PrivacyReffFlashCards
Accountability
The use of organizational and technical measures which demonstrate that personal data is handled in compliance with relevant law.
Adequate Level of Protection
Confirmation that a data transfer accounts for the rule of law and legislation, respect for human rights, data protection rules, professional rules and security measures, data subject rights, independent supervisory authorities, and any international commitments.
Adverse Action
Any business, credit, or employment action that affects consumers negatively, such as denying or canceling credit, insurance, employment, or promotion. A credit transaction where the consumer accepts a counteroffer would not count.
American Institute of Certified Public Accountants
The U.S. professional organization of certified public accountants that co-created the WebTrust seal program.
Americans with Disabilities Act
A U.S. law that prohibits discrimination against certain individuals with disabilities
Anti-discrimination Laws
Indications of special classes of personal data. If these exist based on a class or status, it is likely that the personal information is subject to more prescriptive data protection regulation.
APEC Privacy Principles
A set of non-binding principles adopted by the Asia-Pacific Economic Cooperative (APEC) that mirror the OECD Fair Information Privacy Practices. These promote electronic business in the Asia-Pacific region with a balance of information privacy and business need.
Background Screening/Checks
Verifying an applicant’s ability to function in the working environment in a way that ensures the safety and security of existing workers. These could involve checking a person’s educational background or past criminal activity. Employee consent requirements may be negotiated with work councils and varied by member state.
The Bank Secrecy Act
A U.S. federal law requiring U.S. financial institutions, money services businesses, or entities that sell money orders or provide cash transfer services, to report, retain, and record qualified financial transactions to the federal government. This is meant to help the government investigate instances of money laundering, tax evasion, terrorist financing and other criminal activities.
Behavioral Advertising
Advertising targeted at individuals based on the observations about their activity over time, most often done via automated processing of personal data, or profiling.
Binding Corporate Rules
An appropriate GDPR safeguard for cross-border transfers of personal data between two or more entities of a corporate group. These ensure that the same high level of personal data protection is followed by all members of the group through a set of enforceable rules.
Binding Safe Processor Rules
Binding Corporate Rules that may now be used for both controllers and processors under the GDPR.
Breach Disclosure
An organization must notify regulators and/or victims of incidents that have impacted the confidentiality and security of personal data. This transparency mechanism brings light to operational failures, helps mitigate harm, and assists in the identification of causes of failure.
Bring your own device(BYOD)
Allowing employees to use their own personal computing device for work.
California Consumer Privacy Act
The first state-level comprehensive privacy law in the U.S. which applies to businesses that collect personal information from California consumers. This law created consumers’ rights to access, deletion, opt-out of sale, and nondiscrimination while also imposing specific transparency and disclosure obligations. The precursor to the California Privacy Rights Act, which will enter into force Jan 1, 2023
California Investigative Consumer Reporting Agencies Act
The California state law establishing that employers must notify applicants and employees of any intention to obtain and use their consumer report
California Online Privacy Protection Act
This act requires that all websites targeted to California citizens must provide a privacy statement to visitors with an easy-to-find link. Websites that collect personal data from individuals under 18 years of age must permit those children to delete their data. Websites are required to inform visitors of which Do Not Track mechanisms they support, if any.
California Privacy Rights Act
This act amended the California Consumer Privacy Act with more consumer privacy protections and an enforcement agency, the California Privacy Protection Agency. The provisions entering into force January2023 will apply in retrospect up to January 2022
Case Law
Law principles established by judges in previous decisions. When similar issues come back up, judges use the prior decisions as precedents and keep new case decisions consistent.
CCTV
An acronym for “closed circuit television” which has become shorthand for any video surveillance system. These can be hosted via TCP/IP networks and accessed remotely, and the footage very easily shared
Children’s Online Privacy Protection Act(COPPA) of 1998
A U.S. federal law applying to operators of commercial websites and online services either directed to children under the age of 13 or known to collect personal information from children under the age of 13. Operators are required under this law to post a privacy notice on the website, provide notice about collection practices to parents, obtain verifiable parental consent before collecting personal information of children, give parents the choice about whether their child’s personal information will be shared with third parties, provide parents with rights to access, delete, and opt out of future collection or use of the information, and maintain the confidentiality, security and integrity of children’s personal information.
Choice
The concept that consent must be freely provided and data subjects have a true choice whether to provide personal data or not, without which it is unlikely the consent would be considered valid under GDPR.
Cloud Computing
Information technology services provided over the Internet by organizations for internal users or third-party suppliers. The service options may be software, infrastructure, hosting, or platforms for applications ranging from personal e-mail to corporate data storage.
Collection
Limitation
The fair information practices principle
which says that there should be limits in the
collection of personal data, where data
should be gathered y fair and lawful means
with the knowledge or consent of the data
subject.