In order to eliminate spam, this Wiki requires a login. To request a wiki account, e-mail aaron.titus, thomas.gideon, or robert.obrien [at] this domain.
The following is a list of potential subject matter each PC Policy might address. Please see the Community of Interest page for other potential sources of subject matter and potentially related organizations. The draft also includes some of Daniel Solve's concepts in "Taxonomy of Privacy."
Definitions
- Global Definitions: References to commonly understood privacy terminology.
- Company Specific Definitions (ie, trade names, publication names, etc)
- Legal Definitions
Parties to a Privacy Policy or Contract
- Data Steward
- Relatives of the Steward (ie, children subsidiaries, parent companies, employees, contractors)
- Friends of the Steward (ie, affiliated organizations, third parties)
- Data Subject
- Data Subect's References (ie, "send this link to your friend," "Get 10% off when you refer a friend to our service")
- Governmental Actors (ie, law enforcement officer, judicial officer, political officials)
- Non-Affiliated/ Unauthorized Parties (ie, hackers, breachers, unauthorized parties)
Protections
- Information Collected and Protected by Steward
- By Enumerated List of Information Types (ie, "Name," "E-mail," "SSN," "Address," etc.)
- By Demonstrative List of Information Types (ie, "Financial Account Information," "Credit Information," "Physical Location Information")
- By Method of Collection (ie, data collected online, information from all sources, information given by the Subject, information provided by third parties, etc)
- Information Excluded from Protection
- By Enumerative Class (ie, Facts, Images, Video, Biometrics)
- By Enumerative Type (ie, SSN, address, phone number, geolocation, purchase history, etc.)
- By Demonstrative Type (ie, "Personally identifiable information," "Medical information," "Directory Information," "Financial Information")
- By Method of Collection (ie, "collected online," "from third parties," "in person or on the phone," "given by the data subject," "through behavioral advertising," "through deep packet inspection")
- Individuals Protected by Steward
- Protected Individuals by Class: (ie, Customers, visitors, members, third parties, friends, references, data subjects, employees, contractors)
- Protected Individuals by Relationship: Dominant/Recessive (ie, Merchant/Customer, Doctor/Patient, Bank/Client, Employer/Employee, Employer/Contractor, Attorney/Client, ), or Equal/Equal (Partner/Partner, Corporation/Corporation)
- Protected Individuals by Enumeration: (ie, Vice President, "You")
- Level of Protection or guarantee
- Exclusions from Protection
- By Class
- By Enumeration
- Level of Protective Exclusion
Information Processing and Dissemination
- Information Processing Policy
- Aggregation
- Identification
- Security
- Physical storage
- Training
- Breach Detection
- Auditing
- Exclusion
- Retention Policies
- Secondary Use
- Use of Aggregated information (Data Profiling)
- Information Dissemination
- Disclosure
- Exposure
- Increased Accessibility
- Appropriation
- Distortion
- Commercial exploitation
- For Providing Services
Consent, Choice, and Control
- Known Risks
- Past incidences of breach
- Consent, Choice & Control
- Method for obtaining Subject's consent
- Subject's Right to consent
- Subject's Right to Opt Out/In
- Subject & Steward's Right to Amend, Correct, Update, or Correct Distortion
- Subject & Steward's Right to Disseminate, Control
- Subject & Steward's Right to Hide, Remove, Delete, or Purge
- Invasions
- Intrusions
- Decisional Interference
Contract Creation
- Method of contract creation (ie, contract creation by checking a box, yielding personal information, creating an account, logging in)
- Effect of contract (ie, which sections become warrantees, obligations, or optional)
- Responsibilities of Steward
- Enforceability of contract (Offer, Acceptance, consideration)
- Warrantees and Guarantees
- Security
- Warrantees of Confidentiality / Non-Disclosure
- Future Changes to the policy
- Right to and manner of notice
- Effect on existing or prior contracts
- If Contractual, method of acceptance
Harms and Remedies
- Recognized Harms
- Objective Harms
- Lost Wages
- Financial Loss
- Property Loss
- Harm to Credit
- Harm to medical record
- Loss of Liberty (ie, arrest, surveillance)
- Brand diminishment
- Subjective Harms
- Emotional Distress
- Lost Time
- Embarrassment
- Harm to Reputation
- Level of Protection
- No Representation of Protection
- Disclaim Responsibility to the full extent of the law
- Protect to current industry standard
- Insure against harm
- Indemnify
- Remedies
- Enforcement
- Express Remedies
- Limitations on Remedies
Other Considerations
- Need for industry-specific policies
Complexity
Above all, it strikes me that with such a large number of relevant variables (especially in comparison with Creative Commons), we will probably have to devise an a-la-carte approach to devising PC Policies, in addition to a suite of model policies.