Ming Ding | Information Security and
Privacy Group | Data61, CSIROPrivacy legislation and regulations
•The United States of America (USA)
➢2020 -California Privacy Rights Act ( CPRA ): This Act significantly amends and expands the CCPA,
and it is sometimes referred to as “ CCPA 2.0 ” [~GDPR equivalent]
(https://oag.ca.gov/privacy/ccpa )
✓Came into effect in January 2023
✓The CPRA defines “sensitive personal information” as a consumer’s personal information that reveals, e.g.,
social security, driver’s license, state identification card, passport number, account log -in, precise
geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, the contents of a
consumer’s mail, email and text messages genetic data
✓The right to correct inaccurate personal information;
✓The right to limit use and disclosure of sensitive personal information.