- Data Minimization: Limit collection of personal data to what is adequate, relevant, and reasonably necessary (such as, the specified and express purposes for processing).
- Purpose Limitation: Process personal data only for purposes reasonably necessary or compatible with the purposes disclosed to the consumer (for example, in a privacy notice).
- Security Controls: Establish, implement, and maintain 'reasonable administrative, technical, and physical data security practices' to protect consumers' personal data.
- Non-Discrimination: Not process personal data in a way that violates state or federal anti-discrimination laws.
- Consent: Obtain express consent from consumers when the business (1) processes sensitive data, or (2) deviates from the purposes of data processing disclosed to the consumer (for example, within the business's privacy notice).