Intro Privacy Flashcards

1
Q

Name the important FIPS and the years

A

-The 1973 U.S. Department of Health, Education and Welfare Fair Information
Practice Principles
-The 1980 Organisation for Economic Co-operation and Development (OECD)
Guidelines on the Protection of Privacy and Transborder Flows of Personal
Data (“OECD Guidelines” )
-The 1981 Council of Europe Convention for the Protection of Individuals with Regard to the Automatic Processing of Personal Data (“Convention 108”)
-The Asia-Pacific Economic Cooperation (APEC), which in 2004 agreed to a
Privacy Framework
-The 2009 Madrid Resolution–International Standards on the Protection of Personal Data and Privacy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

FIPS HEW

A

-no personal record keeping that is secret
-a person to find out what is in the record and how it is used
-person can prevent info that was collected for one purpose for other purposes
-correct and amend
-Organization to prevent misuse.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Personal

A

Personal names ssn passport- Identifiable - street address telephone number and email.
Sensitive personal information - Ssn financial drivers license.
Sensitive needs more protection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Non personal

A

Sim terms - deidentified or anonymized
Pseuadonymized

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Is IP address personal information?

A

Us fed agency’s under the privacy act say no! The FTC says Yes! When connected with breach of healthcare.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

HIPAA applies to

A

Covered Entities and for Personal health information only.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Sources of Personal information

A

Public Records - govt info
Publicly Available - Telephone Book
Non public Information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Can info be public record, publicly available or non public?

A

Yes. A name and address as an example. Restrictions may apply to a name and address in a healthcare file.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Processing Personal Information

A

Collection, Recording, organization, storage, updating or modification, retrieval, consultation and use of personal information.
Data Subject
Data controller
Data processor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Data Subject

A

About whom the data is being collected

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Data controller

A

Org that has authority how and why personal info is to be processed. Can be individual or organization (corporations or partnership). Focus

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Data Processor

A

Individual or Org. Hippa calls them Business associates. Third party’s expected to follow the same rules and can’t do extra.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Sources of Privacy Protection

A

Markets
Technology
Law
Self regulation
Co regulation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Sources of Privacy Protection markets

A

Let the market dictate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Sources of privacy protection technology

A

Encryption. Security best practice

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Sources of privacy protection law

A

Traditional approach - “laws may not be well drafted and may be poorly enforced”

17
Q

Sources of Privacy protection self regulation

A

Compliment the law.
Legislation - who defines privacy rules.
Enforcement - data protection authorities DPA, other government agencies, industry code enforcement or affected individuals.
Adjudication- who is guilty??industry association, government agency or judicial officer.

18
Q

World Models of Data Protection

A

Comprehensive
Sectoral
Co-Regulatory and Self-Regulatory Models