Data Assessments Flashcards

1
Q

What is a Privacy Impact Assessment? (PIA)

A

A privacy impact assessment, or PIA, is an analysis that specifically assesses the privacy risks associated with processing personal information in relation to a project, product or service.

Requirements around PIAs may be mandated by industry, organizational policy, and laws and regulations.

PIAs can help facilitate privacy by design

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

When should a PIA be conducted?

A
  • Prior to deployment of a project, product or service that involves the collection of personal information
  • When there are new or revised industry standards, organizational policies, or laws and regulations
  • When the organization makes changes to methods in which personal information is handled that create new privacy risks
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a Data Protection Privacy Impact Assessment? (DPIA) What laws require this?

A

A data protection privacy impact assessment, or DPIA, has specific triggers and requirements under the GDPR (EU) and LGPD (Brazil). DPIAs are intended to help incorporate privacy considerations into organizational planning and demonstrate GDPR compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

When should I conduct a DPIA?

A

Triggers for conducting DPIAs include processing that is “likely to result in a high risk to the rights and freedoms of natural persons” (GDPR Article 35) and the use of new technologies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What should a DPIA include?

A

DPIAs should include: a description of the processing, including its purpose, and including, where applicable, the legitimate interest being pursued; the necessity of the processing, its proportionality and the risks that it poses to data subjects; and measures to address the risks identified.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is “Attestation” in the privacy context?

A

Attestation is a self-assessment tool for ensuring functions outside the privacy team are held accountable for privacy-related responsibilities. Once the privacy responsibilities of each department are documented, the departments may be asked specific questions about each responsibility.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a Transfer Impact Assessment?

A

A transfer impact assessment, or TIA, is a new assessment to ensure an adequate level of data protection in a third country. TIAs consider the sufficiency of foreign protections on a case-by-case basis when data is transferred using standard contractual clauses (SCCs), binding corporate rules (BCRs) or other EU-approved data transfer mechanisms.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a Legitimate Interests Assessment?

A

A legitimate interests assessment, or LIA, is a form of risk assessment and should be conducted when your personal data processing is based on legitimate interest. LIAs include identifying the legitimate interest and conducting necessity and balancing tests. An LIA demonstrates accountability and the lawfulness of your processing while confirming your compliance to the supervisory authority

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a privacy assessment? General what/ when/ who/ result.

A

Measures an organization’s compliance with laws, regulations, adopted standards and internal policies/procedures

Can be on a regular basis, ad hoc due to a privacy/security event, or at the request of an enforcement authority

Performed by an internal audit function, the DPO, self-assessment, or 3rd party

Results in documentation to upper management, analysis of results to improve & remediate program, monitor changes on ongoing basis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

At the time of a merger, acquisition, or divestiture, what checkpoints should privacy teams look at?

A
  • Applicable new compliance requirements
  • Existing client agreements
  • New resources, technologies and processes (to bring them into alignment)
  • Standards and sectoral-specific laws
  • Comprehensive laws and regulations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

If a merger or acquisition means that you must transfer data to another controller, you need to:

A
  • Ensure you consider the data sharing as part of the due diligence you carry out
  • Establish what data you are transferring and document the data sharing
  • Identify the purposes for which the data was originally obtained
  • Establish your lawful basis for sharing the data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What specific areas should I focus on when evaluating a cloud service provider?

A

certifications and standards, technologies, service road map, data management, information security, subcontractors and service dependencies, and data policies and protection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the common risks of working with vendors?

A
  • Scope creep
  • Process/quality standards
  • Data breaches
  • Oversight
  • Laws and regulations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the basics of vendor assessment?

A

Vendor assessment is the evaluation of a vendor for privacy and information security policies, access controls, where the personal information will be held, and who has access to it. Risk assessment should be extended to all areas of the business, including procurement. The same assessment process should be followed every time the organization considers using a new vendor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly