Privacy Harm and Non-Compliance from a Legal Perspective

Saved in:
Bibliographic Details
Title: Privacy Harm and Non-Compliance from a Legal Perspective
Language: English
Authors: Suvineetha Herath (ORCID 0009-0002-1262-7823), Haywood Gelman (ORCID 0009-0009-7208-1624), Lisa Mckee (ORCID 0009-0008-1320-3815)
Source: Journal of Cybersecurity Education, Research and Practice. 2023 2023(2).
Availability: Kennesaw State University. 1000 Chastain Road, Kennesaw, Georgia 30144. Tel: 470-578-3568; e-mail: cybersec@kennesaw.edu; Web site: https://digitalcommons.kennesaw.edu/jcerp/
Peer Reviewed: Y
Page Count: 10
Publication Date: 2023
Document Type: Journal Articles
Reports - Evaluative
Descriptors: Information Security, Privacy, Data, Standards, Laws, Information Technology, Best Practices, Legal Responsibility, Information Policy, Design Requirements, Confidentiality, Compliance (Legal), Identification, Data Use, Legal Problems, Governance
ISSN: 2472-2707
Abstract: In today's data-sharing paradigm, personal data has become a valuable resource that intensifies the risk of unauthorized access and data breach. Increased data mining techniques used to analyze big data have posed significant risks to data security and privacy. Consequently, data breaches are a significant threat to individual privacy. Privacy is a multifaceted concept covering many areas, including the right to access, erasure, and rectify personal data. This paper explores the legal aspects of privacy harm and how they transform into legal action. Privacy harm is the negative impact to an individual as a result of the unauthorized release, gathering, distillation, or expropriation of personal information. Privacy Enhancing Technologies (PETs) emerged as a solution to address data privacy issues and minimize the risk of privacy harm. It is essential to implement privacy enhancement mechanisms to protect Personally Identifiable Information (PII) from unlawful use or access. FIPPs (Fair Information Practice Principles), based on the 1973 Code of Fair Information Practice (CFIP), and the Organization for Economic Cooperation and Development (OECD), are a collection of widely accepted, influential US codes that agencies use when evaluating information systems, processes, programs, and activities affecting individual privacy. Regulatory compliance places a responsibility on organizations to follow best practices to ensure the protection of individual data privacy rights. This paper will focus on FIPPs, relevance to US state privacy laws, their influence on OECD, and reference to the EU General Data Processing Regulation. (GDPR).
Abstractor: As Provided
Entry Date: 2024
Accession Number: EJ1415199
Database: ERIC
FullText Text:
  Availability: 0
CustomLinks:
  – Url: https://eric.ed.gov/contentdelivery/servlet/ERICServlet?accno=EJ1415199
    Name: ERIC Full Text
    Category: fullText
    Text: Full Text from ERIC
Header DbId: eric
DbLabel: ERIC
An: EJ1415199
AccessLevel: 3
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Privacy Harm and Non-Compliance from a Legal Perspective
– Name: Language
  Label: Language
  Group: Lang
  Data: English
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Suvineetha+Herath%22">Suvineetha Herath</searchLink> (ORCID <externalLink term="https://orcid.org/0009-0002-1262-7823">0009-0002-1262-7823</externalLink>)<br /><searchLink fieldCode="AR" term="%22Haywood+Gelman%22">Haywood Gelman</searchLink> (ORCID <externalLink term="https://orcid.org/0009-0009-7208-1624">0009-0009-7208-1624</externalLink>)<br /><searchLink fieldCode="AR" term="%22Lisa+Mckee%22">Lisa Mckee</searchLink> (ORCID <externalLink term="https://orcid.org/0009-0008-1320-3815">0009-0008-1320-3815</externalLink>)
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="SO" term="%22Journal+of+Cybersecurity+Education%2C+Research+and+Practice%22"><i>Journal of Cybersecurity Education, Research and Practice</i></searchLink>. 2023 2023(2).
– Name: Avail
  Label: Availability
  Group: Avail
  Data: Kennesaw State University. 1000 Chastain Road, Kennesaw, Georgia 30144. Tel: 470-578-3568; e-mail: cybersec@kennesaw.edu; Web site: https://digitalcommons.kennesaw.edu/jcerp/
– Name: PeerReviewed
  Label: Peer Reviewed
  Group: SrcInfo
  Data: Y
– Name: Pages
  Label: Page Count
  Group: Src
  Data: 10
– Name: DatePubCY
  Label: Publication Date
  Group: Date
  Data: 2023
– Name: TypeDocument
  Label: Document Type
  Group: TypDoc
  Data: Journal Articles<br />Reports - Evaluative
– Name: Subject
  Label: Descriptors
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Information+Security%22">Information Security</searchLink><br /><searchLink fieldCode="DE" term="%22Privacy%22">Privacy</searchLink><br /><searchLink fieldCode="DE" term="%22Data%22">Data</searchLink><br /><searchLink fieldCode="DE" term="%22Standards%22">Standards</searchLink><br /><searchLink fieldCode="DE" term="%22Laws%22">Laws</searchLink><br /><searchLink fieldCode="DE" term="%22Information+Technology%22">Information Technology</searchLink><br /><searchLink fieldCode="DE" term="%22Best+Practices%22">Best Practices</searchLink><br /><searchLink fieldCode="DE" term="%22Legal+Responsibility%22">Legal Responsibility</searchLink><br /><searchLink fieldCode="DE" term="%22Information+Policy%22">Information Policy</searchLink><br /><searchLink fieldCode="DE" term="%22Design+Requirements%22">Design Requirements</searchLink><br /><searchLink fieldCode="DE" term="%22Confidentiality%22">Confidentiality</searchLink><br /><searchLink fieldCode="DE" term="%22Compliance+%28Legal%29%22">Compliance (Legal)</searchLink><br /><searchLink fieldCode="DE" term="%22Identification%22">Identification</searchLink><br /><searchLink fieldCode="DE" term="%22Data+Use%22">Data Use</searchLink><br /><searchLink fieldCode="DE" term="%22Legal+Problems%22">Legal Problems</searchLink><br /><searchLink fieldCode="DE" term="%22Governance%22">Governance</searchLink>
– Name: ISSN
  Label: ISSN
  Group: ISSN
  Data: 2472-2707
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: In today's data-sharing paradigm, personal data has become a valuable resource that intensifies the risk of unauthorized access and data breach. Increased data mining techniques used to analyze big data have posed significant risks to data security and privacy. Consequently, data breaches are a significant threat to individual privacy. Privacy is a multifaceted concept covering many areas, including the right to access, erasure, and rectify personal data. This paper explores the legal aspects of privacy harm and how they transform into legal action. Privacy harm is the negative impact to an individual as a result of the unauthorized release, gathering, distillation, or expropriation of personal information. Privacy Enhancing Technologies (PETs) emerged as a solution to address data privacy issues and minimize the risk of privacy harm. It is essential to implement privacy enhancement mechanisms to protect Personally Identifiable Information (PII) from unlawful use or access. FIPPs (Fair Information Practice Principles), based on the 1973 Code of Fair Information Practice (CFIP), and the Organization for Economic Cooperation and Development (OECD), are a collection of widely accepted, influential US codes that agencies use when evaluating information systems, processes, programs, and activities affecting individual privacy. Regulatory compliance places a responsibility on organizations to follow best practices to ensure the protection of individual data privacy rights. This paper will focus on FIPPs, relevance to US state privacy laws, their influence on OECD, and reference to the EU General Data Processing Regulation. (GDPR).
– Name: AbstractInfo
  Label: Abstractor
  Group: Ab
  Data: As Provided
– Name: DateEntry
  Label: Entry Date
  Group: Date
  Data: 2024
– Name: AN
  Label: Accession Number
  Group: ID
  Data: EJ1415199
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=eric&AN=EJ1415199
RecordInfo BibRecord:
  BibEntity:
    Languages:
      – Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 10
    Subjects:
      – SubjectFull: Information Security
        Type: general
      – SubjectFull: Privacy
        Type: general
      – SubjectFull: Data
        Type: general
      – SubjectFull: Standards
        Type: general
      – SubjectFull: Laws
        Type: general
      – SubjectFull: Information Technology
        Type: general
      – SubjectFull: Best Practices
        Type: general
      – SubjectFull: Legal Responsibility
        Type: general
      – SubjectFull: Information Policy
        Type: general
      – SubjectFull: Design Requirements
        Type: general
      – SubjectFull: Confidentiality
        Type: general
      – SubjectFull: Compliance (Legal)
        Type: general
      – SubjectFull: Identification
        Type: general
      – SubjectFull: Data Use
        Type: general
      – SubjectFull: Legal Problems
        Type: general
      – SubjectFull: Governance
        Type: general
    Titles:
      – TitleFull: Privacy Harm and Non-Compliance from a Legal Perspective
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Suvineetha Herath
      – PersonEntity:
          Name:
            NameFull: Haywood Gelman
      – PersonEntity:
          Name:
            NameFull: Lisa Mckee
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 01
              Type: published
              Y: 2023
          Identifiers:
            – Type: issn-electronic
              Value: 2472-2707
          Numbering:
            – Type: volume
              Value: 2023
            – Type: issue
              Value: 2
          Titles:
            – TitleFull: Journal of Cybersecurity Education, Research and Practice
              Type: main
ResultId 1