C. Physical assessments Flashcards

1
Q

Data Assessment

A

Help inventory and track personal information and determine the impact org systems/processes will have on Privacy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Benefits of a Data Assessment (4)

A

1) Help identify privacy risks to individuals in advance and deal with them effectively
2) Help achieve more robust compliance
3) Help reduce cost in the long run

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Three types of Inventories/Records

A

1) Data inventory or data map
2) Inventory of applicable laws and regulations
3) Records of processing activities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Data inventories help answer

A

1) How do you know where your personal information is?
2) How it is used in the organization
3) Why the data is important

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Data categorized by subject area helps

A

1) Identify inconsistent data
2) Remediate discrepancies in data
3) Determine which is the most/least important data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Data inventory topics to cover (5)

A

1) Collection
2) Usage
3) Transfers
4) Retention
5) Destruction

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Responsibility of Data inventory

A

Often shared between Privacy and IT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Elements of data inventory (11)

A

1) The nature of a repository of privacy-related information
2) The owner of the repository
3) Location of the repository
4) The volume of information in repository
5) Format of information
6) Use of information
7) Type of privacy related information
8) Where data is stored
9) Where data is accessed
10) International transfers
11) with whom the data is shared

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Data inventories can be used to (3)

A

1) address incidents and risk assessments
2) Help set organization’s priorities for privacy initiatives
3) Provide data locations, usage, storage, and access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Methods to build Data inventory (3)

A

1) Spreadsheet
2) GRC software
3) Internally developed system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Inventory of applicable laws and regulations considerations (3)

A

1) Gap analysis
2) International, local, and industry specific standards and laws
3) Including the legal team

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Why Records of Processing activities are important

A

Required for controllers and processors under GDPR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What to include in Record of processing - both (3)

A

1) Name and contact information of the controller/processor
2) Any international transfers to third countries
3) General descriptions of security controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What to include in Record of processing - controller (4)

A

1) Purpose of processing
2) categories of data and categories of data subjects
3) Categories of recipients
4) Retention periods for various categories of personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What to include in Record of processing - processor (1)

A

Categories of data and categories of processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Exceptions to requirement to provide detailed record of processing (3)

A

If the company has less than 250 employees and processing is

1) occasional
2) does not include sensitive personal information
3) not likely to result in risk to the data subject

17
Q

Data flow analysis

A

Helps meet the requirements of providing a detailed record of processing under GDPR