Privacy Law Flashcards
Name given to laws in this subject in the USA.
privacy law
Name given to laws in the subject in the EU.
data protection law
What is included in the class of privacy known as information privacy?
Concerned with establishing rules that govern the collection and handling of personal information (ex. financial information, government records, internet history)
Define “sensitive personal information.”
“special categories of data”
Personal data revealing racial of ethnic origins, political opinions, religious or philosophical beliefs, trade union memberships, or data concerning health or sex life
The line between personal and nonpersonal information depends on what?
Depends on what is “identifiable” and is often unclear
What are the 3 sources of personal information?
- public records
- publicly available information
- nonpublic information
Define “processing.”
The collection, recording, organization, storage, updating or modification, retrieval, consultation, and use of personal information. Also includes dissemination of information.
Define “data subject.”
Is the individual about whom information is being processed.
Define “data controller.”
Is an organization that has the authority to decide how and why personal information is to be processed.
Define “data processor.”
Is an individaul/organization (often a third-party) that processes data on behalf of the data controller.
Typical elements of personal information:
Name, gender, contact information, age & dob, marital status, income, education, languages spoken
Typical elements of human resources information:
Salary, job title, productivity and performance statistics, medical and pension benefits, employee evaluations, disabled veteran status, location information (GPS), nationality
Typical elements of customer information:
Contact information, purchase history, history of interactions, info about leads or prospects, former customers, market research participants, recording of telephone calls, citizens that receive benefits from government, tax records
Privacy notice
A statement made to a data subject that describes how an org collects, uses, retains, and discloses personal info (contracts, applications, icons, terms of use, etc.)
Serves two important services:
- consumer education
- organizational accountability
3 categories of safeguards
- administrative safeguards - company policies
- technical safeguards - passwords
- physical safeguards - a lock