Assigment Week 6 – BD308 – Hilma Aulia – 2581494366

Nama : Hilma Aulia Daffa
NIM : 2581494366

Pertanyaan:

  1. What are the core principles of GDPR (e.g., data minimization, purpose limitation)?
  2. What is “personal data” or “Personally Identifiable Information (PII)”? Provide five examples.
  3. How can a digital business ensure it gets proper consent from users before collecting their data?

Jawaban:

1.

Understanding the GDPR isn’t just about memorizing a bunch of rules; it’s really about a specific mindset on how we should treat people’s information. Basically, there are seven core pillars that everything else in the regulation sits on. First off, there’s the whole idea of Lawfulness, Fairness, and Transparency. It sounds like legal jargon, but it basically means you can’t be “sneaky” with data. If you’re collecting someone’s info, you need a solid legal reason to do it, and you have to be upfront about it. No hidden agendas.PreviewThen we have Purpose Limitation. This is a big one because it stops organizations from gathering data for one thing and then using it for something completely different later on. You have to be specific from the start about why you need it. Along the same lines is Data Minimization—which is pretty much the “less is more” rule. You shouldn’t be asking for a user’s home address if you only need their email to send a newsletter. Just take what’s actually necessary.Accuracy is also a major point. The Accuracy principle means that if you’re holding onto someone’s data, you’re responsible for making sure it’s not outdated or flat-out wrong. If it is, you’ve got to fix it or toss it out. This connects to Storage Limitation too. You can’t just keep data forever “just in case.” Once it’s served its purpose, it needs to be deleted. PreviewSecurity is obviously huge, which is where Integrity and Confidentiality come in. It’s the baseline requirement to keep things locked down so hackers or unauthorized staff can’t get to it. You have to prove you’ve got the right tech and protocols in place to prevent leaks. Finally, there’s the Accountability principle. This is the “teeth” of the GDPR. It’s not enough to just follow the other six rules; you have to be able to prove it. If a regulator knocks on the door, the burden is on the company to show exactly how they’re staying compliant. It’s basically about taking ownership of the data you’re handling.

When we talk about “Personal Data” in the context of GDPR—or what people in the US usually call PII (Personally Identifiable Information)—we’re basically looking at any bit of information that can point back to a specific person. It’s not just about having someone’s name on a screen; it’s about whether that data, either on its own or when you piece it together with something else, makes that individual “identifiable.” Essentially, if you can figure out who someone is through a specific identifier, it counts.

2.

Preview

To make it a bit more concrete, here are five common examples of what this actually looks like in practice:

  1. Full Names: This is the most obvious one. A person’s legal first and last name is the primary way we distinguish one person from another in any system.
  2. Email Addresses: These are unique by nature. An address like [email protected] doesn’t just send mail; it acts as a digital trail that leads directly to one specific user.
  3. Physical Addresses: Whether it’s where someone lives or where they work, a street address is a massive giveaway for someone’s identity and their daily location.
  4. Official ID Numbers: Things like Social Security Numbers (SSN), passports, or even a driver’s license. These are government-issued and strictly tied to one person, making them high-stakes identifiers.
  5. IP Addresses: This one is a bit more “behind the scenes.” Even though it looks like just a string of numbers for a device, it can be used to track a person’s digital footprint and eventually pin down who is behind the screen.

3.

PreviewPreview

When we talk about digital privacy today, especially with regulations like GDPR and CCPA in play, “consent” isn’t just a checkbox you tick—it’s a standard for how businesses treat their users. To actually stay compliant, a company’s approach to data has to be grounded in transparency and real user control. The first thing to consider is whether the consent is actually “freely given.” It’s a bit of a red flag when a service forces you to agree to data collection that has nothing to do with the service itself. If I’m using a calculator app, I shouldn’t have to give up my location just to get an answer. It has to be a genuine choice, not a “take it or leave it” ultimatum. This leads into being specific and informed. People need to know exactly what they’re signing up for—who is taking the data, what’s being tracked, and what they’re actually going to do with it. Instead of hiding this in 50 pages of legal jargon, it needs to be clear. Along those same lines, we’ve moved past the era of pre-ticked boxes. Modern standards require an “unambiguous opt-in,” meaning the user has to take a deliberate, active step—like clicking a button or checking a box themselves—to say “yes.” I also think “granularity” is a huge factor that often gets overlooked. Instead of one massive “Accept All” button that covers everything from functional cookies to aggressive marketing, businesses should give users the ability to choose. Maybe I’m okay with cookies that save my login, but I don’t want my email sold to a third-party marketing list. Then, there’s the “exit” strategy. One of the clearest indicators of a fair system is how easy it is to leave. If it took one click to give consent, it should take one click to withdraw it. Usually, this means having a straightforward “Privacy Settings” dashboard or an obvious unsubscribe link. It’s about making the opt-out process just as accessible as the opt-in. Finally, from a back-end perspective, none of this matters if the business doesn’t keep records. Compliance isn’t just about doing the right thing; it’s about being able to prove it. Keeping a solid audit trail of how and when consent was obtained is basically the safety net for any digital business during an audit.

Previous Post Previous Post
Newer Post Newer Post

Leave a comment