Privacy Laws Flashcards
What is the purpose of privacy laws?
To safeguard personal or sensitive information stored by organisations about people.
List some items that would be classified as personal information.
Name, address, age, sex, shopping habits, personal opinions, living arrangements, partners, children etc.
What is not classified as personal information in business?
Records held by an employer about an employee, including health information.
List some items that would be classified as sensitive information.
racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, membership of a trade union, sexual preferences or practices, criminal record.
List some items that would be classified as medical information.
medical history, current medical condition and treatments, dental records, genetic information, notes and opinions of health service provider (e.g. doctor, psychiatrist).
What is the year in which the Federal Privacy Act was legislated?
1988
Who is subject to the Federal Privacy Act of 1988?
Any federal government department
Any private organisation which:
• Turns over $3 million or more annually, or
• Profits from trading in personal information, or
• Holds health information about people (not including employees)
What forms the basis of the rules of the Privacy Act?
The Information Privacy Principles (IPPs)
List the ten IPPs.
1) Collection
2) Use and disclosure
3) Data quality
4) Data security
5) Openness
6) Access and correction
7) Identifiers
8) Anonymity
9) Transborder data flow
10) Sensitive information
Describe the IPP of Collection.
Organisations should only collect personal information that is necessary for one or more of its functions and activities.
Describe the IPP of Use and Disclosure.
An organisation must not use or disclose information about an individual for any other purpose (a secondary purpose) other than the purpose for which the information was collected, except in a number of exceptions specified in the Act.
Describe the IPP of Data Quality.
An organisation must take reasonable steps to ensure that the personal information it collects, uses or discloses is accurate, complete and up to date.
Describe the IPP of Data Security.
An organisation must take reasonable steps to ensure that the personal information that it collects is protected from misuse such as unauthorised access, modification or disclosure, or loss.
Describe the IPP of Openness.
An organisation must set out in a document a clearly expressed policy on its management of personal information and make this document available to anyone who asks for it.
Describe the IPP of Access and Correction.
If an organisation holds personal information about an individual, it must provide the individual with access to the information on request by the individual.