ANSWERS SURE A+
✔✔Commonalities between many privacy and data protection laws, regulations, and
standards - ✔✔Notice, Data Retention Limits, Purpose Limitations, Choice and
Consent, Individual Rights, Obligations
✔✔There must be a legal basis for cross-border data transfers. What are potential
options for legally transferring PI between jurisdictions? - ✔✔1. Adequacy Decisions
2. Contracts - ad hoc or standard clauses
3. Binding Corporate Rules
4. Codes of Conduct, Self-Certification
✔✔Define Data Mapping - ✔✔Map data inventories including flows and classification.
Create a record of authority of systems. Map and document data flow in systems and
applications. Analyze and classify types and uses of data.
Should include: purpose of repository, owner, location, volume, format, usage, type,
geography, shared with whom
✔✔When can Data Mapping be used - ✔✔• A precursor to compliance and risk analysis
• Assess data, systems, processes
• Inform data assessments, priorities, life cycle management
✔✔How to Start Data Mapping? - ✔✔1. Who is responsible? Often budget shared
across depts.
2. Identify depts that hold and use PI - can be done via internal audit or outside
consultancy
3. Plan intake questions - organized around data lifecycle (collection, usage, transfers,
retention, destruction, security), should be specific to LOBs
✔✔Define and Describe a Privacy Assessment - ✔✔Measure an organization's
compliance
, Can be on scheduled basis, ad hoc as a result of a privacy or security event, or upon
request from an authority.
Can review logs, scores, tools or interviews/questionnaires
Can be conducted by internal auditor, DPO, Business Function, third party
Document results and analyze for improvement/remediation
✔✔Define and describe a Privacy IMPACT Assessment - ✔✔Specifically assess the
privacy risks associated with processing PI in relation to a project, product, or service.
Should be conducted prior to a deployment that involved the collection of PI, when there
are new standards regulations or policies, or a change in methods to which PI is
handled, collection of new information
This allows stakeholders to dedicate resources more effectively
✔✔DPIA vs. PIA - ✔✔DPIA=EU
Synonymous except DPIA has specific triggers and requirements under GDPR
Values of DPIA: Incorporate privacy considerations into org planning, demonstrate
GDPR Compliance
✔✔DPIA Triggers - ✔✔Article 35: processing is likely to result in high risk to rights and
freedoms
Use of new technologies whose risks are less understood may increase likelihood
✔✔DPIA Components - ✔✔Description of the processing, including purpose and
legitimate interest
Necessity of processing and its proportionality of risk
Measures to address risks
✔✔What is Attestation? - ✔✔A tool for ensuring functions outside the privacy team are
held accountable for privacy responsibilities
Answering yes/no questions and maybe providing evidence
✔✔Physical environments that may require risk assessment - ✔✔Data centers, offices,
physical access, telework, media sanitation and disposal, device forensices, device
security (imaging/hardware)