Privacy Program Management: Chapter 2 Frameworks and Governance Flashcards
Vision and Mission
Align with orgs broader purpose
Privacy mission statement
describes the purpose and ideas in just a few sentences
should take less than 30 seconds to read
Privacy program scope
- Identify personal info collected and processed (Article 30)
- identify applicable privacy and data protection laws and regulations
Privacy Strategy Value
Org approach to communicating and supporting the privacy program
Management growing awareness of the importance of protecting personal data
Privacy Program Governance
- identify stakeholders and partners
- Establish an executive privacy team, sponsor
- develop best practices
- conduct privacy workshops for stakeholders
- Keep a record of ownership, discussions
Goals of a Privacy Framework
- Help achieve compliance with laws
- Serve as a competitive advantage
- Support business commitment and objectives
Common Privacy Frameworks
- Fair Information Practices: provide basic privacy principles (rights, controls, life cycle, management)
- Org for Economic Co-operation and Development (IECD) Guidelines: basis for GDPR, most widely accepted
- AICPA, CICA, GAPP
- NIST Privacy Framework: Core, Profile, Tiers
- PbD: proactive, default, embedded in design, full functionality (positive sum), end-to-end security, visibility / transparency, respect for user privacy
Privacy team structures
Centralized
Local / Decentralized
Hybrid
Org roles for privacy
CPO: corporate leader for strategy
Privacy Director / Manager: implement strategy
Privacy analyst: entry level, tactical
Bus Line Leader: senior management
Privacy Legal Counsel: legal experts
First Responders: support specific processes
DPO: required by Article 37
Privacy Engineer: technical implementation
Privacy Technologist: audit, risk, compliance
Rationalize
Implement a solution that materially addresses wide range of privacy requirements
AICPA/CICA (GAPP) Principals
- Management of privacy
- Notice provided about privacy policies
- Choice and consent
- Collection only for purposes disclosed
- Use, retention, and disposal
- Access provided to data subjects for review and collection
- Disclosure to Third-parties only within purpose
- Security for Privacy
- Quality of data is ensured
- Monitoring and Enforcement
GDPR Article 37
DPO must be appointed, expert in privacy
GDPR Article 38
DPO must report to the highest levels of the org
GDPR Article 39
Activities shall include:
- monitoring companies compliance with GDPR
- provide advice during DPIAs
- cooperate with supervisory authorities