Intro Privacy Flashcards
Name the important FIPS and the years
-The 1973 U.S. Department of Health, Education and Welfare Fair Information
Practice Principles
-The 1980 Organisation for Economic Co-operation and Development (OECD)
Guidelines on the Protection of Privacy and Transborder Flows of Personal
Data (“OECD Guidelines” )
-The 1981 Council of Europe Convention for the Protection of Individuals with Regard to the Automatic Processing of Personal Data (“Convention 108”)
-The Asia-Pacific Economic Cooperation (APEC), which in 2004 agreed to a
Privacy Framework
-The 2009 Madrid Resolution–International Standards on the Protection of Personal Data and Privacy
FIPS HEW
-no personal record keeping that is secret
-a person to find out what is in the record and how it is used
-person can prevent info that was collected for one purpose for other purposes
-correct and amend
-Organization to prevent misuse.
Personal
Personal names ssn passport- Identifiable - street address telephone number and email.
Sensitive personal information - Ssn financial drivers license.
Sensitive needs more protection.
Non personal
Sim terms - deidentified or anonymized
Pseuadonymized
Is IP address personal information?
Us fed agency’s under the privacy act say no! The FTC says Yes! When connected with breach of healthcare.
HIPAA applies to
Covered Entities and for Personal health information only.
Sources of Personal information
Public Records - govt info
Publicly Available - Telephone Book
Non public Information
Can info be public record, publicly available or non public?
Yes. A name and address as an example. Restrictions may apply to a name and address in a healthcare file.
Processing Personal Information
Collection, Recording, organization, storage, updating or modification, retrieval, consultation and use of personal information.
Data Subject
Data controller
Data processor
Data Subject
About whom the data is being collected
Data controller
Org that has authority how and why personal info is to be processed. Can be individual or organization (corporations or partnership). Focus
Data Processor
Individual or Org. Hippa calls them Business associates. Third party’s expected to follow the same rules and can’t do extra.
Sources of Privacy Protection
Markets
Technology
Law
Self regulation
Co regulation.
Sources of Privacy Protection markets
Let the market dictate
Sources of privacy protection technology
Encryption. Security best practice
Sources of privacy protection law
Traditional approach - “laws may not be well drafted and may be poorly enforced”
Sources of Privacy protection self regulation
Compliment the law.
Legislation - who defines privacy rules.
Enforcement - data protection authorities DPA, other government agencies, industry code enforcement or affected individuals.
Adjudication- who is guilty??industry association, government agency or judicial officer.
World Models of Data Protection
Comprehensive
Sectoral
Co-Regulatory and Self-Regulatory Models