Privacy Operational Life Cycle: Chapter 9 Respond: Data Subject Rights Flashcards

1
Q

Privacy Policy

A

Internal document directed at employees

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Privacy Notice

A

External document directed at data subjects

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Privacy Policy Common Elements

A

Who the org is and contact info (DPO)
What info is collected
How the org will use it
With whom the data is shared, and if sold
Applicable data subject rights, how to exercise
How info is protected and processed
When the org is a processor
How web visitors are monitored

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Privacy Notice and Consent

A

DO NOT solicit or imply consent
US: implied consent is ok
GDPR: express consent is required

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

GDPR Lawful Basis

A

Consent
Contract
Legal obligation
Vital interest
Public Interest
Legitimate interest

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Obtaining consent

A

Record of consent

Prechecked box is not sufficient

Cookies
ICO: can’t emphasize agree over block for cookies
US: dark patterns are not sufficient

Consent for a single purpose

Consent must be revokable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Consent from children

A

COPPA, GDPR: special privacy notice for children, parental consent

CCPA: selling requires parental consent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Ages requiring parental consent

A

US: < 13
GDPR: < 16
UK: < 17
Aus: < 15

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

DSR: Fair Credit Reporting Act

A

Customers can obtain copy of all info credit agencies have

Free of charge, 1x per year

Correct or delete incorrect info

30 days to examine disputed data

7-10 years of data

Notification rights

Written consent prior to background check

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

DSR: HIPAA

A

Regulates use and disclosure of PHI

Revocable authorization by patient

Right to obtain info within 30 days

Changes within 60 days

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

DSR: Do Not Call Registry

A

FCC enforces
Stop unwanted commercial solicitation calls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

DSR: CAN-SPAM

A

Can forward unwanted or deceptive messages to the FTC

Commercial messages

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

DSR: Privacy Act of 1974

A

Written request to access own records of Fed agency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

DSR: Freedom of Info Act

A

Must disclose records except:
- Info is classified
- Info is related only to internal rules/practices
- Info is prohibited from disclosure
- Trade secrets/commercial/financial info that is confidential
- Privileged comms within agencies
- Info that would invade another individuals privacy
- info compiled for law enforcement purposes
- Info that concerns supervision of financial institutions
- Geological info on wells

Also
- Ongoing criminal investigation where individual is unaware
- Informant information
- FBI and foreign intelligence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

COPPA

A

PII on CA residents
Privacy notice reqs:
- Categories of PII
- How material changes to privacy notice are notified to consumers
- How Do Not Track requests are honored

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

DOPPA

A

PII for Delaware residents
Much the same as COPPA
Users instead of consumers
Broader entities covered

17
Q

Nevada

A

Similar to other states but adds third party tracking over time

18
Q

CA Shine the Light

A

How businesses use or share data for direct marketing

19
Q

CA Online Erasure Law

A

Allows minors to erase data
Too many exceptions

20
Q

CCPA

A

CA residents can get info on:
- what the org has
- how the data is used
- right to erasure
- do not sell

21
Q

Virginia Consumer Data Protection Act

A

Confirm controller is processing data
Correct data
Delete data
Access portable format of data
Opt out of profiling, sales

22
Q

Biometric Privacy Law

A

IL, WA, TX

23
Q

GDPR

A

Article 12-14: Right of tranparent comms and info
Article 15: Right of Access
Article 16: Right of Rectification
Article 17: Right of Erasure (Recitals 42, 65, and Art 7 Right to withdraw consent)
Article 18: Right to restrict processing
Article 19: Obligations to notify recipients (downstream disclosure)
Article 20: Right to data portability
Article 21: Right to object
Article 22: Right to not be subject to auto decision making

Requires reasonable identity verification

30 days, with up to 60 day extension