Information Management from a U.S. Perspective Flashcards
18-22 questions
Define:
information management
establishing, implementing and monitoring the organization’s privacy program under the direction of a senior person in the organization
duties of a chief privacy officer
developing and implementing policies related to data processing and properly handling of personal information
duties of a data protection officer
- ensures organization’s processing and handling of personal info is in compliance with legal privacy requirements
- cannot be directly involved with decision-making regarding data processing activities
duties of a privacy engineer
works to ensure that compliance with legal requirements has occurred through the technical processes of the organization
duties of a privacy manager
responsible for development, maintenance and enforcement of privacy policies and procedures within an organization
duties of a privacy analyst
manages legal and operational risks related to personal information held by the organization
what are the stages of a data life cycle?
- data creation
- data storage
- data sharing and usage
- data archival
- data deletion
Define:
data inventory
undertake an inventory of the PI it collects, stores, uses or discloses within the organization and to outside entities
Define:
data classification
- classify data according to its level of sensitivity
- defines clearance of individuals who can access or handle that data, as well as the baseline level of protection appropriate for that data
Define:
data flow mapping
examine and document data flows
top-down vs. bottom-up data flow mapping
- top-down: starts with record of processing activities (RoPA) which is required under GDPR
- RoPA process involves documenting the purpose for processing the PI; parties to whom any PI was disclosed; retention period for PI; and details about the safeguards in place for PI
- bottom-up: understanding data assets; data inventory and classification; delineating data processes (RoPA); documenting data lineage
privacy program should…
- demonstrate effective and auditable framework to enable compliance with applicable privacy laws and regulations
- promote trust and confidence in the organization’s handling of personal data
- respond effectively to requests by consumers
- address privacy and security breaches
- continually monitor and improve the maturity of the privacy program
privacy mission statement
describes core function of privacy within the org
How to ensure appropriate metrics for privacy program framework?
- identifying intended audience for metrics
- defining reporting sources
- defining privacy metrics for oversight and governance
- identifying systems/application collection points
What are the four stages of privacy operatonal life cycle?
- assess
- protect
- sustain
- respond
assess
- document baseline of privacy program
- evaluate processors and third parties
- identify operational risks
- document the assessment
protect
- review access controls and technical controls
- review incident response plan
- integrate privacy requirements into functional areas of the organization
sustain
- monitor and audit compliance with privacy policies
- monitor regulatory changes
- hold employee, management and contractor trainings
respond
- consumer requests
- address privacy incidents
Define:
privacy policy
high-level document that helps an organization meet policy goals contained within an org’s privacy vision or mission statement
typical components of a privacy policy
- purpose
- scope
- applicability
- roles and responsibilities
- compliance
- penalties and sanctions for noncompliance
revision to privacy policy
- according to FTC, companies should obtain express affirmative consent before making material retroactive changes to privacy representations
- material change at a minimum includes sharing consumer information with 3Ps after committing at the time of collection not to share the data
Define:
privacy notice
- external statement that provides transparency concerning the org’s privacy practices
- how it collects, uses, shares, retains and discloses PI based on org’s privacy policy
organization can communicate privacy notice to consumer by:
- making notice accessible online
- making notice accessible in places of business