1. Introduction Flashcards
(30 cards)
What is privacy program management?
A structured approach of combining several projects into one framework and life cycle to protect personal information and the rights of individuals.
What can an organization with an integrated privacy management program hope to achieve?
A properly structured and maintained privacy program will enable:
- compliance with legal regulatory requirements
- meet the expectations of clients or customers
- prevent and mitigate privacy risks
What is program management?
Is the process of managing multiple projects across the organization to improve performance.
What can be achieved through program management?
- Oversight and status of projects to ensure goals of the program are met
- Holistic view of multiple projects and change management
- Valued metrics across the program
What is a framework?
The skeletal structure needed to support program management.
How is a privacy framework created?
By analyzing
- The applicable laws, regulations
AND
- Best practices that are tailored specifically for the goals of each organization.
What is a life cycle?
The series of stages that something passes through during its existence.
(PPM - privacy governance life cycle of assets, protect, sustain, and respond)
What are the components of a privacy framework and life cycle?
- Consideration of privacy laws and regulations
- incorporation of program management principles
- Implementation of concepts such as:
- Privacy by design (PbD); and
- Privacy by default
Is privacy the same as secrecy?
NO and should not be confused with data classification models used by governments which may rate information as sensitive, secret, or top secret.
What does a structured privacy program exhibit?
An organization’s thoughtful and intentional plan to protect personal information and the rights of individuals.
What does a privacy governance life cycle provide?
The methods to
- assess
- protect
- sustain; and
- respond
to the positive and negative effects of all influencing factors.
What does a “privacy program framework” provide?
Provides
- inquiry topics
AND
- direction (e.g., problem definition, purpose, literature review, methodology, data collection, and analysis)
to ensure quality through a repeatable programmatic steps, thereby reducing errors or gaps in knowledge or experience.
Who owns the privacy program framework?
The framework is usually owned by the privacy team or privacy professional (e.g., data protection officer) and ownership as well as management is shared with other stakeholders throughout the organization, including employees, executive leadership, management, and external entities, such as partners, vendors and customers.
What are the four principles of the privacy operational life cycle?
- Assess - provide the steps, checklists, and processes necessary to assess any gaps in a privacy program as compared to industry best practices, corporate privacy policies, applicable privacy laws and regulations, and the framework developed for the organization.
- Protect - provides the data life cycle, information security practices, and PbD principles to protect personal information.
Embeds privacy principles and information security management practices within the organization to address, define, and establish privacy practices.
- Sustain - provides privacy management through the monitoring, auditing, and communication aspects of the management framework.
Monitoring throughout several functions in the organization, to include audit, risk and security practices, ensures “business as usual” for identification, and reporting.
- Respond - includes the respond principles of information requests, legal compliance, incident response planning, and incident handling.
Aims to reduce organizational risk and bolster compliance of regulations.
What should organizations be prepared for?
Be prepared to respond to customers, partners, vendors, employees, regulators, shareholders, or other legal entities.
The requests can take a broad form from simple questions over requests for data corrections to more in-depth legal disclosures about individuals.
What are the responsibilities of a Privacy Program Manager?
- Align the various parts of the privacy program to business objectives so as not be in contention.
- Support business as a valued partner (not see it as a blocker)
What are the goals of a privacy program manager?
- Define the privacy obligations for the organization
- Identify and mitigate privacy risks
- Create, revise, and implement policies and procedures that effect positive practices and together comprise a privacy program
- Raise the data IQ of the organization to drive and embed a privacy-oriented culture
What are the goals of a privacy program?
- Demonstrate an effective and auditable framework to enable legislative compliance
- Promote trust and confidence in the data entrusted by individuals
- Highlight that the organization takes its data privacy obligations seriously
- Respond effectively to privacy breaches and data subject requests
- Continually monitor, maintain, and improve the maturity of the privacy program
What are the specific responsibilities of privacy program manager?
- Policies, privacy notices, procedures, and governance
- Privacy-related awareness and training
- Incident response and privacy investigations
- Regulator complaints
- Data subject requests
- Communications
- Privacy controls
- Privacy issues with existing products and services
- Privacy-related monitoring
- Privacy impact assessments
- Development of privacy staff
- Privacy-related data committees
- PbD in product development
- Privacy-related vendor management
- Privacy audits
- Privacy metrics
- Cross-border data transfers
- Preparation for legislative and regulatory change
- Privacy-related subscriptions
- Privacy-related travel
- Redress and consumer outreach
- Privacy -specific or -enhancing software
- Privacy related certification seals
- Cross-functional collaboration (legal, IT, cybersecurity, ethics etc.)
- Internal and external reporting
What is accountability?
Accountable organizations have the proper policies and procedures to promote best practices in handling personal information and, generally, can demonstrate they have capacity to comply with applicable laws.
They promote trust and transparency to provide individuals with confidence in their abilities to protect their personal information and respect their data rights.
What are the legal requirements of accountability?
It is not only about saying the organization is taking action, but also being able to prove it is.
The organization is accountable for the actions it takes or does not take to protect personal data.
When organizations collect and process information about people they are responsible for it. They need to take ownership of it and take care of it throughout the data life cycle.
What should an organization do regarding it’s data practices?
If an organization has a data protection policy in place, the organization should comply with that policy and document any deviations and actions taken for any failures in complying with the policy.
Does the accountability principle impose obligations on an organization?
YES. Accountability, may impose obligations to take ownership and demonstrate how an organization is compliant.
Privacy program managers may be accountable for the safekeeping and responsible use of personal information - not just to investors and regulators, but also to everyday consumers and their fellow employees.
Why does an organization need a privacy program?
Accountability. Showing proper respect for individuals’ personal information shows that the organization is reputable.