Foundations of Data Privacy and Comparative Regulations Flashcards

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/99

flashcard set

Earn XP

Description and Tags

A comprehensive set of 100 vocabulary flashcards covering global data privacy regulations (GDPR, DPDPA, APPI, UAE PDPL), core principles, stakeholder roles, data rights, and enforcement mechanisms based on lecture notes.

Last updated 1:24 PM on 5/28/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

100 Terms

1
New cards

Data Privacy

The essential tenet governing the rights, regulations, and practices for the collection, use, storage, and sharing of personal information.

2
New cards

Four Pillars of Personal Data

The four integrated criteria under GDPR: Any information, Relating to, Identified or Identifiable, and Natural Person.

3
New cards

Content Element

A condition for information relating to an individual where the data is directly about the person, such as medical records.

4
New cards

Purpose Element

A condition for information relating to an individual where data is used to influence or analyze a person, such as targeted advertising.

5
New cards

Result Element

A condition for information relating to an individual where the use of data impacts an individual's rights or interests, even if it appears impersonal.

6
New cards

Right to Privacy (1890)

An article by Warren and Brandeis arguing for the 'right to be left alone.'

7
New cards

Article 12 of the Universal Declaration of Human Rights

The 1948 global standard recognizing privacy as a fundamental right.

8
New cards

1980 OECD Guidelines

Guidelines issued to address the rise of computer-based business processing.

9
New cards

1983 German Census Judgment

A landmark German Federal Constitutional Court ruling on informational self-determination.

10
New cards

EU Directive 95/46/EC

The 1995 organized framework establishing the foundation for modern data transfer and processing until the GDPR.

11
New cards

Justice K.S. Puttaswamy (Retd.) vs. Union of India

The landmark Supreme Court judgment that declared the Right to Privacy as a fundamental right under Article 21 of the Indian Constitution.

12
New cards

Srikrishna Committee

The committee formed following the Puttaswamy ruling that led to the notification of the DPDPA in 2023.

13
New cards

Natural Person

A living human being, as opposed to legal entities, to whom personal data protections apply.

14
New cards

Data Protection

The technical responsibility of a company focusing on mechanisms, tools, and procedures to enforce privacy policies.

15
New cards

Data Security

Broad measures designed to protect data from external and internal threats, emphasizing confidentiality, integrity, and availability.

16
New cards

Right to Nominate

A unique DPDPA feature allowing a Data Principal to name another person to exercise privacy rights on their behalf in case of death or incapacity.

17
New cards

Digital Personal Data

The specific scope of the DPDPA, which excludes non-digital data stored in physical formats.

18
New cards

Personal Information Handling Business Operator (PIHBO)

Any entity under Japan's APPI, including individuals and non-profits, using a personal information database for business.

19
New cards

Extraterritorial Application (APPI)

The APPI applies to foreign entities handling Japanese individuals' information in connection with supplying goods or services.

20
New cards

Free Zones (UAE)

Areas like DIFC or ADGM that have their own independent data protection regulations and are exempt from the UAE PDPL.

21
New cards

Establishment Principle

A jurisdictional threshold where laws apply to organizations based in a specific region, regardless of where data processing occurs.

22
New cards

Targeting Principle

A jurisdictional threshold where laws apply to non-resident entities if they offer goods/services or monitor residents in a specific region.

23
New cards

Statutory Reference for SMI

Under DPDPA Notified Rules, Social Media Intermediaries are defined by a reference to the IT Rules, 2021.

24
New cards

Material Scope Exclusion (GDPR)

Exclusions under Article 2(2) for household activity, law enforcement, national security, and common foreign security policy.

25
New cards

Publicly Available Data (DPDPA)

Personal data explicitly excluded from scope if made public by the Data Principal or under legal obligation.

26
New cards

Real and Effective Activity

The flexible interpretation of 'Establishment' under GDPR that focuses on stable arrangements rather than legal incorporation.

27
New cards

Special Care-Required Personal Information

Japan's version of sensitive data, including race, creed, medical history, or criminal record.

28
New cards

Section 17(2)(b) of the DPDPA

Provides a wide exemption for data processing undertaken for research, archiving, or statistical purposes.

29
New cards

Lawfulness, Fairness, and Transparency

The base layer principle requiring a valid legal reason, no surprises for the user, and clear communication.

30
New cards

Purpose Limitation

The rule that data must be collected for specific reasons and not used for incompatible 'scope creep' later.

31
New cards

Data Minimization

The requirement to collect only data that is strictly adequate and relevant for a specific task.

32
New cards

Accuracy Principle

The proactive duty of an organization to take reasonable steps to ensure data is not incorrect or misleading.

33
New cards

Storage Limitation

The requirement to delete or anonymize personal data once it is no longer needed after a set retention period.

34
New cards

Integrity and Confidentiality

The security principle mandating technical measures like encryption to protect data from leaks, loss, or damage.

35
New cards

Accountability Principle

The 'deemed principle' requiring a company to prove its compliance through evidence like logs, policies, and training.

36
New cards

Rule 10 (DPDPA)

Mandates verifiable parental consent through held information, parent-provided ID, or government-issued tokens.

37
New cards

Children's Tracking Exemption (India)

Permits tracking without parental consent strictly for real-time location safety or avoiding detrimental advertisements.

38
New cards

Data Controller (or Data Fiduciary)

The entity that decides the 'Why' and 'How' of personal data processing and carries ultimate responsibility.

39
New cards

Data Processor

A separate entity handling data on behalf of a Controller with limited autonomy and strict documented instructions.

40
New cards

Joint Controllers

Two or more organizations that together decide the purposes and means of processing and share accountability.

41
New cards

Consent Manager (DPDPA)

A registered entity acting as an agent for the Data Principal to manage, review, and withdraw consents across services.

42
New cards

Data Subject (or Data Principal)

The natural person whose data is being processed.

43
New cards

Contractual Necessity

A legal basis for processing data required to deliver a product or service the person signed up for.

44
New cards

Vital Interests

A legal basis for processing in emergency 'life-or-death' situations to save a person's life.

45
New cards

Legitimate Interests

A balancing act where a company's valid business reason (e.g., fraud prevention) does not override individual privacy rights.

46
New cards

Two-Layer Retention Framework

A DPDPA update requiring 1-year general log retention and 3-year deletion for inactive platforms.

47
New cards

Retained Personal Data Rights (Japan)

Rights allowing individuals to request disclosure, correction, or cessation of use/third-party transfer.

48
New cards

Voluntary Purpose (DPDPA)

A category where consent is assumed if a person willingly gives data for a specific reason, like a digital receipt.

49
New cards

Strict Consent Requirements

Criteria requiring consent to be freely given, specific, informed, unambiguous, and easy to withdraw.

50
New cards

Explicit Consent

The default requirement for sensitive data processing, stricter than regular consent.

51
New cards

Pseudonymization

Replacing direct identifiers with artificial ones so data cannot be linked to a person without additional information.

52
New cards

PPC (Personal Information Protection Commission)

The Japanese regulator to whom significant data breaches must be reported.

53
New cards

UAE Breach Reporting Timeline

The Controller must notify the UAE Data Office 'immediately' upon a data breach.

54
New cards

DPDPA Comprehensive Breach Report

A detailed report that must be submitted to the Data Protection Board within 72 hours of initial discovery.

55
New cards

90 Days

The maximum period allowed for an organization to respond to a Data Principal's grievance under DPDPA Rules.

56
New cards

Right to be Informed

Requirement for organizations to provide clear details on the 'Who, What, Why, and How Long' of processing.

57
New cards

Right of Access (GDPR)

The right to ask for a copy of actual personal data and an explanation of its use.

58
New cards

Right of Access (DPDPA)

The right to receive a summary of data processed and a list of entities with whom data was shared.

59
New cards

Right to Restriction of Processing

A 'pause button' where processing stops but data remains stored, used during accuracy disputes.

60
New cards

Right to Erasure

Also known as the 'Right to be Forgotten,' it allows users to demand total deletion of data.

61
New cards

Right to Data Portability

The technical requirement to provide data in a structured, machine-readable format like CSV or JSON.

62
New cards

Right to Object

The right to halt specific processing types, most commonly applied to direct marketing.

63
New cards

Privacy by Design

Integrating privacy protections into product development from the very first line of code.

64
New cards

Privacy by Default

A system setting where the most privacy-friendly options are automatically active without user intervention.

65
New cards

Data Breach

Any security incident leading to unauthorized destruction, loss, alteration, or access to personal data.

66
New cards

Data Protection Officer (DPO)

A specialized officer responsible for overseeing data protection strategy and ensuring legal compliance.

67
New cards

DPO Independence

The guarantee that a DPO must not receive instructions from management on how to perform their duties.

68
New cards

Significant Data Fiduciary

Entities in India for whom appointing a DPO based in India is mandatory.

69
New cards

Adequacy Decision

A 'Green List' of countries officially recognized by the European Commission as having equivalent data protections.

70
New cards

Standard Contractual Clauses (SCCs)

Pre-approved, non-negotiable contract templates used to legally bind data importers to GDPR-level standards.

71
New cards

Binding Corporate Rules (BCRs)

A single set of internal privacy rules for global company branches to follow for international transfers.

72
New cards

Transfer Impact Assessment (TIA)

A proactive assessment evaluating the laws of a destination country, made famous by the Schrems II case.

73
New cards

Legitimate Interest Assessment (LIA)

A tool used to prove a company's business need outweighs the individual's privacy risk.

74
New cards

Blacklist (DPDPA Transfers)

A restricted list of countries to which the Indian government may prohibit data transfers.

75
New cards

Supervisory Authority

Independent 'referees' like the ICO (UK) or CNIL (France) that investigate complaints and issue fines.

76
New cards

GDPR Tier 1 Penalty

Fines up to 1010 million Euro or 2%2\% of global annual turnover for administrative failures.

77
New cards

GDPR Tier 2 Penalty

Fines up to 2020 million Euro or 4%4\% of global annual turnover for core principle violations.

78
New cards

DPDPA Security Breach Fine

Fixed cap up to 250\text{₹}250 Crores for failing to take reasonable security measures.

79
New cards

DPDPA Children's Data Fine

Fixed cap up to 200\text{₹}200 Crores for violating minor-specific obligations.

80
New cards

Blocking Power (Section 37)

The Indian Government's power to block public access to a platform if a Fiduciary is a repeat offender.

81
New cards

Cambridge Analytica Saga

A case where negligence in overseeing third-party developers led to unauthorized harvesting of millions of users' data.

82
New cards

Schrems I (2015)

Legal judgment that invalidated the 'Safe Harbor' framework for EU to U.S. data transfers.

83
New cards

Schrems II (2020)

Legal judgment that invalidated 'Privacy Shield' and mandated TIAs for international transfers.

84
New cards

Access Control

The technical measure ensuring only authorized staff with a 'need-to-know' can access specific datasets.

85
New cards

Supplementary Measures

Additions like strong End-to-End Encryption required if a TIA identifies high risk in a destination jurisdiction.

86
New cards

DPIA (Data Protection Impact Assessment)

A mandatory safety audit for projects involving high-risk data processing or large-scale monitoring.

87
New cards

Opt-out Scheme (Japan)

A registered scheme allowing third-party data provision unless the individual opts out.

88
New cards

72 Hours

The reporting window under GDPR and DPDPA for notifying authorities of a data breach.

89
New cards

Identified or Identifiable

Pillar of personal data where a person is distinguishable or can be identified by combining disparate identifiers.

90
New cards

Automated Decision-Making

Processes where algorithms make significant decisions (like loan denials) without human oversight.

91
New cards

Human Intervention

The right of a user to request a review of an algorithmic decision by a real person.

92
New cards

Confidentiality, Integrity, and Availability

The three core pillars emphasized by Data Security measures.

93
New cards

Consent (UAE Basis)

While primary, it is not mandatory if processing is for contracts, legal obligations, or public interest.

94
New cards

Physical Data Exclusion

The DPDPA explicitly excludes non-digital data that is stored in physical formats and not digitized.

95
New cards

Informational Self-Determination

A concept originating from the German 'census judgment' of 1983.

96
New cards

Deceased Individuals' Data

Excluded by GDPR but covered by the 'Right to Nominate' under the Indian DPDPA.

97
New cards

Itemized Description

A requirement for DPDPA Privacy Notices to list specific data and processing purposes.

98
New cards

Access Tokens

A technical metaphor for the legal grounds required before a system can execute data processing logic.

99
New cards

User API

A technical metaphor for the set of rights endpoints an organization must expose to let individuals control their data.

100
New cards

Digital Office

The designated nature of the Data Protection Board of India for handling complaints and breach remediation.