8. Sustain: Training and Awareness Flashcards
Training vs. Awareness
Training - Communicates an organization’s privacy message, policies, and process to motivate retention.
Awareness - Reinforces lessons learned in training through diverse methods.
Inadequate Training & Awareness Consequences:
- Non-compliance w/ laws and regulations
- mishandling of PII
- Reputational Harm
Training Must Do:
- Address applicable laws
- Identify potential violations
- Address privacy complaints and misconduct
- Proper reporting procedures and consequences for violating laws
- Require acknowledgement
Method and Delivery Options: Training vs. Awareness
Training
- In-Person or Virtual Instruction
- Self-led e-learning modules
- Simulators
- Just-In-Time Information
Awareness
- Newsletters
- Email Reminders
- Intranet Announcements
- Posters, Stickers, Signage
- Privacy Day Post
Steps to Create a Privacy Program
- Ensure a Privacy Policy exists and is up to date
- Ensure employees are trained on the Privacy Policy
- Ensure training records exist
- Use metrics to measure results
- Update training based on feedback & compliance changes
- Reinforce learning with awareness activities
Privacy Training Best Practices
- Partner with the Training/HR department
- Make it fun and customized to participants
- Use motivators like digital badges
- Ensure all new employees are trained
- Ensure repeat training is provided
- Solicit feedback
Benefits of Creating a Privacy Program
- Establishing a common understanding of privacy
- Reducing human error
- Considering Privacy Up Front
- Improving customer interactions
- Expanding privacy office eyes and ears
- Changing the conversation