RFI Flashcards
General authority
Blanket authority to regulate a specific field
Specific authority
Authority over a specific regulation. Specific authorities are assigned (COPPA)
CCPA Do not sell doesn’t include…
Public information like social media
Covered entity in a state breach notification law
Those that will receive the notifications
FACTA requires (7)
Truncating numbers
Credit score explanations
Free credit report
Disposal rule
Red flag rules
Limits on sharing
Ensuring accuracy
CANSPAM opt out best practice
Offer opt out in the marketing channel.
What must an employer provide if they deny employment because of a CRA?
Notice of adverse action
21st Century Cares does not protect…
PI in the public interest
PCI-DSS, AdChoices, and TrustArc certification are all…
Self-regulatory systems for complying with industry standards and best practices
Which self-regulatory framework does the Digital Advertising Alliance run?
AdChoices
What does AdChoices allow?
Setting preferences for ads
Which state is considered to have the strictest data security law?
Massachusetts
(Requires administrative, technical, and physical safeguards)
ADEA
Age Discrimination in Employment Act
Title VII of the Civil Rights Act prohibits…
Discrimination based on race, color, religion, sex, and national origin
Telemarketing sales rule requirements (3)
No calls before 8AM and after 9PM
CallerID must identify caller
Sweepstakes calls allowed if there is an “established business relationship”
Does FERPA include police, employment, health records?
No
Does FERPA cover grades from peer-graded papers?
No
Does FERPA cover alumni records?
No
What two things matter in data destruction laws?
Definition of PI
Destruction method based on media used
Who role has overall responsibility for a privacy program?
CPO
Anti-discrimination laws relation to workplace privacy
Minimize collection of PI to avoid identifying people in a protected class
Which major privacy law has a disposal rule?
FACTA
Asia Safe Harbor Program
CBPR
Which state law considers photographs PI?
Washington
Which state law protects reading habits?
DOPPA
State law that covers retailers scanning ID cards
NJ
State law that aligns with NIST framework
NIST
ECPA requirements for video monitoring in the workplace
Consent
Business purpose