M13: Privacy and GDPR Flashcards

1
Q

Why do ecommerce sites use personalized features?

A

To build relationships with customers and increase purchases.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is a major privacy concern with ecommerce personalization?

A

Users worry about their personal data being inferred and accessed by others.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What might cause users to avoid ecommerce sites?

A

Privacy concerns and fear of unsolicited marketing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How can personalization systems improve user trust?

A

By enhancing privacy and ensuring data security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is one risk of personalization related to marketing?

A

Receiving unwanted emails, calls, and mail.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Why might users feel uncomfortable with personalization?

A

Because computers can infer personal information about them.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is price discrimination in the context of personalization?

A

Charging different prices based on user profiles.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How can personalization lead to unauthorized access?

A

If profiles contain passwords or sensitive information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a potential legal risk of storing user profiles?

A

Information might be subpoenaed in legal cases.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How can personalization systems limit data collection?

A

By only collecting necessary data and using pseudonymous profiles.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a pseudonymous profile?

A

A profile that uses a fake name to protect the user’s identity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How can client-side profiles enhance privacy?

A

By storing data on the user’s computer instead of a server.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the benefit of user-initiated personalization?1

A

Users are more aware and in control of the data being collected.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How can sites make personalization more privacy-friendly?

A

By providing clear notices and options to disable personalization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the role of fair information practice principles in personalization?

A

They guide the design of systems to protect user privacy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the main focus of the document?

A

The document focuses on data protection and security requirements under GDPR, specifically Articles 25 and 32.

17
Q

What is Article 32 about?

A

Article 32 deals with ensuring the security of data processing by implementing appropriate technical and organizational measures.

18
Q

Why is data protection by design important?

A

It ensures that data protection measures are integrated from the start of system development, making it easier to comply with GDPR.

19
Q

What does “data protection by default” mean?

A

It means setting systems and processes to automatically provide the highest level of data protection without requiring user intervention.

20
Q

What are some risks mentioned in the document?

A

Risks include unauthorized access, data breaches, accidental loss, and misuse of data.

21
Q

What is pseudonymization?

A

Pseudonymization is a process where personal data is processed in such a way that it cannot be attributed to a specific individual without additional information.

22
Q

Why is encryption important?

A

Encryption makes data unreadable to unauthorized users, protecting its confidentiality and integrity.

23
Q

What should be done in case of a data breach?

A

Organizations should have a plan to quickly restore access to data and ensure that the breach is contained and reported if necessary.

24
Q

What is the role of risk assessment in data protection?

A

Risk assessment helps identify potential threats to data security and determine the appropriate measures to mitigate those risks.

25
Q

What are some technical measures for data protection?

A

Technical measures include
* Antivirus software
* Firewalls,
* Encryption
* Regular software updates.

26
Q

What are some organizational measures for data protection?

A

Organizational measures include
* Employee training
* Access controls
* A clear data protection policy.

27
Q

How does GDPR define sensitive personal data?

A

Sensitive personal data includes information like
* Racial or ethnic origin,
* Political opinions
* Religious beliefs
* Health data.

28
Q

What is the purpose of data minimization?

A

Data minimization aims to collect only the data that is necessary for a specific purpose, reducing the risk of misuse.

29
Q

What is the significance of ISO 27001?

A

ISO 27001 is an international standard for managing information security, helping organizations implement effective security controls.

30
Q

How can organizations ensure ongoing data protection?

A

By regularly reviewing and updating their data protection measures, conducting audits, and staying informed about new threats and regulations.