Handout 9 Flashcards

(28 cards)

1
Q

What are the Fundamental Principles of Privacy?

A
  • Lawfulness, fairness, transparency
  • Purpose limitation
  • Data minimization
  • Accuracy
  • Storage Limitation
  • Integrity and Confidentiality
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are a Subject’s Data Rights?

A

Right to:
- Information
- Access
- Rectification
- Erasure
- Restrict Processing
- Data Portablility
- Object
- Automated Decisions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Personal Data VS Sensitive Personal Data

A
  • Personal Data identifies a person
  • Sensitive Personal Data is more Sensitive and Tightly Guarded Data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Different the Conditions for Two Fine Tiers in the GDPR

A
  • Tier 1: Failing to meet Processor obligations, failing to appoint a DPO
  • TIer 2: Breaching core principles, breaking data subject rights.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the Time Window for Notification for Data Breaches in GDPR Compliant Organizations?

A

72 Hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the Lawful Bases for Data Processing in the GDPR?

A
  • Freely given, informed consent
  • Necessary contract
  • Required legal obligation
  • Vital interests of user
  • Public task or local authority
  • Legitimate interests
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the Key Obligations in the GDPR?

A
  • Privacy by design and default
  • Data Protection Impact Assesments (DPIAs)
  • Data Protection Officer (DPO)
  • Data Breach Notification
  • International Data Transfers
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the Two Tiers of Fines in the GRPR?

A
  1. Up to 10 million euros or 2%
  2. Up to 20 million euros or 4%
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the GDPR?

A

Europe’s General Data Protection Regulations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the HIPAA?

A

The US’ Health Insurance Portability and Accountability Act sets standards for patient health information protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the Primary Goals of HIPAA?

A
  • Health insurance portability
  • Combating Healthcare fraud and abuse
  • Protecting patient health information
  • Ensure electronic personal health information security
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Who are the HIPAA-covered entities

A
  • Health providers
  • Health planners
  • Clearing houses
  • All business associates from above
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the Time Window for Notification for Data Breaches in HIPAA Compliant Organizations?

A

60 Days

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What actions are permitted without authorization in HIPAA?

A
  • Treatment
  • Payment
  • Healthcare Operations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are some actions that are not permitted without authorization in HIPAA?

A
  • Marketing
  • Sale of PHI
  • Psychotherapy notes
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the HIPAA Penalty Tiers?

A

Per Violation:
1. $100 - $50,000 (Didn’t know or couldn’t have known)
2. $1,000 - $50,000 (Reasonable cause)
3. $10,000 - $50,000 (Willful neglect, corrected within 30 days)
4. $50,000+ (Wilful neglect, not corrected)

17
Q

What is the UAE PDPL?

A

The UAE’s Personal Data Protection Law is the UAE’s first comprehensive federal data protection law

18
Q

What is the Scope of the UAE’s PDPL

A
  • Controllers/processors in the UAE
  • Processing of individuals in the UAE
  • all Sectors
19
Q

What is the Maximum Penalty of the UAE PDPL?

A

10 million dirhams (~ $2.7 million)

20
Q

What are the UAE PDPL’s Data Processing Principles?

A
  • Lawfulness and Fairness
  • Purpose Limitation
  • Data Minimization
  • Accuracy
  • Storage Limitation
  • Security
  • Accountability
21
Q

What are the Legal Bases for Data Processing in the UAE PDPL?

A
  • Clear, informed consent
  • Contractual Necessity
  • Vital interests of user
  • Public Interest
  • Legitimate Interest
22
Q

What are the Data Rights of a Subject in the UAE PDPL?

A
  • Information and Access Rights
  • Correction and Deletion
  • Control and Portability
  • Sensitive data requires explicit consent or specific legal authorization
23
Q

What is the Expected Subject Response Time in the UAE PDPL?

A

30 days (can be extended to 60 with justification)

24
Q

What are the Controller Obligations in the UAE PDPL?

A
  • Privacy by Design and Default
  • Data Protection Impact Assessment
  • Data Protection Officer
  • Data Breach Notification
  • International Transfers
25
What are the Core Principles of Privacy as a Design Principle?
- Privacy by default - Data minimization - End-to-end security - Visibility and transparency - User-centric
26
What are the Practices all Developers Should Follow?
- Privacy by Design - Security First - Documentation - Stay Informed
27
What are the Practices all Professionals Should Follow?
- Question - Advocate - Learn - Reflect
28
What should be Done upon the Discovery of a Breach (0-24 Hours)
- Contain the breach - Assess scope of breach - Assemble response team - Start incident log