Privacy Principles & Online-Data Ethics
Chapter 2 uses privacy law to show how ethical principles become organizational obligations. It compares OECD Fair Information Processing ideas, GDPR principles, PIPEDA and FTC criteria. For CDMP study, learn the recurring management themes and the named GDPR set as presented in the source; do not turn this chapter into an unsourced current-law course.
GDPR principles presented in Chapter 2
| Principle | Practical study meaning |
|---|---|
| Fairness, Lawfulness, Transparency | Process personal data lawfully, fairly and understandably. |
| Purpose Limitation | Collect for explicit legitimate purposes; do not repurpose incompatibly. |
| Data Minimization | Use data adequate, relevant and necessary for the purpose — not “just in case” excess. |
| Accuracy | Keep personal data accurate/current and address inaccurate data appropriately. |
| Storage Limitation | Do not retain identifiable personal data longer than necessary for its purpose. |
| Integrity and Confidentiality | Protect against unauthorized/unlawful processing and accidental loss/damage. |
| Accountability | Controllers are responsible and must be able to demonstrate compliance. |
Consent and individual rights
Where consent is the processing basis, Chapter 2 describes it as an affirmative action that is freely given, specific, informed and unambiguous.
Qualified rights discussed include access, correction/rectification, portability, objection and erasure.
Recurring privacy-management themes across OECD / GDPR / PIPEDA / FTC
Do not pretend the regimes are identical. Instead recognize the repeated Data Management logic:
- Accountability / enforcement — somebody or some mechanism is responsible.
- Purpose / notice — identify or disclose why data is collected and how it will be used.
- Consent / choice — meaningful options where applicable.
- Collection/use limitation — use what is necessary and appropriate for identified purposes.
- Accuracy / integrity — data must be reliable enough for intended use.
- Security / safeguards — protect against unauthorized use/disclosure.
- Openness / transparency — practices should be understandable and visible.
- Access / challenge / redress — people should be able to see, contest, correct or seek redress where applicable.
- Lifecycle discipline — retention and Privacy by Design extend responsibility beyond collection.
Deciding pattern
If a team says “we collected it legally, so we can keep it forever and invent new uses later,” the Chapter 2 response should surface purpose limitation, minimization/collection limitation, storage limitation, transparency and accountability.
Online data in an ethical context
Chapter 2 highlights four areas:
Ownership of personal data
People may not realize how platforms or downstream brokers aggregate personal information into deep profiles. The ethical question includes control, notice, downstream use and economic benefit.
Right to be Forgotten
Online persistence can conflict with a person's interest in erasure and reputation adjustment. This connects directly to retention practice.
Identity
People have interests in correct identity, one identity and, in some contexts, a private identity.
Freedom of speech online
Expression must be considered alongside harmful online behavior such as bullying, terror incitement, trolling or insult.
Distinction to retain
Privacy is inside Data Ethics. Data Ethics is not reducible to privacy. A misleading chart, biased sample or untrustworthy integration can be unethical even when no personal-data disclosure occurs.
Source anchors: Chapter 2 §3.2–3.3, pp. 55–59; Tables 1–3.