Download as pdf or txt
Download as pdf or txt
You are on page 1of 1

Nymity Privacy Management Accountability Framework

TM

UPDATED MARCH 2017


A Menu of Privacy Management Activities (Technical and Organizational Measures)

1. Maintain Governance Structure 5. Maintain Training and Awareness Program


9. Respond to Requests and Complaints from Individuals
Ensure that there are individuals responsible for data privacy, accountable management, Provide ongoing training and awareness to promote compliance with the data privacy policy
Maintain effective procedures for interactions with individuals about their personal data
and management reporting procedures and to mitigate operational risks

Privacy Management Activities Privacy Management Activities Privacy Management Activities


• Assign responsibility for data privacy to an individual (e.g. Privacy • Engage stakeholders throughout the organization on data privacy • Conduct privacy training • Maintain privacy awareness material (e.g. posters and videos) • Maintain procedures to address complaints • Maintain procedures to respond to requests for data portability
Officer, Privacy Counsel, CPO, Representative) matters (e.g. information security, marketing, etc.) • Conduct privacy training reflecting job specific content • Conduct privacy awareness events (e.g. an annual data privacy • Maintain procedures to respond to requests for access to • Maintain procedures to respond to requests to be forgotten or
• Engage senior management in data privacy (e.g. at the Board of • Report to internal stakeholders on the status of privacy • Conduct regular refresher training day/week) personal data for erasure of data
Directors, Executive Committee) management (e.g. board of directors, management) • Incorporate data privacy into operational training, such as HR, • Measure participation in data privacy training activities • Maintain procedures to respond to requests and/or provide a • Maintain Frequently Asked Questions to respond to queries from
• Appoint a Data Protection Officer/Official (DPO) in an independent • Report to external stakeholders on the status of privacy security, call centre (e.g. number of participants, scoring) mechanism for individuals to update or correct their personal data individuals
oversight role management (e.g. regulators, third-parties, clients) • Deliver training/awareness in response to timely issues/topics • Enforce the requirement to complete privacy training • Maintain procedures to respond to requests to opt-out of, restrict • Investigate root causes of data privacy complaints
• Assign responsibility for data privacy throughout the organization • Conduct an Enterprise Privacy Risk Assessment • Deliver a privacy newsletter, or incorporate privacy into existing • Provide ongoing education and training for the Privacy Office or object to processing • Monitor and report metrics for data privacy complaints
(e.g. Privacy Network) • Integrate data privacy into business risk assessments/reporting corporate communications and/or DPOs • Maintain procedures to respond to requests for information (e.g. number, root cause)
• Maintain roles and responsibilities for individuals responsible for • Maintain a Privacy Strategy • Provide a repository of privacy information (e.g. an internal data • Maintain certification for individuals responsible for data privacy,
data privacy (e.g. job descriptions) • Maintain a privacy program charter/mission statement privacy intranet) including continuing professional education
• Conduct regular communication between the privacy office, privacy • Require employees to acknowledge and agree to adhere to the 10. Monitor for New Operational Practices
network and others responsible/accountable for data privacy data privacy policies
Monitor organizational practices to identify new processes or material changes to existing
processes and ensure the implementation of Privacy by Design principles
2. Maintain Personal Data Inventory and Data Transfer Mechanisms 6. Manage Information Security Risk
Maintain an inventory of the location of key personal data storage or personal data flows, Maintain an information security program based on legal requirements and ongoing
including cross-border, with defined classes of personal data risk assessments Privacy Management Activities
• Integrate Privacy by Design into system and product development • Track and address data protection issues identified during
• Maintain PIA/DPIA guidelines and templates PIAs/DPIAs
• Conduct PIAs/DPIAs for new programs, systems, processes • Report PIA/DPIA analysis and results to regulators (where
Privacy Management Activities Privacy Management Activities • Conduct PIAs or DPIAs for changes to existing programs, systems, required) and external stakeholders (if appropriate)
• Maintain an inventory of personal data holdings (what personal • Use Binding Corporate Rules as a data transfer mechanism • Integrate data privacy risk into security risk assessments • Integrate data privacy into a corporate security policy (protection
or processes
data is held and where) • Use contracts as a data transfer mechanism (e.g. Standard • Integrate data privacy into an information security policy of physical premises and hard assets)
• Engage external stakeholders (e.g., individuals, privacy
• Classify personal data holdings by type (e.g. sensitive, confidential, Contractual Clauses) • Maintain technical security measures (e.g. intrusion detection, • Maintain human resource security measures (e.g. pre-screening,
advocates) as part of the PIA/DPIA process
public) • Use APEC Cross Border Privacy Rules as a data transfer firewalls, monitoring) performance appraisals)
• Obtain regulator approval for data processing (where prior approval mechanism • Maintain measures to encrypt personal data • Integrate data privacy into business continuity plans
is required) • Use the EU-US Privacy Shield as a data transfer mechanism • Maintain an acceptable use of information resources policy • Maintain a data-loss prevention strategy
• Register databases with regulators (where registration is required) • Use regulator approval as a data transfer mechanism • Maintain procedures to restrict access to personal data • Conduct regular testing of data security posture 11. Maintain Data Privacy Breach Management Program
• Maintain flow charts for data flows (e.g. between systems, between • Use adequacy or one of the derogations from adequacy (e.g. role-based access, segregation of duties) • Maintain a security certification (e.g. ISO) Maintain an effective data privacy incident and breach management program
processes, between countries) (e.g. consent, performance of a contract, public interest) as a
• Maintain records of the transfer mechanism used for cross-border data transfer mechanism
data flows (e.g. standard contractual clauses, binding corporate
rules, approvals from regulators)
Privacy Management Activities
• Maintain a data privacy incident/breach response plan • Conduct periodic testing of data privacy incident/breach plan
3. Maintain Internal Data Privacy Policy 7. Manage Third-Party Risk • Maintain a breach notification (to affected individuals) and • Engage a breach response remediation provider
Maintain a data privacy policy that meets legal requirements and addresses operational risk reporting (to regulators, credit agencies, law enforcement) protocol • Engage a forensic investigation team
Maintain contracts and agreements with third-parties and affiliates consistent with • Maintain a log to track data privacy incidents/breaches • Obtain data privacy breach insurance coverage
and risk of harm to individuals the data privacy policy, legal requirements, and operational risk tolerance • Monitor and report data privacy incident/breach metrics
(e.g. nature of breach, risk, root cause)

Privacy Management Activities Privacy Management Activities


• Maintain a data privacy policy • Document legal basis for processing personal data • Maintain data privacy requirements for third parties (e.g. clients, • Maintain a policy governing use of cloud providers 12. Monitor Data Handling Practices
• Maintain an employee data privacy policy • Integrate ethics into data processing (Codes of Conduct, policies vendors, processors, affiliates) • Maintain procedures to address instances of non-compliance Verify operational practices comply with the data privacy policy and operational policies and
• Maintain an organizational code of conduct that includes privacy and other measures) • Maintain procedures to execute contracts or agreements with with contracts and agreements procedures, and measure and report on their effectiveness
all processors • Conduct ongoing due diligence around the data privacy and
• Conduct due diligence around the data privacy and security security posture of vendors/processors
4. Embed Data Privacy Into Operations posture of potential vendors/processors • Review long-term contracts for new or evolving data privacy risks
• Conduct due diligence on third party data sources
Privacy Management Activities
Maintain operational policies and procedures consistent with the data privacy policy, • Conduct self-assessments of privacy management • Engage a third party to conduct audits/assessments
• Maintain a vendor data privacy risk assessment process
legal requirements, and operational risk management objectives • Conduct Internal Audits of the privacy program (i.e. operational • Monitor and report privacy management metrics
audit of the Privacy Office) • Maintain documentation as evidence to demonstrate compliance
• Conduct ad-hoc walk-throughs and/or accountability
• Conduct ad-hoc assessments based on external events, such • Maintain certifications, accreditations or data protection seals for
Privacy Management Activities
as complaints/breaches demonstrating compliance to regulators
• Maintain policies/procedures for collection and use of sensitive • Integrate data privacy into hiring practices
personal data (including biometric data) • Integrate data privacy into the organization’s use of social media 8. Maintain Notices
• Maintain policies/procedures for collection and use of children and • Integrate data privacy into Bring Your Own Device (BYOD) Maintain notices to individuals consistent with the data privacy policy, legal requirements,
minors’ personal data policies/procedures and operational risk tolerance 13. Track External Criteria
• Maintain policies/procedures for maintaining data quality • Integrate data privacy into health & safety practices
Track new compliance requirements, expectations, and best practices
• Maintain policies/procedures for the de-identification of personal data • Integrate data privacy into interactions with works councils
• Maintain policies/procedures to review processing conducted wholly • Integrate data privacy into practices for monitoring employees
or partially by automated means • Integrate data privacy into use of CCTV/video surveillance Privacy Management Activities
• Maintain policies/procedures for secondary uses of personal data • Integrate data privacy into use of geo-location (tracking and or • Maintain a data privacy notice that details the organization’s • Provide notice in contracts and terms
personal data handling practices • Maintain scripts for use by employees to explain or provide the Privacy Management Activities
• Maintain policies/procedures for obtaining valid consent location) devices
• Provide data privacy notice at all points where personal data is data privacy notice • Identify ongoing privacy compliance requirements e.g., law, • Seek legal opinions regarding recent developments in law
• Maintain policies/procedures for secure destruction of personal data • Integrate data privacy into policies/procedures regarding access
collected • Maintain a privacy Seal or Trustmark on the website to increase case law, codes, etc. • Identify and manage conflicts in law
• Integrate data privacy into use of cookies and tracking mechanisms to employees' company e-mail accounts
• Provide notice by means of on-location signage, posters customer trust • Maintain subscriptions to compliance reporting service/law firm • Document decisions around new requirements, including their
• Integrate data privacy into records retention practices • Integrate data privacy into e-discovery practices
• Provide notice in marketing communications (e.g. emails, flyers, updates to stay informed of new developments implementation or any rationale behind decisions not to
• Integrate data privacy into direct marketing practices • Integrate data privacy into conducting internal investigations
offers) • Attend/participate in privacy conferences, industry association, implement changes
• Integrate data privacy into e-mail marketing practices • Integrate data privacy into practices for disclosure to and for law
or think-tank events
• Integrate data privacy into telemarketing practices enforcement purposes
• Record/report on the tracking of new laws, regulations,
• Integrate data privacy into digital advertising practices (e.g. online, • Integrate data privacy into research practices (e.g. scientific and
amendments or other rule sources
mobile) historical research)

The Nymity Privacy Management Accountability FrameworkTM was developed based on Nymity’s global research on data privacy accountability. Copyright © 2017 by Nymity Inc. All rights reserved. All text, images, logos, trademarks and information contained in this document are the intellectual property of
The Framework is a comprehensive listing of over 130 Privacy Management Activities (PMAs) categorized into 13 Privacy Management Categories (PMCs). Nymity Inc. unless otherwise indicated. Reproduction, modification, transmission, use, or quotation of any content, including text, images, photographs etc., requires
Once implemented, the activities highlighted in BLUE will help achieve ongoing compliance with the GDPR and produce documentation to demonstrate compliance. the prior written permission of Nymity Inc. Requests may be sent to info@nymity.com.

You might also like