Currently, there is no comprehensive West Virginia privacy law or West Virginia consumer privacy act in effect. Although there is no West Virginia privacy act being considered, West Virginia recognizes all four common law invasions of privacy in its state constitution.
Explanation of the Four Torts of Privacy Invasion
- Intrusion upon seclusion: This tort occurs when someone intentionally intrudes upon the private affairs or seclusion of another person in a manner that would be highly offensive to a reasonable person. It involves invading someone’s physical or personal space without their consent, such as through unauthorized surveillance or trespassing.
- Appropriation of likeness or identity: This tort, also known as the right of publicity, involves the unauthorized use of someone’s name, image, or likeness for commercial purposes. It generally applies to situations where a person’s image or identity is used without their consent in advertising, endorsements, or other promotional activities.
- Public disclosure of private facts: This tort occurs when private, non-public information about an individual is disclosed to the public without their consent, and the disclosure would be highly offensive to a reasonable person. It typically involves the public dissemination of personal details, such as private medical information, financial records, or intimate details of a person’s personal life.
- False light: False light is a tort that involves the publication or dissemination of false or misleading information about an individual that places them in a false or distorted light and is highly offensive to a reasonable person. It differs from defamation in that it does not necessarily involve making false statements about someone but rather presenting true information in a way that creates a false impression or conveys a false meaning.
What is a Comprehensive Privacy Law?
A comprehensive privacy law, also known as a comprehensive data protection law or a general data protection regulation, is a legal framework that sets out rules and regulations for the collection, use, storage, and protection of personal data. It is designed to safeguard individuals’ privacy rights and establish guidelines for organizations that handle personal information.
A comprehensive privacy law typically encompasses several key elements:
- Scope and applicability: It defines the types of personal data covered by the law and specifies the entities and individuals subject to its provisions. This may include businesses, government agencies, and other organizations that process personal data.
- Consent and individual rights: It outlines the requirements for obtaining valid consent from individuals before collecting and processing their personal data. It also grants individuals certain rights, such as the right to access their data, correct inaccuracies, and request its deletion.
- Data handling practices: It establishes rules and principles for how organizations should handle personal data. This may include requirements for data minimization (collecting only the necessary data), purpose limitation (using data only for specified purposes), and data accuracy.
- Security and data breaches: It mandates organizations to implement appropriate security measures to protect personal data from unauthorized access, loss, or misuse. It may also require organizations to report data breaches promptly and take necessary actions to mitigate harm.
- Enforcement and penalties: It establishes regulatory authorities responsible for enforcing the privacy law, conducting investigations, and imposing penalties or fines for non-compliance. The penalties may vary based on the severity of the violation.
The European Union’s General Data Protection Regulation (GDPR) is an example of a comprehensive privacy law that sets high standards for data protection and privacy across its member states. Many US states have also implemented comprehensive laws, and the trendsetter is California’s CPRA.