Privacy Operational Life Cycle: Chapter 6 Protect: Policies Flashcards
Privacy policy
Governs the privacy goals and strategic direction of the orgs privacy office
Also known as the Privacy Notice
Privacy policy goals
Explain to customers how the org handles PI
Explains to employees how the org handles PI
Describes steps for employee handling PI and responsibilities
Outline how personal data will be processed
Privacy policy components
Purpose
Scope
Applicability
Roles and responsibilities
Compliance
Policy vs Notice
Internal vs external
Employee policy
Sections:
Issue/objective statement
Statements of the orgs position
Applicability
Roles and Responsibilities
Compliance
Points of contact
Procurement: vendors
Identify vendors and their legal obligations
Evaluate risk, policies and server location
Develop a thorough contract
Monitor vendors practices and performance
Use a vendor policy
Data retention
Determine what data is being retained, how and where stored
Understand legal requirements for data
Brainstorm scenarios that would require data retention
Estimate business impacts of retaining vs storing data
Develop and implement a policy
Policy completion
Communicate to org
Awareness
Formal training
Policies apply to everyone in the org