Privacy Operational Lifecycle - Section III.D. - Respond: Data Subject Request Flashcards

1
Q

True or False: It is always best practice to provide consumers an electronic form in which to exercise opt-out consent.

A

False. Best practice is to permit consumer choice in the same form as you are communicating with a consumer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

True or False: The right to request information under Article 15 of the GDPR is limited to what information is processed and the reasons for processing.

A

False. There are at least eight required disclosures that must be made under Article 15, including the source of the information and the period of retention, among other disclosures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the “No Option” form of consent?

A

Consent that is inferred based upon the context of a transaction or a company’s relationship with a consumer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What two requirements are necessary for the right not to be subject to automated processing to apply under the GDPR?

A

(1) The decision-making is based solely on automated processing; and
(2) The processing “produces legal effects concerning him or her or similarly significantly affects him or her.”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

As a general rule, should data be processed according to the privacy notice currently in effect or the privacy notice in effect at the time data was collected?

A

The privacy notice in effect at the time the data was collected.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are some consequences that an organization may face if it fails to adequately respond to data subject requests?

A

Individual lawsuits,
regulatory scrutiny, and
adverse market consequences.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Other than the obligation to respond, what is another important component of most data protection laws related to data subject rights requests that organizations must address?

A

The timing in which organizations have to respond.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are some best practices for responding to data subject requests?

A

Data subject requests should be fulfilled in their entirety in a timely manner, without charge to the individual, and in the same form as the request was made.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does the GDPR require for consent to be considered valid before processing activities can begin?

A

It must be “freely given.”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the age of consent for data processing in the European Union under the GDPR?

A

16 years old, but member states can lower that age to as low as 13 years old.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are privacy icons?

A

A symbol that indicates certain privacy practices of an organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Under the transparency-related requirements of the GDPR, when must data controllers make disclosures about their data practices to data subjects?

A

At the time when personal information is obtained.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the three main ways to present consumers a choice about whether they would like their data collected?

A

(1) Opt-in consent;
(2) Opt-out consent; and
(3) “No option” consent.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

True or False: Data subject requests typically are made to organizations through one point of contact with the organization.

A

False. Data subject requests and complaints can take many forms and reach an organization through many different channels.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What three tasks are vital for any robust data subject request or complaint handling process?

A

(1) Differentiate between the types of requests received;
(2) Identify the proper recipient to handle the request;
(3) Implement a centralized process that can receive and track the handling of the request or complaint.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

All things being equal, what is the form of consent preferred by regulatory authorities?

A

Opt-in consent.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What data subject right under the GDPR was not provided for under its precursor, the Data Protection Directive?

A

The right to data portability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What right under the GDPR is often a prelude to further legal action by a data subject?

A

The right to access information under Article 15.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What two situations has the FTC stated always call for express, affirmative consumer consent?

A

(1) Before a company uses personal information in a manner materially different than the manner in which data was used when initially collected; and
(2) When particularly sensitive data is collected and processed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Under the GDPR, consent is not considered to have been freely given in the following situations:

A

If the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment.

21
Q

Other than applicable data protection laws and regulations, what is one other source of data subject rights?

A

Contractual agreements, such as those contained in an organization’s privacy notice.

22
Q

What are some of the primary purposes for providing consumers notice about their privacy-related rights?

A

(1) Compliance with applicable law;
(2) Building trust with consumers;
(3) Meeting market or industry-wide expectations;
(4) Providing transparency; and
(5) Providing details about how personal information is processed in an accessible manner.

23
Q

Who has the burden of establishing that a weighing of the legitimate interests of the data controller and the rights of a data subject comes out in their favor?

A

A data controller has the burden of demonstrating that its legitimate interests outweigh the rights of the data subject.

24
Q

How does the implementation of a centralized data subject request and complaint handling process facilitate information security?

A

It facilitates training for those involved in the process, such as how to verify and authenticate data subjects.

25
Q

What federal law in the United States provides data subject rights to individuals that may be enforced against federal government agencies?

A

The Privacy Act of 1974

26
Q

True or False: Federal law in the United States requires that consent be provided by a user before a web cookie may be placed on their computer.

A

False. This is a requirement in the EU, but not in the United States.

27
Q

True or False: The right to erasure is always available to data subjects under the GDPR.

A

False. The right to erasure applies only in limited situations.

28
Q

What four requirements must be met in order for consent to be considered valid under the GDPR?

A

Consent must be (1) freely given; (2) specific to the processing at issue; (3) informed; and (4) unambiguous.

29
Q

In designing and managing user preferences, organizations should be mindful of what three considerations?

A

(1) The scope of consent;
(2) The form of consent; and
(3) How consumer choice is implemented.

30
Q

True or False: Companies may be required to provide a privacy notice to their customers under federal laws in the United States.

A

True. Though there is no overarching obligation to have a privacy notice under federal law, some federal laws (such as the GLBA and HIPAA) have privacy notice requirements.

31
Q

What are the circumstances in which a member state of the European Union may restrict data subject rights under the GDPR by passing legislation?

A

Where doing so is necessary to safeguard the security of the nation or its public, to facilitate law enforcement, to facilitate public government functions, to protect judicial independence, to regulate certain professions, to protect the rights of other data subjects, or to permit the enforcement of civil claims.

32
Q

What obligation does Article 12 of the GDPR impose on data controllers?

A

The obligation to facilitate the exercise of data subject rights.

33
Q

Opt-out consent is also referred to as what other name?

A

Implied consent.

34
Q

True or False: The FTC has stated that consumers should provide affirmative consent before their data is used in a manner materially different than how data was used when first obtained.

A

True.

35
Q

What are some situations in which the FTC has said that a “no option” form a consent is permissible?

A

Product fulfillment,
Fraud prevention,
Internal operations,
Legal compliance, and
Most first-party marketing.

36
Q

True or False: “Opt-in” consent refers to a passive form of consumer consent implied by a person’s conduct.

A

False. This is referred to as “Opt-out” or implied consent.

37
Q

Who should always review a company’s privacy notice?

A

A lawyer and an employee/executive with the authority to make legal decisions on behalf of the company.

38
Q

Express consent is also referred to as what other name?

A

Opt-in consent.

39
Q

What must data controllers implement to verify the identity of data subjects making data subject rights requests under the GDPR?

A

Verification requirements that are reasonable and proportionate, while being limited to the minimum necessary to verify data subject identity.

40
Q

What law in the United States contains specific requirements necessary to obtain consent from a child before his or her data can be processed?

A

The Children’s Online Privacy Protection Act (“COPPA”).

41
Q

True or False: If a data subject requests that no further processing occur of his or her personal information, a data controller must erase the data because storing data is a form of data processing.

A

False. Although storing data is a form of data processing, a request made under Article 18 of the GDPR permits (and may require) a data controller to continue storing the relevant data.

42
Q

True or False: The data subject rights provided under the GDPR are sacrosanct and may never be restricted.

Unantastbar

A

False. Under Article 23, member states are permitted under certain circumstances to restrict data subject rights through legislation.

43
Q

True or False: An organization should never have more than one privacy notice active at any one time.

A

False. A company might consider having multiple privacy notices if different parts of a company or subsidiaries use data in fundamentally different ways.

44
Q

The effectiveness of privacy icons depends on what factor?

A

Whether the symbols are universally adopted or standardized in use.

45
Q

Does the requirement to provide a copy of any information requested by a data subject under the Right to Access materially expand upon this right?

A

No. The obligation to provide a copy does not widen the scope of the right to access; it is intended only as providing modality of a response.

46
Q

What state law implemented in the United States provides broad consumer rights similar to those afforded by the GDPR?

A

The California Consumer Privacy Act.

47
Q

True or False: The right to object to data processing is the same as the right to withdraw consent to processing.

A

False. The right to object to data processing is provided to data subjects when processing is based not on the consent of the individual.

48
Q

How best does a company make consumer choice meaningful?

A

The option of consumer choice should be provided at a time and in a context in which the consumer is making a decision about his or her data.