eBook - Notes Flashcards

1
Q

What is the key role and goals of a Privacy Program Manager?

A

Role: The PPM leads the effort to ensure that privacy principles are being carried out through information security practices.

Goals:
1. Define privacy obligations for the organization
2. Identify and mitigate privacy risks
3. Identify existing documentation, policies, and procedures around the management of personal information.
4. Create, revise, and implement policies for a good privacy program
5. Raise the data IQ of organization to drive a privacy-oriented culture.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the key tasks and responsibilities of a Privacy Program Manager?

A
  1. Establish data governance through proper policies, procedures, and processes.
  2. Privacy related awareness and training
  3. Incident response and privacy investigations
  4. Regulator complaints
  5. Data subject requests
  6. Communications
  7. Privacy controls
  8. Privacy issues with existing products and services
  9. Audits, Metrics, Data Transfers
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Privacy Program Management?

A

A structured approach to combining several projects in to a framework and lifecycle to protect personal information and the rights of individuals.

A structured privacy program reflects an organization’s thoughtful and intentional plan to protect personal information and the rights of individuals.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the four stages of a privacy governance life cycle?

A
  1. Assess - steps, checklists, processes necessary to assess any gaps in a privacy program compared to industry best practices, applicable laws, policies, framework etc.
  2. Protect - data lifecycle, information security and PbyDesign.
  3. Sustain - monitoring, auditing, and communication aspects of the framework. Audit, risk assessments,.
  4. Respond - to information requests, legal compliance, incident-response
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Privacy Governance?

A

The components of a privacy program that guide a privacy function toward compliance with privacy laws, and supports broader business objectives and goals.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the key components of Privacy Governance?

A

-Creating the organizational privacy vision and mission statement
-Defining the scope of the privacy program
- Selecting an appropriate privacy framework
- Developing the organizational privacy strategy
- Structuring the privacy team

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the purpose of the organizational privacy vision and mission statement?

A

It lays the groundwork for the rest of the privacy program.
Should align with the organization’s broader purpose and goal.
It should describe the privacy function’s raison d’etre.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the steps involved in defining the scope of a privacy program?

A
  1. Identify the personal information collected and processed
  2. Identify applicable privacy and data protection laws and regulations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a Privacy Strategy?

A

A privacy strategy is the organization’s approach to communicating
and supporting the privacy program and its vision.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How do you develop a privacy strategy?

A
  1. Identify stakeholders and internal partnerships
    a) Gain consensus from management and key stakeholders
    b) Where does the program sit, who else (Legal, IT, Security, HR etc.) should be involved?
    c) Build a coalition of supporters.
    d) Identify a program sponsor with budgetary powers - e.g. CISO, Chief Compliance Officer
  2. Conduct a privacy workshop for stakeholders
  3. Keep a record of ownership
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Why is it essential to develop and implement a framework?

A
  • A framework can systematically handle risks and obligations of privacy regulations.
  • It can help achieve compliance
  • Serve as a business differentiator, engender trust
  • Support business commitments to stakeholders
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a framework and what does it help a Privacy Program do?

A

A framework is a collection of processes, templates, tools, laws and standards that guide privacy program management.

The privacy framework helps answer:
- Are privacy risks properly identified?
- Are there gaps?
- Monitoring of the program
- Employee Training
- Incident response plan etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the two categories of frameworks?

A

1) Principles and Standards - e.g. Fair Information Principles, OECD Privacy Principles, GAPP, Canada Privacy Code, APEC, NIST, ETSI, PbyD etc.
2) Laws, Regulations, and Programs - GDPR, PIPEDA, BCRs,
3) Rationalizing requirements - e.g. essentially implementing a solution that addresses all the requirements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the seven principles of Privacy-by-design?

A
  1. Proactive not reactive; preventative not remedial
  2. Privacy as the default setting
  3. Privacy embedded into design
  4. Full functionality - positive-sum, not zero-sum
  5. End-to-end security - full life cycle protection
  6. Visibility and transparency - keep it open
  7. Respect for user privacy - keep it user-centric
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are privacy technologies?

A

Privacy technologies help achieve and demonstrate compliance.
It includes things like:
* Consent management
* Data mapping tools
* Due diligence and risk assessment management
* Supplier due diligence
* Managing data subject access requests
* De-identification
* Incident response tools.

Important to understand that a product by itself does not guarantee compliance. It is part of a larger privacy program.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is GRC?

A

Governance, Risk and Compliance

Amazon’s definition: Governance, Risk, and Compliance (GRC) is a structured way to align IT with business goals while managing risks and meeting all industry and government regulations. It includes tools and processes to unify an organization’s governance and risk management with its technological innovation and adoption.

See: https://aws.amazon.com/what-is/grc/#:~:text=Governance%2C%20Risk%2C%20and%20Compliance%20(,its%20technological%20innovation%20and%20adoption.

GRC tools aim to synchronize various internal functions toward “principled performance” integrating the governance, management, and assurance of performance, risk, and compliance activities.

17
Q

What are the key factors in structuring the privacy team?

A
  1. Identifying and selecting a suitable governance model
  2. Establish an organizational model that defines roles, responsibilities, and reporting relationships.
18
Q

What are the different types of governance models?

A
  1. Centralized, Local, Hybrid
  2. Privacy teams can be placed under Legal, IT or other.
19
Q

What are the pros and cons of a centralized approach?

A

Centralized - more streamlined, however, decision making rests at the very top.

Localized - few layers of management, people closes to the problem make decisions, information flows from bottom up. However, it may recreate processes over and over.

20
Q
A