chapter 5 Flashcards
what is data Protection Management Programme
–> builds a strong foundation for data protection within the organisation
DPMP FULL FORM
data Protection Management Programme
what are DPMP SECTIONS
governance and risk assessment
policy and practices
processes
maintenance
what is the purpose of the DPMP
–> Helps organizations demonstrate accountability in data protection
–> Stakeholders and Regulators: Ensures compliance with data protection regulations and addresses the concerns of stakeholders and regulatory bodies
–> Customers and Business Partners: Builds trust and confidence by safeguarding personal data and respecting privacy rights
–> Business Competitiveness: Enhances competitive advantage by demonstrating a strong commitment to data protection and establishing a positive brand image
what are the 2 aspects in governance and risk assessment
Governance Structure
Values Risk Assessment
what is the role of Senior Management
- Defining corporate values that are aligned with data
protection - Allocating resources to data protection
- Appointing a Data Protection Officer (DPO)
- Managing personal data protection risks
- Providing guidance on data protection initiatives
- Supporting data protection policies and programme
- Commissioning Data Protection Impact Assessments
- Advocating data protection training
- Providing directions to the DPO
what is the role of data protection officer
Implementing policies and processes for handling personal data
Fostering a data protection awareness and culture
Managing personal data protection
Communicating to management of any data protection
related risks
Liaising with the PDPC
it is __________ to appoint a data protection officer in singapore
compulsory
who does the DPO report to ?
chief internal audit
chief legal officer
The DPO operations may be outsourced to a service provider, however the DPO responsibility remains with _____________
a member of the senior management
what is data protection as a service
when the DPO operations are outsourced to a service provider
Protecting personal data is the responsibility of
______
everyone in the organization
what is the Culture of Accountability and Staff Training
- Personal data protection education for all staff, from Board to Senior Management to Staff
- Trainings and briefings on personal data protection should be tailored to job functions
- Regular staff communication circulars to include personal data protection topics
what should the senior management have an understanding of ?
Senior management should have an understanding of risks and review how risks affects the organisation
what are the 4 types of risks
Strategic
*Affects achieving company strategic objectives
*e.g. governance, strategic planning
Operational
*Affects organisational operations
*e.g. sales and marketing, production
Compliance
*Affects organisational compliance with regulations
*e.g. legal, code of conduct
Financial
*Affects organisational financial process
*e.g. reporting, tax