Accountability
The implementation of appropriate technical and organizational measures to ensure and be able to
demonstrate that the handling of personal data is performed in accordance with relevant law, an idea
codified in the EU General Data Protection Regulation and other frameworks, including APEC's Cross
Border Privacy Rules. Traditionally, accountability has been a fair information practices principle, that
due diligence and reasonable steps will be undertaken to ensure that personal information will be
protected and handled consistently with relevant law and other fair use principles.
Active Scanning Tools
DLP network, storage, scans and privacy tools can be used to identify security and privacy risks to
personal information. They can also be used to monitor for compliance with internal policies and
procedures, and block e-mail or file transfers based on the data category and definitions.
American Institute of Certified Public Accountants
A U.S. professional organization of certified public accountants and co-creator of the WebTrust seal
program.
Acronym(s): AICPA
Associated term(s): Canadian Institute of Chartered Accountants, Seal Programs, WebTrust
Anonymization
, The process in which individually identifiable data is altered in such a way that it no longer can be
related back to a given individual. Among many techniques, there are three primary ways that data is
anonymized. Suppression is the most basic version of anonymization and it simply removes some
identifying values from data to reduce its identifiability. Generalization takes specific identifying values
and makes them broader, such as changing a specific age (18) to an age range (18-24). Noise addition
takes identifying values from a given data set and switches them with identifying values from another
individual in that data set. Note that all of these processes will not guarantee that data is no longer
identifiable and have to be performed in such a way that does not harm the usability of the data.
Associated law(s):Anonymous Data, De-Identification, Microdata Sets, Re-identification
APEC Privacy Principles
A set of non-binding principles adopted by the Asia-Pacific Economic Cooperative (APEC) that mirror the
OECD Fair Information Privacy Practices. Though based on OECD Guidelines, they seek to promote
electronic commerce throughout the Asia-Pacific region by balancing information privacy with business
needs.
Assess
The first of four phases of the privacy operational life cycle; provides the steps, checklists and processes
necessary to assess any gaps in a privacy program as compared to industry best practices, corporate
privacy policies, applicable privacy laws, and objective-based privacy program frameworks.
Associated term(s): Privacy Operational Life Cycle; Protect; Sustain; Respond
Audit Life Cycle
High-level, five-phase audit approach. The steps include: Audit Planning; Audit Preparation; Conducting
the Audit; Reporting; and Follow-up.