10: 5 Privacy and Compliance Flashcards

1
Q

Jurisdiction of laws that can apply to organizations

A

Federal, State, Industry (worldwide)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

PII

A

Personally Identifiable Information, info that can be traced back to an individual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

PHI

A

Protected Health Information - Individually identifiable health records governed under HIPAA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

GAPP

A

Generally accepted privacy principles - outlines 10 components of data privacy that can help orgs develop their own privacy programs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Management

A

Organizations handling private info should have policies, procedures, governance in place to protect privacy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Notice

A

Data subjects should receive notice that their info is being used and collected, as well as privacy policies and procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Choice and Consent

A

Org should inform data subjects of their options regarding data they own

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Collection

A

Organization should only collect information for disclosed purposes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Use, retention and disposal

A

Org should only use information for disclosed purposes and dispose when needed securely

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Access

A

Orgs should provide data subjects with the ability to review and update their information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Disclosure to Third Parties

A

Orgs should only share information with 3rd parties if that sharing is consistent with disclosed purposes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Security

A

Org must secure private info against unauthorized access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Quality

A

Org should take reasonable steps to ensure the private information is accurate, complete, and relevant

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Monitoring and Enforcement

A

Org should have program in place to monitor compliance with its privacy policies and provide dispute resolution mechanism

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Data Breach Consequences

A

Reputational damage, Identity Theft, Fines, Intellectual Property Theft

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Industry Specific Rules

A

HIPAA, SOX, PCI DSS

17
Q

Jurisdiction Specifics

A

GDPR

18
Q

Common PII elements

A

Social Security #, Driver’s license #, Bank Account #s

19
Q

Breach reaction poicies

A

Notify victims and government of breaches