19. International Agreements and Guidelines Flashcards
International Agreements and Guidelines
OECD
Organisation for Economic Cooperation and Development
- 30 member nations
- Guidelines on the protection of privacy and transborder flows of personal data
- Guidelines = Suggestions = NOT mandatory
- Issued 1980, updated 2013
International Agreements and Guidelines
Collection Limitation Principle
8 driving principles
Collection of personal data should be;
1. Limited
2. Lawful (fair means)
3. Knowledge of the subject
International Agreements and Guidelines
Data Quality Principle
8 driving principles
Data should be (for what it is being used for);
1. Complete
2. Current
3. Relevant
International Agreements and Guidelines
Purpose Specification Principle
8 driving principles
Subjects need to be told
1. Why data is being collected
2. The time it is being collected
3. Company only use it for whatever that purpose is
International Agreements and Guidelines
Use Limitation Principle
8 driving principles
Personal Data cannot be disclosed, made available
UNLESS;
1. consent from subject
2. authority of law
International Agreements and Guidelines
Security Safeguards Principle
8 driving principles
Reasonable safeguards in place to protect the data
International Agreements and Guidelines
Openness Principle
8 driving principles
Practices and policies to personal data must be communicated openly
- Subject must be easily able to establish the existence and nature of personal data
- its use and identity of org that has the data
International Agreements and Guidelines
Individual Participation Principle
8 driving principles
Find out which organisations have your data
- Subject should be able ot correct any of the data that is wrong
- Subject can challenge any requests that are denied
International Agreements and Guidelines
Accountability Principle
8 driving principles
Organisations are held accountable for complying with principles stated in the seven principles
International Agreements and Guidelines
Wassenaar Arrangement
Export/Import controls
Conventional Arms and Dual Use Goods and Technologies
- 41 countries
- Cryptography considered “dual use”
- Iran, Iraq, China, Russia - import restrictions. Want to spy on their citizens
- Security manager must know the cryptography laws of where you are exporting data to
International Agreements and Guidelines
10 categories
Wassenaar Arrangement
- Special materials and related equipment
- Materials Processing
- Electronics
- Computers
- 5.1 - Telecommunications, 5.2 Information Security
- Sensors and “lasers”
- Navigation and Avionics
- Marine
- Aerospace and propulsion