m B2C site GRC
Key Points
- public and private B2C sites subject to many regulations in different jurisdictions
- need to know applicable policies
- need to know how to design and manage for compliance, audits
- PII management policies - GDPR and related personal data privacy policies
- Site access policies
- Implied warranties and merchantibility - don't exist
- Identify contact points and recourse processes
- File, track and manage compliants
- User agreement to arbitration processes in specific jurisdictions
- Token policies by jurisdiction
References
Key Concepts
Data Protection Methods Overview
Data Privacy Studies
GDPR regulations - data privacy limitations
https://www.nytimes.com/2019/09/24/technology/europe-google-right-to-be-forgotten.html
Data Sharing agreement concepts
https://www.jdsupra.com/legalnews/cfpb-outlines-principles-for-consumer-98316/
The Consumer Financial Protection Bureau (CFPB or Bureau) recently released a set of consumer protection principles for protecting consumers when they authorize third party companies to access their financial data to provide certain financial products and services
The principles, which are intended to be read together, relate to:
- data access;
- data scope and usability;
- control of the data and informed consent;
- payment authorizations;
- data security;
- transparency on data access rights;
- data accuracy;
- accountability for access and use; and
- disputes and resolutions for unauthorized access.
Potential Value Opportunities
Potential Challenges
Candidate Solutions
Step-by-step guide for Example
sample code block