APEC, OECD, etc Flashcards
What is APEC?
21 nations on the Pacific Coast in Asia and Americas, in a non-binding agreement. Formed in 1989.
What is the APEC Privacy Subgroup?
Developed in 2003, it’s for “developing a framework for privacy practices”
APEC Cross-Border Privacy Enforcement Agreement
CPEA.
1) Facilitates info sharing among Privacy Enforcers (PEs) in APEC countries
2) promotes effective cooperation between countries for enforcement/investigation in APEC
3) “” outside of APEC
APEC Cross-Border Privacy Rules
CBPR- data privacy certification based around APEC privacy framework.
APEC CBPR Requirements
- Enforceable standards
- Accountability (ID one person)
- Risk-based protections
- Consumer friendly complaint handling
- Consumer empowerment (access, correct data)
- Consistent protection
- Cross-border enforcement cooperation
Which US agency participates in APEC CBPR and CPEA?
FTC
What is the full name of the OECD Guidelines?
Guidelines Governing the Protection of privacy and Transborder Flows of Personal Data
What are the OECD Guidelines principles? (8)
ACID SOUP
- Accountability: data controller supports the above
- Collection limitation: limit collection, get consent when needed.
- Individual participation: Ppl have the right to know if someone has their data. You can ask for the data, and if they say no, challenge it and know why
- Data quality: data is relevant to the reason it was collected. It’s accurate and complete
- Security Safeguards: have ‘em
- Openness: Openness in development, policies, and practices
- Use limitation: Don’t disclose unless you have consent/by law
- Purpose specification: Reason for collecting data shared when it’s collected. Don’t change reasons later
What are the OECD Guidelines based on?
FIPs- perhaps the “most widely recognized framework for FIPS”
EU-US Privacy Shield- what is it, who does it cover?
- Follows transfer of data from EU to US for participating companies.
Only companies under FTC jurisdiction apply. No EU coverage.
23 principles
EU-US Privacy Shield- Exceptions
Healthcare, FinServ, and nonprofits are not covered.
EU-US Privacy Shield- Primary Principles (7)
CASE AND
Of the 23, the primary ones are: Choice Accountability of Transfer Security Enforcement/Recourse/Liability Access Notice Data Security/Purpose Limitation
Who enforces EU-US Privacy Shield?
Dept of Commerce, for those companies covered by the FTC.
It’s in contest!
“Consumer Data Privacy in a Networked World” Paper, 2012 (7)
FAT AIRS
AKA “the White House Report.” 7 focus areas:
- Focused collection
- Access and accuracy
- Transparency (privacy and sec docs should be easily understandable)
- Accountability
- Individual control
- Respect for context (data is used for reasonable things)
- Security
Based on FIPS
“Protecting Consumer Privacy in an Era of Rapid Change: Recommendations for Businesses and Policymakers” 2012 (3)
Privacy by design, simplified consumer choice, and transparency are key.
Based on FIPS