Module 1 - Introduction to Privacy Program Management Flashcards
What are the stages in the privacy operational life cycle?
- Assess
- Steps, checklists and processes to assess privacy program
- Comparing to industry best practices, corporate policies, laws/regs etc.
2 . Protect
- Information security practices to protect the personal information
- Sustain
- Periodic assessments/audits, monitoring, identify and mitigate risks, communication aspects - Respond
- Incident response, respond to information requests, legal compliance etc.
What are a Privacy Program Manager’s Responsibilities?
Responsible for safe keeping and responsible use of personal information.
- Compliance
- Accountability - Demonstrate compliance with evidence.
- Alignment with organizational strategy
What is Privacy Program Management?
It is the structured approach of combining several projects into a framework and life cycle to protect personal information and individual rights.
What are the top three responsibilities of the privacy team?
Compliance is important - but, it is NOT the only driver of a privacy program.
- Meet regulatory compliance.
- Safeguard data against attacks and threats
- Meet expectations of business clients and partners.
What’s the relationship between IT and Security?
Security determines who has access to certain information.
IT implements privacy principles into technology developments - e.g. builds the permission management system that allows only authorized users to have access to data.
Why does the Privacy Program interact with other parts of the organization?
The Privacy Program must integrate requirements and representation from multiple functional areas:
* Internal Audit - assesses controls and whether people/processes follow them
* Learning and development - policies and procedures are transformed into teachable content.
* IT - works with Privacy and information security to ensure alignment.
* HR - data lifecycle of employee records, employee privacy, whistleblowing, ethics office etc.
* Marketing - e.g. personal data related to digital advertising, internet marketing, OBA; do not call registry
* Finance - Financial regulations (e.g. PCI/DSS), payroll, budget
* Legal & Compliance - legal due diligence; minimize legal liability
* Information Security - defines policies and procedures, standards and guidelines, technical and operational controls (e.g. NIST Privacy Framework). CIA Triad
* Communications team - privacy related comms consistent with branding and tone of voice of company.
* Procurement - contracts with third parties, inclusion of security and privacy controls.