1 / 3100%
There are 10 Generally Accepted Privacy Principles (GAPP)
developed by the American Institute of Certified Public Accountants
(AICPA) and the Canadian Institute of Chartered Accountants (CICA):
1) Management - Organizations need to establish a set of procedures
and policies for protecting the privacy of personal information they
collect from customers as well as information about their customers
obtained from third parties such as credit bureaus. They should
assign responsibility and accountability for implementing those
policies and procedures to a specific person or group of employees.
2) Notice - An organization should provide notice about its privacy
policies and practices at or before the time it collects personal
information from customers, or as soon as practicable thereafter. The
notice should clearly explain what information is being collected, the
reasons for its collection, and how the information will be used. The
principle of notice should also apply to any monitoring and logging
for security purposes.
3) Choice and consent - Organizations should explain the choices
available to individuals and obtain their consent prior to the
collection and use of their personal information.
4) Collection - b An organization should collect only the information
needed to fulfill the purposes stated in its privacy policies.
5) Use, retention, and disposal - Organizations should use customers’
personal information only in the manner described in their stated
privacy policies and retain that information only as long as it is
needed to fulfill a legitimate business purpose.
6) Access - An organization should provide individuals with the ability
to access, review, and correct the personal information stored about
them.
7) Disclosure to third parties - Organizations should disclose their
customers’ personal information to third parties only in the situations
and manners described in the organization’s privacy policies and only
to third parties who provide the same level of privacy protection as
the organization that initially collected the information.
8) Security - An organization must take reasonable steps to protect
its customers’ personal information from loss or unauthorized
disclosure.
9) Quality - Organizations should maintain the integrity of their
customers’ personal information and employ procedures to ensure it
is reasonably accurate.
10) Monitoring and enforcement - Organizations must periodically
verify that their employees are complying with stated privacy
policies.
These 10 principles help aide businesses to be compliant with privacy
regulations set forth by the European Union's General Data Privacy
Regulation (GDPR), the California Consumer Privacy Act (CCPA), the
Health Insurance Portability and Accountability Act (HIPPA), the
Health Information Technology for Economic and Clinical Health Act
(HITECH), and the Financial Services Modernization Act, just to name
a few. When a business chooses to offshore outsource their
information system functions, they run the risk of not being able to
adhere to these aforementioned principles. b For example in principle
3, choice and consent, these options may differ across countries and
could cause an issue if not properly adhered to for whatever country
the business is being operated in. Another example would be
principle 4, collection of personal information. By the shear nature of
the information system function being outsourced offshore,
information will definitely have to be collected and sent via the
internet. If the outsourced company doesn't have to proper due
diligence to protect against cookies and other privacy threats,
information is likely to be intercepted and stolen.
Having had my personal information stolen as a result of being the
customer of a certain business, I feel like it was the business's
responsibility to better protect my personal information. In my case,
the information I provided them was necessary because it was for
health insurance, so they needed my address, my date of birth, my
social security number, my maiden name, etc. Such sensitive
information should not be hap-hardly collected and stored. I can't
change my date of birth if someone steals it. I can't move if someone
steals my address. I can't get a different maiden name, etc. b See
where I'm going with this? Some pieces of personal information you
simply cannot replace as easily as a new cell phone number if
someone steals it from you. This information that's crucial to one's
identity should be guarded, heavily, in my opinion. Businesses that
need this information should use encryption tools, heavily train their
staff on how to properly protect the information, use only virtual
private networks (VPN) so the information has to pass through an
encrypted tunnel if being passed from one employee's computer to
another, or require a customer's digital signature, etc. It's up to the
business to take these measures and adhere to the 10 principles to
protect their customers. I think it's just simply the responsibility of
doing business. b No different than paying taxes or stopping at a stop
sign in traffic. It must be done, so just do it!
References
Romney, Marshall, B. et al. Accounting Information Systems. Available
from: MBS Direct, (15th Edition). Pearson Education (US), 2020.
Students also viewed