From the course: CompTIA CySA+ (CS0-002) Cert Prep: 7 Compliance and Assessment

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

Limiting data collection

Limiting data collection

From the course: CompTIA CySA+ (CS0-002) Cert Prep: 7 Compliance and Assessment

Start my 1-month free trial

Limiting data collection

- [Narrator] Limiting data collection is the most important way that an organization can protect personal privacy. If the organization doesn't collect personal information in the first place, it can't abuse, lose, or otherwise mistreat that information. As I discussed in the last video, the generally accepted privacy principles require that organizations provide individuals with notice of the information that they collect, the ways that they will use it, and that they obtained the consent of individuals for that use. This is just the first barrier to data collection. Organizations should never collect information that falls outside of the disclosures that they've made to individuals, even if it's easy to do so or seems to be incidental to the approved purpose. If you do have a legitimate need to collect more information than you've disclosed, you should revise your disclosures, notifying individuals of the new…

Contents