What is a privacy policy?
It governs the privacy goals and strategic direction of the organization’s privacy office
What does a privacy vision and mission statement accomplish?
It serves as the foundation for developing effective privacy policies.
What are the key elements of an effective policy?
What are the components of a privacy policy?
What is the difference between a privacy notice and privacy policy?
Privacy policy is an internal document addressed at employees and data users
Privacy notice is an external communication to individuals, customers, or data subjects to create transparency on how the organization uses, shares, retains and discloses PI
What is the role of a privacy committee?
Making strategic decisions that may affect the the vision, change key concepts, or determine when alterations are needed and act as an additional resource to the privacy function.
*Organizations with a global footprint often create a governance structure composed of representatives from each business function and every geographic region in which the organization has a presence to ensure that privacy policies, processes and solutions align with local laws.
What is the role of a communications plan?
What questions should be considered when developing a communications plan?
What is the privacy balance most organizations must achieve?
Balance between:
What should employee policies include?
Onboarding and exit procedures that ensure full awareness of the organization’s privacy intent while protecting against misappropriation of knowledge and data upon termination of contract of employment.
What is an acceptable use policy (AUP)?
It stipulates rules and constraints for individuals within and outside the organization who access the organization’s mobile devices, computers, network, and internet connection.
In an AUP, through the notice of monitoring what does the user agree to?
The AUP terms that include a privacy notice that details monitoring and logging.
What business function plays a key role in developing an AUP?
The security function.
How often should AUPs be reviewed?
Annually.
*They should be modified and updated as as privacy standards and regulations change, to keep pace with IT, social media and other challenges.
What do information security policies focus on?
Protecting the organization from internal and external threats through use of IT methods and practices:
What is the focus of information security policies?
What are the appropriate privacy standards for vendors?
As the IT boundaries of the organization disappear in the use of external storage and the processing found in the cloud, there must be a strategy and vision for how the organization will remain in control of the data privacy as well as how the data will remain secure and protected.
What should an organization do when engaging with vendors?
What concepts should be considered for vendor contracts?
What is employee data?
Any data the employee has created in the process of preforming normal business efforts for the organization, including emails, phone calls, voicemail, internet browsing, and use of systems.
What are HR privacy concerns that should be addressed through policy?
What defines HR policies?
What dictates the HR policies and protections needed?
Types of data collected, use, and storage.
What actions should be taken to develop a data retention policy?