C. Physical assessments Flashcards
Data Assessment
Help inventory and track personal information and determine the impact org systems/processes will have on Privacy
Benefits of a Data Assessment (4)
1) Help identify privacy risks to individuals in advance and deal with them effectively
2) Help achieve more robust compliance
3) Help reduce cost in the long run
Three types of Inventories/Records
1) Data inventory or data map
2) Inventory of applicable laws and regulations
3) Records of processing activities
Data inventories help answer
1) How do you know where your personal information is?
2) How it is used in the organization
3) Why the data is important
Data categorized by subject area helps
1) Identify inconsistent data
2) Remediate discrepancies in data
3) Determine which is the most/least important data
Data inventory topics to cover (5)
1) Collection
2) Usage
3) Transfers
4) Retention
5) Destruction
Responsibility of Data inventory
Often shared between Privacy and IT
Elements of data inventory (11)
1) The nature of a repository of privacy-related information
2) The owner of the repository
3) Location of the repository
4) The volume of information in repository
5) Format of information
6) Use of information
7) Type of privacy related information
8) Where data is stored
9) Where data is accessed
10) International transfers
11) with whom the data is shared
Data inventories can be used to (3)
1) address incidents and risk assessments
2) Help set organization’s priorities for privacy initiatives
3) Provide data locations, usage, storage, and access
Methods to build Data inventory (3)
1) Spreadsheet
2) GRC software
3) Internally developed system
Inventory of applicable laws and regulations considerations (3)
1) Gap analysis
2) International, local, and industry specific standards and laws
3) Including the legal team
Why Records of Processing activities are important
Required for controllers and processors under GDPR
What to include in Record of processing - both (3)
1) Name and contact information of the controller/processor
2) Any international transfers to third countries
3) General descriptions of security controls
What to include in Record of processing - controller (4)
1) Purpose of processing
2) categories of data and categories of data subjects
3) Categories of recipients
4) Retention periods for various categories of personal data
What to include in Record of processing - processor (1)
Categories of data and categories of processing