Ch 4 - Data Inventory Flashcards
an analysis of the privacy risks associated with processing personal information in relation to a project, product or service
Privacy Impact Assessment
When should you do a PIA?
Early. In other words:
Prior to deployment of a project, product or service that involves the collection of personal information
When there are new or revised industry standards, organizational policies, or laws and regulations
When the organization creates new privacy risks through changes to methods by which personal information is handled
Data inventory
also known as a data map, provides answers to these questions by identifying the data as it moves across various systems, and thus indicating how it is shared and organized and where it is located.
Tools to update data inventory
spreadsheets, a governance, risk and compliance (GRC) software system, an internally developed system or another product.
Privacy assessment
measure an organization’s compliance with laws, regulations, adopted standards and internal policies and procedures.