Privacy Operational Life Cycle: Chapter 6 Protect: Policies Flashcards

1
Q

Privacy policy

A

Governs the privacy goals and strategic direction of the orgs privacy office

Also known as the Privacy Notice

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Privacy policy goals

A

Explain to customers how the org handles PI

Explains to employees how the org handles PI

Describes steps for employee handling PI and responsibilities

Outline how personal data will be processed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Privacy policy components

A

Purpose
Scope
Applicability
Roles and responsibilities
Compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Policy vs Notice

A

Internal vs external

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Employee policy

A

Sections:
Issue/objective statement
Statements of the orgs position
Applicability
Roles and Responsibilities
Compliance
Points of contact

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Procurement: vendors

A

Identify vendors and their legal obligations

Evaluate risk, policies and server location

Develop a thorough contract

Monitor vendors practices and performance

Use a vendor policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Data retention

A

Determine what data is being retained, how and where stored

Understand legal requirements for data

Brainstorm scenarios that would require data retention

Estimate business impacts of retaining vs storing data

Develop and implement a policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Policy completion

A

Communicate to org
Awareness
Formal training
Policies apply to everyone in the org

How well did you know this?
1
Not at all
2
3
4
5
Perfectly