Privacy Program Management: Chapter 1 Intro to program management Flashcards
What is Privacy Program Management
A structured approach to using frameworks and life cycle to protect PII
Responsibilities of a Privacy Organization
- Comply with legal and regulatory requirements
- Meet expectations of clients or customers
- Prevent and mitigate privacy risks
Framework
Skeletal structure needed to support program management
Privacy Program Framework
Analyze applicable laws, regulations and best practices
Privacy Governance Lifecyle
- Assess
- Protect
- Sustain
- Respond
Assess (lifecyle)
- Provide steps, checklists, and processes necessary to assess gaps
- Compared to industry best practices, corporate policies, applicable laws/regs, and privacy framework
- Elements can be performed asynchronously
- Maturity models: AICPA/CICA Privacy Maturity Model, Generally Accepted Privacy Principles (GAPP), Privacy by Design (PbD)
Protect (lifecycle)
- Data lifecycle, information security practices, PbD principles
- Embeds privacy principles and infosec management practices within the org
Sustain (lifecyle)
- Monitoring, auditing, and communication
- Audit, risk, security practices for identification, mitigation and reporting of risk
Respond (lifecycle)
- Info requests, legal compliance, incident-response planning and incident handling
- Reduce org risk and bolster compliance
- Customers, partners, vendors, employees, regulators, shareholders, and other legal entities
- Receive, assess, respond
Orgs must meet privacy demands through:
Greater controls, processes, and procedures for information
Frameworks define
- Problem definition
- Purpose
- Literature review
- Methodology
- Data collection
- Analysis
Goals of a Privacy Program Manager
- Define privacy obligations for the org
- Identify and mitigate privacy risks
- Identify documentation, policies, and procedures around management of personal info
- Create, revise, and implement policies and procedures
- Raise the data IQ of the org to drive and embed privacy-oriented culture
Goals of a Privacy Program
- Demonstrate an effective and auditable framework for compliance
- Promote trust and confidence in data by data subjects
-Highlight that the org takes privacy seriously - Respond effectively to privacy breaches and DSARs
- Continuous monitoring, maintaining and improving the maturity of the program
Privacy Program Manager responsibilities
Policies, notices, procedures, and governance
Privacy training
Incident response and investigation
Data subject requests
Communications
Privacy Controls
Privacy issues with products/services
Privacy monitoring
PIAs
Privacy staff development
Privacy data committees
PbD in product development
Vendor management
Privacy audits
Privacy metrics
Cross-border transfers
Prep for legislative change
Privacy subscriptions
Privacy travel
Redress and consumer outreach
Privacy software
Privacy certification seals
Cross functional collaboration
Internal and external reporting
Accountable organizations
orgs that have the proper policies and procedures to promote proper handling of pii
promote trust and transparency
document policies and any variations to it