1: Introduction to Privacy Program Management Flashcards

1
Q

What is privacy program management?

A

The structured approach of combining several projects into a framework and lifecycle to protect personal information and the rights of individuals.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Results of a properly structured privacy program

A

*Comply with legal and regulatory requirements
*Meet the expectations of customers
*Prevent and mitigate privacy risks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Privacy governance life cycle

A

Assess, protect, sustain and respond

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Key concept: A structured privacy program…

A

exhibits an organization’s thoughtful and intentional plan to protect personal information and the rights of individuals.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Key concept: Privacy program framework…

A

provides inquiry topics and direction, (e.g., problem definition, purpose, literature review, methodology, data collection and analysis) to ensure quality through repeatable programmatic steps, thereby reducing error or gaps in knowledge or experience.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Key concept: Ownership and management of framework shared with

A

other stakeholders throughout the org, including employees, exec leadership, managers and external entities such as partners, vendors and customers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Assess

A

*Provides the steps, checklists and processes necessary to assess any gaps in a privacy program as compared to industry best practices, corp. policies, applicable laws and regulations and the framework developed for the org.
*Elements may be performed in varying order and combinations
*Models and frameworks that allow measurement and alignment of these activities include AICPA/CICA Privacy Maturity Model, Generally Accepted Privacy Principles (GAPP and Privacy by Design (PbD).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Protect

A

*Provides the data life cycle, information security practices and PbD principles to protect personal information.
*Embeds privacy principles and infosec mgmt practices within the org to address, define and establish privacy practices.
*Since privacy spans the org, must take into account laws and regulations applying to other areas such as labor or telecom law as they may interact w/privacy laws.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Sustain

A

*Provides privacy mgmt through the monitoring, auditing and communication aspects of the framework.
*Includes audit, risk and security practices
*Ensures business as usual for identification, mitigation and reporting of risk in variation or gaps in operations to meet regulatory, industry and business objectives.
*Monitoring should be continuous and based on the org’s risk appetite.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Respond

A

*Includes the respond principles of information requests, legal compliance, incident-response planning and incident handling.
*Org needs to be prepared to properly receive, assess and respond to requests from customers, partners, vendors, employees, regulators, shareholders…

How well did you know this?
1
Not at all
2
3
4
5
Perfectly