2. Frameworks and Governance Flashcards
Privacy Governance - Guiding a privacy function toward compliance with privacy laws and regulations and enabling them to support the organization’s broader business goals which are:
- Create a privacy vision and mission statement
- Define a program scope
- Select a privacy framework
- Develop a privacy strategy
- Structure the privacy team
No Standard Organizational Structure for Privacy is required, Instead Consider:
1.Department Influence
- Global Scope
- Best Funded
- Best Executes Enterprise Projects
- Strongest Supporter of Privacy
What do Privacy Program Frameworks do?
- Provide a benchmark to measure your program.
- Create policies, procedures, & processes to ensure the organization knows how to be compliant
- Create checklists to guide the team thru privacy management
-Can be: Standards, Laws/Regulations, and/or Frameworks
Policy Lifecycle
- Draft
- Get Approval
- Disseminate & Socialize
- Train
- Review and Revise
DPO Job Description: Tasks
- Work closely with regulators & advise stakeholders to work toward compliance
- Ensure organizations are aware of their training and awareness obligations
- Keep up with changes to laws and technology
- Build, implement and manage privacy programs
DPO Job Description: Skills
Risk/IT - experience assessing risk & best practice mitigation
Legal - experience and independence
Communication
Leadership & Board Exposure
Self-Starter / Board Level
Common touch teaching
Credible & no conflict of interest
Privacy Governance Models
Centralized: One team or person is responsible.
Decentralized/Local: Decision-making is delegated to lower levels allowing info to flow bottom to top.
Hybrid - Combines centralized and decentralized model is Most Common.
Buy-In for Privacy Strategy
- Build Relationships
- Find champions outside the privacy office
- Pitching Privacy
- Creating steering groups of stakeholders
- Create awareness for the program internally and externally
RACI MATRIX - Ownership of Stakeholders Assets & Responsibilities
- who is Responsible
- who is Accountable
- who needs to be Consulted
- who needs to be Informed
Key Functional Areas (Departments) to Create & Enforce the Privacy Program
- Communications
- IT
- Procurement
- Marketing
- Learning and Development
Internal Audit and Risk Management
Internal Audit - reports to audit committee to ensure its unbiased
Risk Management - ensure business and regulatory requirements are met through detailed analysis.
Some organizations use privacy tech vendors to help achieve compliance
GDPR Article 37
GDPR Article 38
GDPR Article 39
GDPR Article 37 - DPO must be appointed, expert in privacy
GDPR Article 38 - DPO must report to the highest levels of the org
GDPR Article 39: DPO Activities shall include:
- monitoring companies compliance with GDPR
- provide advice during DPIAs
- cooperate with supervisory authorities