2. Frameworks and Governance Flashcards

1
Q

Privacy Governance - Guiding a privacy function toward compliance with privacy laws and regulations and enabling them to support the organization’s broader business goals which are:

A
  1. Create a privacy vision and mission statement
  2. Define a program scope
  3. Select a privacy framework
  4. Develop a privacy strategy
  5. Structure the privacy team
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

No Standard Organizational Structure for Privacy is required, Instead Consider:

A

1.Department Influence

  1. Global Scope
  2. Best Funded
  3. Best Executes Enterprise Projects
  4. Strongest Supporter of Privacy
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What do Privacy Program Frameworks do?

A
  • Provide a benchmark to measure your program.
  • Create policies, procedures, & processes to ensure the organization knows how to be compliant
  • Create checklists to guide the team thru privacy management

-Can be: Standards, Laws/Regulations, and/or Frameworks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Policy Lifecycle

A
  1. Draft
  2. Get Approval
  3. Disseminate & Socialize
  4. Train
  5. Review and Revise
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

DPO Job Description: Tasks

A
  1. Work closely with regulators & advise stakeholders to work toward compliance
  2. Ensure organizations are aware of their training and awareness obligations
  3. Keep up with changes to laws and technology
  4. Build, implement and manage privacy programs
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

DPO Job Description: Skills

A

Risk/IT - experience assessing risk & best practice mitigation
Legal - experience and independence
Communication
Leadership & Board Exposure
Self-Starter / Board Level
Common touch teaching
Credible & no conflict of interest

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Privacy Governance Models

A

Centralized: One team or person is responsible.

Decentralized/Local: Decision-making is delegated to lower levels allowing info to flow bottom to top.

Hybrid - Combines centralized and decentralized model is Most Common.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Buy-In for Privacy Strategy

A
  1. Build Relationships
  2. Find champions outside the privacy office
  3. Pitching Privacy
  4. Creating steering groups of stakeholders
  5. Create awareness for the program internally and externally
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

RACI MATRIX - Ownership of Stakeholders Assets & Responsibilities

A
  • who is Responsible
  • who is Accountable
  • who needs to be Consulted
  • who needs to be Informed
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Key Functional Areas (Departments) to Create & Enforce the Privacy Program

A
  • Communications
  • IT
  • Procurement
  • Marketing
  • Learning and Development
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Internal Audit and Risk Management

A

Internal Audit - reports to audit committee to ensure its unbiased

Risk Management - ensure business and regulatory requirements are met through detailed analysis.

Some organizations use privacy tech vendors to help achieve compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

GDPR Article 37
GDPR Article 38
GDPR Article 39

A

GDPR Article 37 - DPO must be appointed, expert in privacy

GDPR Article 38 - DPO must report to the highest levels of the org

GDPR Article 39: DPO Activities shall include:
- monitoring companies compliance with GDPR
- provide advice during DPIAs
- cooperate with supervisory authorities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly