What are Fair Information Practices?
(FIPs)
Guidelines for handling data with privacy, security, and fairness.
What is the origin of the FIPs?
What are the 5 original HEW principles of FIPs?
What does ‘Access / Individual Participation’ mean in FIPs?
What does ‘Purpose Specification’ mean in FIPs?
The reason for data collection must be specified at the time of collection.
What does ‘Data Minimization’ / ‘Collection Limitation’ mean?
Only collect necessary data and keep it only as long as needed.
What does ‘Data Quality / Relevance’ mean?
Data must be accurate, complete, up to date, and relevant to the specified purpose.
What does ‘Safeguards / Security’ mean?
Implement administrative, technical, and physical protections for data.
What does ‘Notice / Openness’ mean?
Provide advance notice of data collection and ensure transparency of policies.
What does ‘Accountability’ mean in FIPs?
The organization must take responsibility for ensuring compliance with its policies.
What does ‘Use Limitation’ mean in FIPs?
Data must only be used for the purpose specified at collection.
How should ‘Notice’ be applied to AI systems?
What does ‘Choice and Consent’ mean in the context of AI?
What is Privacy by Design?
(PbD)
A proactive approach embedding privacy into IT systems and processes from the start.
Who developed Privacy by Design?
Ann Cavoukian
What is the goal of Privacy by Design?
Build privacy and data protection into design and operation of systems by default.
What are the 7 principles of Privacy by Design?
What is the mnemonic for the seven PbD principles?
Robot Pigs Devour Enormous Purple Eggplant Tacos.
Respect for users, proactive not reactive, default setting, embedded into design, positive sum, end-to-end security, transparent
What is Privacy by Default?
How does Privacy by Default complement Privacy by Design?
It ensures privacy settings are automatically enforced without user intervention.
What does PbDD stand for and what does it mean?
Privacy by Design and Default
What is a PIA or DPIA?
Assessment tool to identify, assess, mitigate privacy risks; done during design and before deployment.
PIA: Privacy Impact Assessment; DPIA: Data Protection Impact Assessment
What is the role of human oversight in AI systems?
Humans review inputs and outputs.
E.g., ‘human in the loop’ process
What is data governance?
Management of data throughout its lifecycle.
Ensures availability, usability, integrity, and security.