Glossary of Privacy Terms Flashcards

Privacy Terms from the CIPP-C May 2025 (105 cards)

1
Q

What is accountability in the context of personal data handling?

A

The implementation of appropriate technical and organisational measures to ensure personal data is handled in accordance with relevant law

Codified in the EU General Data Protection Regulation and other frameworks, including APEC’s Cross Border Privacy Rules.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the three principles espoused by the Act Respecting the Protection of Personal Information in the Private Sector?

A
  • Serious and legitimate reason for establishing a file on another person
  • Access to information contained in the file must not be denied
  • Respect for rules applicable to collection, storage, use, and communication of information
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What constitutes an ‘adequate level of protection’ for personal data transfers from the EU?

A
  • Rule of law and respect for human rights
  • Existence of independent supervisory authorities
  • International commitments related to data protection
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Define ‘administrative purpose’ in the context of personal information use.

A

The use of personal information in a decision-making process that directly affects the individual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does ‘adverse action’ refer to under the Fair Credit Reporting Act?

A

All business, credit, and employment actions affecting consumers that can negatively impact them

Examples include denying or canceling credit or employment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is Alberta PIPA?

A

A privacy law in Alberta, similar to PIPEDA, that clearly applies to employee information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the role of the American Institute of Certified Public Accountants?

A

A professional organization of certified public accountants and co-creator of the WebTrust seal program

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the APEC Privacy Principles?

A

A set of non-binding principles that mirror the OECD Fair Information Privacy Practices

Aimed at promoting electronic commerce in the Asia-Pacific region.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the process of authentication?

A

Determining whether an entity is who it claims to be

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does BC PIPA stand for?

A

A privacy law in British Columbia, similar to PIPEDA, that applies to employee information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Define ‘behavioral advertising’.

A

Advertising targeted at individuals based on their observed behavior over time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is breach disclosure?

A

The requirement for organizations to notify regulators and victims of personal data incidents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does Canada’s Anti-Spam Legislation require for commercial electronic messages?

A
  • Consent from the recipient
  • Identification requirements
  • Unsubscribing options
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the Canadian Institute of Chartered Accountants responsible for?

A

Functions critical to the success of the Canadian CA profession, including strategic leadership and standard setting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the CSA Privacy Principles?

A
  • Accountability
  • Identifying purposes
  • Consent
  • Limiting Collection
  • Limiting Use, Disclosure, and Retention
  • Accuracy
  • Safeguards
  • Openness
  • Individual Access
  • Challenging Compliance
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What does CCTV stand for?

A

Closed circuit television

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What are Charter Rights?

A

Rights created by the Canadian Charter of Rights and Freedoms, considered constitutional rights

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is the Children’s Online Privacy Protection Act (COPPA) of 1998?

A

A U.S. law requiring parental consent for collecting personal information from children under 13

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

In the context of consent, what does ‘choice’ refer to?

A

The idea that consent must be freely given with a genuine choice for data subjects

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is the principle of ‘collection limitation’?

A

Limits to the collection of personal data, obtained by lawful and fair means

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Define ‘commercial activity’ under Canada’s PIPEDA.

A

Any transaction or conduct of a commercial character, including selling or leasing donor lists

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What is a ‘commercial electronic message’?

A

Any electronic message intended to encourage participation in commercial activity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What are comprehensive laws?

A

Laws governing the collection, use, and dissemination of personal information in public and private sectors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What does confidentiality mean in data protection?

A

Protection against unauthorized or unlawful processing of data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
What does consent entail in privacy requirements?
Individuals' ability to prevent the collection of personal data, except when required by law
26
What is Convention 108?
A legally binding international instrument ensuring human rights regarding personal information processing
27
What is a 'cookie' in the context of web technology?
A small text file stored on a client machine that tracks browser activities
28
What is customer access?
A customer's ability to access, review, correct, or delete their personal information
29
Define 'data breach'.
Unauthorized acquisition of computerized data compromising personal information security
30
What is a data controller?
The entity that determines the purposes and means of processing personal data
31
What are data elements?
Units of data that cannot be further broken down or have distinct meanings
32
What does data processing encompass?
Any operation performed on personal data, including collection, storage, and destruction
33
Who is a data processor?
An entity that processes personal data on behalf of the data controller
34
What is a Data Protection Authority?
Independent authorities supervising data protection laws in the EU
35
What does data quality refer to?
The principle that personal data should be relevant, accurate, complete, and up-to-date
36
Who is a data recipient?
An entity to which personal data is disclosed, excluding public authorities in specific inquiries
37
What is a data subject?
An identified or identifiable natural person
38
What does 'de novo' mean in a legal context?
A hearing in which a higher authority makes a new decision, ignoring lower findings
39
What is direct marketing?
When a seller directly contacts an individual for marketing purposes
40
Define 'electronic communications network'.
Transmission systems allowing conveyance of signals by various means, including wire and radio
41
What is an electronic communications service?
Any service providing users the ability to send or receive wire or electronic communications
42
What is an Electronic Communications Service?
Any service which provides to users the ability to send or receive wire or electronic communications.
43
Define Electronic Health Record (EHR).
A computer record of an individual's medical file that may be shared across multiple healthcare settings.
44
What does Employee Information refer to?
Personal information reasonably required by an organization for employment or volunteer work purposes.
45
What is Employee Personal Data according to Article 88 of the GDPR?
Data subject to specific rules around processing employees’ personal data, safeguarding human dignity and fundamental rights.
46
What is Encryption?
The process of obscuring information to make it unreadable without special knowledge.
47
When was the EU Data Protection Directive adopted?
The Directive was adopted in 1995 and became effective in 1998.
48
What is the role of the European Commission?
To implement the EU’s decisions and policies, initiate legislation, and make adequacy determinations regarding data transfers.
49
What is the Fair Credit Reporting Act?
A U.S. federal privacy law enacted in 1970 to mandate accurate data collection and give consumers access to their information.
50
What does the Federal Trade Commission (FTC) do?
Acts as the primary consumer protection agency in the U.S., collecting complaints and enforcing laws against unfair practices.
51
What are the Generally Accepted Privacy Principles?
A framework with ten principles including management, notice, choice, collection, use, retention, access, disclosure, security, and monitoring.
52
What is the Global Privacy Enforcement Network (GPEN)?
A collection of data protection authorities dedicated to privacy law enforcement cooperation and sharing best practices.
53
What is the House of Commons?
One of two chambers of the Canadian Parliament, with members elected at least every five years.
54
What are Identifying Purposes in privacy protection?
The obligation on organizations to document the purposes for collecting personal information at or before collection.
55
What is Individual Access?
The principle that organizations must respond to requests from individuals for access to their personal information.
56
What is Individual Participation in privacy practices?
The right for individuals to obtain confirmation of data held about them and to challenge inaccuracies.
57
What are Information Banks?
Repositories of personal information maintained by the Canadian government under the Privacy Act.
58
What does the Information Life Cycle encompass?
The stages of data management: Collection, processing, use, disclosure, retention, and destruction.
59
What is Information Security?
The protection of information to prevent loss, unauthorized access, and misuse.
60
What is the Model Code for the Protection of Personal Information?
A set of privacy principles developed by the Canadian Standards Association that includes ten key principles.
61
Define Multi-Factor Authentication.
An authentication process requiring more than one verification method.
62
What are the OECD Guidelines?
Internationally accepted privacy principles established in 1980 and updated in 2013.
63
What are Omnibus Laws?
Laws that cover a broad spectrum of organizations or individuals, as opposed to sector-specific laws.
64
What is Online Behavioral Advertising?
Advertising based on tracking user profiles, preferences, and online activity.
65
What is the Online Privacy Alliance?
A coalition of online companies established to encourage self-regulation of online privacy.
66
What does Openness mean in fair information practices?
A general policy of transparency regarding personal data practices.
67
What is the difference between Opt-In and Opt-Out?
Opt-In requires active consent, while Opt-Out implies consent by inaction.
68
What is Outsourcing?
Contracting business processes to a third party, which may include processing personal information.
69
What are Perimeter Controls?
Technologies designed to secure a network environment by preventing external penetration.
70
What is Personal Data as defined by the GDPR?
Any information relating to an identified or identifiable natural person.
71
What is the Privacy Act (Canadian)?
Enacted in 1983, it sets rules for how federal institutions handle personal information.
72
What constitutes a Privacy Breach (Canadian)?
Unauthorized access, collection, use, or disclosure of personal information.
73
What are the steps in a Privacy Breach Response (Canadian)?
* Containment of the breach * Evaluating risks * Notifying affected parties * Preventing future breaches
74
What is Privacy by Design?
A framework for data protection established by Ann Cavoukian, focusing on integrating privacy into operations.
75
What is the role of the Privacy Commissioner of Canada?
To enforce PIPEDA and investigate complaints regarding personal data handling.
76
What are Privacy Impact Assessments (Canadian)?
Assessments required to evaluate compliance with privacy obligations for government initiatives.
77
What is a Privacy Notice?
A statement describing how an organization collects, uses, retains, and discloses personal information.
78
What does Privacy of the Person protect?
Bodily integrity and the right not to have one's body touched or explored without consent.
79
What is the role of a Privacy Officer?
To coordinate and implement privacy compliance efforts within an organization.
80
What is a Privacy Policy?
An internal statement governing an organization’s handling of personal information.
81
Define Public Records.
Information collected and maintained by a government entity and available to the public.
82
What is Radio-Frequency Identification?
Technologies that use radio waves to identify encoded microchips.
83
What is Re-identification?
Reattaching identifying characteristics to pseudonymized or de-identified data.
84
What is Rectification in data privacy?
The right to have personal data corrected if it is inaccurate.
85
What does Retention refer to in the information life cycle?
The practice of retaining personal information only as long as necessary for its intended purpose.
86
What is the Right of Access?
An individual's right to request and receive their personal data from an organization.
87
What is the Right To Correct?
The right for individuals to amend inaccurate information about themselves.
88
What are Seal Programs?
Programs requiring compliance with codes of information practices, allowing participants to display a seal.
89
What are Sectoral Laws?
Laws that exist in specific areas where a particular need has been identified.
90
What is the Senate (Canadian)?
One of two chambers of the Canadian Parliament, with members appointed by the governor in council.
91
What is Sensitive Personal Information?
Data related to a higher expectation of privacy, such as medical or financial information.
92
What does SPAM refer to?
Unsolicited commercial e-mail.
93
What is a Technology-Based Model for data protection?
Utilizes technological measures to protect individuals' personal data.
94
What does Transfer mean in the context of personal data?
The movement of personal data from one organization to another.
95
What does Transparency mean in data processing?
Providing information about processing in a concise and intelligible manner.
96
What is the Universal Declaration of Human Rights?
A declaration adopted by the UN in 1948 recognizing inherent dignity and privacy rights.
97
What are Value-Added Services?
Non-core services in telecommunications that go beyond basic offerings.
98
What does the statement regarding privacy in Article 12 of the Declaration encompass?
[...] no one shall be subjected to arbitrary interference with his privacy, family, home or correspondence ## Footnote This statement covers a wide range of conduct, including both territorial and communications notions of privacy.
99
What are Value-Added Services (VAS) in the telecommunications industry?
Non-core services beyond voice calls and fax transmissions ## Footnote VAS refers to services available at little or no cost that promote the primary business.
100
What are mobile value-added services (MVAS)?
Services like SMS, MMS, and GPRS ## Footnote MVAS may be categorized into standard (peer-to-peer) content and premium-charged content.
101
Who provides value-added services in the telecommunications industry?
Mobile network operators or third-party value-added service providers (VASPs) ## Footnote VASPs are also known as content providers (CP) like Headline News or Reuters.
102
What protocols do VASPs typically use to connect to mobile operators?
Short message peer-to-peer protocol (SMPP) ## Footnote VASPs connect either directly to the short message service center (SMSC) or to a messaging gateway.
103
What are the guidelines regarding video surveillance?
Video should not be the initial security option and must follow these constraints: * Taken only in absence of less intrusive alternatives * Use disclosed to the public * Individuals have access to their personal information * Subject to independent audit * Fair information practices respected ## Footnote These guidelines aim to protect privacy rights.
104
What does Work Product Information refer to in Canada?
Information about an individual's job-related position, functions, and performance ## Footnote It is not defined by PIPEDA and may sometimes fall under personal information.
105
How does Work Product Information differ in Canada and the United States?
In Canada, it relates to job performance; in the U.S., it refers to legal materials prepared for litigation ## Footnote This distinction is important for understanding legal contexts in each country.