CDPSE · Question #134
Which of the following is the BEST way to address privacy concerns when an organization captures personal data from a third party through an open application programming interface (API)?
The correct answer is C. Obtain consent from the data subjects. Under virtually all major privacy frameworks (GDPR, CCPA, PIPEDA, etc.), organizations must have a lawful basis to collect and process personal data. Consent from the data subjects is often the primary and most fundamental basis, especially when collecting data through an open…
Question
Which of the following is the BEST way to address privacy concerns when an organization captures personal data from a third party through an open application programming interface (API)?
Options
- ADevelop a service level agreement (SLA) with the third party
- BImplement encryption for the data transmission
- CObtain consent from the data subjects
- DReview the specification document of the open API.
How the community answered
(25 responses)- A8% (2)
- B4% (1)
- C84% (21)
- D4% (1)
Explanation
Under virtually all major privacy frameworks (GDPR, CCPA, PIPEDA, etc.), organizations must have a lawful basis to collect and process personal data. Consent from the data subjects is often the primary and most fundamental basis, especially when collecting data through an open third-party API where data subjects may not have directly interacted with the collecting organization. An SLA (A) governs the service relationship with the third party but does not legitimize the data collection itself. Encryption (B) protects data in transit but does not address the legal or ethical right to collect. Reviewing the API specification (D) is a technical due-diligence step but does not resolve the underlying privacy obligation.
Topics
Community Discussion
No community discussion yet for this question.