Privacy Law Flashcards

1
Q

Name given to laws in this subject in the USA.

A

privacy law

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Name given to laws in the subject in the EU.

A

data protection law

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is included in the class of privacy known as information privacy?

A

Concerned with establishing rules that govern the collection and handling of personal information (ex. financial information, government records, internet history)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Define “sensitive personal information.”

“special categories of data”

A

Personal data revealing racial of ethnic origins, political opinions, religious or philosophical beliefs, trade union memberships, or data concerning health or sex life

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

The line between personal and nonpersonal information depends on what?

A

Depends on what is “identifiable” and is often unclear

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the 3 sources of personal information?

A
  1. public records
  2. publicly available information
  3. nonpublic information
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Define “processing.”

A

The collection, recording, organization, storage, updating or modification, retrieval, consultation, and use of personal information. Also includes dissemination of information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Define “data subject.”

A

Is the individual about whom information is being processed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Define “data controller.”

A

Is an organization that has the authority to decide how and why personal information is to be processed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Define “data processor.”

A

Is an individaul/organization (often a third-party) that processes data on behalf of the data controller.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Typical elements of personal information:

A

Name, gender, contact information, age & dob, marital status, income, education, languages spoken

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Typical elements of human resources information:

A

Salary, job title, productivity and performance statistics, medical and pension benefits, employee evaluations, disabled veteran status, location information (GPS), nationality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Typical elements of customer information:

A

Contact information, purchase history, history of interactions, info about leads or prospects, former customers, market research participants, recording of telephone calls, citizens that receive benefits from government, tax records

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Privacy notice

A

A statement made to a data subject that describes how an org collects, uses, retains, and discloses personal info (contracts, applications, icons, terms of use, etc.)

Serves two important services:

  1. consumer education
  2. organizational accountability
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

3 categories of safeguards

A
  1. administrative safeguards - company policies
  2. technical safeguards - passwords
  3. physical safeguards - a lock
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Information lifecycle principles

A
  1. Collection
  2. Use
  3. Disclosure
  4. Storage & destruction
17
Q

What is a Privacy Impact Assessment (PIAs)?

A

Checklists or tools to ensure personal information system is evaluated for privacy risks and designed with life cycle principles in mind.

18
Q

What is a Privacy Assessment/Audit?

A

Reviews of an orgs compliance with its privacy policies and procedures, applicable laws, regulations, service-level agreements, standards adopted by the entity, and other contracts.

19
Q

Define “Privacy by Design”.

A

The concept that orgs should build privacy directly into technology, systems, and practices at the design phase to ensure privacy from the outset. (7 principles)