Data collection, use, dissemination, and destruction

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/35

flashcard set

Earn XP

Description and Tags

We use the data life cycle to demonstrate the flow of data across an organization and the unique risks associated with the data lifecycle.

Last updated 1:54 PM on 8/1/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

36 Terms

1
New cards

How to minimise risk during data collection?

To minimise privacy risk during data collection, only collect data for specified purposes and always collect consent from data subjects for sensitive data. Allow data subjects to opt out of services they deem unnecessary.

2
New cards

Data Collection

This is the point at which personal data is collected into an information system, it can be collected multiple times and in multiple ways.

3
New cards

First Party Collection

This type of collection happens when an individual provides their personal information directly to the data controller.

4
New cards

Secondary Use

This occurs when data is re-used and repurposed for a different purpose than the original purpose.

5
New cards

Third Party Collection

This happens when already collected personal data is transferred to a third party organisation.

6
New cards

Surveillance

When the collector observes data produced by the data subject

7
New cards

Active Collection

 This is when the collection of data is obvious and data subject has consented (Like filling out an online form)

8
New cards

Passive Collection

This is when the data collection is not obvious and the data subject has not consented to it (Background collection of a user’s IP address and web activity)

9
New cards

Consent

This is when the data subject agrees to have their data collected. Consent is often required to process data lawfully. It can be explicit or implied.

10
New cards

Explicit Consent

Consent that required the data subject to make an action like checking a box

11
New cards

Implied Consent

Consent that is implied and does not require a data subject to check a box.

12
New cards

Repurposing

When previously collected data is now being used for a different specified purpose.

13
New cards

How to reduce risk during data use / processing?

To minimise privacy risk during this stage, only use data for the original specified purpose. If you use data for any additional purposes, you must collect consent from the data subject.

14
New cards

Use

This is when an organization manipulates personal data they have collected. This includes just reading personal data.

15
New cards

Disclosure

This is when organizations reveal personal data to a third party. Organizations must disclose data lawfully.

16
New cards

Privacy Notice

Statement made to data subjects that describes how organizations collect, use, retain and disclose personal information.

17
New cards

Privacy Policy

This is an internal document that governs how an organization wants to handle personal information.

18
New cards

How to minimise risk during data retention?

Destroy data when it is no longer needed to complete the transaction. Any new uses that motivate longer retention periods require additional consent from the data subject or sending new privacy notices.

19
New cards

How to reduce risk during data destruction?

As soon as data is no longer needed, ensure the data and any derivatives are removed from all systems using appropriate methods to prevent recovery.

20
New cards

Interrogation

Bombarding someone with questions for personal information, especially when there is no pre-existing relationship

21
New cards

How to reduce the risk of interrogation as a privacy technologist?

Ensure that the information you have collected is neccesary ONLY for the purpose of doing business.

22
New cards

How to reduce the risk of surveillance as a privacy technologist?

Inform website visitors or application users of the collection of their personal information, and offer them the choice to opt out or opt in when appropriate

23
New cards

Interference

Interference is any act that prevents or obstructs a process from continuing or being carried out properly.

24
New cards

Decisional Interference

This occurs when a third party, such as a government or organisation gets in the way of an individual’s decision-making.

25
New cards

Can inaccurate data lead to decisional interference?

YES

26
New cards

Interference with self representation

This occurs when a third party alters how an individual is represented, such as their marital status, race or political affiliation

27
New cards

Intrusion

This is when an individual’s solitude or tranquility are disturbed. Personal information is not used. One does not need to know a person’s name to knock on their door to try to sell them something, or to mail an advertisement to a “local resident.”

28
New cards

Upgrades

This helps with fixing bugs and improving a system, it can also be used to replace existing hardware or software

29
New cards

Intrusion Reports

This allows for the system to be monitored for threats and to detect and prevent attacks on the system

30
New cards

How to determine a system vulnerability?

Capability and probability

31
New cards

Patches

Also known as bug fixes are used to fix, update or improve a system.

32
New cards

Disclosure

INTENTIONALLY revealing truthful information about an individual

33
New cards

Distortion

When someone spreads false or inaccurate information about someone else.

34
New cards

Exposure

Exposing information that people normally conceal from others because it may open them up to judgment or harm

35
New cards

Increased accessibility

Where sensitive information is suddenly more accessible due to the digital format

36
New cards

Appropriation

Using someone else’s identity for someone’s purpose or to promote someone’s own interest.