Dictionary · AICPA Privacy Management Framework
privacy-management-framework
Nouns
29 senses- Anonymize
- glossary
The removal of any person-related information that could be used to identify a specific individual.
- Entity
- glossary
An organization that collects, uses, retains and discloses PI.
- policy
- glossary
A written statement that communicates management's intent, objectives, requirements, responsibilities and standards.
- Sensitive PI
- glossary
This is PI that requires a higher duty of care when it comes to processing and controlling, for example, for personal health information including known medical or health conditions, financial information, racial or ethnic origin, political opinions, religious or philosophical beliefs, union membership, sexual preferences or interests, or information related to prior criminal arrests and convictions.
- third party
- glossary
This is an entity or service organization that may not be legally controlled by a covered entity but might otherwise be legally affiliated with the covered entity that collects PI. In many cases, affiliated entities are also impacted by and should be covered by the originating covered entity's privacy agreements or by applicable legal statutes.
- Opting in
- glossary
PI may not be collected, used, retained and disclosed by the entity without the explicit consent of the individual.
- Outsourcing
- glossary
The use and handling of PI by a third-party service organization engaged by a legal entity or person to provide processes, services or products or to operate a business function on behalf of the legal entity or person.
- Personal information (PI)
- glossary
Information and data that can describe, characterize, identify or otherwise verify an identifiable legal person or a group of people (data subject).
- PI lifecycle
- glossary
The end-to-end process of obtaining agreement (consent), collecting, creating, using, storing and retaining, disclosing, erasing and disposing, masking and anonymizing a legal person's identifying information.
- Processor
- glossary
An entity that provides data and information processing services to other legal persons, entities and organizations. A processor entity may be an application, platform, infrastructure, data storage (as a service) organization, or a private or public cloud-providing business entity.
- Privacy
- glossary
The rights and obligations of individuals and organizations concerning the collection, creation, use, retention, disclosure and destruction of PI.
- Privacy breach
- glossary
A data privacy breach occurs when an individual or organization breaks into systems or locations where PI was collected, created, used or stored in an unauthorized manner (without the explicit permission of the data subjects or the entity controlling or processing the data) and causes the data to be disclosed in ways that are not under the entity's policies, applicable laws or regulations.
- Privacy program
- glossary
The organization, people, policies, procedures and preventive and detective controls placed into effect that allow a legal entity to manage and protect the PI collected from data subjects according to its agreements, business needs and applicable laws and regulations.
- Noun #108912
- glossary
The reason why an entity seeks to collect, use, create, store and disclose the PI of a data subject. The purposes should be explicit, acknowledged by the entity in an agreement with affected data subjects, and the entity should not use the data subject's PI for other purposes not agreed to by the data subject.
- Noun #123016
- glossary
To delete or black out PI or data on a physical document or in a data file. Data masking is a technical form of redaction that helps an entity prevent the unauthorized disclosure of a data subject's PI.
- Revocation
- glossary
A data subject must be allowed to request access to the PI an entity has collected from or holds on their behalf and should be able to revoke their continued permission for the entity's collection, creation, use, processing and retention of a data subject's PI. An entity that seeks to transfer processing and control of a data subject's PI to another legal entity or person remains responsible for notifying affected data subjects of the other processor and controller's roles and for allowing a data subject to revoke their permission to continue to use and hold the data subject's PI.
- agreement
- glossary
An explicit agreement between a data subject who is the legal owner of their personal information (PI) with someone who has a fiduciary or legal duty to the data subject, such as a parent or legal guardian of a minor, or someone who has a legal power of attorney to act in the place of an original data subject.
- affiliate
- glossary
An entity that controls, is controlled by, or is under common control with another entity.
- California Consumer Privacy Act (CCPA)
- glossary
A bill that enhances privacy rights and consumer protection for residents of the state of California. The bill became effective Jan. 1, 2020.
- Confidentiality
- glossary
The protection of non-PI and data from the risk of unauthorized disclosure.
- Consent
- glossary
An agreement executed by an individual on behalf of an entity authorizing them to collect, use and disclose PI under an executed privacy agreement. Such agreements should be explicit but may be implied depending on the jurisdiction in which the entity operates or provides services. Explicit consent is generally given orally (if recorded), electronically and in writing, and is unequivocal and must disclose and reflect the purposes and needs for which the entity seeks the data subject's explicit consent.
- Controller
- glossary
An entity that has taken possession and controls access to a data subject's PI.
- Cookie
- glossary
Pieces of data generated or collected in web browsers or by a web server and stored in either a user's computer or web server and are ready for use by the web application when the user browses the application in the future. This data can then be used by an entity hosting the web server to identify and track the user's browsing history and searches or when the user returns to the website. Cookies are also designed to help personalize the web content presented to a user of the browser on which the cookies were stored based on prior interests, preferences, searches and the locations where the user logged in. Cookies can be used to offer targeted marketing materials and items of potential interest based on the user's previous internet sessions. Advertisers can use cookies and other tracking methods to analyze user behaviors. When different users use a computer that was previously used by another person, the website may inspect the cookies could execute the new user's session using the wrong user's preferences. For this reason, recent privacy legislation has focused on the collection of a browser's cookies and browsing history and the use of that data by a website's owner, processor, operator or controller.
- data subject
- glossary
The individual legal person from whom PI is sought, collected, processed, used, controlled and handled by another legal person or entity.
- Encryption
- glossary
The process of transforming information to make it unreadable to anyone except those possessing a special key (to decrypt).
- General Data Protection Regulation (GDPR)
- glossary
A regulation in the European Union (EU) law on data protection and privacy for all individuals within the EU and the European Economic Area (EEA). The regulation is effective as of May 25, 2018.
- Health Insurance Portability and Accountability Act (HIPAA)
- glossary
An act of the U.S. Congress that stipulates how personally identifiable information is to be protected by the health care and health care insurance industries. It was signed into law in 1996.
- Noun #74095
- glossary
The person about whom the PI is being collected (sometimes referred to as the data subject).
- Internal (entity) personnel
- glossary
Employees, sub-contractors, authorized agents and others acting on behalf of the entity, its affiliates and its service providers.