Hello intelligent friends I need help. Let me preface this by saying I am an IT professional but I don't specialize in security. I know enough security to do IT but I don't know about a lot of regulations relating to privacy, so that is specifically what I need help finding. Please don't respond with basic IT suggestions, I'm looking for a regulation in the USA if it exists because my research has come up with nada.
I came into a conundrum at work where I hooked IMAP with our CRM and all of my emails from my work account went to the CRM. that's fine and what I wanted. But those emails... Are visible to everyone in my org in the CRM. So, on Monday, I sent myself my tax return to my personal email via my work email (done through Outlook), and the CRM grabbed out the fact that I had sent an email from an external client, and put that information in the news feed of the CRM. Again, not the biggest deal - but in the CRM, in the news feed... You can open my emails. You can download my tax return. Big no-no.
So basically I spent like 2 hours trying to remove this data, and the CRM has garbage UX and the deletion basically is not working from any front. I'm also an administrator for the CRM. The email will not delete from the news feed and is not anywhere in the email app in the CRM, it only exists in the news feed. I also turned off IMAP and gave it a whack password before I did, so there's no way it's updating at this point with my email.
It's not going away.
So we talked to support, and literally support said "you can't delete from news feed. Sorry about it." (Verbatim)
Where I'm at now is in the boat where I need to tell them that they can fly a kite because we should have the right to delete our data if we wish. They won't allow me to delete my tax return from everyone's view. I left it for now because the CRM is encrypted with SHA256 so it's probably secure from there (relatively), but folks with access to our CRM account including the manufacturer have access to that data.
So my question for you, smart folks, is this: I've been searching for data privacy laws in the US and have come up with nothing of value. The EU has GDPR which gives you the right to delete your data. But unfortunately we aren't in the EU (or California or another state where they have similar laws to gdpr). I am looking for a privacy law that gives me the right to delete my data, especially if it includes my social security number or other PII. I believe NIST has some guidelines for this but I'm not coming up with much. Does anyone know of a regulation giving me the right to delete this data? The USA has absolute trash data privacy laws.
Thanks in advance.
SOCIAL SHARE CARD GENERATOR