Data Subject Rights Flashcards

1
Q

Name four examples of privacy notice design strategies:

A

Layered approach, Just-in-Time notice, Icons/Symbols, Privacy Dashboard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is a layered privacy notice? When should you use one?

A

Layered approach: when the notice has a lot of information
* Short notice with key information
* Links that expand topics or one link that leads to longer privacy notice
* Website search leads to the full notice

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a Just in Time notice? When should you use one?

A

Just-in-time notice: when you do not have a lot of space for communicating the notice
* Type of layered approach
* Notice appears at time of data input
* More information available through link or by hovering
* Alerts/notifications on smart phone

The CPRA requires a just-in-time notice if a business “collects personal information from a consumer’s mobile device for a purpose that the consumer would not reasonably expect.”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

When should you use icons/symbols in a privacy notice?

A

Icons/symbols: when you need to provide clarity
* Type of layered approach
* Indicators of types of processing
* Hyperlinks or hover states may provide more information
* Clear design
* Icon/symbol key

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a privacy dashboard?

A

Privacy dashboard: when you need to provide accessibility and a high-level overview
* Summary of privacy-related information and metrics
* Easy to access and navigate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does a privacy notice explain?

A

o Who the organization is
o What information it collects
o How it will use the information
o With whom it will share the information
o Whether information is collected directly or indirectly
o What are likely future uses of the information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

True or False: Providing a privacy notice implies consent

A

False. Privacy notices inform individuals of an organization’s privacy practices, but do not solicit or imply consent.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the difference between opting in and opting out?

A

Opting in involves an active, affirmative indication, whereas with opting out, a lack of action implies a choice

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the main considerations when presenting privacy notices to children?

A

o Compliance: some laws specify rules for providing privacy notice to children and obtaining parental consent

o Language and delivery: present privacy in ways children can understand

o Age: laws and regulations may establish an age threshold for consent

o Purpose of processing: some purposes may trigger certain rules, like prohibiting the tracking of children for behavioral advertising

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Name three EU-specific data subject rights:

A

-Data portability: personal data must be interoperable—transferrable from one organization to the individual, another controller or a third party designated by the individual in a format that is, according to Article 20 of the GDPR, “structured, commonly used and machine-readable,” and without hindrance.

-Erasure + Right to be Forgotten: Ceasing processing, deleting data, and taking steps to ensure data is deleted by third parties upon withdrawal of subject consent (if subject info was made public)

-Right to Object: With a valid objection, the controller is no longer allowed to process the data subject’s personal data unless it can demonstrate compelling, legitimate grounds for the processing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly