CIPM Flashcards
(100 cards)
Accountability
The implementation of appropriate technical and organizational measures to ensure and be able to demonstrate that the handling of personal data is performed in accordance with relevant law, an idea codified in the EU GDPR and other frameworks, including APEC’s Cross Border Privacy Rules. Traditionally, accountability has been a fair information practices principle, that due diligence and reasonable steps will be undertaken to ensure that personal information will be protected and handled consistently with relevant law and other fair use principles.
Active Scanning Tools
DLP Network, storage, scans, and privacy tools can be used to identify security and privacy risks to personal information. They can also be used to monitor for compliance with internal policies and procedures, and block email or file transfers based on the data category and definition
American Institute for Certified Public Accountants (AICPA)
A US professional organization of certified public accountants and co-creator of the WEbTrust seal program
Anonymization
The process in which individually identifiable data is altered in such a way that it no longer can be related back to a given individual. Among many techniques, there are three primary ways that data is anonymized. Suppression, generalization, and noise addition
APEC Privacy Principles
A set on non-binding principles adopted by the Asia-Pacific Economic Cooperative (APEC) that mirror the OECD Fair Information Privacy Practices. Seek to balance information privacy with business needs
Assess
The first of four phases of the privacy operational cycle; provides the steps, checklists, and processes necessary to assess any gaps in a privacy program as compared to industry best practices, corporate privacy policies, applicable privacy laws. and objective-based privacy program frameworks
Audit Life Cycle
High-level, five-phase audit approach. Steps include: Audit Planning, Audit Preparation, Conducting the Audit, Reporting, and Follow-up
Behavioral Advertising
Advertising that is targeted at individuals based on the observation of their behavior over time
Binding Corporate Rules
BCRs are an appropriate safeguard allowed by the GDPR to facilitate cross-border transfers of personal data between the various entities of a corporate group worldwide. Ensure the same high level of protection of personal data is compiled with by all members of the organization group by means of a single set of binding and enforceable rules
Bureau of Competition
The US FTC Bureau of Competition enforces the nation’s antitrust laws, which form the foundation of our free market economy
Bureau of Consumer Protection
US FTC Bureau of Consumer Protection stops unfair, deceptive, and fraudulent business practices by collecting complaints and conducting investigations, suing companies and people that break the law, developing rules to maintain a fair marketplace, and educating consumers and businesses about their rights and responsibilities
Bureau of Economics
US FTC Bureau of Economics helps the FTC evaluate the economic impact of its actions by providing economic analysis for competition and consumer protection investigations and rulemakings, and analyzing the economic impact of government regulations on business and consumers
Business case
The starting point for assessing the needs of the privacy organization, it defines the individual program needs and the ways to meet specific business goals, such as compliance with privacy laws or regulations, industry frameworks, customer requirements, and other considerations
Business Continuity & Disaster Recovery Plan (BCDR)
A risk mitigation plan designed to prepare an organization for crises and to ensure critical business functions continue. The focus is to recover from a disaster when disruptions of any size are encountered
Business Continuity Plan
Typically drafted and maintained by key stakeholders, spelling out departmental responsibilities and actions teams must take before, during, and after an event in order to help operations run smoothly. Eg: fire, flood, natural disaster, and terrorist attacks
Canadian Institute of Chartered Accountants (CICA)
CICA, pursuant to the 2006 Protocol, is entrusted with the responsibility for providing strategic leadership, co-ordination of common critical function of strategic planning, protection of the public and ethics, education and qualifications, standard-setting, and communication
Centralized Governance
Privacy governance model that leaves one team or person responsible for privacy-related affairs; all other persons or organizations will flow through this point
Children’s Online Privacy Protection Act (COPPA) of 1998
US Federal law that applies to the operators of commercial websites and online services that are directed to children under the age of 13.
Choice
In the context of consent, choice refers to the idea that consent must be freely given and that data subjects must have a genuine choice as to whether to provide personal data or not
CIA Triad
AKA Security Triad; three common information security principles from the 1960’s: Confidentiality, Integrity, and Availability
Collection Limitation
A Fair Information Practices principle - it is the principle stating there should be limits to the collection of personal data, that any such data should be obtained by lawful and fair means and, where appropriate, with knowledge or consent of the data subject
Consent
Privacy requirement is one of the fair information practices. Individuals must be able to prevent the collection of their personal data, unless the disclosure is required by law.
Affirmative/Explicit Consent
A requirement that an individual “signifies” his or her agreement with a data controller by some active communication between the parties
Implicit Consent
Implied consent arises where consent may reasonably be inferred from the action or inaction of the individual