Privacy Fundamentals Flashcards

1
Q

What are the privacy classes?

A

Informational, territorial, bodily, communications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does UDHR cover for privacy and human rights?

A

Art 12- No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does ECHR cover with respect to privacy and human rights?

A

Art 8- Everyone has the right to respect for his private and family life, his home and his correspondence.

There shall be no interference by a public authority with the exercise of this right except such as is in accordance with the law and is necessary in a democratic society in the interests of national security, public safety, or the economic well being of the country, for the prevention of disorder or crime, for the protection of health or morals, or for the protection of rights and freedoms of others.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What principles is the US Fair Information Practices 1973 based on?

A
  1. No secret record systems
  2. Must have way to find our record and usage
  3. Way for preventing use for other purposes.
  4. Way for person to correct or amend a record.
  5. Any organisation creating / maintaining/ using/ disseminating records must Ensure reliability of data for their intended use.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the significance of Council of Europe 1981?

A

Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data

Basic principles:

  • Data quality
  • Special categories of data
  • Data Security
  • Data subject safeguards
  • Sanctions and remedies
  • Extended protection by states
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the scope covered by the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data?

A

Public and private sectors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the key EU directive?

A

Directive 95/46/EC of the European Parliament

Council of 24 Oct 1995

On the protection of individuals with regard to the processing of personal data and on the free movement of such data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the Madrid Resolution?

A

31st International Conference of Data Protection and Privacy - 50 countries approved the resolution.

Sets out 9 data principles:
Lawfulness and fairness 
Purpose specification 
Proportional Principle
Data Quality Principle 
Openness principle 
Accountability Principle 
Rights of individuals
Security measures
Breach notification
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

When was the European Data Protection Board created?

A

On 25 May 2018 it adopted the Guidelines previously issued by the Article 29 Working Party

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

When was the new Privacy Shield finalised?

A

2 Feb 2016

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the US definition of Personal Identifiable Information?

A

Any info relating to an identified or identifiable individual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does sensitive personal info mean in US?

A

Social security number
Financial info
Driver’s license no
Medical records

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does special categories of data mean in Europe?

A
Racial or ethnic origin 
Political opinions
Religious or philosophical beliefs
Trade union membership 
Health or sex life
Criminal convictions or offences
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the primary purposes of the APEC Privacy Framework as approved by the APEC ministers in 2004?

A

(a) improve information sharing among gov agencies and regulators
(b) improve info sharing among gov agencies and regulators
(c) encourage the use of electronic data as a means to enhance and expand business
(d) establish a common set of privacy principles
(E) provide technical assistance to those economies that have yet to address privacy from a regulatory or policy perspective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

In which countries has the European Commission determined there is adequate privacy protection?

A

Andorra, Argentina, Canada, Faeroe Islands, Guernsey, Isle of Man, Israel, Jersey, NZ; Switzerland, Uruguay, US

17 July 2018: Japan/EU concluded their talks on reciprocal adequacy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Which countries have been deemed not adequate?

A

Australia, Mexico, Korea, Japan, Taiwan

But 17 July 2018: Japan/EU conclude talks on reciprocal adequacy

17
Q

Which countries have comprehensive data protection models?

A

EU and HK

18
Q

Which countries have sectoral data protection models?

A

US, Brazil, India, South Korea, South Africa

19
Q

Which countries have co-regulatory data protection models?

A

Australia, NZ, Canada

20
Q

What does a co-regulatory model of data protection mean?

A

Industry development of enforceable codes or standards for privacy and data protection against the backdrop of legal requirements by the government.

21
Q

Which of the following or combination is very similar to the OECD Data Quality Principle?

A

Purpose Limitation & Accuracy Obligation.

Personal data should be relevant to the purposes for which they are to be used, and to the extent necessary for these purposes, should be accurate, complete and kept up to date.

22
Q

What is considered personal info about an employee held by the human resources department of an employer?

A

Sick leave requests, salary, performance evaluations are typically unique to a particular person, and therefore may constitute personal info.

23
Q

What approach does the EU e-Privacy Directive take for unsolicited commercial electronic communications?

A

Opt in approach.

24
Q

How do the rules for government organisations compare to private organisations under the EU Data Protection Directive?

A

There are typically less strict legal rules for gov organisations that hold personal info than for private organisations.

25
Q

What are the APEC Economic Cooperation privacy principles

A
Preventing harm
Notice
Collection limitation 
Uses of PI
Choice
Integrity 
Security safeguards
Access and correction 
Accountability and data export limitations 

PNCUCISAA

Poking naughty cats , UCI so aching angry

26
Q

What are the Fair Information Privacy Practices

A

Efficiency Principle
Surveillance Principle
Finality Principle