GAPP Targets Privacy Risks: Principles Provide a Comprehensive, Scalable Framework for Managing Compliance and Reputation Threats
Bibliographic record
Abstract
EXECUTIVE SUMMARY * State, federal and foreign governments are expanding privacy compliance regulations. * Businesses need to regularly assess privacy risks and deploy effective controls. Good security practices do not by themselves represent effective privacy risk management. * Businesses should prepare flowcharts and have other documentation that show how and when they capture personal information; how it is processed, stored and distributed; and who can access it at any time. * Generally Accepted Privacy Principles (GAPP) provide a comprehensive and scalable approach to managing privacy risks. * Practitioners can leverage GAPP to provide advisory and attestation services. ********** [ILLUSTRATION OMITTED] As of early 2011, 46 states had enacted some form of privacy regulation. In particular, those enacted by Massachusetts and Nevada in 2010 significantly raised the bar in terms of business requirements. Even organizations that have no facilities or personnel in Massachusetts may be subject to the state's regulations if they maintain personal information about any Massachusetts resident. The Nevada law applies only to an organization doing business in Nevada. It requires the use of encryption when data storage devices containing personal information are moved beyond the physical or logical controls of the organization or when data is transferred electronically (other than by fax) outside the secure system of an organization. Beyond the expanding U.S. federal legislation and tougher and more pervasive state legislation, other factors increasing privacy-related risks include expansion and enforcement of the Health Insurance Portability and Accountability Act (HIPAA) and international standards. Particularly noteworthy within international standards is the European Union (EU) Data Protection Directive (also known as Directive 95/46/EC). It requires member states (countries) to enact laws prohibiting the transfer of personal information to those countries outside the EU that fail to ensure an adequate level of privacy protection (the U.S. and the EU have established a safe harbor program to meet this concern). Further, the consequences of failing to protect personal information include potential damage to the organization's reputation, brand or business relationships; the possibility of legal liability and industry or regulatory sanctions; possible charges of deceptive business practices; customer or employee distrust; and, in some extreme cases, possible exposure to criminal charges. Such was the case in March 2011 when Google Inc. agreed, without admitting or denying Federal Trade Commission (FTC) charges, to a settlement with the FTC related to alleged deceptive representations and violation of Google's own privacy policy when it launched its social network, Google Buzz, in 2010. The groundbreaking proposed settlement, a first in the history of FTC settlement orders, required Google to implement a comprehensive privacy program to protect consumers' personal information. It also called for regular, independent privacy audits for the next 20 years. This article provides a brief overview of current and emerging privacy-related risks-from regulation and reputation damage- and then demonstrates how businesses can address these risks by leveraging the AICPA/Canadian Institute of Chartered Accountants' (CICA) Generally Accepted Privacy Principles (GAPP) framework. HOW GAPP CAN HELP GAPP brings together international privacy regulatory requirements and best practices in one framework based on privacy principles (see sidebar, 10 Generally Accepted Privacy Principles). The overall objective of the application of GAPP is as follows: * Personal information is collected, used, retained, disclosed, and disposed of in conformity with the commitments in the entity's privacy notice and with criteria set forth in Generally Accepted Privacy Principles issued by the AICPA and CICA. …
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame distilled prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. Learned from the 10,348 direct Codex labels and 10,348 direct Gemma labels. Candidate is the union of thresholded teacher heads; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels or direct frontier model labels.
Codex and Gemma teacher scores by category
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.002 | 0.002 |
| Meta-epidemiology (narrow) | 0.000 | 0.000 |
| Meta-epidemiology (broad) | 0.001 | 0.000 |
| Bibliometrics | 0.001 | 0.001 |
| Science and technology studies | 0.001 | 0.000 |
| Scholarly communication | 0.000 | 0.005 |
| Open science | 0.001 | 0.000 |
| Research integrity | 0.000 | 0.001 |
| Insufficient payload (model declined to judge) | 0.000 | 0.000 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one teacher head, not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".