Skip to content

Privacy Principles & Online-Data Ethics

Chapter 2 uses privacy law to show how ethical principles become organizational obligations. It compares OECD Fair Information Processing ideas, GDPR principles, PIPEDA and FTC criteria. For CDMP study, learn the recurring management themes and the named GDPR set as presented in the source; do not turn this chapter into an unsourced current-law course.

GDPR principles presented in Chapter 2

Principle Practical study meaning
Fairness, Lawfulness, Transparency Process personal data lawfully, fairly and understandably.
Purpose Limitation Collect for explicit legitimate purposes; do not repurpose incompatibly.
Data Minimization Use data adequate, relevant and necessary for the purpose — not “just in case” excess.
Accuracy Keep personal data accurate/current and address inaccurate data appropriately.
Storage Limitation Do not retain identifiable personal data longer than necessary for its purpose.
Integrity and Confidentiality Protect against unauthorized/unlawful processing and accidental loss/damage.
Accountability Controllers are responsible and must be able to demonstrate compliance.

Where consent is the processing basis, Chapter 2 describes it as an affirmative action that is freely given, specific, informed and unambiguous.

Qualified rights discussed include access, correction/rectification, portability, objection and erasure.

Recurring privacy-management themes across OECD / GDPR / PIPEDA / FTC

Do not pretend the regimes are identical. Instead recognize the repeated Data Management logic:

  • Accountability / enforcement — somebody or some mechanism is responsible.
  • Purpose / notice — identify or disclose why data is collected and how it will be used.
  • Consent / choice — meaningful options where applicable.
  • Collection/use limitation — use what is necessary and appropriate for identified purposes.
  • Accuracy / integrity — data must be reliable enough for intended use.
  • Security / safeguards — protect against unauthorized use/disclosure.
  • Openness / transparency — practices should be understandable and visible.
  • Access / challenge / redress — people should be able to see, contest, correct or seek redress where applicable.
  • Lifecycle discipline — retention and Privacy by Design extend responsibility beyond collection.

Deciding pattern

If a team says “we collected it legally, so we can keep it forever and invent new uses later,” the Chapter 2 response should surface purpose limitation, minimization/collection limitation, storage limitation, transparency and accountability.

Online data in an ethical context

Chapter 2 highlights four areas:

Ownership of personal data

People may not realize how platforms or downstream brokers aggregate personal information into deep profiles. The ethical question includes control, notice, downstream use and economic benefit.

Right to be Forgotten

Online persistence can conflict with a person's interest in erasure and reputation adjustment. This connects directly to retention practice.

Identity

People have interests in correct identity, one identity and, in some contexts, a private identity.

Freedom of speech online

Expression must be considered alongside harmful online behavior such as bullying, terror incitement, trolling or insult.

Distinction to retain

Privacy is inside Data Ethics. Data Ethics is not reducible to privacy. A misleading chart, biased sample or untrustworthy integration can be unethical even when no personal-data disclosure occurs.

Source anchors: Chapter 2 §3.2–3.3, pp. 55–59; Tables 1–3.

← Scope & principles · Next: Unethical practices →