CIPM BOK Outline Flashcards
1
Q
Privacy Program Governance - 4 main subcategories
A
- Organizational Level
- Develop the Privacy Program Framework
- Implement the Privacy Program Framework
- Metrics
2
Q
Governance: Organizational Level - 4 main subcategories
A
- Create a company vision
- Establish Data Governance Model
- Establish a privacy program
- Structure the Privacy Team
3
Q
Create a company vision
Gov., Org level
A
- Acquire knowledge on privacy approaches
- Evaluate the intended objective
- Gain executive sponsor approval for this vision
4
Q
Establish Data Governance Model
Gov., Org level
A
- Centralized
- Distributed
- Hybrid
5
Q
Establish a Privacy Program
Gov., Org Level
A
- Define program scope and charter
- Identify the source, types, and uses of personal information within the organization and the applicable laws
- Develop a Privacy Strategy
6
Q
Privacy Strategy
Gov., Org level, privacy program
A
- Business alignment– finalize the operational business case for privacy, identify stakeholders, leverage key functions, create a process for interfacing within organization, align organizational culture and privacy/data protection objectives, and obtain funding/budget for privacy and the privacy team
- Develop a data governance strategy for personal information (collection, authorized use, access, and destruction)
- Plan inquiry/complaint handling procedures (customers, regulators, etc)
7
Q
Structure the Privacy team
Gov., Org level
A
- Establish the organizational model, responsibilities, and reporting structure appropriate to the size of the organization
- Designate a point of contact for privacy issues
- Establish/endorse the measurement of professional competency
8
Q
Large Organization Structure
A
- Chief Privacy Officer
- Privacy Manager
- Privacy Analysts
- Business line privacy leaders
- “First Responders”
9
Q
Small Organization Structure
A
Sole Data Protection Officer (DPO)
10
Q
Privacy Program Development
Gov
A
- Develop organizational privacy policies, standards, and/or guidelines
- Define privacy program activities
11
Q
Privacy Program Activities
Gov, Program Framework
A
- Education and Awareness
- Monitoring and responding to the regulatory environment
- Internal policy compliance
- Data inventories, data flows, and classification
- Risk assessments (PIAs, PTAs, etc)
- Incident Response and process, including jurisdictional regulations
- Remediation
- Program assurance, including audits
12
Q
Privacy Program Implementation
Gov
A
- Communicate the framework to internal and external stakeholders
- Ensure continuous alignment to applicable laws and regulations to support the development of an organizational privacy program framework
13
Q
Ensuring continuous alignment of program
Gov, Program Implementation
A
- Understand when national laws and regulations apply (e.g., GDPR, CCPA)
- Understand when local laws and regulations apply
- Understand penalties for noncompliance with laws and regulations
- Understand the scope and authority of oversight agencies (e.g., Data Protection Authorities, Privacy Commissioner, FTC, etc.)
- Understand privacy implications of doing business with or basing operations in countries with inadequate, or without, privacy laws
- Maintain the ability to manage a global privacy function
- Maintain the ability to track multiple jurisdictions for changes in privacy law
- Understand international data sharing arrangement agreements
14
Q
Metrics
Gov
A
- Identify intended audience for metrics
- Define reporting resources
- Define privacy metrics for oversight and governance per audience
- Identify systems/application collection points
15
Q
Defining Privacy Metrics
Gov., Metrics
A
- Compliance metrics (i.e., collection, responses to data subject inquiries, use, retention, disclosure to third parties, incidents- breaches, complaints, inquiries- employees trained, PIA metrics, privacy risk indicators, percent of company functions represented by governance mechanisms)
- Trending
- Privacy program return on investment
- Business resiliency metrics
- Privacy program maturity levels
- Resource utilization