chapter 6 Flashcards
what does this
Develop and implement policies and practices to adhere to the PDPA
Data Protection Management Programme
what is the
Inputs to deciding on policies and practices to be implemented
Data Protection Impact Assessment
DPIAs can be conducted on _____ and _______
systems and processes
what are the key tasks in DPIA
- Identifying the personal data handled by the system or
process - Identifying how the personal data flows
- Identifying data protection risks
- Addressing the identified risks
- Checking to ensure that identified risks are adequately
addressed
when to conduct a DPIA
- Creating a new system
- Creating a new process
- Changing existing systems or processes
- Changes to the organisational structure
- Collecting new types of personal data
To address data protection risks effectively, a DPIA should involve ________________
relevant stakeholders and where needed, relevant external parties
who is the DPIA lead
project manager
in charge of the DPIA project
what is the responsibilities of project manager (DPIA Lead)
Overall in-charge of the DPIA and could be supported by a DPIA team.
Seeks input from relevant parties on:
* Data protection risks and challenges
* Possible solutions to address the risks
* Documents DPIA report
* Monitors DPIA outcomes and reviews the DPIA
role of the Data protection officer
Enforcing the Data Protection policies
what is the responsbilities of DPO
Advises DPIA lead throughout the DPIA process, including
providing support based on best practices
* Defining the risk assessment framework
* Ensuring that DPIAs are conducted according to the organisation’s
policies
* Assists in reviewing the DPIA report
role of Project Steering Committee
Management of organisation
responsibilities of project steering committee
Commissions the DPIA
Approves the DPIA report
what is the role of others
Other organisational functions or external parties
what is the responsibilities of others
Provides input on potential risks and challenges, for example
* IT and Legal
* Customer Service, Communications or Operations
* Human Resource or Staff Capability
what are the steps in the Data Protection Impact Assessment Life Cycle
phase 1 assess the need for DPIA
phase 2 plan DPIA
phase 3 Identify Data and personal data flows
phase 4 identify and assess data protection risks
phase 5 create action plan
phase 6 implement and monitor action plan