GAPP Targets Privacy Risks: Principles Provide a Comprehensive, Scalable Framework for Managing Compliance and Reputation Threats
Notice bibliographique
Résumé
EXECUTIVE SUMMARY * State, federal and foreign governments are expanding privacy compliance regulations. * Businesses need to regularly assess privacy risks and deploy effective controls. Good security practices do not by themselves represent effective privacy risk management. * Businesses should prepare flowcharts and have other documentation that show how and when they capture personal information; how it is processed, stored and distributed; and who can access it at any time. * Generally Accepted Privacy Principles (GAPP) provide a comprehensive and scalable approach to managing privacy risks. * Practitioners can leverage GAPP to provide advisory and attestation services. ********** [ILLUSTRATION OMITTED] As of early 2011, 46 states had enacted some form of privacy regulation. In particular, those enacted by Massachusetts and Nevada in 2010 significantly raised the bar in terms of business requirements. Even organizations that have no facilities or personnel in Massachusetts may be subject to the state's regulations if they maintain personal information about any Massachusetts resident. The Nevada law applies only to an organization doing business in Nevada. It requires the use of encryption when data storage devices containing personal information are moved beyond the physical or logical controls of the organization or when data is transferred electronically (other than by fax) outside the secure system of an organization. Beyond the expanding U.S. federal legislation and tougher and more pervasive state legislation, other factors increasing privacy-related risks include expansion and enforcement of the Health Insurance Portability and Accountability Act (HIPAA) and international standards. Particularly noteworthy within international standards is the European Union (EU) Data Protection Directive (also known as Directive 95/46/EC). It requires member states (countries) to enact laws prohibiting the transfer of personal information to those countries outside the EU that fail to ensure an adequate level of privacy protection (the U.S. and the EU have established a safe harbor program to meet this concern). Further, the consequences of failing to protect personal information include potential damage to the organization's reputation, brand or business relationships; the possibility of legal liability and industry or regulatory sanctions; possible charges of deceptive business practices; customer or employee distrust; and, in some extreme cases, possible exposure to criminal charges. Such was the case in March 2011 when Google Inc. agreed, without admitting or denying Federal Trade Commission (FTC) charges, to a settlement with the FTC related to alleged deceptive representations and violation of Google's own privacy policy when it launched its social network, Google Buzz, in 2010. The groundbreaking proposed settlement, a first in the history of FTC settlement orders, required Google to implement a comprehensive privacy program to protect consumers' personal information. It also called for regular, independent privacy audits for the next 20 years. This article provides a brief overview of current and emerging privacy-related risks-from regulation and reputation damage- and then demonstrates how businesses can address these risks by leveraging the AICPA/Canadian Institute of Chartered Accountants' (CICA) Generally Accepted Privacy Principles (GAPP) framework. HOW GAPP CAN HELP GAPP brings together international privacy regulatory requirements and best practices in one framework based on privacy principles (see sidebar, 10 Generally Accepted Privacy Principles). The overall objective of the application of GAPP is as follows: * Personal information is collected, used, retained, disclosed, and disposed of in conformity with the commitments in the entity's privacy notice and with criteria set forth in Generally Accepted Privacy Principles issued by the AICPA and CICA. …
Récupéré en direct depuis OpenAlex et désinversé. Les résumés ne sont pas conservés dans cette base de données : les index inversés représentent 8,6 Go des 9,3 Go de texte de la base, et le serveur dispose de 13 Go libres.
Comment cette classification a été obtenuedéplier
Prédiction distillée sur la base complète
Imitation des enseignantsNi prévalence calibrée, ni vérité terrain. Validation humaine à venir. Apprise à partir de 10 348 étiquettes directes de Codex et de 10 348 étiquettes directes de Gemma. Le mode candidate est l'union des têtes enseignantes seuillées; le consensus est leur intersection. Ces sorties portent le statut machine_predicted_unvalidated et ne sont ni des étiquettes humaines ni des étiquettes directes de modèles de pointe.
Scores Codex et Gemma par catégorie
| Catégorie | Codex | Gemma |
|---|---|---|
| Métarecherche | 0,002 | 0,002 |
| Méta-épidémiologie (sens strict) | 0,000 | 0,000 |
| Méta-épidémiologie (sens large) | 0,001 | 0,000 |
| Bibliométrie | 0,001 | 0,001 |
| Études des sciences et des technologies | 0,001 | 0,000 |
| Communication savante | 0,000 | 0,005 |
| Science ouverte | 0,001 | 0,000 |
| Intégrité de la recherche | 0,000 | 0,001 |
| Charge utile insuffisante (le modèle a refusé de juger) | 0,000 | 0,000 |
Scores machine (provisoires)
Les deux têtes enseignantes du modèle étudiant, lues sur ce travail. Un score ordonne la base pour la relecture; il n'affirme jamais une catégorie, et le statut de validation accompagne chaque rangée tel quel.
Scores de référence d'un modèle non mature (critères de maturité non atteints, 7 itérations). Un score ordonne; il n'affirme jamais une catégorie.
score_only:v0-immature-baseline · tel quel depuis la passe de notation : score_only signifie que le nombre peut ordonner les travaux, et qu'aucune étiquette de catégorie n'en découleClassification
machine, non validéePrédiction automatique; un appel candidat d’une seule tête enseignante, pas un consensus.
Le détail, modèle par modèle et score par score, se trouve en fin de page sous « Comment cette classification a été obtenue ».