I-A: Introduction to Privacy Flashcards
Data Processing
Anything that’s done with personal information (e.g., collection, storage, use, disclosure, transmission, destruction)
Data Subject
The person whose data is being processed
Data Controller
The organization that decides how information is processed
Data Processor
The organization that processes information on behalf of the data controller
Identified vs. Identifiable
Identified - one who can be ascertained with certainty
Identifiable - one that can be indirectly identified through a combination of factors (e.g., name, ID number, location, etc.)
Encryption
the process of taking data and putting it into an unrecognizable form
Anonymization
a technique whereby data is stripped of its identifying information
Pseudonymization
process through which information is associated with a pseudonym such that it can no longer be attributed to a specific person with additional information
Fair Information Practices
Guidelines for handling, storing, and managing data with privacy, security, and fairness.
Fair Information Practices Categories
Rights of the Individual
Controls on the Information
Information Life Cycle
Management
Rights of the Individual
Notice
Choice and Consent
Data Subject Access
Notice
Providing information to consumers related to how an organization processes personal information
Choice and Consent
Providing consumers the ability to determine whether and/or how their personal information is collected, used, and retained by an organization
Data Subject Access
Providing data subjects with access to the information an organization processes about the individual
Express Consent
Express affirmative consent, a.k.a. “opt-in”
Requires an affirmative indication or act that provides consent to collect or use a person’s information
Implied Consent
Passive acceptance a.k.a. “opt-out”
Implied by a person’s conduct or actions as well as the context of the transaction.
Controls on the Information
Organizations should focus on information security and information quality
Information Security
Organizations should use reasonable administrative, technical, and physical safeguards to protect personal information
Information Quality
Organizations should maintain accurate, complete, and relevant personal information for the purposes identified in the notice.
Information Life Cycle
Collection
Use and Retention
Disclosure
Collection
Organizations should collect personal information only for the purpose identified in the notice.
Use and Limitation
Organizations should limit the use of personal information to the purposes identified in the notice.
Organizations should also retain personal information for only as long as necessary to fulfill the stated purpose.
Disclosure
Organizations should disclose personal information to third parties only for the purposes identified in the notice and with the implicit or explicit consent of the individual.
Management
Organizations should ensure that they address both management and administration as well as monitoring and enforcement.