Privacy Operational Life Cycle: Chapter 5 Protect: Personal data Flashcards
Privacy by Design
- Proactive
- Privacy by default
- Embedded in design
- Full Functionality - positive sum
- End to end security
- visibility and transparency
- Respect for user privacy
Data protection GDPR principles
- lawfulness, fairness, transparency
- purpose limitations
- data minimization
- accuracy
- storage limitations
- integrity and confidentiality
- accountability
CIA
Confidentiality Integrity Availability
Controls
Categories:
- Preventative
- Detective
- Corrective
Types:
- Physical
- Admin or policy
- Technical
Data Privacy and InfoSec
Integrity (InfoSec) and Accuracy (Privacy)
Availability (InfoSec) and Access (Privacy)
Accountability (Both)
Confidentiality (when personal and nonpublic)
Data classifications
Privacy: personal, sensitive, nonpersonal
InfoSec: public, confidential, highly confidential, restricted
Role-Based Access Controls (RBAC)
Segregation of duties
Least privilege
Need-to-know access
Linkability in data
Identified: linkable
Pseudonymous: linkable with reasonable effort, or not linkable
Anonymous: unlinkable
InfoSec + Privacy technologies
Teaming: work together to evaluate controls
Don’t Reinvent: use existing reviews/audits and existing review processes
Stay Aware: be aware of security and privacy risks
Rank and Prioritize
GDPR Article 25
Privacy by design
Privacy by default