Week 12 Flashcards

1
Q

What are the four major categories of issues because of the internet?

A

– Information rights – your personal info
– Property rights – how can it be enforced
– Governance –is internet subject to public law?
– Public safety and welfare; gambling, porn, child safety, bullying

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

why when dealing with IT must there be legal protections?

A

Information technology is designed to transmit and associate data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Define privacy

A

Moral right of individuals to be left alone, free from
surveillance or interference from other individuals or organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is information privacy

A

Subset of privacy
The claim that certain information should not be collected at all

The claim of individuals to control the use of whatever information is collected about them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a web cookie?

A

A web cookie is a small piece of data stored on the user’s computer by the web browser while browsing a website.

Cookies can also be used to remember
pieces of information that the user previously entered such as names,
addresses, passwords, phone numbers, etc. While cookies offer convenience for users, they also facilitate tracking of users and so have data protection implications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does GDPR say about cookies

A

GDPR does not prohibit cookies, but requires users to give permission to use them when they first visit a website.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What sort of data is collected at e commerce sites

A

Personally identifitable information
– Name, address, phone, e-mail, social security
– Bank & credit accounts, gender, age, occupation,
education
– Preference data (from your browsing habits), transaction data, clickstream
data, browser type

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What effect does social networks have on a persons privacy

A

Encourages sharing personal details
Poses unique challenge to maintaining privacy.

Social networks mean that people post information about themselves and this
information may not be restricted to a limited group.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is profiling

A

Creation of digital images that characterize online individual and group behavior

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How do advertising networks work on the internet and give an example

A

– Track consumer and browsing behavior on Web

– Dynamically adjust what user sees on screen

– Build and refresh profiles of consumers

Google Adwords - Businesses pay to get their advertisements ranked at the top of the search results page, based on the keywords that want to target

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are some top adwords

A

Insurance
Loan
Mortgage
Attorney
Credit
Lawyer
Donate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is cyberlaw

A

Laws intended to regulate activities over the internet

– Intellectual property
– Privacy
– Freedom of expression
– Jurisdiction

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the issues with cyberlaw

A

Identifying the jurisdiction - usually law is national.
Technology changes very quickly.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What does the data protection act state about collecting data

A

Obtain and process data fairly
* Specified purpose
* Disclose only if compatible with purpose
* Keep safe and secure
* Accurate, complete and up to date
* Relevant and not excessive
* Retain only as long as necessary
* Comply with access request

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What must those holding personal information do?

A

– Give individuals access to their personal data
– Allow individuals to correct or delete any information that’s incorrect/irrelevant
– Obtain information fairly, openly and transparently
– Use it only for purpose for
which it was originally collected
– Secure it against unauthorised access or loss
– Ensure that it is kept accurate and up to date
- Must not further process data or retain it longer for which it was given

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Why can adhering to the data protection act be difficult and give an example

A

– Conflicts with other legislation
– Lack of clear guidelines
E.G retention of data may be desirable for any possible future criminal
investigation, but this may conflict with data protection law

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Explain opt-in and opt- out policies and where they are used

A

Opt in is the EU standard -You must give your explicit consent to
have data compiled
about you

Opt out is the US standard - Data can be compiled about you unless you
specifically request
otherwise

18
Q

What regulates government agencies in the US in relation to information systems security

A

Federal Information Security Management Act of 2002 in the US updated in 2014
by the Federal Information Security Modernization Act and also in 2022 regulates
government agencies in the USA.

19
Q

Explain informed consent int he US

A

U.S. firms can gather and redistribute transaction
information without individual’s informed consent – Illegal in Europe
– Opt-in (EU)
– Opt-out (US)
–Many U.S. e-commerce firms merely publish
information practices as part of privacy policy
without providing for any form of informed consent

20
Q

Explain the European data protection in place

A

Rules data controllers must adhere to
– Your rights as a data subject
– What can you do if your rights are violated
* Regulates data transfers to non-EU countries - there are some approved countires automatically

21
Q

What does GDPR stand for

A

General Data Protection
Regulation

22
Q

What is Pseudoanonymisation

A

Preventing processing personal data being attributed to an individual, without extra information.

EX: Replacing a name with a random code (e.g., “John Smith” → “ID12345”)

23
Q

What is the jurisdiction of the GDPR law and what are fines

A

International scope
– All organisations providing service in EU whether paid or not. Fine are 4% of annual global turnover or €20 million

24
Q

What does personal data mean in GDPR

A

personal data’ means any information, including data that can be combined with other information, relating to an identified or identifiable natural person (‘data subject’)

25
Q

Define natural person in GDPR

A

natural person’ is one who can be identified,
directly or indirectly, in particular by reference to

Natural person
- You have to be alive
- It does not refer to companies etc
Personal data can include things that can identify a natural person
- Biometric data e.g. fingerprints
- Car reg number

26
Q

What is GDPR sesnitive personal data

A

– racial or ethnic origin,
– political opinions
– religious or philosophical beliefs
– trade union membership
– processing of genetic data
– biometric data
– data concerning health
– data concerning a natural person’s sex life

27
Q

What does processing mean as per GDPR

A

Performing any operations on personal data, such as:
– obtaining
– organising
– disclosing the data to a third party
– erasing or destroying the data

28
Q

Define data controller as per GDPR

A

Data Controller: is the person or organisation who decides why the data is collected & how the data is collected

29
Q

Define data processor as per GDPR

A

Data Processor: A person or organisation that processes personal data on behalf of a data
controller, but is not an employee of the DC above

Data might be outsourced to an external company EX: marketing strategist, data entry, analaysts

30
Q

What are the main principles of GDPR

A

Data is processed in transparent way

Collected for a specifict and legitimate purpose

Limited to what is relevant

Data is kept no longer than necessary

Processed in a manner ensuring security of the data

31
Q

What are the different reasons an employee may interact with processing of data

A

Contract
Legal obligation
Vital interest
Public task
Legitimate interests

32
Q

What are the GDPR Controller obligations

A
  • Privacy by design
  • Ensure processors are GDPR compliant
  • Keep data control records
  • Keep data secure
  • Report data breaches
  • Carry out impact assessments
  • Appoint a data protection officer (DPO)
  • Comply with certification
  • Ensure data transfer outside the EU is sufficiently
    compliant
33
Q

What are the rights we have under GDPR

A
  • Transparency
  • Subject access rights (no fee)
  • Right to rectify
  • Right to erasure
  • Right to restriction of processing
  • Right to data portability (new)- right of data transfer in machine readable format
  • Right to object
  • Right not to be subject to automated decision
    taking
34
Q

What are the GDPR requirements of data holders

A

Make an inventory of all personal data you hold and examine it under the following headings:
– Why are you holding it?
– How did you obtain it and why?
– How long will you retain it and how to dispose of it?
– How secure is it?
– Do you share it with 3rd parties and on what basis?
* Many organisation don’t really know what data
they have

35
Q

Give an example of a past data breaching/ GDPR investigation case

A

On 21/9/2020 the Irish DPC started investigating
Instagram re insufficient controls on under 18s
opening accounts
– Certain data on U-18s made public
– European countries did not agree on penalty
EU Data Protection Boards amended decision
– €405 million fine imposed.

36
Q

How do actuaries interact with GDPR

A

Actuaries must ensure that customers have given
consent for any analysis that they wish to
conduct.
– Consent policies have to be updated
* Actuaries must be careful of local stores of data
* Pseudonymisation should be systematic
* Customers have a right to know how their data is
processed

37
Q

What does the DMA stand for

A

Digital markets act

38
Q

What is the EU DMA

A

DMA regulates large gatekeeper businesses
– Allow users install apps from other sources than
the gatekeeper provider
– Prohibit the gatekeeper from favouring its services
– Prohibit data that is not available to third parties
DMA rules enter force in november of this year

39
Q

What is the EU digital services act

A

Regulates Very Large Online Platforms 45m users
– illegal content
– transparent advertising
– disinformation
* Companies are required to be transparent in what
they are doing about illegal content
* Companies are required to be transparent in why
people see certain advertisements

40
Q

What does the criminal justice act 2001 say about computer crime

A

A person who dishonestly, whether within or
outside the State, operates or causes to be
operated a computer within the State with the
intention of making a gain for himself or herself
or another, or of causing loss to another, is guilty
of an offence

41
Q

Can employees have their computers monitored?

A

Yes only is they know about it though - mponitors the employees productivity and behaviour. Employee needs to know:
– That they are being
monitored
– the reasons and
purposes why they
are monitored.
– How the information
is to be used

42
Q

What can automating process lead to (positives and negative)

A
  • Improved work
    conditions
  • Higher quality
    products
  • Lower (unit) cost
  • deskilling of workforce
  • elimination of jobs