3: Privacy Prog Framework: Applicable Privacy Laws and Regs Flashcards

1
Q

What is a major driver for compliance?

A

data protection laws and regulations. The laws and regs often overlap, so consult legal to make sure all the relevant areas are covered

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Global Privacy Laws

A

enforcing how PI is collected and how data subjects are informed and have a right to decide how their PI is used.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

New areas of data protection? (4)

A

AI
ML
Data security measures and controls on new tech, like quantum computing
handing data during pandemics

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Omnibus laws (wrt other countries)

A

you have to abide by the laws of the country you are trying to do business in (not the country you are based in).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

2 important privacy frameworks that many countries have based their data protection laws on?

A
  • Organisation for Economic Co-operation and Development (OECD) guidelines on the protection of privacy and transborder flows of personal data & Asia-Pacific Economic Cooperation (APEC) privacy framework.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What concepts do the OECD and APEC cover?

A
  • colleciton limitation
    data quality
    purpose specification
    use limitation
    security safeguards
    openness
    individual participation
    accountability
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Commonalities btwn global privacy & data protection laws, regulations and standards

A

requirements for ensuring individual rights (access, correction and deletion) and obligations (safeguarding data).
also, contractual requirements, audit protocol, self-regulatory regimes, and market place expectaiton

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

EU General Data Protection Regulation

A

GDPR - framework for data protection with increased accountability for organizations.
Has become the global standard for data protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

General Provisions of the GDPR (3)

A

Subject-matter and Objectives
- protection of people wrt processing, protection and movement of personal data
Material scope
- processing of personal data
Territorial Scope
- processor or controller in the Union, whether the processing takes place in the Union or not

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

CCPA

A

California Consumer Privacy Act
-privacy rights for Californians and significant new data protection obligations for businesses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Other PI and Data Protection law examples (2)

A

Brazil LGPD
China PIPL Personal Information Protection Law
for businesses it resembles the GDPR, does not prevent the PRC (People Republic of China) from accessing data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Sectoral Privacy Laws

A

Privacy and data protection addressed through laws that apply to market sectors and industries, like:
Health care (Protected Health Information in the US, special categories of data in the EU)
Financial
Telecom - includes communication, metadata and location information
Online
Government
Education
Video - including online streaming
Marketing
Energy
HR/Employment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Self-Regulation

A

Industry standards and codes of conduct
Voluntary and contractual initiatives
i.e. PCI DSS, Verisign, CARU (children’s advertising review unity)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Cross-Border Data Transfers

A

Protective measures required when data is crossing borders
EU has the strictest requirements, transfers outside EEA (European Economic Area) are ok if the countries are deemed to have adequate levels of data protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Cross-Border Data Transfers with countries not deems to have adequate data protection…

A

SCC - Standard contractual clauses - valid method of data transfer
- assess on a case by case basis using a DTIA or TIA (Data transfer impact assessment or transfer impact assessment)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Steps for a DTIA or TIA

A
  • Map where the data is and where it is transferred to
  • identify the mechanisms used for the transfer
  • assess effectiveness of transfer mech
  • adopt additional safeguards as needed
  • ensure additional measures align with business requirements
  • monitor for ongoing compliance
17
Q

Question for a DTIA or TIA

A
  • Likelihood of government accessing data
  • is the data within scope of intelligence and law enforcement activities?
  • are proper protective measures in place?
  • what are the applicable privacy and security standards of the receiving country?
  • what are the general human rights ratings of the receiving country?
18
Q

“Surprise Mimimization”

A

is the country to which you’re transferring personal data to likely equivalent in terms of privacy protections?
Would a person who has entrusted you with personal data be likely to object to their data traveling to that country?

19
Q

Ensure the Privacy Program aligns with the Business Initiatives

A
  • compliance should be the baseline
  • PbD will further organizational goals and help strike a balance
  • compliance creates an opportunities to reevaluate and improve data management practices (like data inventory and data access controls)
  • compliance should be achieved with the least amount of business disruption
20
Q

Penalties for Noncompliance

A

Legal and regulatory penalties are typically imposed by and industry to enforce behaviour modification due to previous neglect or improper protection of data

21
Q

HIPAA Violation Penalties

A

4 tiers
$100 up to $1.5 million/year

22
Q

GDPR Violation Penalties

A

two tiers of maximum fines, depends on:
Nature, gravity, and duration of infringement,
Nature, scope and purpose of processing
Number of data subjects concerned
Level of damage and damage mitigation
Intent or negligence
Degree of responsibility
Previous infringements
Degree of cooperation with a supervisory authority
Categories of personal data
Manner of notification
Compliance with measures ordered by supervisory authorities
Adherence to approved codes of conduct/certification mechanisms

23
Q

Scope and Authority of Oversight Agencies

A

“watchful care, management, or supervision”
oversight agencies can fine or impose penalties, civil and criminal, based on laws and regulations
DPA - data protection agencies

24
Q

Monitoring Laws and Regulations

A

Keep up to date on changes, new laws, changing regulations
Consider using a 3rd Party external privacy resource