Data privacy Flashcards
Data privacy
Data Privacy or information privacy is a branch of data security concerned with the proper handling of data consent, notice, and regulatory obligations.
Data Security
Data Security protects data from compromise by external attackers and malicious insiders.
motherfucking PDPA
Consent Obligation Purpose Limitation Obligation Notification Obligation Access and Correction Obligation Accuracy Obligation Protection Obligation Retention Limitation Obligation Transfer Limitation Obligation Accountability Obligation
Consent Obligation
Only collect, use, or disclose personal data for purposes for which an individual has given his or her consent
Purpose Limitation Obligation
An organisation may collect, use, or disclose personal data about an individual for the purposes that a reasonable person would consider appropriate in the circumstances and for which the individual has given consent.
Notification Obligation
Notify individuals of the purposes for which your organisation is intending to collect, use or disclose their personal data on or before such collection, use or disclosure of personal data.
Access and Correction Obligation
Upon request, the personal data of an individual and information about the ways in which his or her personal data has been or may have been used or disclosed within a year before the request should be provided. Organisations are also required to correct any error or omission in an individual’s personal data that is raised by the individual.
Accuracy Obligation
Make reasonable effort to ensure that personal data collected by or on behalf of your organisation is accurate and complete.
Protection Obligation
Make reasonable security arrangements to protect the personal data that your organisation possesses or controls to prevent unauthorised access, collection, use, disclosure, or similar risks.
Retention Limitation Obligation
Cease retention of personal data or remove the means by which the personal data can be associated with particular individuals when it is no longer necessary for any business or legal purpose.
Transfer Limitation Obligation
Transfer personal data to another country only according to the requirements prescribed under the regulations, to ensure that the standard of protection provided to the personal data so transferred will be comparable to the protection under the PDPA, unless exempted by the PDPC.