Section 5 Flashcards

(78 cards)

1
Q

Which city banned employment based on credit history in 2015?

A

New York City

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

When was the California Financial Information Privacy Act passed and what is the other name by which it is known?

A

2004 and known as SB-1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How does the CFIPA (CA Financial Info Privacy Act) add to GLBA?

A
  1. Shifts the requirement for financial institution data sharing from an opt-out under GLBA to an OPT-IN under CFIPA.
  2. requires that financial institutions provide a SEPARATE DOCUMENT that is prominently titled “Important Privacy Choices for Consumers.”
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

In what two days does the Cal ECPA (Electronic Communications Privacy Act) restrict law enforcement in access to electronic comms?

A
  1. Service Provider Records
    - criminal: search warrant or court order
    - non-criminal: subpoena
  2. Electronic Devices
    - search warrant, wiretap order, consent of the customer or certification of an emergency situation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What rights does the CCPA (CA Consumer Privacy Act) of 2018 provide?

A

Right to: KKHOORD
- know what information is collected
- know how the information is shared
- opt out of information sharing
- review information
- request deletion of information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Does the CCPA include a private right of action?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How does the CA Privacy Rights Act update the CCPA?

A
  1. Creates a new category of information: Sensitive PI
  2. Adds new rights like:
    - correct inaccurate information
    - limit use and disclosure of SPI
    - access information on automated decision-making
    - to opt out of that automated decision-making
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What law created the California Privacy Protection Agency?

A

CPRA (2023)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

When did CA pass the CA Data Broker Law?

A

2019

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does the CA Data Broker Law require?

A
  • annual registration with the AG
  • AG publishes list of registered broker on its website
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

When does the CA Age Appropriate Design Code go into effect?

A

was set to go into effect July 2024 but was litigated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does the CAADCA (California Age Appropriate Design Code Act) require that companies do?

A
  1. Annual Data Protection Impact Assessment (DPIA)
  2. Document risks and develop remediation plans
  3. Comply with AG requests
  4. Estimate age of child visitors
  5. Use strong default privacy settings
  6. Write privacy notices that children can understand
  7. Notify children they may be tracked
  8. Provide tools + info that parents and children can use to enforce privacy rights
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What websites does the CAADCA apply to?

A

Those that are already subject to the CCPA AND
- are directed at children (as defined by COPPA)
- are routinely accessed by children
- are similar to another website directed at children
- have advertisements marketed to children
- have design elements interesting to children
- a significant amount of the audience is children

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the possible fines under the CAADCA?

A

Negligent: $2500 per child
Intentional: $7500 per child

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Is there a private right of action under the CAADCA?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What entities does the Colorado Privacy Act apply to?

A

If the business handles PI of 100K or more CO residents or handles PI of 25K or more residents and earns revenue from sharing that info
Does not apply to PI for your own employees

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Does the CO law apply to non-profits?

A

Yes. CA does not.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Does CO Privacy Law have a private right of action?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What companies does the Connecticut Data Privacy Act (CTDPA) apply to?

A

If the business handles PI of 100K or more CT residents or derives over 25% of revenue from selling data AND control or process data of 25K or more CT residents annually

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What does the CTDPA not apply to?

A

governments, non-profits, higher education or entities regulated by GLBA, HIPAA and FCRA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What rights does the CTDPA provide?

A

access, correction and deletion of data
data portability
opt out
appeal denial of requests
designate an authorized agent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Does the CTDPA have a private right of action?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

When did the Delaware Online Privacy and Protection Act (DOPPA) go into effect?

A

2016

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What are the three main categories of DOPPA?

A

Privacy policies
Protections for children (expands to under 18)
Protections for the privacy of users’ reading habits

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
How does the DOPPA definition of website operators affect a service like Amazon Web Servies?
It does not include web hosting services that have nothing to do with operating the actual site so AWS would be excluded
26
What are the Nevada SB 538 requirements?
Disclose clear privacy policies
27
What is the subject matter of the New Jersey Personal Information and Privacy Protection Act?
Customer identity/customer ID cards
28
What are the eight purposes that the NJ law allows retailers to collect customer IDs?
Validate customer identities for refunds Verify customer age if needed Prevent fraud in product returns Prevent identity fraud in retain credit accounts Creating and continuing customer contracts Comply with laws that compel collection or disclosure Disclose records to financial regulation Compliance with HIPAA
29
What kinds of data does the WA Biometric law exclude?
Photographs, videos and audio recordings
30
What does the WA Biometric law require for biometric data?
Notice and consent before data can be "enrolled" in a database for commercial purposes with an exception for data needed to complete a transaction or to comply with other legal obligations
31
What does the NYDFS Cybersecurity Regulation do?
Makes financial institutions operating in NY follow cybersecurity infrastructure under NIST
32
What does WA HB 1149 do?
Requires businesses that manage electronic payment transactions liable to help cover the costs involved in issuing new bank cards if their negligence causes a breach
33
What are the DOPPA conspicuous privacy policy posting options?
1. On the homepage or first significant page of a site 2. Accesible through a textl ink or icon containing the word "privacy" 3. For non-websites, reasonably accessible
34
IL Student Online Personal Protection Act (SOPPA)
Grants parents rights to control student info Data breach notification Applies to govt agencies and educational technology companies
35
What must be in a Privacy Policy under DOPPA?
PII collected Third parties that get the PII How it handles "do not track" requests Policy change notification procedures
36
What must be included on a privacy policy under NV SB 538?
Categories of PII Process to review and correct Notification process for policy changes Use of third party tracking Effective date
37
What did NV SB 260 do?
Expanded 538 to included data brokers
38
What are the cybersecurity controls that NY requires?
Penetration testing vulnerability assessment Audit trail Access privileges Application security Risk assessments Multifactor authentication Encryption Incident response plan Secure disposal
39
What companies are subject to the Utah Consumer Privacy Act?
- Over 25M in annual revenue - Process data of 100K or more Utah residents - Process data of 25K or more Utah residents and sell it
40
How does CalECPA differ from federal telecoms laws?
Cal ECPA requires Cal state law enforcement get a warrant when requesting electronic data
41
Which states have an explicit right to privacy in their Constitution?
Alaska Arizona California Florida Hawaii Illinois Louisiana Montana New Hampshire South Carolina Washington
42
What types of personal information are omitted from the CCPA?
PHI and personal financial information regulated by GLBA
43
What is BIPA? Does it include a private right of action?
Illinois Biometric Information Privacy Act Requires that companies get consent before collecting and using biometric data YES - includes private right of action
44
What are the rights granted under the CCPA?
KADON Know Access Delete Opt out Nondiscrimination
45
What rights does the CPRA add to the CCPA?
CKOR Correction Know about automated decision making Opt out of automated decision making Restrict sensitive personal information
46
What businesses are subject to the Virginia Consumer Data Protection Act (VCDPA) (2021)?
1. Controls or processes the PI of 100K or more VA residents OR 2. Controls or process the PI of 25K if the business earns of HALF ITS REVENUE from selling that PI
47
What are the five major exemptions from the VCDPA?
1. Virginia government agencies 2. Financial institutions regulated under GLBA 3. Healthcare organizations regulated under HIPAA 4. Non-profit organizations 5. Institutions of higher education
48
Does the VCDPA have a private right of action?
No
49
Does the Colorado Privacy Act have a private right of action?
No
50
What entities does the Colorado Privacy Act apply to?
1. 100K or more residents 2. 25K or more if they earn ANY revenue from selling the PI
51
Does the Colorado Privacy Act apply to non-profits?
Yes (while CA and VA laws leave non-profits exempt from their Privacy Acts) There is also an exception for businesses handling information about their employees or other businesses
52
What does Nevada's SB 538 do?
Requires that websites post clear privacy policies (similar to DOPPA)
53
What is a Nevada SB 538 exception?
Website operators in NV with fewer than 20K unique visitors if their revenue is derived primarily from a source other than the sale or lease of goods, services or credit online
54
How does Nevada SB 260 amend Nevada SB 538?
Expands the regulation to cover data brokers who purchase information about NV residents
55
Is there a private right of action under the Connecticut Data Privacy Act?
No
56
What businesses does the Connecticut Data Privacy Act (CTDPA) apply to?
1. 100K or more 2. Derive 25% of gross revenue from selling PI and control or process the data of at least 25K CT residents
57
What does the CTDPA do?
Rights to: access, correction, deletion, data portability, and opt-out, appeals and authorized agent designation Also controls geofencing around health facilities
58
What entities does the Utah Consumer Privacy Act (UCPA) apply to?
1. Annual gross revenue over 5M OR 2. 100K Utah residents OR 3. 15K residents if they SELL AT ALL
59
How does the UCPA (Utah) differ from the Virginia and Colorado laws?
NO: (1) right to appeal denials (2) opt-out of profiling
60
Does the UCPA have a private right of action?
No
61
Which state law makes businesses that manage electronic payment transactions liable for the costs associated with data breaches due to the negligence?
Washington HB 1149
62
What does the California Age-Appropriate Design Code Act (CAADCA) require?
Websites directed at children under the age of 18 must conduct protection impact assessments and take other measures to protect the privacy rights of children NO private right of action
63
Which state law is similar to FERPA?
Illinois Student Online Personal Protection Act
64
What does Massachusetts 201 CMR 17.00 do?
Requires that all companies with info on MA residents have a written information security plan
65
What types of data are omitted from the Washington Biometric Privacy Law (HB1493)?
Photographs Videos Audio recordings
66
How did Illinois HB 1260 update data breach notification laws?
Expanded the definition of personal information to include usernames or email addresses combined with a password that would provide access to an account
67
How did Massachusetts HB 4806 update data breach notification laws?
Added requirements for allowing individuals to place security freezes on their credit reports AND required that companies suffering data breaches offer affected users free credit monitoring
68
Most states trigger breach notification when a business knowns there was a breach. Which do so when there is a reasonable belief of a breach?
Alaska and Kentucky
69
Which state does not require notification to regulators upon the event of a breach?
Indiana
70
How did Tennessee SB 2005 update prevailing state breach notification laws?
It updated to include even encrypted data
71
How did Illinois HB 1260 update prevailing state breach notification laws?
It made usernames or email addresses count as PI if they are disclosed in combination with any information, like a password, that would allow an unauthorized party to get access to someone's account
72
How did California AB 2828 update prevailing state breach notification laws?
Added encrypted data if there is reason to believe the encryption keys were also compromised
73
How did New Mexico HB 15 update prevailing state breach notification laws?
Requires notification if encryption keys are compromised and also includes biometric information
74
What are the notice and choice rules under the CFIPA?
1. Must be notified in advance 2. Provided with time to opt-out When sharing with unaffiliated third parties, there must be written consent
75
What entities does the CFIPA apply to?
Any financial institution doing business in California
76
What right does CAN SPAM grant to states?
Enforcement by state AGs
77
Which state's privacy law applies to non-profits?
CO
78
What businesses are exempt from Nevada SB 538?
- Located in Nevada - Revenue derived outside online - Small business (less than 20K) AND websites must have minimum contacts