Cipm Notes Giveaway
Cipm Notes Giveaway
ACADEMY NOTES
GIVEAWAY
academy.tsaaro.com
About Tsaaro Academy
"It’ s not easy to build trust and manage risks at the same time"
Featured in
1. INTRODUCTION
Privacy Program Management: It is a process to meet the legal data
protection compliance requirement (privacy by design and by default) and
the expectations of customers by combining several disciplines into a
framework and overall reduce the risk of data breach or incidents.
Skills for the managing a privacy program can bring a lot of opportunities
for privacy professionals. In this chapter we will see the skills needed by a
privacy professional for Privacy Program Management.
The goals of the privacy program manager can be summed up in 4 major points:
• Incident response
• Communications
• Privacy controls
• Privacy issues with existing products and services
• Privacy-related monitoring • Privacy impact assessments
• Development of privacy staff
• Privacy-related investigations
• Privacy-related data committees
• Privacy by design in product development
• Privacy-related vendor management
• Privacy audits
• Privacy metrics
• Cross-border data transfers
• Preparation for legislative and regulatory change
• Privacy-related subscriptions
• Privacy-related travel
• Redress and consumer outreach
• Privacy-specific or –enhancing software
• Privacy related web certification seals
• Cross-functional collaboration with legal, information technology (IT),
information security (sometimes referred to as IS or InfoSec), cybersecurity
and ethics teams, among others
• Reporting to chief privacy officer (CPO), data protection officer (DPO),
and/or data protection authority (DPA)
3. Concept of Accountability
Accountability is a principle which requires the organisation to demonstrate
the compliance with the applicable data protection laws through
establishing proper policies and procedures, and documentation. This
documentation will not only help in demonstrating the compliance but also
in handling personal data residing and flowing across the organisation. This
principle requires the organisations to take ownership and secure the
personal data throughout the data lifecycle. If the organisation have placed
the policies, they need to follow it without any deviation. This way, the
organisation can be held accountable. It is the duty of the Privacy
Professionals to demonstrate the accountability by complying with all the
Consumer Trust: Apart from risk of hefty regulatory fines, consumer trust is
an important element for the business especially B2C businesses. Loss of
consumer trust can have broad and severe repercussions including the
ruining of the business. Many organisations are very sincere about their
privacy programs to maintain the consumer trust. Privacy compliance is
equally important for B2B business as it promotes the trust with the partners,
employees, contractors and consumers.
Brand Name: A data breach can affect the brand name of a business badly.
To keep the brand name safe, it is a good place a privacy program.
These can be achieved by
Meeting the regulatory requirements
Reduce the risk of data breach
Meet client expectation
Some of the other departments that can contribute to the privacy are:
i. HR vi. Legal
ii. Ethics vii. Security
iii. Marketing viii. Risk
iv. Business Development ix. Governance
v. Finance x. Research and development
[email protected]
+91 93353 36454