2. Framework: Privacy Governance Flashcards
What does the terms ‘privacy governance’ refer to?
Refers to the components that:
- Guide a privacy function toward compliance
AND
- Enable it to support business objectives and goals.
What are the components of organizational privacy governance?
- Vision and mission statement;
- Scope;
- Framework;
- Strategy; and
- Team structure.
How can the privacy program scope be identified?
Through the identification of the following:
- PI information collected and processed; and
- Applicable privacy and data protection laws and regulations.
Why should an organization identify the PI collected and processed?
Maintaining written documentation about personal information, including information about how an organization (1) processes the data, and (2) the recipients of the data is formalized through Article 30 of the GDPR.
What questions should be asked to define the scope of a privacy program?
- Who collects, uses, and maintains PI ? (Organizations are also required to understand the roles and obligations of service providers)
- What types of PI are collected, and what is the purpose of the collection?
- Where is the data stored? (Applications and systems, as well as countries)
- To whom is the data transferred?
- Who has access to the data both internally and externally? (Ex., third-parties)
- When (ex., during transaction and hiring process) and how (ex. through an online form) is the data collected?
- How long is the data retained, and how is it deleted?
- What security controls are in place to protect the data?
What is considered to be best practice when doing business in a jurisdiction with no data protection regulations?
Best practice is to institute the organization’s requirements, policies, and procedures to the highest level achievable instead of reducing them to the level of the country in which business is being conducted.
In a nutshell, use the most restrictive policies as it also reduces privacy related risks for the organization.
What are some scope challenges?
Domestic privacy programs may need to monitor state and/or regional laws as well as industry-specific laws, while global programs need to be cognizant of cultural norms, differences, and approaches to privacy protection.
What are some examples of privacy protection regulation approaches around the globe?
- US: Sectoral and state specific laws (Laws address specific industry sector and/or apply to the residents of a specific state)
- EU, UK, Canada: Comprehensive laws (Laws govern the collection, use, and dissemination of PI and an official oversight agency).
- Australia: Co-regulatory model (Industry develops enforcement standards that are overseen by a privacy agency).
- US, Japan, Singapore: Self-regulated model (Companies use a code of practice by a group of companies known as industry bodies, ex., Online Privacy Alliance, TrustArc, WebTrust)
What are the privacy challenges faced by organizations operating in the US?
Organizations must determine whether they are subject to a law or industry standard. (Ex., Financial institutions are subject to the Gramm-Leach-Bliley Act (GLBA); health providers are subject to HIPAA and merchants handling cardholder information must follow the Payment Card Industry Data Security Standard)
Do US states have data breach notification laws?
Yes, all 50 states have data breach notification laws.
If an organization processes the PI of any resident of a state, to the extent that nonencrypted data has been compromised, compliance regulations may include notifying the residents of the state, as well as government bodies and state attorneys.
What is a successful approach to scoping an organization’s privacy program?
- Understanding of the end-to-end personal information data life cycle.
- Consideration of the legal, cultural, and personal expectations.
- Customized privacy approach.
- Awareness of privacy challenges, including the interpretation of laws and regulations as well as enforcement activities and processes.
- Monitoring of all legal compliance factors for both local and global markets.
What is a privacy strategy?
Privacy strategy is an organization’s approach to communicating and supporting the privacy program and its vision.
What are the benefits of implementing a privacy strategy?
- Management’s growing awareness of the importance of protecting PI and the financial impacts of mismanagement
AND
- Awareness that everyone has a role in PI protection and every individual within an organization contributes to the success of the privacy program.
What is a challenge when it comes to building a privacy program and supporting strategy?
Gaining consensus from member’s of the organization’s management on privacy as a business imperative.
Who is best suited as a privacy program sponsor?
Someone who understands the importance of privacy and will act as an advocate for the program.
Effective sponsors typically have experience with the organization, the respect of colleagues, and access to or ownership of the budget.
Frequently, sponsors function as risk compliance executives (Ex., chief information security officers, chief compliance officers, or general counsels.)