Page 734

Ming Ding | Information Security and

Privacy Group | Data61, CSIROPrivacy legislation and regulations

•The United States of America (USA)

➢2020 -California Privacy Rights Act ( CPRA ): This Act significantly amends and expands the CCPA,

and it is sometimes referred to as “ CCPA 2.0 ” [~GDPR equivalent]

(https://oag.ca.gov/privacy/ccpa )

✓Came into effect in January 2023

✓The CPRA defines “sensitive personal information” as a consumer’s personal information that reveals, e.g.,

social security, driver’s license, state identification card, passport number, account log -in, precise

geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, the contents of a

consumer’s mail, email and text messages genetic data

✓The right to correct inaccurate personal information;

✓The right to limit use and disclosure of sensitive personal information.