1/35
We use the data life cycle to demonstrate the flow of data across an organization and the unique risks associated with the data lifecycle.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
How to minimise risk during data collection?
To minimise privacy risk during data collection, only collect data for specified purposes and always collect consent from data subjects for sensitive data. Allow data subjects to opt out of services they deem unnecessary.
Data Collection
This is the point at which personal data is collected into an information system, it can be collected multiple times and in multiple ways.
First Party Collection
This type of collection happens when an individual provides their personal information directly to the data controller.
Secondary Use
This occurs when data is re-used and repurposed for a different purpose than the original purpose.
Third Party Collection
This happens when already collected personal data is transferred to a third party organisation.
Surveillance
When the collector observes data produced by the data subject
Active Collection
This is when the collection of data is obvious and data subject has consented (Like filling out an online form)
Passive Collection
This is when the data collection is not obvious and the data subject has not consented to it (Background collection of a user’s IP address and web activity)
Consent
This is when the data subject agrees to have their data collected. Consent is often required to process data lawfully. It can be explicit or implied.
Explicit Consent
Consent that required the data subject to make an action like checking a box
Implied Consent
Consent that is implied and does not require a data subject to check a box.
Repurposing
When previously collected data is now being used for a different specified purpose.
How to reduce risk during data use / processing?
To minimise privacy risk during this stage, only use data for the original specified purpose. If you use data for any additional purposes, you must collect consent from the data subject.
Use
This is when an organization manipulates personal data they have collected. This includes just reading personal data.
Disclosure
This is when organizations reveal personal data to a third party. Organizations must disclose data lawfully.
Privacy Notice
Statement made to data subjects that describes how organizations collect, use, retain and disclose personal information.
Privacy Policy
This is an internal document that governs how an organization wants to handle personal information.
How to minimise risk during data retention?
Destroy data when it is no longer needed to complete the transaction. Any new uses that motivate longer retention periods require additional consent from the data subject or sending new privacy notices.
How to reduce risk during data destruction?
As soon as data is no longer needed, ensure the data and any derivatives are removed from all systems using appropriate methods to prevent recovery.
Interrogation
Bombarding someone with questions for personal information, especially when there is no pre-existing relationship
How to reduce the risk of interrogation as a privacy technologist?
Ensure that the information you have collected is neccesary ONLY for the purpose of doing business.
How to reduce the risk of surveillance as a privacy technologist?
Inform website visitors or application users of the collection of their personal information, and offer them the choice to opt out or opt in when appropriate
Interference
Interference is any act that prevents or obstructs a process from continuing or being carried out properly.
Decisional Interference
This occurs when a third party, such as a government or organisation gets in the way of an individual’s decision-making.
Can inaccurate data lead to decisional interference?
YES
Interference with self representation
This occurs when a third party alters how an individual is represented, such as their marital status, race or political affiliation
Intrusion
This is when an individual’s solitude or tranquility are disturbed. Personal information is not used. One does not need to know a person’s name to knock on their door to try to sell them something, or to mail an advertisement to a “local resident.”
Upgrades
This helps with fixing bugs and improving a system, it can also be used to replace existing hardware or software
Intrusion Reports
This allows for the system to be monitored for threats and to detect and prevent attacks on the system
How to determine a system vulnerability?
Capability and probability
Patches
Also known as bug fixes are used to fix, update or improve a system.
Disclosure
INTENTIONALLY revealing truthful information about an individual
Distortion
When someone spreads false or inaccurate information about someone else.
Exposure
Exposing information that people normally conceal from others because it may open them up to judgment or harm
Increased accessibility
Where sensitive information is suddenly more accessible due to the digital format
Appropriation
Using someone else’s identity for someone’s purpose or to promote someone’s own interest.