Privacy Terms

You should be familiar with these general concepts.

4 slides · 3 min read · Domain 1

Slide 1

DATA SUBJECT

The individual as a human being that the PIl refers to.

DATA PROCESSOR

Any entity, working on behalf or at the behest of the data controller, that processes PIl. Under most Pll-related laws, "processing" can include absolutely anything that can be done with data: creating, storing, sending, computing, compiling, copying, destroying, and so forth. While the data processor does have to comply with applicable PIl law, it is the data owner/controller that remains legally liable for any unauthorized disclosure of PIl even if the processor is proven to be negligent/malicious.

DATA OWNER / DATA CONTROLLER

An entity that collects or creates PIl. The data owner/controller is legally responsible for the protection of the PIl in their control and liable for any unauthorized release of Pll. Ostensibly, the owner/controller is an organization; the legal entity that legitimately owns the data. In some cases (in certain | jurisdictions, under certain laws), the data owner is a named individual, such as an officer of the company, who is the nominal data owner. In actual practice, however, we usually think of the data owner as the managerial person or office that has the most day-to-day use and control of the data; that is, the department or branch that created/collected the data and which puts the data into use for the organization.

NOTIFICATION

The data subject (the individual human related to the personal data in question) should be notified before any of their personal data is collected or created.

PARTICIPATION

The subject should have the option not to take part in the transaction, if the subject chooses not to share their personal data.

DATA CUSTODIAN

The person/role within the organization who usually manages the data on a day-to-day basis on behalf of the data owner/ controller. This is often a database manager or administrator; other roles that might be considered data custodians could be system administrators or anyone with privileged access to the system or data set.

LIMITATION

Any personal data should only be used for the purpose identified in the scope aspect of the transaction; any additional use would require repeating the notification and participation aspects.

RETENTION

Personal data should not be kept any longer than is necessary for the purpose, or as required by applicable law.

DISSEMINATION

Any entity that has possession of personal data should not share it with any other entity, nor release it, without the express permission of the data subject and in accordance with applicable law.

SCOPE

Any personal data collected or created should be for a specific purpose; this purpose should be legal and ethical and be included in the notification aspect of the transaction, as well as inform the limitation aspect.

ACCURACY

Any personal data should be factual and current; data subjects should have a means to correct/edit any information about the subject in a simple, timely manner.

SECURITY

Any entity that has possession of personal data is responsible for protecting it.

Test this domain