17. US Law, EU Law, International Treaties Flashcards
US Law, EU Law, International Treaties
PII
Personally Identifiable Information
- your right for this data to be kept securely
- US privacy - patchwork of laws, no real protection
- EU law - very pro privacy
- Data used to uniquely (in case of a single person);
1. Identify
2. Contact
3. Locate
US Law, EU Law, International Treaties
HIPAA
US
Health Insurance Portability and Accountability Act
- Strict privacy and security rules for handling PHI
- PHI = Protected Health Information
US Law, EU Law, International Treaties
Security Breach Notifications Laws
US
Not Federal Law
- 50 states have individual laws
- Encryption clause - if company lost PII records but data was encrypted, and assume strong enough to not break, company may not have to notify anyone
US Law, EU Law, International Treaties
ECPA
US
Electronic Communications Privacy Act
- Protection against warrantless wiretapping
- Weakened by Patriot act 2001
US Law, EU Law, International Treaties
PATRIOT Act 2001
US
Expands law enforcement electronic monitoring capabilities
- Allows search and seizure without immediate disclosure
- Allows ISPs to hand over private information voluntarily
US Law, EU Law, International Treaties
CFAA
US
Computer Fraud Abuse Act
Title 18 Section 1030
- most commonly used law to prosecute computer crimes
- 2008 - Identity Theft Enforcement and Restitution Act amendment was added
- If individual or company is known to have violated 2008 amendment, can resul tin criminal penalties
US Law, EU Law, International Treaties
Gramm-Leach-Biley Act
US
GLBA
Financial Institutions
- Driven by federal financial institutions
US Law, EU Law, International Treaties
Sarbanes-Oxley Act of 2002
US
SOX
Accounting Scandals
- mandatory standards for accounting
US Law, EU Law, International Treaties
PCI-DSS
US
Payment Card Industry Data Security Standard
- Technically not a law. Created by payment card industry
- Requires merchants to meet minimum set of security requirements
- Mandates security policy, devices, control techniques and monitoring
US Law, EU Law, International Treaties