0% found this document useful (0 votes)
8 views40 pages

Data Privacy Module 4

Module 4 outlines government regulatory frameworks and data protection laws, emphasizing their role in regulating personal data handling and ensuring compliance. It highlights the General Data Protection Regulation (GDPR) as a key framework, detailing its principles, enforcement mechanisms, and the rights of data subjects. The module also discusses the importance of accountability, risk assessments, and the role of Data Protection Officers in organizations.

Uploaded by

Abin Saji
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views40 pages

Data Privacy Module 4

Module 4 outlines government regulatory frameworks and data protection laws, emphasizing their role in regulating personal data handling and ensuring compliance. It highlights the General Data Protection Regulation (GDPR) as a key framework, detailing its principles, enforcement mechanisms, and the rights of data subjects. The module also discusses the importance of accountability, risk assessments, and the role of Data Protection Officers in organizations.

Uploaded by

Abin Saji
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Module 4 | Government Regulatory Frameworks & Data Protection •

MODULE 4
Government Regulatory Frameworks
Data Protection Laws, Security Standards,
Retention Policies, Compliance & International Standards

SECTION 1: Government Regulatory Frameworks

1.1 Definition and Purpose


Government regulatory frameworks are structured sets of laws, guidelines, rules, and standards
enacted by governing authorities to regulate how organisations collect, store, process, share, and
dispose of personal data. They establish legal obligations for organisations, enforceable rights for
individuals, and mechanisms to investigate and penalise non-compliance.

A regulatory framework for data protection serves multiple purposes:


• Protect individuals' fundamental rights to privacy and data control
• Prevent exploitation, discrimination, and misuse of personal data
• Establish legal certainty for businesses operating across jurisdictions
• Enable safe cross-border data flows in the global digital economy
• Provide remedies and redress mechanisms for data-related harms
• Deter cybercrime, data breaches, and irresponsible data handling

1.2 How Regulatory Frameworks Regulate Data Handling


Regulatory frameworks cover the full data lifecycle:

Stage What Regulations Govern Example Requirement

Collection What data can be collected, purpose, GDPR requires lawful basis before
consent collecting personal data

Storage Where data is stored, security ISO 27001 mandates encrypted storage
standards, access control with access logs

Processing Who can process, purpose limitation, GDPR: data must not be processed
data minimisation beyond its original purpose

Sharing / Transfer Third-party agreements, cross- GDPR restricts transfer of EU data to non-
border rules adequate countries

Retention How long data can be kept, deletion 7-year financial record rule; GDPR
timelines storage limitation principle

Page 1 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

Stage What Regulations Govern Example Requirement

Disposal / Erasure Secure deletion, Right to be GDPR Article 17: erasure on request or
Forgotten when no longer needed

1.3 Key Enforcement Mechanisms

Regulatory Fines and Financial Sanctions


GDPR provides for heavy financial penalties for non-compliance.
Two-tier penalty system:
 Up to €10 million or 2% of global annual turnover (whichever is higher)
→ For procedural violations (e.g., record-keeping failures)
 Up to €20 million or 4% of global annual turnover (whichever is higher)
→ For serious violations (e.g., unlawful processing, violation of data subject rights)
Purpose:
 Ensure accountability
 Act as a deterrent
 Encourage organisations to implement strong compliance systems
These penalties apply to both data controllers and data processors.

Supervisory Authority Powers (DPA Powers)


Each EU country has a Data Protection Authority (DPA) to enforce GDPR.
Example:
Data Protection Commission
DPAs have power to:
 Conduct investigations
 Carry out data protection audits
 Access organisational records
 Issue warnings and reprimands
 Make binding legal decisions
These authorities ensure organisations follow lawful processing principles.

Compliance Orders
Regulatory authorities can issue corrective orders requiring organisations to:
 Stop unlawful processing
 Rectify incorrect data practices
 Implement stronger security measures
 Suspend international data transfers

Page 2 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

 Delete unlawfully processed data


This ensures immediate correction of violations.

Criminal Prosecution
Certain data protection violations may lead to criminal liability, especially when:
 There is intentional unlawful access
 Data is misused fraudulently
 Systems are hacked illegally
Example:
Computer Misuse Act 1990
Under such laws, offenders may face:
 Criminal fines
 Imprisonment
 Prosecution in criminal courts
Criminal liability is usually separate from regulatory fines.

Civil Litigation (Article 82 GDPR)


Under Article 82, data subjects have the right to:
 Claim compensation for material damage (financial loss)
 Claim compensation for non-material damage (emotional distress)
Individuals can sue organisations in civil courts if their rights are violated.
This strengthens individual data protection rights.

Mandatory Breach Notification (72-Hour Rule)


Under GDPR:
 Organisations must report personal data breaches to the supervisory authority within 72
hours of becoming aware of the breach.
 If not reported within 72 hours, justification must be provided.
 In high-risk cases, affected individuals must also be informed.
Failure to report breaches can result in additional fines and penalties.

1.4 Role in Organisational Accountability


Regulatory frameworks shift accountability from individuals to organisations. They require:
• Appointment of responsible officers (e.g., Data Protection Officers under GDPR)
• Documented evidence of compliance (Records of Processing Activities)
• Regular risk assessments and audits
• Privacy-by-design and privacy-by-default practices
• Contractual obligations on third-party processors

Page 3 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

🌍 Real-World Example: IT Act 2000 in India's E-Governance


India's Information Technology Act 2000 (amended in 2008) governs electronic records, digital
signatures, and cyber offences.
Section 43A: Organisations handling sensitive personal data must implement 'reasonable security
practices' or face compensation liability.
Section 72A: Disclosure of personal information without consent by an intermediary is a punishable
offence (up to 3 years imprisonment).
In e-governance: Aadhaar data stored by UIDAI is governed by the Aadhaar Act 2016, imposing
strict restrictions on storage and disclosure.
The Digital Personal Data Protection Act 2023 (DPDPA) is India's comprehensive new framework,
aligned closely with GDPR principles.

Page 4 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

SECTION 2: General Data Protection Regulation (GDPR)

2.1 Overview
GDPR (Regulation EU 2016/679) came into force on 25 May 2018, replacing Directive 95/46/EC. It
is the most comprehensive and influential data protection law globally, establishing a unified
framework across all EU member states with extraterritorial reach.

Feature Details

Full Name General Data Protection Regulation (EU) 2016/679

Effective 25 May 2018

Jurisdiction All EU/EEA member states; applies to non-EU organisations


processing EU residents' data

Enforcer National Data Protection Authorities (DPAs) — e.g., ICO (UK), CNIL
(France), DPC (Ireland)

Max Fine (Upper) €20 million or 4% of global annual turnover — whichever is higher

Max Fine (Lower) €10 million or 2% of global annual turnover — whichever is higher

2.2 Key Principles of GDPR (Article 5) — The 7 Pillars


Every organisation processing personal data of EU residents must adhere to these seven principles:

Principle Meaning Practical Implication

1. Lawfulness, Fairness Processing must have a legal Privacy notices, consent forms, lawful
& Transparency basis; individuals must be basis documentation
informed clearly

2. Purpose Limitation Data collected for specified Cannot reuse customer email collected for
purposes cannot be used for billing to send marketing without consent
incompatible ones

3. Data Minimisation Only collect what is strictly A hospital app should not collect social
necessary media logins just for appointment booking

4. Accuracy Data must be kept accurate Regular data audits; individuals must be
and up to date able to correct their data

5. Storage Limitation Data must not be kept longer Deleting ex-employee records after the
than necessary legally required period (often 6–7 years)

6. Integrity & Appropriate technical and Encryption, access controls, staff training,
Confidentiality organisational measures to pseudonymisation
(Security) protect data

7. Accountability Controllers must demonstrate Maintain Records of Processing Activities


compliance; not just comply, (RoPA), conduct DPIAs, appoint DPO
but prove it

Page 5 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

2.3 Lawful Bases for Processing (Article 6)


Processing personal data is unlawful unless at least one of these six bases applies:
• Freely given, specific, informed, unambiguous. Must be as easy to withdraw as to give.
Pre-ticked boxes = invalid.: Consent
• Processing necessary to fulfil or enter into a contract with the data subject: Contract
• Processing required by law (e.g., tax records, employment law): Legal Obligation
• Necessary to protect life (e.g., hospital sharing patient data in an emergency): Vital
Interests
• Exercising official authority or public interest function (e.g., government services):
Public Task
• The controller's interests that override the data subject's rights — requires a balancing
test: Legitimate Interests

2.4 Rights of Data Subjects (Articles 12–22)


Right Article Description Time Limit

Right to be Informed Art. Must be told: what is collected, why, At point of collection
13–14 retention period, third parties

Right of Access Art. 15 Request a copy of all personal data held 1 month (extendable to
(SAR) (Subject Access Request) 3)

Right to Rectification Art. 16 Have inaccurate/incomplete data 1 month


corrected

Right to Erasure Art. 17 'Right to be Forgotten' — delete data 1 month


when no longer needed or consent
withdrawn

Right to Restrict Art. 18 Limit how data is used while a complaint 1 month
Processing is resolved

Right to Data Art. 20 Receive data in machine-readable 1 month


Portability format (JSON/CSV) to transfer
elsewhere

Right to Object Art. 21 Object to processing for direct Immediate for marketing
marketing, research, or legitimate
interests

Rights re: Automated Art. 22 Not to be subject to purely automated 1 month


Decisions decisions with significant effects (e.g.,
loan rejection by AI)

🌍 Real-World Example: GDPR Rights in Action — Google Spain Case (2014)


Before GDPR, the European Court of Justice established the 'Right to be Forgotten' in Google
Spain SL v. AEPD (2014).

Page 6 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

Mario Costeja González requested removal of outdated newspaper links from Google search
results about his debt proceedings.
The Court ruled Google must de-index results upon request if information is inadequate, irrelevant,
or excessive.
This case directly shaped GDPR Article 17. Since GDPR (2018), Google has received over 1
million erasure requests.

2.5 Obligations of Data Controllers


2.5.1 Privacy by Design and Default (Article 25)
Privacy must be built into systems from the start, not added on afterwards.
• Embed data protection into technical architecture and business processes from
inception: Privacy by Design
• Default settings must always be the most privacy-protective option (e.g., no pre-ticked
marketing consent boxes): Privacy by Default
Example: A new mobile banking app must encrypt data, minimise what is collected, and default to no
sharing with third parties — before launch, not as an afterthought.

2.5.2 Records of Processing Activities — RoPA (Article 30)


Controllers with 250+ employees (and smaller ones doing high-risk processing) must maintain a
RoPA documenting:
• Name and contact details of controller and DPO
• Purposes of processing
• Categories of data subjects and personal data
• Recipients of the data (including third countries)
• Retention periods
• Technical and organisational security measures

Page 7 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

2.5.3 Data Protection Impact Assessment — DPIA (Article 35)


A DPIA is a structured assessment required BEFORE starting high-risk processing. It is mandatory
when:
• Large-scale processing of sensitive data (health, biometric, criminal records)
• Systematic monitoring of public areas (CCTV, employee monitoring)
• Automated processing including profiling that significantly affects individuals (e.g., AI-based
loan decisions)

To Identify Privacy Risks in Advance


DPIA helps organisations detect:
 Security vulnerabilities
 Risk of data misuse
 Risk of discrimination or profiling
 Possible harm to individuals
It ensures problems are identified before implementation.

To Protect Rights and Freedoms


GDPR focuses on protecting:
 Privacy
 Reputation
 Financial security
 Freedom from discrimination
DPIA ensures that personal data processing does not negatively affect these rights.

To Ensure Legal Compliance


DPIA helps organisations:
 Comply with GDPR obligations
 Demonstrate accountability
 Avoid heavy penalties
Failure to conduct a DPIA when required can result in fines.

To Reduce Legal and Financial Risk


By identifying risks early, organisations can:
 Implement safeguards
 Avoid data breaches
 Prevent regulatory fines
 Avoid civil litigation

Page 8 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

To Promote Transparency and Trust


DPIA increases:
 Organisational transparency
 Customer confidence
 Ethical data governance

DPIA Process:
Step Activity

1. Describe Describe the processing: what data, why, how, who

2. Assess Is it necessary and proportionate for the purpose?


Necessity

3. Identify Risks What risks does it pose to individuals' rights and freedoms?

4. Identify What safeguards will mitigate those risks?


Measures

5. Consult DPA If residual risk remains high, consult the supervisory authority before proceeding

2.5.4 Data Breach Notification (Articles 33–34)


Notification To When Timeframe Content Required

Supervisory Authority Breach likely to result in risk Within 72 hours of Nature of breach,
(DPA) to individuals' awareness categories/number of
rights/freedoms affected individuals,
likely consequences,
measures taken

Data Subjects Breach likely to result in Without undue Clear, plain language
HIGH risk delay description of breach
and what affected
individuals should do

🌍 Real-World Example: British Airways Data Breach (2018)


BA suffered a breach affecting approximately 500,000 customers — hackers diverted users to a
fraudulent site collecting payment card details.
ICO (UK) initially proposed a £183 million fine (1.5% of annual turnover) under GDPR.
Final fine: £20 million (reduced due to COVID-19 financial impact on the airline sector).
Key failure: Inadequate security measures and delayed detection of the breach.
Lesson: GDPR's Integrity & Confidentiality principle and mandatory breach notification obligations
require proactive, not reactive, security.

Page 9 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

2.6 Data Protection Officer (DPO) — Articles 37–39


Mandatory appointment when the organisation is a:
• Public authority or body
• Controller or processor carrying out large-scale regular systematic monitoring (e.g.,
behavioural advertising)
• Controller or processor of special category data at large scale (e.g., hospitals, insurance
companies)

DPO Function Description

Advisory Informs and advises the controller/processor and employees on GDPR


obligations

Monitoring Monitors internal compliance including staff training and data protection
audits

DPIA Advisor Advises on DPIAs and monitors their performance

DPA Liaison Acts as contact point for the supervisory authority and cooperates with
them

Data Subject Contact Contact point for data subjects exercising their rights

2.7 International Data Transfers (Chapter V)


Personal data of EU residents cannot be transferred outside the EU/EEA (European Economic Area-
Norway, Iceland , Liechtenstein) unless adequate protection is guaranteed. Transfer mechanisms
include:
Mechanism Description Examples

Adequacy Decision European Commission officially UK, Japan, South Korea,


recognises destination country as Canada (commercial), New
providing equivalent protection Zealand, Switzerland

Standard Contractual Pre-approved contract terms binding Google using SCCs for
Clauses (SCCs) importer to GDPR-equivalent standards transferring EU user data to US
servers

Binding Corporate Internal privacy policies approved by a IBM, Microsoft internal BCRs
Rules (BCRs) DPA for intra-group transfers in
multinationals

Derogations (Art. 49) Exceptional cases: explicit consent, Hospital sending patient record
contract necessity, vital interests, public to foreign specialist with patient
interest consent

Adequacy Decision

An Adequacy Decision is issued by the European Commission declaring that a non-EU


country provides data protection standards equivalent to GDPR.

Page 10 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

If a country has adequacy status:

 Data can flow freely


 No additional safeguards are required

Examples of Adequate Countries:

 United Kingdom
 Japan
 South Korea
 Canada (commercial organisations)
 New Zealand
 Switzerland

Why important?

 Simplest transfer mechanism


 Reduces compliance burden

Standard Contractual Clauses (SCCs)


What are SCCs?

SCCs are pre-approved legal contract clauses issued by the European Commission.

They:

 Bind the data importer (foreign organisation)


 Require GDPR-equivalent protection
 Provide legal remedies to data subjects

Example:

Google using SCCs to transfer EU user data to servers in the US.

Key Features:

 Legally binding contract


 Must not be modified
 Requires risk assessment
 Often used when no adequacy decision exists

Why needed?

Page 11 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

Countries like the US do not have full adequacy, so companies rely on SCCs.

Binding Corporate Rules (BCRs)


What are BCRs?

BCRs are internal data protection policies used by multinational companies to transfer
data within their corporate group internationally.

They must:

 Be approved by a Data Protection Authority (DPA)


 Be legally binding on all group entities
 Ensure consistent GDPR-level protection

Examples:

 IBM internal BCR framework


 Microsoft internal BCR policies

Used for:

 Intra-group transfers
 Large multinational corporations

Advantage:

 Long-term solution for global companies


 Strong internal compliance structure

Derogations (Article 49 GDPR)


Derogations are exceptional situations where data can be transferred without adequacy,
SCCs, or BCRs.

These are used only in specific cases, not for regular large-scale transfers.

Situations include:

✔ Explicit consent of the data subject


✔ Contract necessity

Page 12 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

✔ Vital interests (life-saving situations)


✔ Important public interest
✔ Legal claims

Example:

A hospital sends a patient’s medical record to a foreign specialist with the patient’s explicit
consent.

⚖ Case Study: Meta Ireland — €1.2 Billion GDPR Fine (2023)


Background: Meta (Facebook) transferred EU users' personal data to US servers relying on
Standard Contractual Clauses (SCCs) after the Schrems II ruling invalidated the Privacy Shield
framework.
Finding: Ireland's DPC ruled that the SCCs Meta used were insufficient to protect EU data from
US government surveillance (under FISA 702 / Executive Order 12333).
Penalty: Record €1.2 billion fine — the largest GDPR fine ever. Meta ordered to suspend data
transfers to the US.
Outcome: The EU–US Data Privacy Framework was adopted in 2023 as the new adequacy
decision, allowing lawful transfers.
Lesson: Chapter V international transfer rules are strictly enforced. Organisations cannot simply
paper over structural legal incompatibility with contracts.

Page 13 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

SECTION 3: California Consumer Privacy Act (CCPA) and CPRA

3.1 Overview
The California Consumer Privacy Act (CCPA) came into effect on 1 January 2020, making California
the first US state with a comprehensive consumer privacy law. It was significantly amended and
strengthened by the California Privacy Rights Act (CPRA), effective 1 January 2023.

Feature CCPA (2020) CPRA (2023 Amendments)

Applicability Businesses meeting size/revenue Same, with added category of


thresholds processing CA 'sensitive personal information'
residents' data

New Regulator California Attorney General California Privacy Protection


Agency (CPPA) — dedicated
agency

New Rights Added Know, Delete, Opt-Out, Non- Correct, Limit use of sensitive PI,
Discrimination Opt-Out of automated decision-
making

Employee Data Initially exempt Employee data included from


January 2023

B2B Data Initially exempt B2B data included from January


2023

3.3 Consumer Rights under CCPA/CPRA


Right Description Example Use Case

Right to Know Know what personal information Consumer requests a list of all data
is collected, used, disclosed, sold Amazon holds about them

Right to Delete Request deletion of personal User demands a retailer delete their
information collected from them purchase history

Right to Opt-Out of Stop the business from Clicking 'Do Not Sell My Personal
Sale/Sharing selling/sharing their PI to third Information' link on website
parties

Right to Correct Request correction of inaccurate Correcting wrong home address held by
personal information (CPRA an insurer
addition)

Right to Limit Sensitive Restrict use of sensitive PI to Limiting use of health data to processing
PI necessary purposes (CPRA) insurance claim only

Right to Non- Cannot be denied services or Cannot charge higher price for opting
Discrimination charged more for exercising out of data sale
rights

Page 14 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

Right Description Example Use Case

Right re: Automated Opt-out of automated profiling for Opting out of AI-based credit scoring
Decision-Making significant decisions (CPRA)

Practical Example
Right to Know (CCPA)
A customer asks an online retailer:
“What personal data have you collected about me?”
The company must provide:
 Categories of data
 Purpose of collection
 Third parties with whom it was shared

Right to Delete (CCPA)


A customer closes their account and requests:
“Delete all my personal information.”
The company must erase data unless legally required to retain it.

Right to Correct (Added by CPRA)


A customer notices their birthdate is wrong in records.
They can request correction, and the company must update it.

Right to Limit Use of Sensitive Personal Information (CPRA)


Sensitive PI includes:
 Social Security numbers
 Precise geolocation
 Biometric data
 Health information
Example:
A mobile app collecting precise GPS data must allow users to limit its use.

Employee Data Inclusion (CPRA)


Before 2023:
Employee HR records were exempt.
After 2023:
Employees can:
 Request access to performance records

Page 15 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

 Ask for deletion of unnecessary personal data

B2B Data Inclusion (CPRA)


If a supplier’s representative shares:
 Name
 Business email
 Phone number
They now have privacy rights under CPRA.

3.2 Who Must Comply with CCPA?


A for-profit business doing business in California that meets ANY ONE of:
• Annual gross revenue exceeding $25 million
• Buys, sells, or receives/shares personal information of 100,000+ consumers or households
annually
• Derives 50% or more of annual revenue from selling consumers' personal information

3.4 GDPR vs. CCPA — Key Comparison


Dimension GDPR (EU) CCPA/CPRA (California, USA)

Approach Rights-based: opt-in by default Market-based: opt-out of sale

Opt-In vs. Opt-Out Requires opt-in consent for most Defaults to data collection allowed;
processing opt-out of sale

Sensitive Data Explicit list; requires explicit consent Sensitive PI category; right to limit use

Scope Any organisation processing EU For-profit businesses meeting


residents' data California thresholds

Enforcement DPAs; individuals can sue California AG; CPPA; private right of
action for data breaches

Fines Up to €20M or 4% global turnover Up to $7,500 per intentional violation

DPO Required? Yes, in certain cases No equivalent requirement

🌍 Real-World Example: CCPA in Practice — Sephora Settlement (2022)


California AG sued Sephora (cosmetics retailer) for selling consumer data to third parties without
disclosing it as a 'sale' and without honouring opt-out requests.
Settlement: $1.2 million fine. Sephora required to add 'Do Not Sell My Personal Information' links
and honour opt-out browser signals (Global Privacy Control).
This was the first major CCPA enforcement action and set the precedent for how opt-out
mechanisms must function.
Lesson: Under CCPA, sharing data with analytics providers for advertising constitutes a 'sale' —
even without money changing hands.

Page 16 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

Page 17 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

SECTION 4: Information Security Standards — ISO/IEC 27001 &


ISO/IEC 27701

4.1 What are Information Security Standards?


Information security standards are internationally recognised frameworks of best practices, controls,
and requirements designed to help organisations systematically protect information assets. They
provide a structured, auditable approach to managing information security risks.
Standards are developed by bodies such as the International Organisation for Standardisation (ISO)
and the International Electrotechnical Commission (IEC). Compliance with standards can be certified
by accredited third-party auditors.

4.2 ISO/IEC 27001 — Information Security Management System (ISMS)


4.2.1 Overview
ISO/IEC 27001 is the world's leading international standard for Information Security Management
Systems (ISMS). It specifies requirements for establishing, implementing, maintaining, and
continually improving an ISMS.

Aspect Details

Full Title ISO/IEC 27001:2022 — Information Security, Cybersecurity and Privacy


Protection

Purpose Provide a systematic approach to managing sensitive company


information so it remains secure

Certification Organisations can be certified by accredited certification bodies (third-


party audit)

Core Framework Plan-Do-Check-Act (PDCA) cycle for continuous improvement

Annex A Controls 93 controls across 4 themes: Organisational, People, Physical,


Technological

4.2.2 Three Objectives of ISO 27001 — The CIA Triad


Objective Meaning Example Control

Confidentiality Information is accessible only to Access control, encryption, need-to-know


authorised individuals policies

Integrity Accuracy and completeness of Hash verification, checksums, audit logs,


information is maintained and version control
protected

Availability Authorised users can access Redundant systems, backups, disaster


information when needed recovery, DDoS protection

Page 18 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

4.2.3 ISMS Components


An Information Security Management System (ISMS) under ISO 27001 includes:
• Identify information assets, threats, vulnerabilities, and impact: Risk Assessment
• Apply controls from Annex A or justify exclusions in a Statement of Applicability (SoA):
Risk Treatment
• Written policies covering acceptable use, incident response, access control, etc.:
Security Policies
• Inventory of all information assets with designated owners: Asset Management
• Procedures for detecting, responding to, and learning from security incidents: Incident
Management
• Regular audits to verify ISMS effectiveness: Internal Audit
• Senior leadership reviews ISMS performance periodically: Management Review
• Corrective actions and ongoing enhancement of the ISMS: Continual Improvement

Risk Assessment

(Identify assets, threats, vulnerabilities, and impact)

The organization identifies:

 Information assets
 Possible threats
 Weaknesses (vulnerabilities)
 Impact if something goes wrong

Example (E-commerce Company)

Element Example
Asset Customer payment database
Threat Hacker attack
Vulnerability Weak password policy
Impact Financial loss, legal penalty, reputational damage

The company calculates risk level (High/Medium/Low).

Risk Treatment

Page 19 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

(Apply Annex A(Annex A of ISO/IEC 27001 is a structured list of 93 security controls


that organizations select and implement to treat identified information security risks
within their ISMS.) controls or justify exclusions in Statement of Applicability – SoA)

After identifying risks, the organization:

 Selects appropriate security controls from Annex A


 Or justifies why a control is not applicable
 Documents this in the Statement of Applicability (SoA)

Example:

Risk: Unauthorized access to database

Treatment:

 Implement Multi-Factor Authentication


 Enable encryption
 Apply role-based access control

If a control (e.g., physical data center security) is not applicable because the company uses
AWS cloud, it must justify this in the SoA.

Security Policies

Examples:

 Acceptable Use Policy (no personal USB devices)


 Access Control Policy
 Password Policy
 Incident Response Policy
 Remote Work Policy

Example: Employees must use strong passwords (minimum 12 characters)

Asset Management

Maintain an inventory of all information assets and assign an owner.

Example:

Asset Owner
Customer Database IT Manager
Website Server Cloud Administrator
Employee Laptops HR Manager

Page 20 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

Every asset must have a responsible person.

Incident Management

Procedures to detect, respond, and learn from security incidents.

Example:

Incident: Customer data breach

Steps:

1. Detect unusual database activity


2. Isolate affected server
3. Inform management
4. Notify affected customers
5. Conduct root cause analysis
6. Improve controls

The organization learns and prevents recurrence.

Internal Audit

Regular internal checks to verify if ISMS is working effectively.

Example:

Internal audit team checks:

 Are access controls properly implemented?


 Are logs monitored regularly?
 Are policies updated?

If gaps are found, they are reported.

Management Review

Top management reviews ISMS performance periodically.

Example:

CEO reviews:

 Number of security incidents


 Audit findings
 Risk levels

Page 21 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

 Compliance status

Decisions may include increasing cybersecurity budget.

Continual Improvement

Correct problems and continuously enhance the ISMS.

Example:

After a phishing attack:

 Conduct employee awareness training


 Upgrade email security filters
 Improve password policy

Security keeps improving over time (PDCA cycle).

4.3 ISO/IEC 27701 — Privacy Information Management System (PIMS)


ISO/IEC 27701:2019 is an extension to ISO 27001 that specifically addresses privacy protection and
personal data management. It adds requirements for establishing a Privacy Information Management
System (PIMS).

Feature ISO 27001 ISO 27701 (Extension)

Focus Information security broadly Privacy and personal data


protection specifically

Framework Type ISMS PIMS — Privacy Information


Management System

Roles Addressed General information security Specifically addresses PII


(Personally Identifiable Information)
Controllers and Processors

GDPR Alignment Supports GDPR's security principle Directly maps to GDPR and other
privacy regulation requirements

Standalone? Yes — can be certified Requires ISO 27001 as a base;


independently extends it

4.4 How ISO Standards Protect Sensitive Customer Data


Consider an e-commerce company storing customer payment and address data:

Page 22 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

Threat ISO 27001 Control ISO 27701 Addition

Unauthorised access to Annex A: Access control, multi-factor Restrict access to PII to only
customer database authentication, privileged access those who need it for
management processing purpose

Data breach / exfiltration Encryption of data at rest and in Privacy breach response
transit; DLP tools procedures; notification
obligations

Third-party vendor risk Supplier security assessments; Data processing agreements


contractual security clauses with vendors handling PII;
privacy assessments

Data retention beyond Data lifecycle management Retention schedules for PII
necessity procedures aligned with legal requirements
and purpose limitation

Insider threat Audit logging; separation of duties; Restricting access to PII to


background checks minimum necessary

🌍 Real-World Example: ISO 27001 Certification — HDFC Bank


HDFC Bank (India's largest private bank) has achieved ISO 27001 certification for its data centres
and critical IT infrastructure.
This certification assures regulators, customers, and business partners that customer financial
data is protected through a systematic, audited security management framework.
The certification covers controls across physical security of data centres, logical access to banking
systems, encryption of customer transactions, and incident response.
For GDPR compliance: multinational banks use ISO 27001 + ISO 27701 together to demonstrate
the 'appropriate technical and organisational measures' required under GDPR Article 32.

Page 23 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

SECTION 5: Data Retention Policies

5.1 What is Data Retention?


Data retention refers to the policies and procedures that govern how long an organisation keeps
personal or business data before it must be securely deleted, archived, or anonymised. It is a critical
component of data governance and legal compliance.

A Data Retention Policy is a formal document that specifies:


• What data is collected and stored
• The legal or business basis for retaining it
• How long each category of data is retained (retention schedule)
• When and how data is securely deleted or anonymised
• Who is responsible for enforcing retention schedules

5.2 Why Defined Retention Periods are Essential


• Laws mandate minimum or maximum retention periods for specific data types: Legal
Compliance
• Retaining data longer than necessary increases exposure in a data breach and
regulatory liability: Risk Reduction
• Unnecessary data retention wastes storage resources and creates management
overhead: Storage Cost
• Processing data beyond its original purpose violates GDPR and similar laws: Purpose
Limitation
• Clear policies demonstrate accountability and build customer and regulatory trust:
Trust

5.3 GDPR Data Retention Principles


GDPR does not prescribe specific retention periods for most data categories, but establishes
governing principles:

GDPR Principle Retention Implication Practical Requirement

Storage Limitation (Art. Data must not be kept in Define maximum retention period at
5(1)(e)) identifiable form longer than the time of collection; delete when
necessary for its original purpose purpose is achieved

Purpose Limitation (Art. Data collected for one purpose Separate datasets with distinct
5(1)(b)) cannot be retained for another retention schedules per purpose
incompatible purpose

Accountability (Art. 5(2)) Controllers must be able to Documented retention schedules in


demonstrate compliance with Records of Processing Activities
storage limitation (RoPA)

Page 24 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

GDPR Principle Retention Implication Practical Requirement

Right to Erasure (Art. 17) Individuals can demand deletion Systems must support reliable,
when data is no longer needed, verifiable data deletion on request
consent is withdrawn, or
processing was unlawful

Data Minimisation (Art. Avoid retaining more data than Regular data audits to identify and
5(1)(c)) necessary purge unnecessary records

5.4 The 7-Year Retention Policy


The 7-year retention rule is widely applied in financial, tax, and corporate contexts. It is not a single
law but a convergence of multiple regulatory requirements:

Jurisdiction / Law Data Type Retention Period Authority

UK — Companies Act Accounting records 6 years from HMRC / Companies


2006 financial year end House

UK — HMRC Guidance Tax records (self- 6 years after HMRC


employed/companies) relevant tax year

India — Companies Act Books of accounts and 8 years from date of Ministry of Corporate
2013 financial statements financial year Affairs

India — GST Act 2017 GST records and 6 years from due GSTN / GST Council
invoices date of annual
return

USA — IRS Code Tax records 7 years (if claiming IRS


loss for worthless
securities)

EU — Anti-Money KYC and transaction 5 years (extendable Financial regulators


Laundering Directive records to 10)

Banking — Basel III Transaction and risk 5–7 years typically Central banks /
records regulators

Key point: The '7-year rule' is a practical standard used by auditors and compliance teams to ensure
organisations retain sufficient financial and business records for regulatory inspections, litigation, or
audit purposes. After the period, data should be securely deleted or anonymised.

5.5 Purpose Limitation in Data Retention


Purpose limitation means that data may only be retained for the specific, documented purpose for
which it was originally collected. Once that purpose is fulfilled, the data must be deleted or
anonymised.

Page 25 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

Data Type Original Purpose Retention Period What Happens After

Customer order Fulfil e-commerce Duration of order + Anonymised for sales


records transaction warranty period + legal analytics or deleted
limitation period (typically 6
years)

Employee payroll Pay employees and 6–7 years after employment Securely shredded /
records comply with tax law ends permanently deleted

CCTV footage in Physical security 30 days typically (longer if Automatically


office incident under overwritten
investigation)

Job applicant CVs Recruitment process 6 months (or as notified) Deleted; cannot be
(unsuccessful) used for future roles
without fresh consent

Medical records Patient treatment 8–10 years (UK: minimum 8 Archived then
years for adults) destroyed per NHS
records management
code

🌍 Real-World Example: Improper Retention — UK Fertility Clinic Case


A UK fertility clinic retained donor's genetic and contact data indefinitely 'just in case' future patients
or donor-conceived children contacted them.
ICO found this violated GDPR's Storage Limitation principle — data was kept long beyond the
clinical purpose and mandatory NHS retention period.
The clinic was ordered to implement a data retention schedule and conduct a purge of overdue
records.
Lesson: Indefinite retention 'just in case' is not a lawful basis. Every dataset needs a defined
deletion date aligned with its purpose.

Page 26 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

SECTION 6: Compliance and Data Protection Audits

6.1 What is Compliance in Data Protection?


Compliance in data protection means an organisation's practices, processes, policies, and systems
conform to applicable legal, regulatory, and contractual requirements for personal data handling. It is
ongoing — not a one-time achievement.

Compliance involves:
• Understanding applicable laws (GDPR, CCPA, IT Act, DPDPA, etc.)
• Implementing required technical and organisational measures
• Documenting and evidencing that measures are in place
• Continually monitoring, testing, and improving measures
• Training staff at all levels on their data protection obligations

6.2 Role of Compliance Programmes


A compliance programme is a structured set of policies, controls, and oversight mechanisms that
embed regulatory requirements into daily operations. Key elements:
Element Description

Data Protection Policy High-level statement of the organisation's commitment to data


protection; reviewed annually

Records of Processing Living document cataloguing all processing activities (mandatory under
Activities (RoPA) GDPR Art. 30)

Data Processing Contracts with third-party processors specifying their obligations (GDPR
Agreements (DPAs) Art. 28)

Privacy Notices Transparent information provided to data subjects at point of collection

Consent Management Systems for collecting, recording, and managing consents; easy
withdrawal mechanisms

Training Programmes Regular, role-specific data protection training for all staff

Incident Response Plan Documented procedure for detecting, containing, assessing, and
notifying data breaches

Data Protection Officer Independent oversight function (mandatory for many organisations
under GDPR)

6.3 Data Protection Compliance Audits


6.3.1 What is a Compliance Audit?
A data protection compliance audit is a systematic, independent examination of an organisation's
data protection practices to assess whether they comply with applicable laws, standards, and internal

Page 27 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

policies. Audits can be internal (conducted by the compliance team or DPO) or external (conducted
by a regulatory body or independent auditor).

6.3.2 Objectives of Data Protection Audits


• Verify that processing activities are lawful and match documented purposes
• Identify gaps between current practices and legal requirements
• Assess the effectiveness of technical and organisational security measures
• Evaluate data retention practices and deletion compliance
• Check third-party processor compliance (DPAs in place, sub-processor rules)
• Ensure data subject rights processes are functioning correctly
• Produce a gap analysis report with prioritised remediation recommendations

6.3.3 Process of Conducting a Data Protection Compliance Audit


Stage Activities

1. Planning Define scope, objectives, and methodology; gather background documentation;


identify key stakeholders; prepare audit checklist based on GDPR Articles or
relevant law

2. Data Discovery Map all data flows: what personal data is collected, from whom, stored where,
shared with whom; validate against RoPA

3. Documentation Review policies, privacy notices, consent records, DPAs, DPIA reports, training
Review records, breach logs

4. Technical Test access controls, encryption, vulnerability management, logging and


Assessment monitoring, backup integrity

5. Interviews & Speak with DPO, IT security, HR, marketing teams; observe actual practices vs
Observations documented procedures

6. Gap Analysis Compare findings against legal requirements; classify gaps by risk level
(High/Medium/Low)

7. Reporting Produce audit report: findings, evidence, non-conformities, recommendations,


suggested timelines for remediation

8. Remediation Monitor implementation of recommendations; schedule follow-up audit to verify


Tracking closure

6.4 How Compliance Audits Prevent Legal Penalties and Breaches


Proactive compliance audits provide several defensive advantages:
• Early detection of non-compliances before regulators discover them
• Demonstrate 'accountability' principle to regulators — reducing fines if breach occurs
• Identify technical vulnerabilities before they can be exploited
• Ensure data retention schedules are followed — reducing breach exposure surface
• Verify third-party processors are meeting contractual security obligations

Page 28 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

• Support legal defensibility: documented compliance programme is a mitigating factor in


regulatory investigations

⚖ Case Study: Marriott International Data Breach — £18.4 Million ICO Fine (2020)
Background: Marriott acquired Starwood Hotels in 2016 but failed to conduct adequate due
diligence on Starwood's IT systems. Hackers had been in Starwood's reservation system since
2014.
Breach discovered: November 2018 — 339 million guest records exposed, including passport
numbers, payment card data, and travel details of customers worldwide.
ICO Finding: Marriott failed to undertake sufficient due diligence during the Starwood acquisition;
technical security measures were inadequate; no proper review of data processing activities
inherited.
Fine: £18.4 million (reduced from initial proposed £99 million due to COVID-19 and mitigation steps
taken).
Audit Lesson: A pre-acquisition data protection audit of Starwood would have identified the lurking
breach and the inadequate security. GDPR Article 28 requires processor due diligence.
Compliance Programme Failure: No DPIA, no data mapping of acquired systems, no ISMS
assessment — all basic compliance audit activities that would have prevented or minimised this.

📝 Exam Tip
9-mark question: 'Evaluate how compliance audits help organisations avoid legal penalties and
data breaches.' — Cover: (1) What audits are (2) 8-stage audit process (3) Objectives (4) How
they prevent breaches (5) Real case — Marriott shows the cost of NOT auditing.
'Illustrate the consequences of improper data retention' — Use retention linked to breach exposure:
more data retained = larger breach impact = higher regulatory fine.

Page 29 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

SECTION 7: International Data Protection Standards

7.1 What are International Data Protection Standards?


International data protection standards are globally recognised frameworks, guidelines, and technical
specifications that provide consistent approaches to managing information security and privacy
across borders. Unlike national laws (which are binding in their jurisdiction), international standards
are generally voluntary but often become de facto requirements through regulatory expectations,
contractual obligations, or certification demands.

Standard / Framework Issuing Body Focus Area

ISO/IEC 27001:2022 ISO / IEC Information Security Management System


(ISMS)

ISO/IEC 27701:2019 ISO / IEC Privacy Information Management System


(PIMS) — extends 27001

ISO/IEC 27017:2015 ISO / IEC Cloud computing security controls

ISO/IEC 27018:2019 ISO / IEC Protection of PII in public cloud (cloud


processor standard)

NIST Privacy Framework (2020) NIST (USA) Privacy risk management for US
organisations

NIST CSF 2.0 (2024) NIST (USA) Cybersecurity risk management


framework

PCI-DSS v4.0 PCI Security Payment card data security


Standards Council

SOC 2 Type II AICPA Service organisation controls for security,


availability, confidentiality

OECD Privacy Guidelines OECD Principles for protection of personal data


across member countries

7.2 Significance of ISO 27001 and ISO 27701 in Global Data Protection
7.2.1 Global Recognition and Cross-Border Trust
ISO 27001 certification is accepted by organisations and regulators worldwide as evidence of robust
information security. It enables:
• Multinational organisations to demonstrate a consistent security baseline across all their
offices globally
• Cross-border data transfers with confidence that recipient meets adequate security standards
• Clients and partners to trust that a supplier's data handling meets internationally recognised
standards
• Easier compliance with multiple national laws — meeting ISO 27001 often satisfies the
'appropriate technical and organisational measures' required by GDPR, CCPA, DPDPA, and
similar laws

Page 30 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

7.2.2 How ISO 27001 + 27701 Together Support GDPR Compliance


GDPR Requirement ISO 27001 Control ISO 27701 Addition

Art. 5(1)(f) — Integrity & Access control, encryption, PII-specific access restrictions;
Confidentiality logging controls in Annex A privacy-preserving data handling

Art. 25 — Privacy by Risk assessment and treatment Integrate privacy requirements into
Design at design stage ISMS scope at system design

Art. 30 — Records of Asset management and risk PII processing records; identify data
Processing register flows; document lawful basis

Art. 33–34 — Breach Incident detection and response Privacy incident classification;
Notification procedures notification obligations for PII
breaches

Art. 35 — DPIA Risk assessment methodology Privacy risk assessment integrated


into ISMS; template for PII-specific
DPIAs

Art. 28 — Processor Supplier security assessments Data processor requirements under


Obligations PIMS; contractual privacy obligations

7.3 Benefits of Adopting International Data Protection Standards


• Single framework applicable across jurisdictions — reduces compliance complexity
for multinationals: Unified Framework
• ISO 27001/27701 certification signals trustworthiness to customers, partners, and
investors: Competitive Advantage
• Certification is evidence of accountability; regulators consider it a mitigating factor:
Regulatory Goodwill
• Large enterprises (e.g., banks, government contractors) increasingly require ISO 27001
from vendors: Supply Chain Security
• Annual surveillance audits and 3-year recertification cycles ensure standards evolve
with threats: Continuous Improvement
• ISO 27001 certification often reduces cyber insurance premiums: Cyber Insurance

7.4 Challenges of Implementing International Standards


• Initial implementation requires significant investment in gap analysis, documentation,
controls, and certification audit fees: Cost and Resource Intensive
• Staff at all levels must change behaviour and adopt security-conscious practices —
resistance is common: Cultural Change
• Deciding what is 'in scope' for certification is complex — too narrow is misleading; too
broad is unmanageable: Scope Definition
• Standards must be continuously maintained — policies updated, audits conducted,
risks reassessed annually: Maintenance Burden

Page 31 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

• Standards are not automatically accepted as legal compliance — must be mapped to


each jurisdiction's law: Jurisdictional Gaps
• Emerging technologies (AI, cloud, IoT) create new risks that standards address with a
lag: Keeping Pace with Technology

🌍 Real-World Example: How Multinationals Manage Data Privacy — Microsoft


Microsoft holds ISO 27001, ISO 27017, ISO 27018, and ISO 27701 certifications across its cloud
services.
For EU customers: Microsoft uses GDPR-compliant data processing agreements, EU Standard
Contractual Clauses for transfers, and EU Data Boundary (data stays within the EU).
For US government: Microsoft Government Cloud meets FedRAMP High and NIST 800-53
requirements.
For healthcare: Microsoft Azure Health Data Services meets HIPAA compliance requirements.
This multi-standard approach allows Microsoft to serve customers across 190 countries, each with
different privacy laws, while maintaining a consistent security baseline validated by ISO
certifications.

Page 32 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

SECTION 8: Ethical Considerations in Data Protection

8.1 Ethical Principles in Data Protection Practice


Ethical Principle Meaning in Data Protection Context Example

Transparency Individuals must know what data is Clear, plain-language privacy notice
collected and why; no hidden — not buried in 50-page terms
processing

Autonomy / Informed Individuals must have meaningful Granular consent for different
Consent choice and control over their data purposes; easy opt-out

Fairness Processing must not disadvantage or AI credit scoring must not use proxy
discriminate against individuals variables that discriminate by
race/gender

Accountability Organisations must own responsibility DPO, compliance programmes, audit


for how they handle data trails

Non-maleficence Processing should not cause harm — Health data breaches can cause
physical, financial, reputational, or insurance discrimination and
psychological psychological harm

Beneficence Processing should provide genuine Medical research using patient data
benefit to society or individuals, should demonstrably advance public
proportionate to risks health

Justice / Data collected and used must be CCTV in public spaces must be
Proportionality proportionate to the purpose justified by public safety needs — not
mass surveillance

8.2 Ethical Dilemmas in Data Protection


8.2.1 Business Interests vs. Privacy Rights
Organisations generate revenue through data-driven advertising, personalisation, and analytics. This
creates tension with individuals' rights to privacy.

🌍 Real-World Example: Targeted Advertising — Facebook (Meta) Business Model


Meta's core revenue model (advertising ~97% of revenue) depends on granular personal data
profiling of users.
Ethical tension: Users 'consent' to data collection as part of using a 'free' service — but the consent
is structurally coerced (no meaningful alternative for social connection).
GDPR (DPC Ireland, 2023): €390 million fine for relying on 'contract' as lawful basis for behavioural
advertising instead of consent. Meta ordered to obtain explicit consent.
Ethical dilemma: The business model itself was found incompatible with data protection law — not
just a compliance gap but a fundamental conflict between the monetisation model and privacy
rights.
Lesson: Legitimate interests and contract cannot be used to override the GDPR's core requirement
that individuals have genuine choice over how their data is used for advertising.

Page 33 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

8.2.2 Research and Public Interest vs. Individual Privacy


Using personal health or financial data for research can deliver enormous public benefit (e.g., COVID-
19 vaccine development using NHS patient data) but raises questions of consent, identifiability, and
secondary use.

8.2.3 Security vs. Privacy


Government surveillance for national security (e.g., bulk metadata collection by intelligence agencies)
conflicts with citizens' right to privacy. Courts and laws attempt to balance these interests through
oversight mechanisms, proportionality tests, and judicial authorisation requirements.

8.3 Ethical Responsibilities of Data-Driven Organisations


• Treat privacy as a genuine value, not a box-ticking exercise: Go beyond minimum
compliance
• Embed privacy into all products and services from inception: Design for privacy
• Explain automated decisions affecting individuals in clear language: Be transparent
about AI decisions
• Ensure that individuals can actually exercise their rights, not just nominally: Provide
meaningful redress
• Children, elderly, and marginalised groups require extra protection: Consider vulnerable
groups
• Regular ethics committee review of high-risk data use cases — not just legal review:
Conduct ethical reviews

Page 34 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

SECTION 9: Real-World Case Studies in Data Protection

9.1 Purpose of Case Studies in Data Protection


Real-world case studies illustrate how data protection principles and laws apply in practice. They
reveal the types of failures organisations make, the consequences they face, and the lessons that
can prevent future incidents. Regulators often publish case studies to guide organisations.
• Demonstrate the real-world cost of non-compliance (financial penalties, reputational damage)
• Show how abstract legal principles (e.g., Purpose Limitation) translate into concrete failures
• Provide precedents for how regulators interpret and apply rules
• Enable organisations to learn from others' mistakes rather than their own

9.2 Major Data Breach Cases and Lessons

⚖ Case Study: Case 1: Meta (Facebook) — €1.2 Billion Fine (2023)


Violation: International data transfer violation — EU users' data transferred to US servers without
adequate protection after Schrems II invalidated Privacy Shield.
Finding: SCCs used by Meta insufficient to protect EU data from US government surveillance law
(FISA Section 702).
Penalty: €1.2 billion — largest GDPR fine in history. Meta ordered to suspend US transfers and
delete unlawfully transferred data.
Legal/Ethical Lesson: Structural legal incompatibility between US surveillance law and EU privacy
rights cannot be papered over with contractual clauses.
Corrective Action: EU-US Data Privacy Framework (DPF) adopted in 2023 as new adequacy
decision — though already challenged by privacy advocates.

⚖ Case Study: Case 2: Amazon — €746 Million Fine (Luxembourg, 2021)


Violation: Advertising targeting system processed personal data without a valid lawful basis.
Consent given by users was deemed invalid — not freely given, not specific enough.
Context: Amazon's system for targeting ads to users based on behavioural profiling was found to
violate GDPR's transparency and lawful basis requirements.
Penalty: €746 million — second-largest GDPR fine. CNPD (Luxembourg DPA) issued the fine after
a complaint by French privacy rights group La Quadrature du Net.
Lesson: Consent for advertising profiling must meet the GDPR high bar: granular, specific, freely
given, and as easy to withdraw as to give. Amazon's consent mechanism failed this test.

⚖ Case Study: Case 3: British Airways — £20 Million ICO Fine (2020)
Breach: Hackers injected malicious code into BA's website, diverting customers to a fraudulent
site that harvested payment card details. ~500,000 customers affected.
Violation: GDPR Article 5(1)(f) — Integrity and Confidentiality; inadequate security measures
allowed the breach to persist undetected.

Page 35 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

Original proposed fine: £183 million (1.5% of annual turnover). Final fine: £20 million (reduced due
to COVID-19 financial hardship and mitigation measures).
Technical Failure: Outdated software, lack of multi-factor authentication, insufficient monitoring
and anomaly detection.
Lesson: GDPR requires 'appropriate technical and organisational measures' proportionate to the
risk. Outdated legacy systems and absence of modern security monitoring violate this obligation.

⚖ Case Study: Case 4: WhatsApp (Meta) — €225 Million Fine (Ireland, 2021)
Violation: GDPR transparency obligations — WhatsApp failed to tell users in a clear and accessible
way how their data was being processed, including data shared with other Meta companies.
Finding: Privacy notices were confusing, vague, and did not adequately explain the legal basis for
processing or how data was shared across the Meta group.
Penalty: €225 million. WhatsApp ordered to bring its processing into compliance.
Transparency Lesson: GDPR Article 13 requires privacy information to be provided in a 'concise,
transparent, intelligible and easily accessible form, using clear and plain language.' Legal jargon
and buried disclosures are non-compliant.

⚖ Case Study: Case 5: Cambridge Analytica / Facebook (2018–2019)


Background: Cambridge Analytica harvested data of approximately 87 million Facebook users
without adequate consent, via a personality quiz app. Data was used to build psychographic
profiles for targeted political advertising (US 2016 election, Brexit).
Violations: Facebook breached its own platform policies; Cambridge Analytica used data far
beyond the original purpose of the quiz (purpose limitation violation).
Consequences: Facebook fined $5 billion by FTC (USA); £500,000 by ICO (UK — maximum under
pre-GDPR law); Cambridge Analytica shut down.
GDPR Relevance: Had GDPR been in force, Facebook could have faced fines up to €1.6 billion
(4% of ~€40 billion turnover at the time).
Ethical/Legal Lesson: Third-party app developers accessing platform data must be contractually
bound and technically constrained to prevent secondary use. Purpose limitation applies to
downstream data users, not just the original collector.
Corrective Measures: Facebook introduced App Review, restricted API access, and implemented
data abuse bug bounty programmes.

⚖ Case Study: Case 6: Equifax Data Breach — $575 Million FTC Settlement (USA, 2019)
Breach: In 2017, Equifax (US credit bureau) suffered a breach exposing sensitive personal and
financial data of 147 million Americans, 15 million UK citizens, and ~19,000 Canadian consumers.
Root Cause: Failure to patch a known Apache Struts vulnerability (CVE-2017-5638) for over two
months after a patch was available. Inadequate network segmentation allowed lateral movement.
Penalty: $575 million FTC settlement; $575–700 million total settlements including with state AGs
and class actions. UK ICO: £500,000 (pre-GDPR maximum).
Violations: Failure to maintain adequate security measures; retaining sensitive data longer than
necessary; unencrypted storage of certain data.
GDPR Lesson: Under GDPR, Equifax's UK fine would have been up to €20 million or 4% of global
turnover — approximately €160 million at 4%.

Page 36 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

Systemic Failure: No effective vulnerability management programme, inadequate security


monitoring, poor network architecture — all failures that a rigorous ISO 27001 ISMS would have
addressed.

9.3 Framework for Analysing a Data Breach Case Study


Use this structure to answer 9-mark case study questions:
Step Question to Answer

1. Facts What happened? Who was affected? What data was involved?

2. Violation Which specific legal obligations / GDPR Articles were violated?

3. Penalty What regulatory action / fine was imposed?

4. Root Cause What was the underlying technical, organisational, or process failure?

5. Lesson What should other organisations learn? What compliance measures would have
prevented this?

6. Corrective What did the organisation do (or should have done) to remediate?
Action

📝 Exam Tip
Q: 'Analyze a practical case of data protection failure and recommend corrective measures.' (9
marks)
Choose: British Airways (security failure), Meta (transfer failure), or Equifax (vulnerability
management). Use the 6-step framework above.
Q: 'Discuss a major data breach case study and its legal and ethical implications.' — Cover BOTH
legal (what law was violated, what fine) AND ethical (what rights were harmed, what trust was
broken).
Q: 'How can organisations learn from past data breach case studies?' — Answer: Regulatory
publications, industry information sharing (e.g., ISACs), post-incident reviews, compliance
programme updates.

Page 37 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

SECTION 10: Consolidated Quick Reference for Exam

10.1 Key Numbers and Timelines


Item Value / Timeframe

GDPR effective date 25 May 2018

GDPR upper tier fine €20 million or 4% of global annual turnover (higher of the
two)

GDPR lower tier fine €10 million or 2% of global annual turnover (higher of the
two)

GDPR breach notification to DPA Within 72 hours of becoming aware

GDPR response to data subject requests Within 1 month (extendable by 2 months for complex
cases)

CCPA effective date 1 January 2020

CPRA effective date 1 January 2023

CCPA fine per intentional violation Up to $7,500

7-year financial record retention (UK) 6 years from financial year end (Companies Act 2006)

India DPDPA enacted August 2023

ISO 27001 latest version ISO/IEC 27001:2022

ISO 27701 issued 2019 — Privacy extension to ISO 27001

Largest GDPR fine (as of 2024) €1.2 billion — Meta (DPC Ireland, 2023)

10.2 Definitions Cheat Sheet


Term Definition

Personal Data Any information relating to an identified or identifiable natural


person

Data Controller Entity that determines the purposes and means of processing
personal data

Data Processor Entity that processes personal data on behalf of a controller

Data Subject The natural person whose personal data is being processed

DPO (Data Protection Officer) Mandatory independent expert responsible for overseeing GDPR
compliance in certain organisations

DPIA (Data Protection Impact Structured risk assessment required before high-risk processing
Assessment) activities

RoPA (Records of Processing Mandatory documentation of all personal data processing activities
Activities) (GDPR Art. 30)

Page 38 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

Term Definition

ISMS (Information Security Systematic framework of policies, processes, and controls for
Management System) managing information security (ISO 27001)

PIMS (Privacy Information Extension of ISMS focused on personal data protection (ISO
Management System) 27701)

CIA Triad Confidentiality, Integrity, Availability — the three core objectives of


information security

Adequacy Decision European Commission ruling that a third country provides


equivalent data protection to the EU

SCCs (Standard Contractual Pre-approved contract terms for lawful cross-border data transfers
Clauses) from the EU

Purpose Limitation Principle that data can only be used for the specific purpose for
which it was originally collected

Storage Limitation GDPR principle that data must not be kept longer than necessary
for its purpose

Pseudonymisation Replacing identifying information with a pseudonym/code, so data


cannot be attributed without additional information

Data Retention Policy Formal document specifying how long different categories of data
are kept before deletion

Compliance Audit Systematic independent review to verify an organisation's practices


conform to applicable laws and standards

Ethical Dilemma A situation where complying with legal requirements alone is


insufficient to ensure ethical use of data

10.3 Module 4 Syllabus Coverage Map


Syllabus Topic Section in These Notes Key 9-Mark Q Numbers

Government Regulatory Frameworks Sections 1, 2, 3 Q145, 146, 147, 151, 152, 153
— GDPR, CCPA

Security Standards (ISO 27001, ISO Section 4 Q157, 158, 159, 162
27701, CIA)

Data Retention Policies — GDPR, 7- Section 5 Q163, 164, 165, 172


Year Rule

Compliance and Audits Section 6 Q169, 170, 171, 172

International Standards Section 7 Q175, 176, 177, 178

Ethical Considerations Section 8 Q181, 182, 183, 184

Real-World Case Studies Section 9 Q187, 188, 189

End of Module 4 — Detailed Classroom Notes

Page 39 | Data Privacy & Ethics | Academic Use


Module 4 | Government Regulatory Frameworks & Data Protection •

Government Regulatory Frameworks | Data Protection | Security Standards | Retention | Compliance | International
Standards

Page 40 | Data Privacy & Ethics | Academic Use

You might also like