Privacy & Data Ethics Flashcards
7 cards from real CEA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Privacy & Data Ethics flashcards as text
A company collects customer location data to improve delivery routes but later decides to use it for targeted advertising without notifying customers. This practice violates which core data ethics principle?
Answer: Purpose limitation
Purpose limitation requires that data collected for one specific purpose not be used for a different, incompatible purpose without obtaining new consent.
Which legal framework established the 'right to be forgotten,' allowing individuals to request deletion of their personal data from online platforms?
Answer: GDPR
The EU's General Data Protection Regulation (GDPR) codified the right to erasure, commonly called the 'right to be forgotten,' in Article 17.
An employee accidentally emails a spreadsheet containing Social Security numbers to the wrong distribution list. Under data breach ethics, what is the FIRST obligation of the organization?
Answer: Assess the scope and notify affected individuals promptly
Ethical breach response prioritizes assessing harm and notifying affected individuals in a timely manner so they can take protective action.
What does 'contextual integrity' mean in the context of privacy ethics?
Answer: Information flows appropriately when they match the norms of the context in which data was shared
Contextual integrity, developed by philosopher Helen Nissenbaum, holds that privacy is violated when information flows in ways that don't match the norms of the original social context.
A data analytics firm de-identifies patient records before sharing them with researchers. However, researchers later re-identify individuals by combining the data with publicly available datasets. This scenario illustrates the risk of:
Answer: Re-identification
Re-identification occurs when anonymized data is combined with auxiliary information to reveal the identity of individuals, undermining de-identification protections.
Which of the following best describes a 'privacy by design' approach?
Answer: Embedding privacy protections into systems and processes from the outset
Privacy by design, developed by Ann Cavoukian, requires that privacy be proactively integrated into the design of systems and business practices from the very beginning.
Under the Children's Online Privacy Protection Act (COPPA), operators of websites directed to children under 13 must obtain verifiable parental consent before:
Answer: Collecting personal information from the child
COPPA mandates verifiable parental consent before collecting, using, or disclosing personal information from children under age 13.