subject is often called personal data or personal information. Definitions vary: the European Union’s General Data Protection Regulation includes online identifiers and location data, while some United States laws apply only to specified categories or covered businesses.1 Privacy rules may therefore follow the person, the data, the organization, the sector, or the transaction.
Privacy law is organized through several overlapping architectures rather than one universal code. The European Union uses a comprehensive, technology-neutral regime under the GDPR, with duties for controllers and processors, restrictions on international transfers, and independent supervisory authorities.1 The Council of Europe’s Convention 108 provides an international treaty framework for protecting individuals in automated personal-data processing.6
The United States relies heavily on sectoral and state laws, including rules for health information, financial records, children’s data, consumer reporting, and communications. California’s Consumer Privacy Act, as amended, gives qualifying consumers rights to know, delete, correct, opt out of certain sales or sharing, and limit some uses of sensitive personal information.4 Contract, tort, constitutional, and consumer-protection doctrines can supplement dedicated privacy statutes.
Modern privacy regimes commonly combine individual rights with organizational accountability. Depending on the jurisdiction, a person may request access to data, correction of inaccuracies, deletion, portability, objection to processing, restriction of use, or review of significant automated decisions; exemptions often protect legal obligations, public interests, security, and other individuals’ rights.1
Organizations typically must provide notices, define purposes, limit collection, manage vendors, secure information, document decisions, respond to rights requests, and report or contain certain breaches. The NIST Privacy Framework presents privacy risk management as an adaptable governance and engineering activity rather than a single checklist.5 Regulators can investigate, order corrective action, impose administrative penalties, or pursue consumer-protection cases; private lawsuits exist in some legal systems but not all.
Privacy law reaches beyond obvious databases and advertising profiles. Inferences can be personal information even when they were not directly supplied by an individual, and pseudonymized data may remain regulated when re-identification is reasonably possible.1 Small devices, biometric templates, precise location records, workplace monitoring, loyalty programs, and publicly available information can each raise different questions.
Cross-border processing is a particularly technical edge case: a company may need a lawful transfer mechanism, contractual safeguards, or an adequacy decision, while also assessing the receiving country’s public-authority access rules. Privacy impact assessments are often required or strongly encouraged for high-risk projects such as large-scale profiling or sensitive-data processing.1 Specialized rules also address children, deceased persons, journalistic purposes, scientific research, archives, and national security, so compliance frequently depends on context rather than on the data label alone.
Legal rights, exemptions, definitions, deadlines, and remedies vary substantially by jurisdiction and sector; authoritative local law should be consulted for a specific matter.
Help improve the encyclopedia. Reports go straight to the site manager.