Overview:
Responsible to prove to the organization that it has the proper controls to demonstrate to regulators that the organization handles personal data responsibly.
Promote consumer trust and confidence
Maintain the reputation of the organization.
Facilitates privacy program awareness
Respond effectively to privacy breaches.
Continually monitor, maintain, and improve the privacy program.
SPecifics
Improve staff
Develop monitoring, impact assessments,
Privacy Audits
Cross border data transfers
Web Certification seals
Collaborate with IT, Security, and
Where do privacy pros sit?
Mature Organization: throughout the ranks, HR, IT, marketing, and sales
Immature Organization: In the middle of the org
What is PPM:
Combining of disciplines into a framework that allows an organization to meet legal compliance requirements and the expectations of business clients.
GDPR
CCPA
Other privacy regulations
Why?
Reduce threat vector for Data Breach
Accountability
Having proper policies and procedures in place - prove accountability
Organization takes care of data throughout the data lifecycle.
How do policies help?
Allows organizations to meet guidance on their own terms.
Beyond Law and Compliance
Very critical to show customer trust
Fines and fees from regulators are bad, but not nearly as bad as other.
Mature privacy program to maint brand reputation.
Why have a privacy program?
Reduce lawsuit risks.
Meet compliance requirements.
Meet consumer expectations/enhance trust.
Reduce risk of data breach.
Privacy Across the organization.
Functional groups must understand
How they impact privacy
The privacy requirements themselves.
Functional/Large Org
Marketing will have a privacy rep to sign off all marketing materials after privacy review
HR will have a privacy rep to ensure that privacy is okay with HR regcords
Enforcement
Enforcement done at the functional level, not after the fact
HR Policies have to be reviewed by a privacy rep
Technical Infrastructure must pass a privacy impact assessment
Learning and Development Group
Manages activities related to employee training
Makes policies and procedures relatable to teachable content
Communication Group
Sends out privacy related information to all employees.
Information Security Group
More closely aligned to the privacy group
Implements privacy controls for GDPR
DLP
Encryption
Security Controls
Role based access
IT Group
Adds Processes and controls to support and enhance privacy
Creates role based access controls and other controls to better protect sensitive information.
Internal Audit Group
Independent Group
Assesses whether controls in place to protect personal data are effective
Procurement
Contracts are in place with proper language for service providers that process personal information.
Data controllers must ensure that the protection requirements are fulfilled.
Awareness, Alignment, and Involvement
Priv Mgr creates the program but it takes an organization to implement.
Priv Mgr is the conductor, while the organization is the symphony.
Priv Mgr needs to be proactive in driving the organization.
Summary
PM work for everyday consumers and fellow employees, not just investors and regulators.