A+
✔✔Decentralized Governance - ✔✔Also known as "local governance," this governance
model involves the delegation of decision-making authority down to the lower levels in
an organization, away from and lower than a central authority. There are fewer tiers in
the organizational structure, wider span of control and bottom-to-top flow of decision-
making and ideas.
✔✔Electronic Communications Privacy Act of 1986 - ✔✔The collective name of the
Electronic Communications Privacy and Stored Wire Electronic Communications Acts,
which updated the Federal Wiretap Act of 1968. ECPA, as amended, protects wire, oral
and electronic communications while those communications are being made, are in
transit, and when they are stored on computers. The act applies to e-mail, telephone
conversations and data stored electronically. The USA PATRIOT Act and subsequent
federal enactments have clarified and updated ECPA in light of the ongoing
development of modern communications technologies and methods, including easing
restrictions on law enforcement access to stored communications in some cases.
Reference(s) in IAPP Certification Textbooks: US142,143; G108-109; M38
Link to text of law: Electronic Communications Privacy Act of 1986
✔✔EU Data Protection Directive - ✔✔Several directives deal with personal data usage
in the EU, but the most overarching is the general policy approved by the European
Commission in 1995 (95/46EC) which protects individuals' privacy and personal data
use. The Directive was adopted in 1995, became effective in 1998 and protects
individuals' privacy and personal data use. The Directive recognizes the European view
that privacy is a fundamental human right and establishes a general comprehensive
legal framework that is aimed at protecting individuals and promoting individual choice
regarding the processing of personal data. The Directive imposes an onerous set of
requirements on any person that collects or processes data pertaining to individuals in
, their personal or professional capacity. It is based on a set of data protection principles,
which include the legitimate basis, purpose limitation, data quality, proportionality and
transparency principles, data security and confidentiality, data subjects' rights of access,
rectification, deletion and objection, restrictions on onwards transfers, additional
protection where special categories of data and direct marketing are involved and a
prohibition on automated individual decisions. The Directive applies to all sectors of
industry, from financial institutions to consumer goods companies, and from list brokers
to any employer. The Directive's key provisions impose severe restrictions on personal
data processing, grant individual rights to "data subjects" and set forth specific
procedural obligations including notification to national authorities. This was followed in
1997 by a more specific directive for the telecom sector (97/66/EC), which was replaced
in mid-2002 by the European institutions to adapt it to new technologies and business
practices (2002/58/EC). The Directive has been supplemented by additiona
✔✔Five-Step Metric Life Cycle - See Metrics - ✔✔<Metrics> Tools that facilitate
decision-making and accountability through collection, analysis, and reporting of data.
They must be measurable, meaningful, clearly defined (with boundaries), indicate
progress, and answer a specific question to be valuable and practical.
✔✔Gap Analysis - ✔✔Performed to determine the capability of current privacy
management to support each of the business and technical requirements uncovered
during an audit or privacy assessment, if any exist; requires reviewing the capabilities of
current systems, management tools, hardware, operating systems, administrator
expertise, system locations, outsourced services and physical infrastructure.
✔✔Generally Accepted Privacy Principles - ✔✔A framework promulgated by the
American Institute of Certified Public Accountants (AICPA) in conjunction with the
Canadian Institute of Chartered Accountants (CICA). The ten principles are
management, notice, choice and consent, collection, use and retention, access,
disclosure to third parties, security for privacy, quality, monitoring and enforcement.
✔✔Gramm-Leach-Bliley Act - ✔✔The commonly used name for The Financial Services
Modernization Act of 1999. The act re-organized financial services regulation in the
United States and applies broadly to any company that is "significantly engaged" in
financial activities in the U.S. In its privacy provisions, GLBA addresses the handling of
non-public personal information, defined broadly to include a consumer's name and
address, and consumers' interactions with banks, insurers and other financial
institutions. GLBA requires financial institutions to securely store personal financial
information; give notice of their policies regarding the sharing of personal financial
information, and give consumers the ability to opt-out of some sharing of personal
financial information.
✔✔Health Insurance Portability and Accountability Act - ✔✔A U.S. law passed to create
national standards for electronic healthcare transactions, among other purposes. HIPAA
required the U.S. Department of Health and Human Services to promulgate regulations
to protect the privacy and security of personal health information. The basic rule is that