click below
click below
Normal Size Small Size show me how
2KMASDSKsmdsam
21m123m122
| Term | Definition |
|---|---|
| 10173 Section 12 | Processing of Personal Information States that you can process regular personal data if you have consent, a contract, a legal obligation, or if it protects a vital interest. |
| 10173 Section 13 | Processing of Sensitive Personal Information States that sensitive data (race, health, government IDs) can generally only be processed with specific consent, for medical treatment, or by court order. |
| 10173 Section 12 and Section 13 | When is it legal to use data? You legally give a gym your name and email for a contract (Sec 12). However, they cannot legally demand your HIV status without explicit consent or a medical emergency (Sec 13). |
| 10173 Section 16 | Rights of the Data Subject You have the right to be informed, access, correct, erase, or object to the use of your data. |
| 10173 Section 17 | Transmissibility of Rights If you pass away or become incapacitated, your legal heirs can invoke your data rights on your behalf. |
| 10173 Section 16 and Section 17 | Your Privacy Rights You demand an app delete your credit card details from their server (Sec 16). If you pass away, your spouse has the legal right to demand the bank close and erase your account data (Sec 17). |
| 10173 Section 20 | Security of Personal Information Companies must implement physical, technical, and organizational measures to protect data. |
| 10173 Section 21 | Principle of Accountability The company remains strictly accountable for your data, even if they outsource the processing to a third party. |
| 10173 Section 20 and Section 21 | Protecting the Data A hospital installs encrypted servers to protect patient records (Sec 20). If they hire a third-party IT firm that gets hacked, the hospital is still the one legally accountable to the patients (Sec 21). |
| 10173 Section 25 | Unauthorized Processing Penalizes processing data without consent or legal authority (doing it on purpose). |
| 10173 Section 26 | Accessing Due to Negligence Penalizes people who, out of sheer carelessness, allow unauthorized persons to access data. |
| 10173 Section 25 and Section 26 | Crimes of Mishandling An employee secretly copies files to intentionally sell to a marketer (Sec 25). If the employee accidentally leaves a master flash drive on a cafe table and a stranger takes it, that is negligence (Sec 26). |
| 10173 Section 27 | Improper Disposal Penalizes throwing away data without properly shredding or destroying it. |
| 10173 Section 28 | Processing for Unauthorized Purposes Penalizes using collected data for a purpose totally different from what the person originally agreed to. |
| 10173 Section 27 and Section 28 | Crimes of Misuse A clinic throws intact patient medical records into a public garbage bin (Sec 27). A school legally collects numbers for storm alerts, but illegally uses them to text advertisements for a summer camp (Sec 28). |