Intro Privacy Flashcards
Name the important FIPS and the years
-The 1973 U.S. Department of Health, Education and Welfare Fair Information
Practice Principles
-The 1980 Organisation for Economic Co-operation and Development (OECD)
Guidelines on the Protection of Privacy and Transborder Flows of Personal
Data (“OECD Guidelines” )
-The 1981 Council of Europe Convention for the Protection of Individuals with Regard to the Automatic Processing of Personal Data (“Convention 108”)
-The Asia-Pacific Economic Cooperation (APEC), which in 2004 agreed to a
Privacy Framework
-The 2009 Madrid Resolution–International Standards on the Protection of Personal Data and Privacy
FIPS HEW
-no personal record keeping that is secret
-a person to find out what is in the record and how it is used
-person can prevent info that was collected for one purpose for other purposes
-correct and amend
-Organization to prevent misuse.
Personal
Personal names ssn passport- Identifiable - street address telephone number and email.
Sensitive personal information - Ssn financial drivers license.
Sensitive needs more protection.
Non personal
Sim terms - deidentified or anonymized
Pseuadonymized
Is IP address personal information?
Us fed agency’s under the privacy act say no! The FTC says Yes! When connected with breach of healthcare.
HIPAA applies to
Covered Entities and for Personal health information only.
Sources of Personal information
Public Records - govt info
Publicly Available - Telephone Book
Non public Information
Can info be public record, publicly available or non public?
Yes. A name and address as an example. Restrictions may apply to a name and address in a healthcare file.
Processing Personal Information
Collection, Recording, organization, storage, updating or modification, retrieval, consultation and use of personal information.
Data Subject
Data controller
Data processor
Data Subject
About whom the data is being collected
Data controller
Org that has authority how and why personal info is to be processed. Can be individual or organization (corporations or partnership). Focus
Data Processor
Individual or Org. Hippa calls them Business associates. Third party’s expected to follow the same rules and can’t do extra.
Sources of Privacy Protection
Markets
Technology
Law
Self regulation
Co regulation.
Sources of Privacy Protection markets
Let the market dictate
Sources of privacy protection technology
Encryption. Security best practice