Untitled Flashcards Set

MODULE 1: PPM

 

I. Privacy Program Lifecycle (LIFECYCLE)

  • Assess

    • Compare program practices to best practices, standards, laws, regulations, and internal privacy frameworks.

    • Use checklists and defined processes for assessment.

  • Protect

    • Embed privacy principles and security practices into data lifecycle management.

    • Implement controls to safeguard personal information.

  • Sustain

    • Monitor, audit, and communicate ongoing compliance.

    • Identify, mitigate, and report risks continuously.

  • Respond

    • Manage information requests, incident response planning, and compliance.

    • Execute effective breach response strategies.

 

II. Responsibilities of Privacy Program Managers

Key Goals

  • Identify Privacy Obligations:

    • Understand legal, regulatory, and corporate privacy requirements.

  • Risk Identification:

    • Assess business, employee, and customer privacy risks.

  • Documentation & Policies:

    • Develop, revise, and implement comprehensive privacy policies and procedures.

  • Program Enhancement:

    • Promote consumer trust, enhance reputation, and ensure program awareness.

  • Breach Response:

    • Respond effectively to breaches and continuously improve the program.

Core Responsibilities

  • Governance and Policy Development

  • Privacy-related training and awareness programs

  • Incident response planning and management

  • Regular communications on privacy practices

  • Conducting privacy impact assessments and audits

  • Managing cross-functional collaboration (legal, IT, security, etc.)

  • Monitoring privacy metrics and vendor management

  • Facilitating redress and consumer outreach

 

III. Rationale for a Privacy Program Manager (PPM)

  • Brand and Trust Enhancement:

    • Build and maintain consumer confidence.

  • Regulatory Compliance:

    • Meet requirements such as the GDPR and other laws.

  • Risk Reduction:

    • Lower the risk of data breaches, lawsuits, and regulatory scrutiny.

  • Market Enablement:

    • Support global operations and new market entry.

  • Competitive Differentiation:

    • Increase value, improve data quality, and drive revenue growth.

 

IV. Cross-Functional Collaboration

Key Stakeholders & Functions

  • Learning & Development:

    • Translate policies into training content.

    • Approve and reinforce privacy practices.

  • Communications:

    • Disseminate privacy information via intranet, email, posters, etc.

  • Information Security:

    • Deploy technology (e.g., encryption, DLP) to enforce security controls.

    • Ensure compliance with EU data protection law security provisions.

  • Internal Audit:

    • Evaluate controls and adherence to privacy practices.

  • Procurement:

    • Manage contracts with third-party service providers handling personal data.

Organizational Integration

  • Finance:

    • Manage payroll, reimbursements, and financial transactions.

  • Marketing & Business Development:

    • Ensure compliance with legal and self-regulatory marketing practices.

  • Human Resources:

    • Oversee employee data, investigations, and training.

  • Information Technology:

    • Collaborate on technology-enabled privacy controls.

  • Legal:

    • Perform due diligence, maintain controls, and manage documentation.

 

V. Accountability & Beyond Compliance

  • Accountability:

    • Demonstrate compliance through documented evidence and responsible use of personal data.

    • Answerable to customers, employees, regulators, and investors.

  • Beyond Law & Compliance:

    • Meet client expectations.

    • Enhance marketplace reputation and operational value.

    • Act as a competitive differentiator and good corporate citizen.

 

 

MODULE 2: Privacy Governance

I. Core Concepts

  • Key Activities:

    • Creating, Defining, Selecting, Developing, Structuring a privacy program

  • Positioning Privacy in the Organization:
    Consider factors such as:

    • Influence: Which department holds the most sway over business decisions

    • Global Scope: Which functions have worldwide reach

    • Budget: Where funding is strongest

    • Project Management: Which group excels in executing enterprise projects

    • Support: Which team best champions privacy initiatives

 

II. Privacy Vision & Mission

  • Purpose:

    • Communicate the organization’s stance on privacy to all stakeholders

  • Development Process:

    • Acquire privacy knowledge

    • Evaluate intended objectives

    • Secure executive sponsor approval

  • Common Elements:

    • Value of privacy to the organization

    • Organizational objectives

    • Strategies for achieving outcomes

    • Defined roles and responsibilities

 

III. Privacy Strategy & Program Structure

A. Components of a Privacy Strategy

  • Program Scope Definition:

    • Identify Personal Protected Information (PPI), laws, and regulations

  • Framework Selection:

    • Choose a privacy framework that aligns with organizational needs

  • Business Alignment:

    • Build relationships, form a privacy committee, and integrate privacy into operational processes

  • Data Governance:

    • Develop an approach for handling and protecting personal data across its lifecycle

  • Inquiries & Complaints Procedures:

    • Establish processes for handling concerns from regulators, customers, and employees

B. Structuring the Privacy Team

  • Ensure proper alignment between privacy, legal, IT, security, and other relevant functions

  • Secure adequate budget and resources

 

IV. Principles, Standards & Legal Frameworks

A. Foundational Principles

  • Fair Information Practices (FIPs):

    • Central privacy principles found in many modern frameworks

B. Key Frameworks & Laws

  • International & National Examples:

    • OECD Guidelines, Council of Europe’s Convention 108, GDPR (EU)

    • PIPEDA (Canada) & Australian Privacy Principles

    • HIPAA (U.S.) for healthcare information protection

    • Brazil’s LGPD and China’s Personal Information Protection Law

  • Standards & Best Practices:

    • Privacy by Design (PbD)

    • AICPA/CICA’s Generally Accepted Privacy Principles (GAPP)

    • ISO standards (e.g., ISO 27701, ISO 27000 series)

C. Privacy Management Solutions

  • Utilize privacy engineering processes and vendor tools to ensure robust compliance and data protection

 

V. Governance Models

  • Centralized Model:

    • One team/person manages all privacy-related activities (best for single-channel organizations)

  • Decentralized (Local) Model:

    • Decision-making is delegated to local levels, widening the span of control

  • Hybrid Model:

    • A central governing body with localized support for a balanced approach

 

VI. Stakeholders & Internal Partners

A. Data Protection Officer (DPO)

  • Designation & Requirements:

    • Required under Article 37 of the GDPR for certain organizations

    • Must report to the highest management level (Article 38)

  • Key Responsibilities:

    • Work with regulators, monitor privacy impact assessments, and serve as a point of contact for data subjects

  • Required Skills:

    • Risk assessment and IT familiarity

    • Legal expertise and independence

    • Leadership, project management, and effective communication

B. Internal Audit & Risk Management

  • Internal Audit:

    • Operates independently to evaluate control design and implementation

    • Reports to the audit committee, ensuring unbiased oversight

  • Risk Management:

    • Evaluates the risk management culture and identifies key risk factors across systems and processes

 

MODULE 3: Laws & Regs

 

I. Individual/Data Subject Rights

A. Rights under GDPR vs. LGPD

  • Access:

    • GDPR: Right to access/copy personal data (Art. 15)

    • LGPD: Right to access, obtain a free copy, and confirm consent (Art. 6(IV), 18(II))

  • Correction/Rectification:

    • GDPR: Right to correct inaccurate or outdated data (Art. 16)

    • LGPD: Right to correct incomplete, inaccurate, or outdated data (Art. 18(III))

  • Deletion/Right to be Forgotten:

    • GDPR: Right to delete data (with limitations) (Art. 17)

    • LGPD: Right to delete or block data (Art. 18(IV))

  • Portability:

    • GDPR: Right to obtain data in a structured format for transfer (Art. 20)

    • LGPD: Right to data portability (Art. 18(V))

  • Processing Limitations/Opt-Out:

    • GDPR: Right to restrict processing and withdraw consent (Arts. 18, 7, 21)

    • LGPD: Detailed opt-out and consent withdrawal rights (Arts. 18(VIII), 18(IX))

  • Sensitive Data Processing:

    • GDPR: Explicit consent required for special categories (Art. 9)

    • LGPD: Processing sensitive data permitted under special circumstances (Art. 11)

  • Automated Decision-Making:

    • GDPR: Right to object and request human intervention (Art. 22)

    • LGPD: Right to object and request review of automated decisions (Art. 20)

 

II. Business Obligations

A. Core Principles

  • Notice/Transparency:

    • Publish clear, customer-facing privacy notices (GDPR Art. 12; LGPD Art. 10, Sec. 2)

  • Lawfulness of Processing:

    • Establish mechanisms (consent, contract, legal obligations, etc.) (GDPR Art. 6; LGPD Art. 7)

  • Purpose Limitation:

    • Data collected only for specified, explicit, and legitimate purposes (GDPR Art. 5(1)(b); LGPD Art. 6(I))

  • Data Minimization:

    • Collect only the minimum necessary data (GDPR Art. 5(1)(c); LGPD Art. 6(III))

  • Security:

    • Implement technical and organizational measures (GDPR Art. 32; LGPD Arts. 6(VII) & 46–49)

  • Privacy by Design:

    • Build privacy protections into systems and processes (GDPR Art. 25; LGPD: not explicitly referenced)

  • Processor/Service Provider Requirements:

    • Ensure third-party compliance with privacy measures (GDPR Art. 28; LGPD Arts. 37, 39, 40)

  • Record Keeping & Risk Assessments:

    • Maintain records of processing activities and conduct impact assessments (GDPR Arts. 30, 35; LGPD Arts. 37, 38)

  • Data Breach Notification & DPO:

    • Notify regulators and/or data subjects as required (GDPR Arts. 33–34, 37; LGPD Arts. 41)

  • International Data Transfers:

    • Use mechanisms (adequacy, contractual clauses, BCRs, etc.) to safeguard data when transferred internationally (GDPR Arts. 44–50; LGPD Art. 33)

 

III. Regulatory Enforcement

A. Enforcement Actions

  • Compliance Records:

    • Regulators may request documentation (processing records, risk assessments, etc.)

  • Penalties & Fines:

    • GDPR: Fines up to €20 million or 4% of annual revenue

    • LGPD: Penalties up to 2% of annual revenue (capped at 50 million reais per infraction)

  • Consumer Rights vs. Business Obligations:

    • Rights include access, correction, deletion, opt-out, portability, and protection against automated decisions

    • Businesses must provide clear disclosures, accessible mechanisms for consumer requests, and avoid discrimination against those exercising their rights

 

IV. Cross-Border Data Transfers

A. Mechanisms

  • Adequacy Decisions:

    • Recognition that a third country’s data protection laws are adequate (e.g., Privacy Shield under GDPR)

  • Appropriate Safeguards:

    • Standard Contractual Clauses (SCCs), Codes of Conduct, or Self-Certification Mechanisms

    • Ad Hoc Contractual Clauses (subject to supervisory approval)

  • International Agreements & Binding Corporate Rules (BCRs):

    • Legal frameworks and internal rules approved by supervisory authorities

  • Derogations:

    • Exceptions under GDPR (Art. 49) for compelling legitimate interests with explicit consent

 

V. Global Regulatory Environment & Compliance Considerations

A. Jurisdictional Approaches

  • Sectoral vs. Comprehensive Models:

    • US: Sector-specific laws

    • EU/Canada: Comprehensive privacy frameworks enforced by regulatory agencies

    • Australia: Co-regulatory approach

    • Self-Regulated: Examples in US, Japan, Singapore

B. Common Elements Across Jurisdictions

  • Fair Information Practices (FIPs):

    • Core principles such as notice, consent, individual rights, purpose limitations, data retention, and accountability

  • OECD Guidelines:

    • Widely recognized framework covering FIP aspects like openness, collection/use limitations, and security safeguards

C. Ongoing Compliance

  • Continuous Effort:

    • Regular monitoring of changes (new processes, acquisitions, technology, etc.)

    • Adapt privacy programs to evolving legal obligations and business changes

  • Regulatory Awareness:

    • Stay informed of new legislation, enforcement trends, and compliance requirements via industry news and privacy organizations

D. Organizational Integration

  • Aligning Compliance with Business Strategy:

    • Merge regulatory compliance with overall business strategy to improve data management practices

    • Employ techniques like Privacy by Design to integrate compliance seamlessly into operations

 

VI. Additional Key Regulations & Frameworks

A. Specific Laws & Standards

  • GDPR (EU):

    • Comprehensive framework with specific consumer rights, business obligations, and enforcement actions

  • LGPD (Brazil):

    • Similar framework with differences in language and specific articles

  • Other Notable Regulations:

    • HIPAA (U.S.) for healthcare, CCPA (California) for consumer privacy, and other international laws

B. Consumer and Business Dynamics

  • Consumer Rights Overview:

    • Access, correction, deletion, opt-out, portability, opt-in for sensitive data processing, and protection against automated decision-making

  • Business Obligations Overview:

    • Transparent notices, risk assessments, record keeping, proper data handling, and robust processes to address consumer requests

 

MODULE 4: Data Assessment

I. Regulatory Requirements & Gap Analysis

  • Regulatory Comparison Example:

    • HIPAA (164.308(a)(1)(i)(C)):

      • Requirement: Enforce a sanction policy for noncompliance

      • Domain: Security policies/procedures

      • Conclusion: No gaps identified

    • GDPR (Article 28, Section 3):

      • Requirement: Establish data processor agreements with detailed terms

      • Domain: Data management

      • Conclusion: Gap exists with processor Smith & Jones Insurance (missing agreement)

  • Gap Analysis:

    • Create an inventory of applicable laws and regulations

    • Map requirements against current practices

    • Involve legal teams to address overlaps and discrepancies

 

II. Data Protection Impact Assessments (DPIA & PIA)

  • When is a DPIA Required?

    • Under GDPR:

      • If processing is “likely to result in a high risk to rights and freedoms” (Art. 35)

      • Consider nature, scope, context, purpose, and new technologies

      • Refer to Article 29 Working Party guidelines for examples

    • Under LGPD:

      • When processing triggers risks to civil liberties and fundamental rights

      • Recommended when processing is based on legitimate interest or involves sensitive data

  • Key DPIA Components:

    • Description of processing, purpose, and legitimate interest

    • Necessity, proportionality, and risk identification

    • Mitigation measures and, if needed, supervisory authority notification

  • PIA vs. DPIA:

    • PIA: Broad assessment of privacy risks for a project, product, or service

    • DPIA: Specific to high-risk processing under GDPR with mandated triggers

 

III. Data Inventories & Mapping

  • Purpose:

    • Create a complete record (data map) of all personal information processed by the organization

    • Serve as a precursor for regulatory compliance, risk analysis, and data lifecycle management

  • Key Considerations:

    • Document data flows, classification, and system authority

    • Update inventory regularly, especially after organizational changes (e.g., new vendors, product launches)

    • Tools may include spreadsheets, GRC software, or custom systems

  • Responsibilities:

    • Typically managed by the privacy and IT functions, sometimes with shared budgets

 

IV. Assessments & Impact Assessments

  • Privacy Assessment:

    • Measures compliance with laws, standards, and internal policies

    • Conducted regularly or ad hoc after events

    • Involves internal audit, DPO, business functions, or external parties

  • Impact Assessments (PIA/DPIA):

    • Identify privacy risks and inform privacy by design

    • Should be triggered by changes like:

      • Conversion of anonymous data to identifiable data

      • Merging or matching databases

      • Implementation of new technologies or third-party services

  • Assessment Process:

    • Document results, obtain management sign-off, and remediate gaps

    • Utilize both subjective (interviews) and objective (system logs) metrics

 

V. Additional Assessment Tools

  • Attestation:

    • A self-assessment tool ensuring accountability across departments

    • Uses specific, often yes/no, questions (e.g., data classification based on NIST 800-60)

  • Physical Assessments:

    • Evaluate operational risks in data centers, offices, and physical access points

    • Consider device security, document destruction, media disposal, etc.

 

VI. Processor & Vendor Assessments

  • Vendor/Processor Risk:

    • Common risks: scope creep, quality standards, data breaches, compliance gaps

  • Assessment Methods:

    • Use questionnaires, privacy/security checklists, and privacy impact assessments

  • Contractual Requirements:

    • Ensure vendor contracts address:

      • Data protection measures

      • Breach response and incident management

      • Audit rights and data disposal on contract termination

  • Ongoing Monitoring:

    • Continually assess and audit vendors to maintain compliance

 

VII. Mergers, Acquisitions, & Divestitures

  • Privacy Checkpoints:

    • Evaluate new compliance requirements and sector-specific laws (e.g., HIPAA, PCI DSS, GDPR)

    • Review existing client agreements and new technologies/processes

    • Ensure divestitures remove unauthorized information from organizational systems

  • Integration Considerations:

    • Align privacy practices prior to merging or acquiring entities

    • Conduct thorough assessments to mitigate risks related to different regulatory environments

 

MODULE 5: Protecting Personal Information

I. Distinction Between Security and Privacy

  • Security Focus:

    • Controls and processes to protect the integrity, availability, and confidentiality of information.

  • Privacy Focus:

    • Focuses on the protection of personal data and the rights of individuals represented by that data.

 

II. International Standards & Frameworks

  • ISO/IEC Standards:

    • ISO/IEC 27001 & 27002:

      • Internationally recognized standards defining requirements and guidelines for an Information Security Management System (ISMS).

    • ISO/IEC 27701:

      • Extension to 27001/27002 for managing privacy information.

    • ISO/IEC 27000 & 27003:

      • Provide vocabulary, overview, and implementation guidance for ISMS.

  • Other Frameworks:

    • NIST Frameworks:

      • Includes Risk Management, Cybersecurity, and Privacy Frameworks for managing cybersecurity risks.

    • CNIL Methodology:

      • Uses risk maps to evaluate privacy risks and breach severity.

 

III. Types of Controls & Their Roles

  • Control Categories by Objective:

    • Preventive Controls:

      • Aim to stop incidents from occurring.

    • Detective Controls:

      • Identify and characterize incidents in progress or that have occurred.

    • Corrective Controls:

      • Limit the damage and restore systems after an incident.

  • Control Types by Nature:

    • Administrative Controls:

      • Policies, procedures, and management-driven measures.

    • Physical Controls:

      • Safeguards for facilities, hardware, and environmental protections.

    • Technical Controls:

      • Technologies and tools such as encryption, data minimization, and privacy-enhancing technologies.

 

IV. Strategies for Data Protection

A. Process-Oriented Strategies

  • Key Focus Areas:

    • Enforce and demonstrate adherence to established privacy policies and processes.

    • Clearly inform individuals about data handling practices and provide them control over their data.

B. Data-Oriented Strategies

  • Technical Approaches:

    • Data Separation:

      • Isolate processing either logically or physically.

    • Data Minimization:

      • Collect and process only what is necessary.

    • Data Abstraction & Hiding:

      • Summarize or group data to reduce detail and obscure connections.

 

V. Information Security & Risk Management

  • Continuous Process:

    • Information security practices are applied throughout the data lifecycle—from creation to destruction.

  • Risk Management Components:

    • Risk Identification:

      • Recognize potential threats (e.g., weak technology, social engineering, outdated security software).

    • Control Implementation:

      • Select and apply appropriate preventive, detective, and corrective measures.

    • Monitoring & Evaluation:

      • Track risk and validate control effectiveness.

  • Examples of Information Security Risks:

    • Technology vulnerabilities, social media attacks, mobile malware, third-party access, poor configurations, lack of encryption, and inadequate device security.

 

VI. Information Security Controls (Examples)

  • Policy & Organization:

    • Information security policies, organization of security functions, HR controls.

  • Asset & Access Management:

    • Asset management, access control, cryptography.

  • Operational & Environmental:

    • Physical and environmental security, operational security, communications security.

  • Systems & Vendor Management:

    • Systems acquisition, development and maintenance, supplier relationships, incident management, business continuity, and compliance.

 

MODULE 6: Privacy Operation Lifecycle

I. Privacy Documents: Notice vs. Policy

  • Privacy Notice (External):

    • Communicates to customers/data subjects how personal data is collected, used, shared, retained, and disclosed.

    • Focused on transparency, compliance, and building trust.

  • Privacy Policy (Internal):

    • Directed to employees and data users.

    • Details how personal information is handled, stored, and transmitted to meet legal and organizational needs.

    • Guides the creation of privacy notices.

 

II. Privacy Policy Lifecycle Phases

  1. Drafting:

    • Create clear, simple, and practical policies.

  2. Approval:

    • Obtain buy-in from decision-makers and stakeholders.

  3. Dissemination:

    • Socialize policies via internal channels (e.g., intranet).

  4. Training & Enforcement:

    • Train employees; enforce policies with measurable consequences.

  5. Review & Revision:

    • Regularly update policies to reflect changes in law, technology, and business processes.

 

III. Key Policy Qualities & Components

  • Qualities:

    • Clarity and accessibility

    • Comprehensive yet concise

    • Action-oriented and measurable

    • Testable with available audit evidence

  • Core Components:

    • Scope and Risks

    • Organizational Responsibilities

    • Data Subject Rights

    • Data Use Rules

    • Other privacy-related practices

 

IV. Types of Privacy-Related Policies

  • Information Security Policies:

    • Protect data integrity, confidentiality, and availability.

  • Acceptable Use Policies:

    • Govern network and Internet access for internal and external users.

  • HR Policies:

    • Cover handling of employee data (e.g., background checks, BYOD, monitoring).

  • Procurement/InfoSec Policies:

    • Address vendor selection, risk assessment, contract terms, and ongoing monitoring (including for cloud services).

  • Data Retention & Destruction Policies:

    • Ensure personal data is retained only as long as necessary and disposed of properly.

 

V. Integration with Business Processes

  • Alignment:

    • Integrate privacy policies with HR, project management (privacy by design), procurement, risk management, and incident management.

  • Awareness & Training:

    • Secure senior leadership buy-in and conduct regular awareness initiatives (e.g., Data Privacy Day, simulations, lunch-and-learns).

  • Enforcement:

    • Establish clear consequences for non-compliance by employees and vendors.

    • Regularly audit policies for effectiveness.

 

VI. Privacy Program Metrics & Auditing

  • Trend Analysis:

    • Time Series: Monitor trends (e.g., privacy incidents over time).

    • Cyclical Components: Observe regular fluctuations (e.g., post-training incidents).

    • Irregular Components: Identify anomalies beyond expected trends.

  • Monitoring Areas:

    • Compliance and risk (review data handling throughout the lifecycle)

    • Regulatory changes (track via publications/external vendors)

    • Environmental vulnerabilities (physical access, authentication, training gaps)

  • Audit Phases:

    1. Audit Planning

    2. Audit Preparation

    3. Audit Execution

    4. Reporting

    5. Follow-Up

  • Audit Types:

    • First-Party Audits: Self-assessments by internal teams.

    • Second-Party Audits: Supplier or partner audits.

    • Third-Party Audits: Independent audits (e.g., by regulators or external assessors).

 

VII. Privacy Training Program Essentials

  • High-Level Steps:

    • Ensure policies are current and accessible.

    • Train employees on privacy requirements.

    • Maintain training records and measure results with metrics.

    • Update training based on feedback and compliance changes.

    • Reinforce learning with ongoing awareness activities.

 

MODULE 7: Monitoring & Auditing

I. Audiences for Monitoring & Auditing

  • Primary Audiences:

    • Legal & Privacy Officers (incl. DPO), Senior Leadership, CIOs, CSOs, Program Managers, Information System Owners, CISOs, and other operational managers.

  • Secondary Audiences:

    • CFOs, Training Organizations, HR, Inspectors General, HIPAA Security Officials.

  • Tertiary Audiences:

    • External watchdog groups, sponsors, stockholders, and in healthcare, additional roles like HIPAA Privacy Officers and interdisciplinary readiness teams.

 

II. Key Metrics & Analysis Techniques

A. Metrics Overview

  • Purpose:

    • Measure program effectiveness, risk, compliance, and ROI.

  • Examples Include:

    • Data subject inquiry responses, incident counts, employee training levels, privacy impact assessments (PIA) metrics, and risk indicators.

B. Trend Analysis

  • Time Series:

    • Identify upward/downward trends (e.g., privacy breaches over time).

  • Cyclical Component:

    • Analyze regular fluctuations (e.g., changes post-privacy training).

  • Irregular Component (“Noise”):

    • Detect anomalies beyond expected trends.

C. Return on Investment (ROI)

  • Definition:

    • Financial gain or loss relative to investment costs in privacy controls.

  • Considerations:

    • Must relate to function’s purpose and asset value (including hardware, personnel, IT, operational assets).

D. Maturity Program Assessment

  • Maturity Levels:

    1. Ad Hoc: Informal and inconsistent practices.

    2. Repeatable: Processes exist but are not fully documented.

    3. Defined: Fully documented and implemented processes.

    4. Managed: Regular reviews assess control effectiveness.

    5. Optimized: Continuous improvement via feedback and regular review.

 

III. Types & Forms of Monitoring

A. Categories of Monitoring

  1. Compliance & Risk Monitoring:

    • Review how personal data is collected, used, and retained.

    • Utilize self-monitoring, internal audits, and risk management processes.

  2. Regulatory & Legislative Monitoring:

    • Track changes in laws and update policies accordingly.

    • May involve external subscription services.

  3. Environmental Monitoring:

    • Assess physical and operational vulnerabilities (e.g., building access, data authentication, training gaps).

B. Tools & Methods

  • Active Scanning Tools:

    • e.g., Data Loss Prevention (DLP) systems to detect risks and policy noncompliance.

  • Audit Activities:

    • Internal, supplier (second-party), and independent (third-party) audits.

  • Breach Monitoring:

    • Track types, severity, and remediation times of breaches.

  • Complaint Tracking:

    • Monitor and resolve privacy-related complaints.

  • Dashboards & Control-Based Monitoring:

    • Automate risk identification and document control effectiveness.

 

IV. Audit Process & Types

A. Audit Phases

  1. Planning:

    • Conduct risk assessments, schedule audits, select auditors, and compile checklists.

  2. Preparation:

    • Confirm schedules, finalize checklists, and sampling criteria.

  3. Execution (Audit Itself):

    • Meet stakeholders, review processes, and test controls.

  4. Reporting:

    • Document noncompliance (major/minor), produce formal reports, and hold close-out meetings.

  5. Follow-Up:

    • Confirm remediation, adjust scope, and ensure closure of identified issues.

B. Audit Types

  • First-Party Audits:

    • Self-assessments by internal teams to review risk management and control effectiveness.

  • Second-Party Audits:

    • Supplier audits to ensure outsourced functions comply with organizational standards.

  • Third-Party Audits:

    • Independent assessments (e.g., by regulators or external bodies) often tied to legal requirements or consent decrees.

 

V. Implementing & Reporting Metrics

  • Metric Ownership:

    • A designated owner (process champion) manages each metric, ensures clarity, documents definitions, and minimizes variance.

  • Defining Reporting Resources:

    • Establish flowcharts, visual displays, and regular reviews to ensure metrics remain relevant.

  • Key Considerations for Value Assessment:

    • Consider costs of producing information, market value, repercussions of data loss, and potential damage to reputation.

 

VI. Continuous Improvement & Follow-Up

  • Monitoring Effectiveness:

    • Regularly analyze monitoring data to identify triggers for policy reviews or audits.

  • Feedback Loop:

    • Use audit findings to drive corrective actions, update training, and adjust policies.

  • Resiliency & Alignment:

    • Evaluate business resiliency metrics and ensure continuous alignment with regulatory changes and internal risk assessments.

MODULE 9: Data Subject Rights

I. Overview of Privacy Communications

  • Privacy Notice vs. Privacy Policy:

    • Privacy Notice:

      • An external statement for customers or data subjects that explains how personal information is collected, used, shared, retained, and disclosed.

      • Should be a "living document" that is layered (high-level summary with links for more detail), clear, accessible, and designed with the intended audience in mind (e.g., mobile devices, IoT devices).

    • Privacy Policy:

      • An internal document for employees or contractors detailing how the organization handles personal information.

 

II. Design & Communication of Privacy Notices

  • Design Challenges & Strategies:

    • Use a layered approach to provide both a brief overview and detailed explanations as needed.

    • Ensure accessibility with clear icons, symbols, or dashboards.

    • Adapt delivery based on context (e.g., “just in time” notices at data input).

  • Communication Considerations:

    • Notices inform individuals of privacy practices but do not by themselves imply consent.

    • When consent is required, records must show what was agreed to.

 

III. Choice, Consent, and Opt-Out Mechanisms

  • Consent Requirements:

    • Under the GDPR, consent must be given by an affirmative action (e.g., swiping a bar, checking a box that is not pre-ticked).

    • Consent mechanisms should be designed to be clear and unambiguous.

  • Special Considerations for Children:

    • COPPA (U.S.) and GDPR require parental consent for processing personal data of children under 13 (or applicable age thresholds).

    • Privacy notices for children should be presented in child-friendly language.

  • Opt-In vs. Opt-Out:

    • Opt-In: Active, affirmative indication (e.g., checking a box to agree).

    • Opt-Out: Consent is presumed unless the individual acts to withdraw it—but such approaches are less favored under stricter regimes like the GDPR.

 

IV. Key Data Subject Rights Under the GDPR

  • Transparent Communication (Articles 12–14):

    • Right to clear, accessible information about processing practices.

  • Right of Access (Article 15):

    • Data subjects can request access to their personal data and obtain a copy.

  • Right to Rectification (Article 16):

    • Correction of inaccurate or incomplete data.

  • Right to Erasure / Right to be Forgotten (Article 17):

    • Request deletion of personal data under specific conditions (e.g., data no longer needed, withdrawal of consent).

  • Notification Obligation (Article 19):

    • Controllers must inform recipients of any rectifications or erasures.

  • Right to Restriction of Processing (Article 18):

    • Data subjects can request limitations on how their data is processed.

  • Right to Data Portability (Article 20):

    • Obtain and transfer personal data in a structured, commonly used, and machine-readable format.

  • Right to Object (Article 21):

    • Object to processing based on legitimate interests or direct marketing activities.

  • Right Not to be Subject to Automated Decision-Making (Article 22):

    • Safeguards against decisions made solely by automated processes that have significant effects on individuals.

 

V. Modalities & Operational Aspects

  • Facilitating Data Subject Rights:

    • Controllers must verify the identity of requesters using reasonable, non-intrusive methods.

    • Requests should be acknowledged promptly (typically within one month) and processed in the same form in which they were received.

  • Process Documentation:

    • Maintain documented procedures for handling access, rectification, erasure, portability, restriction, and objections.

    • Ensure systems update corrections across all databases and third-party systems where applicable.

 

VI. Rights in Other Jurisdictions

  • Beyond the EU:

    • Countries such as Canada (under PIPEDA) and many Latin American nations have similar data subject rights (e.g., Mexico’s ARCO rights).

    • Local laws may vary, but common elements include notice, access, correction, and, in some cases, deletion rights.

 

VII. Handling Complaints and Redress

  • Complaint Procedures:

    • Establish centralized, accessible processes for receiving, tracking, and resolving complaints from data subjects.

    • Clearly designate channels (e.g., phone, email, physical addresses) and document resolutions and any redress provided.

  • Ensuring Redress:

    • Provide remedies or compensation for grievances related to privacy mishandling.

 

VIII. Summary of Best Practices

  • Design Privacy Notices with a layered, accessible approach tailored to various devices and audiences.

  • Implement Clear Consent Mechanisms that allow for both giving and withdrawing consent easily.

  • Establish and Document Procedures for all data subject rights, ensuring timely and complete responses.

  • Monitor and Update Practices regularly to comply with evolving laws and regulatory guidance.

 

MODULE 10: Data Breach Plans

I. Privacy Incident Response

  • Incident vs. Breach:

    • Incident: A compromise of data confidentiality, integrity, or availability that may not require notification.

    • Breach: A confirmed unauthorized disclosure of data requiring notification to authorities and/or affected individuals.

    • Note: Only designated privacy or legal teams should declare a breach.

  • Liability Considerations:

    • Understand internal liability for harm caused by data breaches.

    • Contracts between controllers and processors must clearly assign responsibilities, ensuring that if a processor’s actions cause a breach, the controller can recover remediation costs.

  • Notifying Affected Individuals:

    • Notifications should be issued by recognizable representatives from the organization.

 

II. Legal Compliance & Reporting Obligations

  • Core Principles:

    • Prevent Harm: Provide affected individuals with the means to protect themselves (e.g., against identity theft).

    • Collection Limitation: Collect only necessary data.

    • Accountability: Maintain transparency and compliance to satisfy regulatory demands.

    • Monitoring & Enforcement: Use internal channels (e.g., dedicated contact points) and document remedial actions and disciplinary measures.

  • Jurisdictional Guidelines:

    • GDPR: Controllers must notify supervisory authorities and data subjects; processors must inform controllers.

    • PIPA (Canada): Requires notification to the Privacy Commissioner and may dictate further actions based on risk evaluation.

 

III. Incident Response Planning

  • Establishing Roles & Responsibilities:

    • Key Stakeholders:

      • Information Security: Detect, isolate, remove, and preserve evidence.

      • Legal: Advise on liability, regulatory requirements, and mitigation.

      • HR: Serve as a communication bridge for internal matters.

      • Marketing/Public Relations: Manage customer communications and public messaging.

      • Business Development & Finance: Address key account notifications and cost management.

      • CEO/President: Allocate resources and guide public response.

    • Incident Oversight Team: Led by the privacy or legal office, with inputs from IT, HR, communications, and senior management.

  • Planning Components:

    • Identify key information: types and categories of personal data, third-party relationships, prior incidents, and regulatory obligations.

    • Develop guidelines and procedures: roles, severity ratings, escalation triggers, contact lists, and integration with business continuity plans.

    • Include post-incident processes for review and lessons learned.

 

IV. Incident Detection, Handling, & Follow-Up

  • Detection:

    • Define what constitutes a privacy incident.

    • Establish a reporting process involving IT, physical security, HR, and vendors.

  • Handling:

    • Develop a communications plan to notify executive management.

    • Assemble a breach response team including data forensics, legal counsel, and privacy experts.

    • Immediate Actions:

      • Secure physical areas and systems.

      • Prevent further data loss and remove improperly disclosed information.

      • Preserve electronic evidence with an established chain of custody.

    • Investigation & Response:

      • Analyze the breach, determine remedial actions, execute containment, and monitor recovery.

    • Notification:

      • Notify law enforcement, supervisory authorities, and, if applicable, affected individuals (especially under HIPAA for health information).

  • Follow-Up:

    • Review the incident thoroughly, document all actions, and incorporate lessons learned to strengthen future responses.

 

V. Incident Reduction Techniques & Metrics

  • Reduction Strategies:

    • Implement technical, administrative, and physical controls to lower breach risk.

  • Incident Metrics:

    • Quantify the cost and impact of privacy incidents.

    • Use metrics to evaluate breach frequency, severity, and remediation costs to improve response and prevention efforts.