Introduction to privacy Flashcards
How do you define privacy?
The right to be let alone, an individuals right to control the collection, use and disclosure of personal information. Also includes the right to keep personal information private.
what are fair information practices?
set of guidelines for handling, storing, protecting and managing personal information
what are the four categories of FIPs (CRIM)
- controls of the information(information security, information quality)
- rights of individuals- notice, choice and consent, data subject access
- information life cycle- collection, use and retention, disclosure, destruction
- management- management and administration, monitoring, and enforcement
what states have privacy laws?
Virginia, California, Utah and Colorado
What is the definition of personal information?
any information relating to an identified or identifiable living individual.
note: applies to both electronic and paper records.
what are examples of personal information?
name, gender, address, telephone number, email address, martial status
what is sensitive information examples
SSN number, financial information, driver’s license number, medical records.
what is the definition of sensitive information?
data that is more significantly related to the notice of a reasonable expectation of privacy, such as medical or financial information.
When does personal information become non-personal?
when the information is anonymized to the point that the associated individual can no longer be identified.
T or F unless personal information is truly anonymized, privacy and data protection laws still apply
true
What is pseudonymized data?
data that has been processed in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information
For example: hashing, using blockchain, differential privacy
What are sources of personal information on a data subject?
public records, publicly available information, nonpublic information
what is non public information
information not easily accessible due to law or custom(e.g. medical records, financial information, adoption records.)
T or false, the same information may be public record publicly available and nonpublic
T
what is a data subject?
an individual about whom information is being processed (e.g. employee, consumer, patient)
what is a data controller?
an organization or individual with the authority to decide how and why information about data subjects is to be processed
what is a data processor
an organization or individual that processes data on behalf of the data controller
what is a data protection authority?
supervisory authority chartered to enforce privacy or data protection laws and regulations (DPA)
Does the U.S have a national data protection authority ?
No., but the FTC, state attorney generals, federal financial regulators play a role
Hypo: Identify who fulfills each role in the following scenario
Jim is employed by ABC company. The HR department keeps much of his personal data on file, and it contracts with a payroll company that directly deposits Jim’s paychecks into his bank account.
who is the data subject? data controller and data processor?
Jim- data subject
ABC company- data controller
HR company- data processor
Name ways to protect personal information
Markets, technology, law, self regulation/co-regulation
Name the privacy protection models
- few or no laws(Cuba)
- co-regulatory (Australia)
- sectoral- covers industry specific laws -(U.S.)
- Comprehensive omnibus laws- EU
what are the branches of the U.S. Government
executive, legislative, judicial
T or F? state constitutions may create stronger privacy rights that the federal constitution?
True
what is a consent decree/order in a data privacy context
an agreement or settlement that resolves a dispute between a regulator and a private party without admission of guilt or liability. It also describes the actions the defendant will take(e.g. defendant agrees to stop alleged illegal activity)
T or F- the FTC can assess fines directly in consent orders or decrees?
No, the matter must go to court
Does CAN-SPAM supersede a stricter state law?
Yes. it prempts a stricter state law
what is a privacy notice
a description of an organizations information management practices
what is the initial mechanism used by regulatory agencies to determine if a controller or a processor is complying with the law and with the organizations own privacy commitments?
privacy notices do this. privacy notices help data subjects enforce their rights
what is another name for a privacy notice?
privacy policy or privacy statement