cipm Flashcards

1
Q

Define privacy governance

A

Privacy governance refers to the framework and processes that ensure an organization effectively manages and protects personal information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the components of a privacy vision/privacy mission statement?

A
  • Value of privacy to the organization
  • Organizational objectives
  • Strategies to drive tactics to achieve intended outcomes
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the purpose of a privacy mission statement?

A

To create awareness about the organization’s privacy practices both internally and externally.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How can a privacy mission statement create internal awareness?

A

By integrating the mission statement into training programs and internal communications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How can a privacy mission statement create external awareness?

A

By sharing the mission statement externally to demonstrate transparency and commitment to privacy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

List considerations for defining a privacy program’s scope and charter.

A
  • Initiation of a new privacy strategy
  • Formal sign-off from the C-suite
  • Justification for investment in a privacy program
  • Program charter detailing what, why, how, who, how much, and when
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What should a privacy strategy lay out?

A

Goals of the privacy program.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the basics of a privacy strategy?

A
  • Business alignment
  • Data governance of personal information
  • Inquiry-/complaint-handling procedures
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a privacy framework?

A

A structure that guides the privacy program, including policies, procedures, and processes for compliance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What distinguishes a privacy strategy from a privacy framework?

A

A privacy strategy answers ‘why’ privacy is important, while a privacy framework answers ‘what’ form the privacy program will take.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are common elements of privacy program frameworks?

A
  • Policies
  • Procedures
  • Processes
  • Checklists for privacy management
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Name some widely recognized privacy frameworks.

A
  • Fair Information Practices (FIPs)
  • OECD Guidelines
  • AICPA/CICA Generally Accepted Privacy Principles (GAPP)
  • Canadian Standards Association Privacy Code
  • APEC Privacy Framework
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does the GDPR require regarding a Data Protection Officer (DPO)?

A

Organizations must appoint a DPO to help with compliance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

List required skills for a Data Protection Officer under the GDPR.

A
  • Risk/IT assessment
  • Legal expertise
  • Communication skills
  • Leadership abilities
  • Self-starter mentality
  • Ability to teach and handle requests
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are typical responsibilities of a Data Protection Officer?

A
  • Working with regulators
  • Ensuring organizational training
  • Keeping up with changes in law and technology
  • Managing privacy programs
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

True or False: A Data Protection Officer can be dismissed for performing DPO-related duties.

17
Q

What is a privacy champion?

A

An executive who serves as a sponsor for the privacy program and advocates for privacy as a core organizational concept.

18
Q

How can organizations receive buy-in for a privacy program?

A
  • Building relationships with key stakeholders
  • Aligning business objectives with privacy objectives
  • Demonstrating privacy as a benefit
19
Q

What are the two main types of awareness for a privacy program?

A
  • Internal awareness
  • External awareness
20
Q

Fill in the blank: The __________ provides guidelines for the protection of privacy and transborder flows of personal data.

A

[OECD Guidelines]

21
Q

What is the significance of keeping a record of ownership in a privacy program?

A

To establish clear responsibilities and support from key stakeholders.

22
Q

What is essential for the success of an organization’s privacy program?

A

Organization-wide effort

Each department must understand the impact of its activities on data protection.

23
Q

How can advanced privacy programs benefit organizations externally?

A

Protect consumer data and create trusting customer relationships

Communicating the privacy program can build customer confidence and deliver measurable returns.

24
Q

What is a RACI matrix used for?

A

To embed responsibilities

RACI stands for Responsible, Accountable, Consulted, Informed.

25
What should be kept to ensure clear ownership of assets and responsibilities?
A record of ownership ## Footnote Key internal stakeholders may form a steering committee to support the program.
26
What is the role of internal audit in privacy governance?
Reviews and analyzes operations across all departments ## Footnote It helps ensure unbiased reporting of audit findings and typically reports to the audit committee.
27
What factors does risk management evaluate?
Risk management culture, risk factors, control design, control operation ## Footnote Ensures business and regulatory requirements are met.
28
What drives the growth of the privacy tech vendor market?
New compliance requirements and consumer awareness ## Footnote GDPR, CPRA, and new investments from venture capitalists are key contributors.
29
What should organizations consider when choosing a privacy technology product?
Organizational needs, cost vs. savings, risks vs. benefits, vendor vetting, usability, contract negotiations ## Footnote Consideration of implementation and training is also crucial.
30
What are some components of privacy program management technologies?
Privacy assessment management, consent management, data mapping, incident response ## Footnote These tools work directly with the privacy office.
31
What strategies can help align privacy compliance with organizational strategy?
Involvement of privacy office, IT, and C-suite in enterprise program management ## Footnote This includes activity monitoring and data discovery.
32
What are key considerations for conducting international data transfers?
Privacy compliance considerations ## Footnote Understanding differing privacy laws in other countries is crucial.
33
What implications should be understood when operating in countries with differing privacy laws?
Privacy implications and territorial scope ## Footnote This is essential for compliance and operational planning.