Legal Source Notes for WorkTwins Documents
These notes are for internal use and legal review. Do not treat them as legal advice.
Europe / UK
- GDPR Article 13 concerns information to be provided where personal data are collected from the data subject.
- GDPR Article 28 concerns processing by processors and processor contracts.
- GDPR Article 35 concerns Data Protection Impact Assessments for high-risk processing.
- UK ICO guidance emphasizes transparent privacy information and DPIAs for high-risk processing.
United States
- California CCPA/CPRA grants consumers rights such as knowing, deleting, correcting, and opting out of sale/share in covered cases.
- The FTC enforces against unfair or deceptive practices, so public statements must match actual product behavior.
LATAM
- Brazil LGPD is the Brazilian general data protection framework.
- Argentina, Mexico, Chile, and other LATAM jurisdictions have national data protection frameworks and rights-based privacy obligations.
- Chile Law 21.719 modernizes Chile's data protection regime and is expected to become fully effective after its transition period.
Payments and app distribution
- PayPal requires merchants to publish refunds/returns and privacy policies where required.
- PayPal and Stripe require merchants to comply with acceptable use / restricted business policies.
- PCI DSS applies to entities handling cardholder data environments; hosted payment providers can reduce direct card data handling.
- Apple App Store privacy details require disclosure of app privacy practices and third-party partner practices.