Memra

Privacy principles — GDPR, OECD, PIPEDA — and auditing a real policy

◈ 4 cards

Three principle sets, what each one covers that the others do not, and how to audit a privacy policy you have actually accepted — clause by clause, treating silence as the finding.

Privacy is not confidentiality

The definitional pair is exact and it is examinable. Privacy is the control individuals have over who may access their personal information. Confidentiality is the principle that only authorised persons should have access. Confidentiality is a property of a system; privacy is a right of a person. An organisation can hold your data in perfect confidentiality and still violate your privacy — by using it for a purpose you never agreed to, by keeping it for a decade after it stopped being needed, or by declining to tell you it holds it at all. That gap is what the principle sets below exist to close, and an answer that treats we encrypted it as a privacy answer has missed the question.

GDPR Article 5 — the seven processing principles

The General Data Protection Regulation was adopted in 2016 and became enforceable in 2018. Two features made it globally important. Its definition of personal data is deliberately broad — any information relating to an identified or identifiable person — which brings IP addresses, device identifiers, location data and usernames inside it. And its extraterritorial reach over organisations outside the EU that serve EU residents has made it effectively a global baseline, which is why a policy written in another country still tends to be written against it.

Article 5's seven principles are the yardstick:

  1. Lawfulness, fairness and transparency — including telling the subject what the data will be used for.
  2. Purpose limitation — collected for specified, explicit purposes, and not further processed for a new incompatible purpose.
  3. Data minimisation — adequate, relevant and limited to what the purpose requires.
  4. Accuracy — kept accurate and up to date; inaccurate data erased or rectified without delay.
  5. Storage limitation — kept in identifiable form no longer than necessary.
  6. Integrity and confidentiality — processed with appropriate security.
  7. Accountability — the controller must be able to demonstrate compliance with the other six. Note the verb: it is not enough to comply, you must be able to show it.

Related articles worth naming because they carry the rights a policy audit checks for: Article 6 consent and the other lawful bases; Article 9 special categories (racial or ethnic origin, political opinions, religious beliefs, union membership, and genetic, health and biometric data); Article 15 right of access; Articles 16 and 17 rectification and erasure; and Articles 33 and 34 breach notification. Get 33 and 34 the right way round: Article 33 notifies the supervisory authority; Article 34 notifies the individual, and only where the breach is likely to result in a high risk to their rights and freedoms.

The OECD guidelines — eight principles

Older, shorter, and in practice the more useful yardstick for auditing a commercial privacy policy, because it says more about what the organisation must tell you and let you do.

Collection limitation — limits on collection, by lawful and fair means, with the subject's knowledge or consent where appropriate. Data quality — relevant, accurate, complete and up to date. Purpose specification — purposes specified not later than at the time of collection, and re-specified on each change. Use limitation — no disclosure or other use beyond those purposes, except with consent or by authority of law. Security safeguards. Openness — a general policy of openness, and readily available means of establishing what data exists, its purposes, and the identity and usual residence of the data controller. Individual participation — the right to confirm whether data about you is held; to have it communicated within a reasonable time, at a non-excessive charge, in intelligible form; to be given reasons for a refusal and to challenge it; and to challenge the data itself and have it erased, rectified, completed or amended. Accountability.

Where the two sets part company

The mapping is close but not one-to-one, and saying exactly where it breaks is what a strong comparison looks like.

OECD's collection limitation and purpose specification both feed GDPR's purpose limitation and data minimisation — the eight and the seven cut the same territory differently. GDPR has a storage limitation principle with no OECD counterpart at all: retention is simply not one of the eight. And in the other direction, OECD's openness and individual participation correspond to GDPR Articles 15–17 rather than to anything in Article 5 — so an audit conducted against Article 5 alone will miss access, rectification and erasure entirely, which are exactly the clauses a real policy is most often silent about. Use both sets, or use OECD and say why.

PIPEDA — the Canadian instrument

An Athabasca learner sits in Canadian law, and the textbook does not mention its statute. The Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5) is the federal private-sector privacy law, and its ten fair information principles — set out in Schedule 1, derived from the CSA Model Code — are: accountability · identifying purposes · consent · limiting collection · limiting use, disclosure and retention · accuracy · safeguards · openness · individual access · challenging compliance.

Compare that list with the OECD eight and you will see the family resemblance immediately: PIPEDA splits OECD's purpose specification into identifying purposes and consent, splits individual participation into individual access and challenging compliance, and — unlike Article 5 and unlike the OECD list — folds retention in with use and disclosure, so it does have the storage-limitation idea, just not under that name. If you audit a Canadian service, PIPEDA is the instrument that actually binds it, and naming it earns credit that quoting an EU regulation at a Canadian company does not.

Two more frames worth having

The four Common Criteria privacy properties are precise, mutually distinguishable, and almost always confused:

  • Anonymity — use a resource without disclosing identity; others cannot determine the identity bound to an operation, and the system will not solicit the user's real name.
  • Pseudonymity — use a resource without disclosing identity but remain accountable: others cannot determine the identity, but the system itself can, from the assigned alias.
  • Unlinkability — make multiple uses without others being able to link them to each other.
  • Unobservability — use a resource without others being able to observe that it is being used at all.

Two discriminations to hold: pseudonymity preserves system-side identifiability so that accountability survives; anonymity does not. And unlinkability hides the relationship between uses, while unobservability hides that a use occurred. The framing point the exam wants: this class concerns an individual's privacy with respect to their use of computer resources, not the privacy of personal information about them — which is what GDPR and organisational policy address. Note too that anonymity does not conflict with access control, which binds to computer-based user IDs rather than to personal identities.

Privacy, big data and social media. The core tension is between beneficial outcomes in research, public health, security and law enforcement, and individuals' rights to privacy, fairness, equality and free expression. The social-media-specific concern is that regulation has concentrated on what the platform does with a user's own data, while very little addresses the effect of other people's data on an individual — photographs and posts uploaded by others that include you, often carrying time and location metadata, usable to your detriment by employers, insurers and investigators. Technical responses include database security, privacy settings and tagging notifications (access control at enormous scale — and the fact that these controls change constantly is evidence that the right ones have not been found), and anonymisation before release, with the explicit caveat that anonymised data can sometimes be re-identified by combining sources. We anonymised it is therefore not a complete answer; it is a control that can be defeated.

Organisationally, privacy needs three artefacts paralleling their security counterparts — a privacy policy document, a strategic privacy plan and a privacy awareness programme — plus a chief privacy officer. Privacy is governed with the same machinery as security, not instead of it.

Worked example — auditing a policy, and treating silence as the finding

Take a policy you have actually accepted: a fitness-tracking app, say, that records workouts, heart rate, GPS routes and a social feed. Read it clause by clause against a named principle set, and write down what it says and what it does not.

Lawfulness, fairness, transparency. The policy states that data is processed to provide and improve the service. That phrase is doing far too much work: improve is elastic enough to cover model training, and provide does not distinguish the workout log from the social feed. Finding: transparency is nominal.

Purpose limitation / purpose specification. Purposes are listed, which satisfies the letter. But a later clause reserves the right to use data for other purposes we describe to you at the time — which is compatible with the principle only if a genuine choice accompanies the description. Finding: conditional pass, with a question to put to the controller.

Data minimisation / collection limitation. GPS is collected continuously while the app is open, including indoor sessions where a route has no meaning. Finding: fail — the data is not limited to what the stated purpose requires.

Accuracy / data quality. No mechanism is described for correcting an erroneous record. Finding: silent.

Storage limitation. The policy says data is kept as long as necessary for the purposes described, which is circular — a purpose that never ends produces a retention period that never ends. No period, no deletion trigger, no distinction between the workout history and the heart-rate series. Finding: fail, and this is the clause most policies are weakest on.

Integrity and confidentiality / security safeguards. Industry-standard encryption is claimed. Finding: unverifiable, so treat it as a claim rather than a control; note that the principle is about appropriate security, and no organisation-specific measure is stated.

Accountability. No named controller, no contact point, no mention of how compliance is demonstrated. Finding: fail.

Openness and individual participation (which Article 5 would have missed entirely, and which the OECD set and PIPEDA both catch). There is a data-download button — good, that is individual access. There is no described route to challenge the data or have it corrected, and no reasons-for-refusal process. Finding: partial.

Silence is the finding, and this is the sentence to write down. A policy that does not mention retention is not neutral about retention — it has reserved an unbounded permission and told you nothing. A policy silent on the controller's identity has removed your means of exercising every other right. When you audit, list the principles the policy does not address as a group, and say what each silence permits. That list is usually shorter than the compliance list and worth more marks, because it is the part the average answer omits.

Finish with a judgement and a concrete change, not a summary. This policy is adequate on access and inadequate on retention and accountability; the single change with the largest effect would be a stated retention period per data category, with automatic deletion, because it converts an unbounded permission into a bounded one and makes every other principle auditable.

GDPR Article 5OECD principleWhere they part companyLawfulness, fairness,transparencyOpenness (in part)GDPR requires a lawfulbasis; OECD names nonePurpose limitationPurpose specification + UselimitationOECD splits specifying thepurpose from using the dataData minimisationCollection limitationOECD limits at collection;GDPR at adequacy for thepurposeAccuracyData qualityclosest match of the eightStorage limitation— none —retention is simply not oneof the OECD eightIntegrity andconfidentialitySecurity safeguardssame idea, different nameAccountabilityAccountabilitythe only principle bothsets name identically— not in Article 5 —Individual participationGDPR carries it in Articles15–17, so an Article 5audit misses itPIPEDA’s ten split these differently again — and do include retention.
The mapping is close but not one-to-one, and the two gaps are the examinable part: GDPR has a storage-limitation principle the OECD set lacks, and the OECD’s openness and individual participation live in GDPR Articles 15–17 rather than in Article 5 at all.
NORMAL ~/memra/learn/comp-400/privacy-principles-gdpr-oecd-pipeda-and-auditing-a-real-policy utf-8 LF