Privacy Program Frameworks: Chapter 3 Flashcards

1
Q

Argentina

A

Personal Data Protection Law No 25,326 (PDPL)

Agency for Access to Public Information (AAPI)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Australia

A

Privacy act of 1988

Office of the Australian Information Commissioner (OAIC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Brazil

A

Lei Geral de Proteção de Dados (LGPD), Law No. 13.709/20183

Autoridade Nacional de Proteção de Dados (ANPD)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Canada

A

Personal Information Protection and Electronic Documents Act (PIPEDA)4

Office of the Privacy Commissioner of Canada (OPC)

Note: Canadian provinces have their own, often stricter, privacy laws

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

China

A

Cybersecurity Law of the People’s Republic of China

Cyberspace Administration of China (CAC

Data Security Law of the PRC
Personal Information Protection Law of PRC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

European Union

A

General Data Protection Regulations (GDPR)

Member state supervisory authorities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Hong Kong

A

Personal Data (Privacy) Ordinance

Office of the Privacy Commissioner for Personal Data (PCPD)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

India

A

Information Technology Act 2000
Ministry of Electronics and Information Technology (MeitY)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Israel

A

Protection of Privacy Law 5741-1981

Privacy Protection Authority

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Japan

A

Act on the Protection of Personal Information (APPI)

Personal Information Protection Commission (PIPC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

GDPR

A

Passed: 12/2016. Effective: 05/25/2018

Art 1: Subject matter and objectives
1. Natural persons
2. Fundamental freedoms
3. Free movement of personal data in the Union shall not be restricted

Art 2: Material Scope
1. automated or manual data
2. Not apply in certain issues
3. all member states
4. also directive 2000

Art 3: Territorial Scope
1. All controllers or processors in the union
2. Individuals in the union
3. Anywhere else where member state laws apply

Penalty: 4% of revenue, or 20m euros

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

GDPR Data subject rights

A
  • withdraw consent
  • request a copy of their data
  • request to move their data to another org
  • request to delete all their data
  • object to automated decision making, profiling
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

CCPA

A

Passed: June 2018. Effective Jan 1, 2020

Consumers:
- request a record for the type of data and how it is used / shared
- request erasure
- opt out of sale of data

Orgs:
- verification for consumers
- respond to DSARs within 45 days
- provide methods for receiving requests
- disclose to whom they sell their data, all do not sell
- non-discrimination for exercising these rights
- Children optin (13-16 by child, under 13 by parent)

30 days to address
Penalty: $7500 fine (intentional) or $2500 fine (unintentional)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

GDPR Org reqs

A
  • Implement PbD&D
  • Maintain appropriate safeguards
  • Notify DPA within 72 hours of breach
  • Collect consent and provide notification of processing activities
  • Parental consent for under 16
  • Keep records of all processing
  • Appoint a DPO
  • Responsibility for security and processing by vendors
  • DPIA for new or high-risk processing activities
  • Safeguard cross-border data transfers
  • Consult regulators when necessary
  • Demonstrate compliance
  • Provide training for those with access
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

LGPD

A

Passed Aug 2018. Effective Aug 1, 2021

Penalty: 2% of revenue in Brazil, max of 50m reals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

China Personal Info Protection Law

A

Passed Aug 2021. Effective Nov 1, 2021

Penalty: $7.7m or up to 5% of previous year revenue

17
Q

FTC Act (Section 5) of 1914

A

Unfair and deceptive practices

18
Q

Fair Credit Reporting Act (FCRA) of 1970

A

Accuracy and fairness of data with consumer reporting agencies

19
Q

FERPA of 1974

A

Protect students data

20
Q

Fed Privacy Act of 1974

A

fair information practices for fed collected PII

21
Q

Electronic Communications Privacy Act of 1986

A

fed wiretapping limits

22
Q

Video Privacy Protection Act of 1988

A

vcr rental records

23
Q

Telephone Consumer Protection Act of 1991

A

limits auto-dialing systems

24
Q

Drivers Privacy Protection Act of 1994

A

privacy for DMV collected PII

25
Q

HIPAA of 1996

A

protects PHI

26
Q

Children’s Online Privacy Protection Act of 1998 (COPPA)

A

Protects the PII of minors, specifically 12 and under

27
Q

Gramm-Leach-Bliley Act of 1999

A

consumer financial services must explain sensitive data sharing

28
Q

CAN-SPAM Act of 2003

A

controls unsolicited commercial email

29
Q

Fair and Accurate Credit Transaction Act of 2003

A

consumer protection to prevent identity theft

30
Q

National Do Not Call Registry

A

no telemarketing for numbers on the list

31
Q

Health Info Tech for Economic and Clinical Health Act of 2009

A

HHS has authority to set higher system requirements

32
Q

Self Regulations

A

PCI DSS: payment processing
DMA: data-driven marketing
Verasign, TrustArc, PaPal trust marks: vendor validation
Childrens Advertising Review Unit: target ads
Network Ad Initiative: privacy and data governance
EU Code of Conduct: B2B Cloud Serv

33
Q

GDPR Article 45

A

Adequacy for countries

34
Q

GDPR Article 46

A

Non-adequate country transfer
BCRs or SCCs