Missed Questions Flashcards
What legislation ended certain bulk collection practices of the US government for national security purposes?
The USA Freedom Act
What are requirements regarding use of directory information under FERPA?
social security number may never be considered directory information
students must be provided right to opt out before directory info is shared
schools can determine their own list of what constitutes directory information
what organization created K-12 school service provider pledge to safeguard student privacy?
software and information industry association in concert with the Future Privacy Forum
pledgees agree not to undertake numerous activities as well as undertake affirmative obligations aimed at protecting student privacy
violation is enforced as deceptive trade practice by FTC
majority of state data breach notification laws include
requirement that notice to affected consumers be provided in writingm
minority of state data breach notification laws include
- materiality requirement for determining when breach occurs
- specific requirements about what must be included in notice to affected individuals
- inclusion of biometric data in definition of personal info
type of security failure that is primary cause of most data security incidents
human error
technical protection examples
computer code
electronic systems designed to limit access to authorized users and maintain integrity of data from outside attack
administrative protections examples
policies designed to limit access to data to only employees who need access to accomplish their assigned job functions
are non profit entities are subject to FTCs jurisdiction under FTC ACT or COPPA or both
neither FTC act nor COPPA
COPPA_ exempt from definition of operator
FTC- specifically exempt under FTC act
HITECH made the following changes to HIPAA
- business associates directly subject to HIPPA
- term limited data set is defined
- term covered entity, business associate, and protected health information are codified
didn’t change minimum necessary requirements
what feature of binding corporate rules separates it from other international transfer mechanisms available under GDPR
only apply to international data transfers that occur within an organization not transfers to 3rd parties
Fair Information Practice of access is commonly considered to include
- ability to view information an organization collects
- ability to update or correct inaccurate info
what must a user of a consumer report do before re-selling a consumer report?
notify CRA of
1. identity of end users of report
2. each permissible purpose to which the end user will be utilizing the report for
what are benefits of data flow mapping
- mitigate risk associated with data processing
- facilitate identifying problems within an organizations data processing
- increase confidence in regulatory compliance
doesn’t help limit amount of data disclosed in event of data breach
GDPR individual rights
- data portability
- rectify data
- right to be forgotten
- consent
doesn’t include right to opt out of data selling
National Institute of Standards and Technology recommends that employees be provided data privacy and security training when all of the following occurs
- upon being hired (or promoted)
- as needed by the organization
- when changes are made to the information system or policies
not once annually
What article in the GDPR makes it illegitimate to transfer data to a 3rd country or to an international organization in the absence of a valid transfer mechanism?
article 44
what type of privacy protection model is overseen by multiple regulators
sectoral model
- select market segments are governed by different privacy laws
- no overarching regulatory regimen applicable across the entire economy
standard order of privacy operational life cycle
assess (create processes to evaluate program)
protect (implement practices)
sustain (manage program)
respond (respond to failures)
when is no option form of consent to be expected
product fulfillment
fraud prevention
internal operations
legal compliance
public purpose
1st party marketing
CA attorney general has authority to bring civil action for violation in
- Consuperm Financial Protection Act
- Fair Credit Reporting Act
- Red Flags Rule
not GLBA
GLBA privacy rule notice requirement
notice must be provided at the start of customer relationship and annually thereafter
no requirement for notice to be online but doing so is a best practice and may be required under state law (CALOPPA)
what law or regulation was enacted to facilitate in certain cases the compassionate sharing of info related to patients
21st Century Cures Act
- HHS must issue guidance on compassionate sharing of mental health and substance abuse info with family members and caregivers
CCPA parental consent must be obtained before selling PI of children under what age
under 13 years old
13-15- may obtain consent directly from child through opt in procedure
what unique characteristic makes a consent decree different than most other types of contracts?
a consent decree is approved by a court which enters a judgement incorporating the parties settlement agreement
what change to the VPPA was made by congress in 2012
contemporaneous consent to disclosure of personally identifiable information is not necessary and a one time consent may be made that is valid for two years
social engineering refers to
manipulation of individuals so as to create security vulnerabilities
often used in concert with specific types of cyber attacks
two primary goals served by implementing legal protections over personal information
compensation to those ho have been wronged
create deterrence
what is thought of as the 3rd model of governmental privacy protection
co-regulatory model
combines aspects of self regulatory model and either comprehensive or sectoral model
industry will develop and enforce appropriate standards but that industry is then overseen by a government regulatory agency
Tennessee data breach notification law
amended law in 2016 to remove provision that exempted encryption data from notification requirements
following year it provided that a breach of encrypted data will only subject a company to the laws notice requirements where the encryption key is also compromised
HIPPA privacy rule not entitled to access to
psychotherapy notes
information compiled in anticipation of litigation or regulatory action
what jurisdiction recently imposed a requirement on employers utilizing automated tools to make employment decisions the requirement to conduct bias audits related to the use of any such tool?
New York city
must be subject of bias audit conducted no more than 1 year prior to use of tool
bias audit- impartial evaluation by independent auditor that includes assessment of its disparate impact on persons on basis of sex race or ethnicity
pseudonymizing data
process of transforming data so that it can no longer be attributed to a specific person without the use of additional information
can be reversed so that info can be reidentified with specific person
what type of information may never be shared with nonaffiliated 3rd party for marketing purposes under GLBA privacy rule
customer account number and access codes
what entities have authority to enforce HIPAA
department of HHS
state attorneys genera
department of justice
not private individuals
who the protection of pupil rights amendment act of 198 grants individual rights to
parents of student if student is under 18
student if student is over 18 or emancipated
medical examinations
ADA- prospective employee may be required to submit to medical examination if
- all entering employees are subject to same examination
- info about any med condition is kept separate form other info and treated as confidential med record
- results of test are used only in accordance with the other provisions of ADA
MAY NEVER BE USED UNLESS EXAM OR INQUIRY IS JOB RELATED AND CONSISTENT WITH BUSINESS NECESSITY
Fair Credit Reporting Act mandates what type of consumer consent with respect to the use of firm offers of credit or insurance
opt out consent
structure transaction under bank secrecy act
engaging in transactions in such a way as to avoid reporting requirements
what law does the department of labor enforce
fair labor standards act
employment retirement security act
houses occupational safety and health administration which oversees the enforcement of workplace safety
who bears the burden of considering the impact that a 3rd country’s laws will have on the use of standard contract clauses
controllers and processors that make use of the standard clauses
preemption GLBA vs FCRA
there is no preemption under GLBA
FCRA preempts state laws
exception for laws relating to identify theft and laws carved out by congress
Prism and upstream programs are authorized under which of the following
section 702 of the Fish amendment act of 2008
allows attorney general and director of national intelligence to jointly authorize for period of up to one year the targeting of persons outside the US to acquire foreign intelligence information
SCC schemes II
- supervisory authorities must prohibits use of SCC if they are not and cannot be complied with in 3rd county
- SCC must ensure essentially equivalent level of protection as that afforded under GDPR
- determining whether the use of SCC is valid requires consideration of the legal system of the 3rd country where data will be transferred
what is the third form of litigation
administrative enforcement action
CPPA is 1st administrative agency dedicated solely to consumer privacy issues and is created by CPRA