Chapter 1 Flashcards
What is PPM?
Privacy Program Management/Manager
structured approach, integrating privacy into framework & lifecycle to protect PI and individual rights
What is program management
Manage multiple projects to improve performance
Allows for oversight and status of projects
View on change management
What is framework?
Structure to support program management
Created by analyzing laws, regulations and best practices to meet organizational goals
Lifecycle - stages
Assess
Protect
Sustain
Respond
Commonality with Framework & Lifecycle?
both include PbD principles & Privacy by Default
Organizations Privacy Program includes
Intentional plan to protect PI and individual rights
FW & LC allow orgs to…
FW and LC allows orgs to reuse procedures and processes, repeatable to reduce errors &/ gaps
What makes up the Privacy Program Framework?
FW and LC
Assess stage
-Steps, checklist and processes necessary to assess gaps (based on established best practices, corporate privacy policies, privacy laws and regulations & the organizations privacy framework (ie. PbD))
Protect stage
- Data lifecycle, information security practices, PbD principles to protect PI
- Technical aspect
Sustain stage
- Monitoring, auditing and communication aspects of management framework.
- Audit, risk and security practices to meet regulatory, industry and business objectives
Respond stage
- Principles for legal requests, info requests, incident response planning, and incident handling
- Aim is to reduce organizational risk and increase compliance
Responsibilities of a PPM
- Align and support (not block) the business
- Define privacy obligations
- ID and mitigate privacy risks
- Documentation (policies and procedures)
- identify
- create, revise, implement
- raise data IQ of organization
Privacy Program Goals
- Effective & auditable framework
- Promote trust & confidence for customers and employees
- Highlight that privacy is important/taken serioulsy
- Respond to breaches and data subject requests
- Monitor, maintain and improve privacy program
Accountability
- Policies and procedures for best practices and compliance
- Accountable for the actions it does or does NOT take
Consumer Trust
- transparent, accountable and good data stewards
Privacy across the organization
- Constantly evolving
- Build privacy into the organization
- align with other key departments (legal, IT, etc.)
Teams involved in privacy ( top 5)
Learning & development –> employee training
Communications –> internal content
Info security team –> encryption, data loss prevention (DLP), technological controls
IT team –> support privacy by adding processes & controls
Internal audit team –> are controls in place? adhered to?