AND ANSWERS SURE A+
✔✔Protective Order - ✔✔A judge-issued determination of what information contained in
court records should not be made public and what conditions apply to who may access
the protected information.
✔✔Publicity Given to Private Life - ✔✔A tort claim that considers publicity given to an
individual's private life by another is an invasion of privacy and subject to liability.
✔✔Qualified Protection Order (QPO) - ✔✔Under HIPAA, a QPO prohibits the use of
disclosure of PHI for any purpose other than the litigation for which the information was
requested; it also requires the return of PHI to the covered entity at the close of
litigation.
✔✔Red Flags Rule - ✔✔Promulgated under FACTA, the Red Flags Rule requires
certain financial entities to develop and implement identity theft detection programs to
identify and respond to "red flags" that signal identity theft.
✔✔Redaction - ✔✔The practice of identifying and removing or blocking information from
documents being produced pursuant to a discovery request or evidence in a court
proceeding.
✔✔Sedona Conference - ✔✔A nonprofit research and educational institute responsible
for the establishment of standards and best practices for managing electronic discovery
compliance through data retention policies.
✔✔Stored Communications - ✔✔A category of data prohibited from unauthorized
acquisitionn, alteration or blocking while stored in a facility through which electronic
communications service is provided.
✔✔Substitute Notice - ✔✔Pursuant to breach notification laws, certain entities must
provide for substitute notice of data breach in a situation where insufficient or out-of-
date contact information is held.
✔✔Trust Marks - ✔✔Demonstration of compliance with self-regulatory programs by
display of a seal, logo, or certification.
✔✔Unfair Trade Practices - ✔✔Along with deceptive trade practices, behavior of an
organization that can be enforced against by the FTC.
✔✔Authentication - ✔✔The identification of an individual account user based on a
combination of security measures.
,✔✔Authorization - ✔✔After authentication, the proces of determining if the end user is
permitted to have access to the desired resource, such as the information asset or the
information system containing the asset.
✔✔Choice and Consent - ✔✔Organizations should describe the choices available to
individuals and should get implicit or explicit consent with respect to the collection, use,
retention and disclosure of personal information. Consent is often considered especially
important for disclosures of personal information to other data controllers.
✔✔Comprehensive Model - ✔✔A method of data protection to govern the collection,
use and dissemination of personal information in the public and private sectors,
generally with an official or agency responsible for overseeing enforcement.
✔✔Confidentiality - ✔✔The obligation of an individual, organization or business to
protect personal information and not misuse or wrongfully disclose that information.
✔✔Co-regulatory Model - ✔✔Used in Australia and New Zealand, this model
emphasizes industry development of enforceable codes or standards for privacy and
data protection, against the backdrop of legal requirements by the government.
✔✔Data Controller - ✔✔An organization that has the authority to decide how and why
personal information is to be processed. The data controller may be an individual or an
organization that is legally treated as an individual, such as a corporation or partnership.
✔✔Data Processor - ✔✔An individual or organization, often a third-party outsourcing
service, that processes data on behalf of the data controller.
✔✔Data Protection Authority (DPA) - ✔✔An official, or body, who ensures compliance
with the law and investigates alleged breaches of the law's provisions.
✔✔Data Subject - ✔✔The individual about whom information is being processed, such
as the patient at a medical facility, the employee of a company, or the customer of a
retail store.
✔✔EU Data Protection Directive - ✔✔The EU Directive was adopted in 1995 and
became effective in 1998 and protects individuals' privacy and personal data use. The
Directive recognizes the European view that privacy is a fundamental human right, and
establishes a general comprehensive legal framework that is aimed at protecting
individuals and promoting individual choice regarding the processing of personal data.
✔✔Habeas Data - ✔✔Constitutional guarantees that the citizenry may "have the data"
archived about them by governmental and commercial repositories.
✔✔Privacy Impact Assessment (PIA) - ✔✔Checklists or tools to ensure that a personal
information system is evaluated for privacy risks and designed with life cycle principles
, in mind. An effective PIA evaluates the sufficiency of privacy practices and policies with
respect to legal, regulatory and industry standards, and maintains consistency between
policy and practice.
✔✔Sectoral Model - ✔✔This framework protects personal information by enacting laws
that address a particular industry sector.
✔✔Sensitive Personal Information - ✔✔That which is more significantly related to the
notion of a reasonable expectation of privacy. One's medical or financial information is
often considered sensitive personal information (SPI), but other types of personal
information might be as well.
✔✔Opt In - ✔✔Opt in means an individual actively affirms that information can be
shared with third parties (e.g., an individual checks a box stating that she wants her
information to go to another organization).
✔✔Opt Out - ✔✔Opt out means that, in the absence of action by the individual,
information can be shared with third parties (e.g., unless the individual checks a box to
opt out, her information can go to another organization).
✔✔What are the four phases of privacy program development? - ✔✔1. Discover
- Issue identification
- Identify best practices
- Perform PIA
2. Build
- Procedure development and identification
- Full implementation
3. Communicate
- Documentation (Training and Awareness)
4. Evolve
- Affirmation and Monitoring
- Adaptation
✔✔What are the elements of data sharing and transfer? - ✔✔1. Data inventory
2. Data classification
3. Data flows
4. Accountability
✔✔What are the four elements of privacy policies and disclosure? - ✔✔1. How many
policies?
2. Policy review and approval
3. Privacy notice
4. Policy version control
✔✔What are the six phases of privacy incident response programs? - ✔✔1. Detection