M(2) 10 Fair Information Principles Flashcards

1
Q

Name the 10 Principles

A Ip C L L A S O Ia Cc

A

1) Accountability
2) Identifying Purposes
3) Consent
4) Limiting Collection
5) Limiting Use, Disclosure, Retention
6) Accuracy
7) Safeguards
8) Openness
9) Individual Access
10) Challenging Compliance
Form the ground rules for the CUD of personal information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

(1) Accountability

A

an organization is responsible for the info it CUD’s, and should appoint someone to this position

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

(2) Identifying Purposes

A

The purpose for the information being collected should be made clear before/at the time of collection

ie needs to be a reason for collection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

(3) Consent

A

Knowledge and consent of the individual are required for the CUD of personal information

EXCEPT - when breach of agreement/fraud is suspected

UNLESS - the law already gives consent ie bartender have consent to ask age under Liquer Control Act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

(4) Limiting Collection

A

The extent of information collected should be limited to what it’s intended use is, no unlawful or unfair means must be used

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

(5) Limited Use, Disclosure, and Retention

A

Unless the individual consents or it is required by law, personal information can only be used/disclosed for the purposes for which it was collected, and only kept as long as it serves that purpose

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

(6) Accuracy

A

(job of gov/org to uphold)
Personal information should be as accurate/complete and up to date as possible in order to properly satisfy the purposes for which it is to be used

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

(7) Safeguards

A

Personal information must be protected by an appropriate amount of proper security relative to the sensitivity of the information

(ie Security! )

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

(8) Openness

A

An organization must make detailed info about its privacy policies and practices public and readily available

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

(9) Individual Access

A

Upon request, an individual must be informed of the existence, use, and disclosure of their personal information and be given access to that information. An individual shall be able to challenge the accuracy and completeness of the information and have it amended as appropriate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

(10) Challenging Disclosure

A

An individual should be able to challenge an organizations compliance with the above principles, their challenge should be addressed to the person accountable for their organizations compliance with PIPEDA, usually their Chief Privacy Officer, this officer should be able to provide a reasonable reason

CA has two types :

(1) Power/Order Making - can make you do something
(2) Ombudsman’s - can’t make you do anything

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Additional OPC unreasonable purposes

A
  • CUD for unlawful purposes
  • profiling/categorizing in unethical/unfair ways
  • CUD of personal information for purposes known to cause harm
  • publishing personal information with the intent of charging for its removal
  • requiring passwords to social account of employees for screening
  • conducting surveillance on an individual using their own audio or video devices
How well did you know this?
1
Not at all
2
3
4
5
Perfectly