Chapter 9: International Privacy Flashcards
GDPR Personal Data
Any information that identifies an individual
GDPR applies to…
Anyone physically located in the EU
Who determines the purposes and means of processing personal information?
Data controller
Data Processor
Anyone that processed data on behalf of the controller
Dereferencing
Removing search results
GDPR dereferening only applies to
EU versions of search results
Adequacy decision
EU decides a country has adequate privacy laws and allows data transfers.
GDPR Consent
Written consent required for almost all cases
Clear and accessible
Must be able to revoke consent
GDPR Data subject rights (7)
Erasure/be forgotten
Access (Copy of the data and info about how it was collected)
Rectification
Restriction of processing (without erasure)
Data portability (in machine readable format)
Object (or opt out)
Automated individual decision making (for decisions of significance or legal impact)
GDPR Fines max
Up to €20 million or 4% of annual revenue (whichever is greater)
Countries with adequacy decisions (4)
JP, NZ, Argentina, Canada
US-EU Privacy Shield
Negotiated by the Dept. of commerce and EU
US companies in compliance with privacy framework could transact data with the EU
Basically, an adequacy decision for a company
Privacy shield struck down in…
2020
Alternatives to Privacy Shield (2)
Binding Corporate Rules
Standard Contractual Clauses
Binding Corporate Rules (BCR)
Complex agreements where all parties agree to adhere to GDPR standards
Must be legally binding
Who approves BCR’s?
A state supervisory authority after review
What happens if an organization must violate a BCR?
They must notify the appropriate EU authority.
Standard Contractual Clauses
Standard contractual language created by the EU to cover data transfers.
Two roles in Standard contractual clauses
Data Exporter
Data Importer
GDPR derogations
Specific and limited exemptions that permit transferring data outside the EU.
Situations allowing derogations
“Compelling legitimate interest” (Contractual, legal, public)
APEC Framework
Starting point for trade agreements. (Non-Binding)
9 principles
Cross Border Privacy Rules (CBPR)
APEC Privacy Safe Harbor
Who oversees APEC Privacy Framework for the US? (Govt agency and verifier)
FTC and TrustArc
GPEN
Global Privacy Enforcement Network
Global Privacy Enforcement Network
Created by the OECD to improve international cooperation enforcing privacy
GPEN Five part mission