{"id":2567,"date":"2023-03-29T14:01:00","date_gmt":"2023-03-29T20:01:00","guid":{"rendered":"https:\/\/trustarc.com\/?post_type=resource&#038;p=2567"},"modified":"2025-05-08T14:13:49","modified_gmt":"2025-05-08T19:13:49","slug":"your-2023-privacy-compliance-roadmap-tips","status":"publish","type":"resource","link":"https:\/\/trustarc.com\/resource\/your-2023-privacy-compliance-roadmap-tips\/","title":{"rendered":"Navigating Your 2023 Privacy Compliance Roadmap: Tips for Companies"},"content":{"rendered":"\t\t<section id=\"block_5f4c74afd0bb747d7c9abd08661f03b5\" class=\"resource-intro intro-simple\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<strong class=\"sub-title block uppercase\">Articles<\/strong>\n\t\t\t\t\t\t\t\t\t\t<h1>Navigating Your 2023 Privacy Compliance Roadmap: Tips for Companies<\/h1>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t<section id=\"block_3c21d4951098cc87264bc6da35387297\" class=\"columns-content\">\n\t\t<div class=\"container\">\n\t\t\t<div class=\"left\">\n\t\t\t\t\t\t<div class=\"person-wrap\">\n\t\t\t<span>\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"1080\" height=\"1080\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/casey-thumbnail.png\" class=\"attachment-full size-full wp-post-image\" alt=\"\" srcset=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/casey-thumbnail.png 1080w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/casey-thumbnail-300x300.png 300w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/casey-thumbnail-1024x1024.png 1024w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/casey-thumbnail-150x150.png 150w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/casey-thumbnail-768x768.png 768w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/casey-thumbnail-199x199.png 199w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/casey-thumbnail-120x120.png 120w\" sizes=\"auto, (max-width: 1080px) 100vw, 1080px\" \/>\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t<strong class=\"block name\">Casey Kuktelionis<\/strong>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/span>\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t<div class=\"middle\">\n\t\t\t\t<div class=\"content\">\n\t\t\t\t\t<p>If the first quarter has been any indication, 2023 will be yet another busy year in data protection and privacy. With so many global regulations to pay attention to, knowing where to focus your privacy resources is challenging. But despite the chaos, these are the key laws and topics you should have on your 2023 privacy compliance roadmap.<\/p>\n<h2>Anticipated changes to existing privacy regulations<\/h2>\n<h3>Five U.S. State privacy laws go into effect in 2023<\/h3>\n<p>In January, the Virginia Consumer Data Protection Act (finalized) and the\u00a0<a href=\"https:\/\/blog.trustarc.com\/2022\/10\/20\/california-privacy-rights-act-updates-the-california-consumer-protection-act\/\">California Privacy Rights Act (CPRA) (amending the California Consumer Protection Act (CCPA))<\/a>\u00a0became effective.<\/p>\n\t\t\t\t\t\t\t\t<div class=\"wide-img\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/US-State-Privacy-Law-Effective-Dates-Compliance-Blog-1.png\" class=\"attachment-full size-full\" alt=\"\" srcset=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/US-State-Privacy-Law-Effective-Dates-Compliance-Blog-1.png 1024w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/US-State-Privacy-Law-Effective-Dates-Compliance-Blog-1-300x225.png 300w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/US-State-Privacy-Law-Effective-Dates-Compliance-Blog-1-768x576.png 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<p><strong>Although the CPRA does make significant changes to the CCPA, rulemaking is still in progress.<\/strong>\u00a0On February 14, 2023,\u00a0<a href=\"https:\/\/cppa.ca.gov\/regulations\/pdf\/20221102_mod_text.pdf\">CCPA regulations<\/a>\u00a0were submitted to the Office of Administrative Law for final review, which has 30 business days to review the rulemaking package. Enforcement of the CCPA is already underway, but CPRA enforcement is expected to start in July 2023.<\/p>\n<p>However, that date could change, and you should monitor the\u00a0<a href=\"https:\/\/cppa.ca.gov\/regulations\/consumer_privacy_act.html\">California Privacy Protection Agency\u2019s<\/a>\u00a0announcements. CCPA rulemaking will continue in phases and focus on different types of notices, Global Privacy Control (GPC) and universal opt-out mechanisms, how to exercise individual rights, and other topics such as the annual security audit and privacy impact assessment requirements.<\/p>\n<p>Next, Connecticut CT-SB6 (CTDPA) and the Colorado Privacy Act will become effective on July 1, 2023. The CTDPA won\u2019t require controllers to enable consumers to exercise their opt-out rights through a universal mechanism until January 1, 2025.<\/p>\n<p><a href=\"https:\/\/coag.gov\/app\/uploads\/2023\/03\/FINAL-CLEAN-2023.03.15-Official-CPA-Rules.pdf\">Final rules for the Colorado Privacy Act<\/a>\u00a0were filed with the Secretary of State on March 15, 2023. Regulations include consumer rights, universal opt-out mechanisms, controller obligations, data protection assessments, and important topics such as automated decision making and consent.<\/p>\n<p>And lastly, to ring in the new year, The Utah Consumer Protection Act will go into effect on December 31, 2023. Because each U.S. state privacy law is different, all five should be on your privacy compliance roadmap.<\/p>\n<h3>EU-U.S. Cross-border data transfers and The Executive Order<\/h3>\n<p>It\u2019s been over a year since the EU and the U.S. struck an understanding on a revamped Privacy Shield data transfer agreement, now called the\u00a0<a href=\"https:\/\/blog.trustarc.com\/2022\/03\/25\/trans-atlantic-data-privacy-framework\/\">EU-U.S. Data Privacy Framework<\/a>\u00a0(DPF). In December 2022, the European Commission published its\u00a0<a href=\"https:\/\/commission.europa.eu\/system\/files\/2022-12\/Draft%20adequacy%20decision%20on%20EU-US%20Data%20Privacy%20Framework_0.pdf\">draft adequacy decision<\/a>\u00a0recognizing the essential equivalence of U.S. data protection standards.<\/p>\n<p>&nbsp;<\/p>\n\t\t\t\t\t\t\t\t<blockquote class=\"w-indent\">\n\t\t\t\t\t\t\t\t\t<p>\u201cWe will analyze the draft decision in detail the next days. As the draft decision is based on the known Executive Order, I can\u2019t see how this would survive a challenge before the Court of Justice. It seems that the European Commission just issues similar decisions over and over again \u2013 in flagrant breach of our fundamental rights.\u201d<\/p>\n\t\t\t\t\t\t\t\t<\/blockquote>\n\t\t\t\t\t\t\t\t<p>A final decision should come in the next few months. And because data transfers have become vital to international trade, this decision will be critical for your 2023 privacy compliance roadmap.<\/p>\n<h2>More data protection and privacy regulations to watch in 2023<\/h2>\n<p>Although a U.S. federal privacy law was proposed in 2022, that bill stalled before the close of federal government business in December. Both political parties have different motivations for the\u00a0<a href=\"https:\/\/www.congress.gov\/bill\/117th-congress\/house-bill\/8152\">American Data Privacy Protection Act<\/a>, and it may be brought before congress again.<\/p>\n<p>Whether or not we will see a\u00a0<a href=\"https:\/\/blog.trustarc.com\/2023\/01\/26\/state-privacy-laws-vs-federal-privacy-law\/\">U.S. federal privacy law<\/a>\u00a0in 2023 remains uncertain. But don\u2019t give up hope. At a recent hearing, the Innovation, Data, and Commerce Subcommittee Chair Gus Bilirakis (R-FL) declared,\u00a0<em><strong>\u201cAmericans need and deserve more transparency over how their information is collected, processed, and transferred.\u201d<\/strong><\/em><\/p>\n<p>In March 2023, the Iowa Senate and House unanimously voted to approve\u00a0<a href=\"https:\/\/www.legis.iowa.gov\/legislation\/BillBook?ga=90&amp;ba=SF%20262\">Senate File 262<\/a>, potentially making Iowa the\u00a0<strong>sixth U.S. state<\/strong>\u00a0to enact an omnibus privacy law. Iowa\u2019s law is similar to the frameworks in Colorado, Connecticut, Utah, and Virginia\u2019s laws and is set to take force on January 1, 2025. Notably missing from Iowa\u2019s Bill are sensitive data opt-in consent requirements, a user\u2019s right to correct, required risk assessments, and practice purpose limitations.<\/p>\n<p>Across the Atlantic, the U.K. government released the second draft reform of the UK GDPR, called the\u00a0<a href=\"https:\/\/bills.parliament.uk\/bills\/3430\">Data Protection and Digital Information (No.2) Bill<\/a>. This bill doesn\u2019t change the fundamental principles of the U.K. GDPR, data subject rights, or core obligations. IAPP writer Joe Jones summarizes the\u00a0<a href=\"https:\/\/iapp.org\/news\/a\/top-ten-takeaways-from-the-draft-uk-gdpr-reform\/\">top 10 takeaways from the draft reform<\/a>.<\/p>\n<h2>2023 data protection and governance hot topics<\/h2>\n<p>Two new Acts passed in the EU raise the question of what the government\u2019s role should be regarding major tech companies and online services.<\/p>\n<p>The\u00a0<a href=\"https:\/\/blog.trustarc.com\/2023\/01\/04\/what-is-the-eu-digital-markets-act-dma\/\">EU Digital Markets Act (DMA)<\/a>\u00a0will apply in the EU from May 2023 to ensure dominant tech companies behave fairly online. Including the monitoring of practices that might restrict the growth of new and alternate platforms.<\/p>\n<p>In the DMA, large platforms like Google, Facebook, and Amazon are given the title\u00a0<em>Gatekeepers<\/em>.\u00a0<strong>Gatekeepers are prohibited from:<\/strong><\/p>\n<ul>\n<li>Processing consumers\u2019 personal data collected from third-party services to provide online advertising services without prior consent, and<\/li>\n<li>Reusing personal data collected during a service for the purposes of another service without prior consent, among other things.<\/li>\n<\/ul>\n<p>The\u00a0<a href=\"https:\/\/blog.trustarc.com\/2023\/01\/18\/digital-services-act\/\">Digital Services Act (DSA)<\/a>\u00a0was also proposed by the European Commission to provide a safer, fairer, and more open digital playing field across the EU. It sets out new standards for online accountability and imposes rules around how platforms moderate content, advertise, and use algorithmic processes.<\/p>\n<p>The DSA entered into force on November 16, 2022. It applies fully to all relevant entities 15 months after entering into force: from February 17, 2024.\u00a0<strong>There are additional deadlines before this<\/strong>, however. For example, online platforms have been asked to report the number of end users they have by February 17, 2023. The European Commission will use this information to determine which ones should be designated very large online platforms\/search engines.<\/p>\n<h3>Artificial Intelligence (AI) regulations<\/h3>\n<p>As AI and machine learning take the world by storm, regulators are increasing legislation and enforcement. Meanwhile, privacy professionals are trying to understand the current AI privacy requirements and monitor future legislation.<\/p>\n<p>The GDPR and the CPRA refer to\u00a0<strong><em>automated decision making (ADM)<\/em><\/strong>\u00a0technologies (and offer consumers the right to opt out of such data processing). Also, if AI is used to process personal data, the principles of the GDPR, such as accountability, fairness, data minimization and security, and transparency should be considered.<\/p>\n<p><a href=\"https:\/\/blog.trustarc.com\/2023\/01\/31\/ai-governance-regulation-2023-trends\/\">AI is increasingly a concern of regulators<\/a>, and already several new laws and changes have been proposed for safeguards to ensure the responsible use of AI and regulatory compliance.<\/p>\n<ul>\n<li>The European Commission proposed the\u00a0<a href=\"https:\/\/artificialintelligenceact.eu\/\" target=\"_blank\" rel=\"noopener\">Artificial Intelligence Act (AI Act)<\/a>.<\/li>\n<li>California State Assembly introduced\u00a0<a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/billTextClient.xhtml?bill_id=202320240AB331\">Bill AB-331 Automated Decision Tools<\/a>.<\/li>\n<li>The FTC is investigating potential new rules for AI use.<\/li>\n<li>Other States, such as Alabama, Colorado, Mississippi, Vermont, and Washington are working on new AI rules.<\/li>\n<\/ul>\n<p>Although no federal regulation exists regarding ethical AI use in the U.S., the White House released a\u00a0<a href=\"https:\/\/www.whitehouse.gov\/ostp\/ai-bill-of-rights\/\">Blueprint for an AI Bill of Rights<\/a>\u00a0in 2022. The blueprint is a set of five principles and practices to guide using automation while protecting the rights of the American public. Additionally, all U.S. Federal organizations are to follow the\u00a0<a href=\"https:\/\/www.ai.gov\/legislation-and-executive-orders\/\">U.S. national strategy on AI<\/a>\u00a0defined through various legislation and executive orders.<\/p>\n<p>The European Commission also\u00a0<a href=\"https:\/\/ec.europa.eu\/newsroom\/article29\/items\/612053\">released guidelines<\/a>\u00a0on automated individual decision-making and profiling for the purposes of regulation in 2018. And even more recently, the Information Commissioner\u2019s Office (ICO)\u00a0<a href=\"https:\/\/ico.org.uk\/for-organisations\/guide-to-data-protection\/key-dp-themes\/guidance-on-ai-and-data-protection\/\">provided updated guidance<\/a>\u00a0for AI and Data Protection in March 2023.<\/p>\n<p>AI and machine learning are poised to become hot-button issues over the next few years. This is an area you\u2019ll want to keep bookmarked in your privacy compliance roadmap.<\/p>\n<h3>Dark patterns<\/h3>\n<p><em>A Dark pattern<\/em>\u00a0is a broad term describing a variety of manipulative design choices to persuade users to make choices they otherwise wouldn\u2019t have made.\u00a0<strong>Dark patterns can include:<\/strong><\/p>\n<ul>\n<li>Pre-selections on forms,<\/li>\n<li>Not giving people opt-out options,<\/li>\n<li>Hidden opt-out controls,<\/li>\n<li>Repetitive attempts to collect information, and<\/li>\n<li>Using algorithms to change purchase decisions.<\/li>\n<\/ul>\n<p>At their core, <a href=\"\/resource\/ux-dark-patterns-consent-data-collection\/\">dark or deceptive patterns<\/a> reflect the opposite of transparency and trust. Not only do we see more data protection regulations covering dark patterns, but consumers have also become more aware of them.<\/p>\n<p>For example, in late 2022, the\u00a0<a href=\"https:\/\/www.consumerfinancialserviceslawmonitor.com\/2022\/11\/ftc-fines-vonage-100m-for-junk-fees-and-using-dark-patterns-to-make-it-hard-for-consumers-to-cancel\/#:~:text=The%20Federal%20Trade%20Commission%20(FTC,difficult%20for%20consumers%20to%20cancel.\">FTC reached a $100 million settlement with Vonage<\/a>\u00a0over allegations of dark pattern use that made it difficult for consumers to cancel services. As these headlines become more mainstream, consumers are more likely to notice and report dark pattern use.<\/p>\n<p>Carefully examine your websites, applications, and privacy notices. Are they transparent? Do they provide users with an opportunity to make choices without being persuaded? If not, act quickly to remedy those issues before consumers or regulators discover them first.<\/p>\n<p>Download the <a href=\"\/wp-content\/uploads\/2024\/02\/Deceptive-Patterns-Consent-Privacy-Infographic.png\" target=\"_blank\" rel=\"noopener\"><em>Deceptive Patterns in Consent and Data Privacy<\/em><\/a> infographic.<\/p>\n<h2>Four steps to build your 2023 privacy compliance roadmap<\/h2>\n<p>Considering the new regulations, changing regulations, and possible regulations, here are four steps to boil that information down into your 2023 privacy compliance roadmap.<\/p>\n<h3>Know where you stand<\/h3>\n<p>Start by answering the following questions to get a general sense of where the organization\u2019s current privacy program status and what important actions need to be taken this year.<\/p>\n<ul>\n<li>What laws\/regulations must your organization comply with?<\/li>\n<li>What do your current privacy program and compliance status look like?<\/li>\n<li>What are the core details of your privacy program?<\/li>\n<li>What are your biggest gaps and risk areas?<\/li>\n<\/ul>\n<h3>Update the data inventory<\/h3>\n<p>An accurate, updated\u00a0<a href=\"https:\/\/blog.trustarc.com\/2022\/08\/11\/data-inventory-and-mapping\/\">data inventory<\/a>\u00a0is critical for compliance with privacy regulations and data subject access requests. You need a detailed outline of:<\/p>\n<ul>\n<li>what data the organization has,<\/li>\n<li>where it lives,<\/li>\n<li>where it\u2019s collected from,<\/li>\n<li>and where it is transferred, sold, or shared.<\/li>\n<\/ul>\n<p>Because most functions in organizations collect or process data, keeping your data inventory updated can be a strenuous effort. Some privacy teams collaborate across business functions using spreadsheets. While others choose to automate the discovery of data and compliance reporting processes.<\/p>\n<h3>Open communication lines with business partners<\/h3>\n<p>Creating a comprehensive 2023 privacy compliance roadmap isn\u2019t possible without connecting to people across the enterprise. The privacy team should be a resource that enables business innovation and value creation. Building relationships outside of the privacy office requires time and visibility.<\/p>\n<p>Working with other business functions, privacy professionals can help\u00a0<strong>enable the development of products and services within the parameters of data protection.<\/strong>\u00a0Does your organization use privacy by design or by default processes and practices for creating new products and services? Have you implemented a privacy training program for all employees? Start from here and build relationships as you go.<\/p>\n<h3>Have your individual rights requests\/data subject requests processes tested and ready<\/h3>\n<p>In addition to European consumers, several U.S. states have recently awarded data subject access rights to individuals. Although the rights and requirements vary, businesses must respond to requests to know, change, delete, or stop the sale\/share of data within a specific timeframe.<\/p>\n<p>In some cases, this includes contacting third parties and vendors down the supply chain to make the necessary changes as well. As you can imagine,\u00a0<strong>this can be a complicated web, and noncompliance can be costly.<\/strong>\u00a0The California Attorney General has already\u00a0<a href=\"https:\/\/blog.trustarc.com\/2022\/09\/30\/ccpa-compliance-lessons-ag-enforcement\/\">announced enforcement actions<\/a>, and its first settlement with Sephora in relation to notice and opt-out requests signaled via the Global Privacy Control (GPC).<\/p>\n<p>The data subject request lifecycle doesn\u2019t have to be managed manually. In fact, it\u2019s nearly impossible to do so. If you don\u2019t want to leave your organization open to enforcement actions, leverage\u00a0<a href=\"https:\/\/trustarc.com\/customer-consent-preference\/\" target=\"_blank\" rel=\"noopener\">TrustArc\u2019s Individual Rights Manager<\/a>.\u00a0<strong>Automate request fulfillment, improve response times, reduce costs, and comply with the most stringent global regulations.<\/strong><\/p>\n<p>You can also take transparency and trust further by providing customers a preference center to manage their consent choices with your business through Consent &amp; Preference Manager.<\/p>\n<h2>Other considerations for your 2023 privacy compliance roadmap<\/h2>\n<p>Depending on the size of the company and its location, your privacy program may be in <a href=\"https:\/\/trustarc.com\/resource\/privacy-program-maturity-checklist\/\" target=\"_blank\" rel=\"noopener\">different stages of maturity<\/a>. In addition to compliance, other best practices also deserve a place in your privacy compliance roadmap.<\/p>\n<h3>Data minimization<\/h3>\n<p>Only collecting the data that is absolutely necessary for business functions can drastically reduce risk and simplify your privacy program. Although it\u2019s tempting to feel like more data is better, focus on collecting the highest quality data with consent from the data subject instead. Work across business departments to stop collecting data unnecessarily.<\/p>\n<h3>Renew privacy certifications<\/h3>\n<p>There are always recurring annual tasks that need to be completed to comply with regulations. For example, in California, you must include annual statistics revealing the number of requests received in your privacy notice.<\/p>\n<p><a href=\"https:\/\/trustarc.com\/resource\/power-data-privacy-certifications\/\" target=\"_blank\" rel=\"noopener\">Certifications are proof of compliance<\/a> and protection practices and demonstrate the organization\u2019s commitment to privacy while reducing the time to finalize vendor partnership agreements.\u00a0<strong>Independent reviews help your organization stand out, reduce risk, and build trust.<\/strong><\/p>\n<p>Keeping those\u00a0<a href=\"https:\/\/trustarc.com\/certifications-and-assurance\/\">third-party certifications<\/a>\u00a0active can be critical to your organization\u2019s bottom line. Identify if you need to add certification renewal to your privacy compliance roadmap this year and ensure it gets done!<\/p>\n<h3>Create an employee privacy policy<\/h3>\n<p>Whether your employees are in California or covered under another data protection regulation, protecting your employee\u2019s data is the right thing to do.\u00a0<strong>Every organization needs an employee privacy notice and policy.<\/strong><\/p>\n<p>Employers often collect very personal information about employees, who deserve to know how their data will be used and protected. <a href=\"https:\/\/trustarc.com\/resource\/employee-data-privacy-balancing-monitoring-and-trust\/\" target=\"_blank\" rel=\"noopener\">Protecting your employee data<\/a> demonstrates that you care about the people working for you. And doing so when it\u2019s not required may even make your employees more loyal to your organization.<\/p>\n<h3>Don\u2019t sweat the small stuff<\/h3>\n<p>The data protection industry is ever-changing. The amount of information and news can be overwhelming. You have to separate what\u2019s most important from the noise. It\u2019s impossible to focus on everything.<\/p>\n<p>To avoid being buried by the small things,\u00a0<strong>the bottom line is, what is the organization\u2019s risk tolerance?<\/strong>\u00a0Don\u2019t try to over-due it, be flexible and ready for new regulations and unexpected developments. Work within the parameters of the organization\u2019s risk tolerance and leave enough room in your privacy compliance roadmap for surprises.<\/p>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\t<div class=\"right sm\">\n\t\t\t\t<div class=\"share-it\">\n\t\t\t\t\t<strong class=\"title block uppercase\">Follow us<\/strong>\n\t\t\t\t\t<div class=\"soc-list\">\n\t\t\t\t\t\t<a href=\"https:\/\/www.linkedin.com\/company\/trustarc\/\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/li-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"\nhttps:\/\/twitter.com\/TrustArc\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/tw-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"javascript:;\" id=\"copy-url\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/link-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<span class=\"copied\" style=\"display:none;\">Link Copied!<\/span>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<div class=\"key-topics\">\n\t\t\t\t\t\t<strong class=\"title block uppercase\">Key Topics<\/strong>\n\t\t\t\t\t\t<ul>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/compliance\/\" class=\"badge\">Compliance<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"cta-area\">\n\t\t\t\t\t<p>Get the latest resources sent to your inbox<\/p>\n\t\t\t\t\t<a href=\"\/subscription-center\/\" class=\"cta\">Subscribe<\/a>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t<\/section>\n\t\n\n\t\t<section id=\"block_88bc13b7372a9fad3a8c5e5b9ece5ee2\" class=\"resource-section\">\n\t\t\t<div class=\"container\">\n\t\t\t<div class=\"resource-head\">\n\t\t\t\t\t\t\t<h2>Related resources<\/h2>\n\t\t\t\t<a href=\"\/resources\/\" class=\"cta block\">View all resources<\/a>\t\t<\/div>\n\t\t\t\t\t\t<ul class=\"resource-lists \">\n\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/global-life-sciences-leader-case-study\/\" class=\"resource-single\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-rect-gray-test-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Case Studies<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>From Days to Minutes: How a Global Life Sciences Leader Automated Global Privacy Compliance<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/india-dpdpa-compliance-checklist\/\" class=\"resource-single\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-rect-blue-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Infographics, Research<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>India\u2019s Digital Personal Data Protection Act (DPDPA) Compliance Checklist<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/global-privacy-trends-apac-consent-latam-adtech-gcc-data-rights\/\" class=\"resource-single\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-woven-pink-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Articles<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Emerging Global Privacy Trends: APAC UX Consent, LATAM AdTech Restrictions, GCC Data Rights Expansion<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\t\t<\/section>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Get your 2023 privacy compliance roadmap and confidently navigate your organization&#8217;s key data protection and privacy regulation considerations.<\/p>\n","protected":false},"featured_media":1686,"template":"","topic-resource":[61],"type-resource":[6],"class_list":["post-2567","resource","type-resource","status-publish","has-post-thumbnail","hentry","topic-resource-compliance","type-resource-articles"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Navigating Your 2023 Privacy Compliance Roadmap: Tips for Companies | TrustArc<\/title>\n<meta name=\"description\" content=\"Get your 2023 privacy compliance roadmap and confidently navigate your organization&#039;s key data protection and privacy regulation considerations.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustarc.com\/resource\/your-2023-privacy-compliance-roadmap-tips\/\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/your-2023-privacy-compliance-roadmap-tips\\\/\",\"url\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/your-2023-privacy-compliance-roadmap-tips\\\/\",\"name\":\"Navigating Your 2023 Privacy Compliance Roadmap: Tips for Companies | TrustArc\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/your-2023-privacy-compliance-roadmap-tips\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/your-2023-privacy-compliance-roadmap-tips\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/res-feat-city-pink.png\",\"datePublished\":\"2023-03-29T20:01:00+00:00\",\"dateModified\":\"2025-05-08T19:13:49+00:00\",\"description\":\"Get your 2023 privacy compliance roadmap and confidently navigate your organization's key data protection and privacy regulation considerations.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/trustarc.com\\\/resource\\\/your-2023-privacy-compliance-roadmap-tips\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/your-2023-privacy-compliance-roadmap-tips\\\/#primaryimage\",\"url\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/res-feat-city-pink.png\",\"contentUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/res-feat-city-pink.png\",\"width\":610,\"height\":152},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\",\"url\":\"https:\\\/\\\/trustarc.com\\\/\",\"name\":\"TrustArc\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/trustarc.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Navigating Your 2023 Privacy Compliance Roadmap: Tips for Companies | TrustArc","description":"Get your 2023 privacy compliance roadmap and confidently navigate your organization's key data protection and privacy regulation considerations.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustarc.com\/resource\/your-2023-privacy-compliance-roadmap-tips\/","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustarc.com\/resource\/your-2023-privacy-compliance-roadmap-tips\/","url":"https:\/\/trustarc.com\/resource\/your-2023-privacy-compliance-roadmap-tips\/","name":"Navigating Your 2023 Privacy Compliance Roadmap: Tips for Companies | TrustArc","isPartOf":{"@id":"https:\/\/trustarc.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustarc.com\/resource\/your-2023-privacy-compliance-roadmap-tips\/#primaryimage"},"image":{"@id":"https:\/\/trustarc.com\/resource\/your-2023-privacy-compliance-roadmap-tips\/#primaryimage"},"thumbnailUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-city-pink.png","datePublished":"2023-03-29T20:01:00+00:00","dateModified":"2025-05-08T19:13:49+00:00","description":"Get your 2023 privacy compliance roadmap and confidently navigate your organization's key data protection and privacy regulation considerations.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustarc.com\/resource\/your-2023-privacy-compliance-roadmap-tips\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/trustarc.com\/resource\/your-2023-privacy-compliance-roadmap-tips\/#primaryimage","url":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-city-pink.png","contentUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-city-pink.png","width":610,"height":152},{"@type":"WebSite","@id":"https:\/\/trustarc.com\/#website","url":"https:\/\/trustarc.com\/","name":"TrustArc","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustarc.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource\/2567","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource"}],"about":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/types\/resource"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media\/1686"}],"wp:attachment":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media?parent=2567"}],"wp:term":[{"taxonomy":"topic-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/topic-resource?post=2567"},{"taxonomy":"type-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/type-resource?post=2567"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}