Missed Questions Flashcards
(113 cards)
What legislation ended certain bulk collection practices of the US government for national security purposes?
The USA Freedom Act
What are requirements regarding use of directory information under FERPA?
social security number may never be considered directory information
students must be provided right to opt out before directory info is shared
schools can determine their own list of what constitutes directory information
what organization created K-12 school service provider pledge to safeguard student privacy?
software and information industry association in concert with the Future Privacy Forum
pledgees agree not to undertake numerous activities as well as undertake affirmative obligations aimed at protecting student privacy
violation is enforced as deceptive trade practice by FTC
majority of state data breach notification laws include
requirement that notice to affected consumers be provided in writingm
minority of state data breach notification laws include
- materiality requirement for determining when breach occurs
- specific requirements about what must be included in notice to affected individuals
- inclusion of biometric data in definition of personal info
type of security failure that is primary cause of most data security incidents
human error
technical protection examples
computer code
electronic systems designed to limit access to authorized users and maintain integrity of data from outside attack
administrative protections examples
policies designed to limit access to data to only employees who need access to accomplish their assigned job functions
are non profit entities are subject to FTCs jurisdiction under FTC ACT or COPPA or both
neither FTC act nor COPPA
COPPA_ exempt from definition of operator
FTC- specifically exempt under FTC act
HITECH made the following changes to HIPAA
- business associates directly subject to HIPPA
- term limited data set is defined
- term covered entity, business associate, and protected health information are codified
didn’t change minimum necessary requirements
what feature of binding corporate rules separates it from other international transfer mechanisms available under GDPR
only apply to international data transfers that occur within an organization not transfers to 3rd parties
Fair Information Practice of access is commonly considered to include
- ability to view information an organization collects
- ability to update or correct inaccurate info
what must a user of a consumer report do before re-selling a consumer report?
notify CRA of
1. identity of end users of report
2. each permissible purpose to which the end user will be utilizing the report for
what are benefits of data flow mapping
- mitigate risk associated with data processing
- facilitate identifying problems within an organizations data processing
- increase confidence in regulatory compliance
doesn’t help limit amount of data disclosed in event of data breach
GDPR individual rights
- data portability
- rectify data
- right to be forgotten
- consent
doesn’t include right to opt out of data selling
National Institute of Standards and Technology recommends that employees be provided data privacy and security training when all of the following occurs
- upon being hired (or promoted)
- as needed by the organization
- when changes are made to the information system or policies
not once annually
What article in the GDPR makes it illegitimate to transfer data to a 3rd country or to an international organization in the absence of a valid transfer mechanism?
article 44
what type of privacy protection model is overseen by multiple regulators
sectoral model
- select market segments are governed by different privacy laws
- no overarching regulatory regimen applicable across the entire economy
standard order of privacy operational life cycle
assess (create processes to evaluate program)
protect (implement practices)
sustain (manage program)
respond (respond to failures)
when is no option form of consent to be expected
product fulfillment
fraud prevention
internal operations
legal compliance
public purpose
1st party marketing
CA attorney general has authority to bring civil action for violation in
- Consuperm Financial Protection Act
- Fair Credit Reporting Act
- Red Flags Rule
not GLBA
GLBA privacy rule notice requirement
notice must be provided at the start of customer relationship and annually thereafter
no requirement for notice to be online but doing so is a best practice and may be required under state law (CALOPPA)
what law or regulation was enacted to facilitate in certain cases the compassionate sharing of info related to patients
21st Century Cures Act
- HHS must issue guidance on compassionate sharing of mental health and substance abuse info with family members and caregivers
CCPA parental consent must be obtained before selling PI of children under what age
under 13 years old
13-15- may obtain consent directly from child through opt in procedure