392
If there are potential sensitivities or risks involved in the disclosure of data, that
data is sensitive. Most FEW systems data is sensitive, along with (for instance) a
person’s medical history (e.g., HIPAA), financial status, student records (e.g.,
FERPA), web searches, and locations of travel. If data is covered by an individual’s
or organization’s right to privacy, this data is private. Privacy is most commonly
granted by custom and law for information about which nobody but the individual
or organization concerned has a legitimate need to know. Trade Secrets are private
data that a business elects to hold private to avoid providing an unfair advantage to
competitors; many businesses consider their supply chains including FEW usage
and production to be trade secrets.
Data Protection is the law, and/or means of enforcement of the law, protecting
private or sensitive data and exercising the right to data privacy. You cannot achieve
Data Ethics or privacy without effective data protection practices. Data protection
principles include minimization, accuracy control, expiry, legitimate purpose, transparency (accountability), integrity (effectiveness), and confidentiality. Privacy
International identifies seven key data protection principles (quoted below; Privacy
International, n.d.).
14.4.1 Privacy International Data Protection Principles
• Fair, Lawful and Transparent: The processing of personal data should be lawful
and fair and done in a transparent manner.
• Purpose Limitation: Personal data should be processed for a specified, explicit,
and legitimate purpose, stated at the point of collection, and further processing
(remains) compatible with this purpose.
• Minimization: The processing of personal data should be adequate, relevant and
limited to the necessity of the purpose for which it is being processed.
• Accuracy: Personal data that is processed should be accurate, complete and measures should be taken to ensure it is up to date.
• Storage Limitation: Personal data should only be retained for the period of time
that is necessary for the purposes for which it was processed.
• Integrity and Confidentiality: Appropriate measures must be taken to ensure the
security of data and systems, and to protect personal data from loss, unauthorized
access, destruction, use, modification, or disclosure.
• Accountability: Those that process personal data must be accountable for
demonstrating compliance with the above principles, their obligations, and facilitate and fulfill the exercise of these rights.
It is easy to see that many modern businesses violate these data protection
principles routinely, for instance by failing to limit the purpose of customer data’s
use to the originally intended purpose, failure to be transparent about how data is
being used or sold, or by failing to protect the confidentiality of the data from
hackers, or by minimizing data collection to that which is strictly necessary.
B. L. Ruddell
If there are potential sensitivities or risks involved in the disclosure of data, that
data is sensitive. Most FEW systems data is sensitive, along with (for instance) a
person’s medical history (e.g., HIPAA), financial status, student records (e.g.,
FERPA), web searches, and locations of travel. If data is covered by an individual’s
or organization’s right to privacy, this data is private. Privacy is most commonly
granted by custom and law for information about which nobody but the individual
or organization concerned has a legitimate need to know. Trade Secrets are private
data that a business elects to hold private to avoid providing an unfair advantage to
competitors; many businesses consider their supply chains including FEW usage
and production to be trade secrets.
Data Protection is the law, and/or means of enforcement of the law, protecting
private or sensitive data and exercising the right to data privacy. You cannot achieve
Data Ethics or privacy without effective data protection practices. Data protection
principles include minimization, accuracy control, expiry, legitimate purpose, transparency (accountability), integrity (effectiveness), and confidentiality. Privacy
International identifies seven key data protection principles (quoted below; Privacy
International, n.d.).
14.4.1 Privacy International Data Protection Principles
• Fair, Lawful and Transparent: The processing of personal data should be lawful
and fair and done in a transparent manner.
• Purpose Limitation: Personal data should be processed for a specified, explicit,
and legitimate purpose, stated at the point of collection, and further processing
(remains) compatible with this purpose.
• Minimization: The processing of personal data should be adequate, relevant and
limited to the necessity of the purpose for which it is being processed.
• Accuracy: Personal data that is processed should be accurate, complete and measures should be taken to ensure it is up to date.
• Storage Limitation: Personal data should only be retained for the period of time
that is necessary for the purposes for which it was processed.
• Integrity and Confidentiality: Appropriate measures must be taken to ensure the
security of data and systems, and to protect personal data from loss, unauthorized
access, destruction, use, modification, or disclosure.
• Accountability: Those that process personal data must be accountable for
demonstrating compliance with the above principles, their obligations, and facilitate and fulfill the exercise of these rights.
It is easy to see that many modern businesses violate these data protection
principles routinely, for instance by failing to limit the purpose of customer data’s
use to the originally intended purpose, failure to be transparent about how data is
being used or sold, or by failing to protect the confidentiality of the data from
hackers, or by minimizing data collection to that which is strictly necessary.
B. L. Ruddell
