unauthorised or unlawful processing and against accidental loss, destruction of or damage to personal data” Guidance from the ICO, 27 March 2008 and 9 February 2010
• Governance groups, teams, steering committees – pick your poison • Ensure the right representatives are on it • Link to KPIs, create accountability • Privacy needs steering
of data loss? • How much data needs to be lost for it to become critical? • What is your policy for informing data owners? • What are your legal and regulatory obligations in case of breach? • Where in the world are you operating and will that change things?
classified or sensitive is it? • Where is your information coming from? • Why are you collecting it*? • In what formats, in what quantities? (*think about active and passive collection)
an organisation • Some will enter and stay (whether we are conscious of it or not)* *sometimes what we believe is happening is very different from what is actually happening
access personal information? • What controls are in place? • Are they being enforced? • Where are the audit trails and logs? • How is data protected at rest (cryptography, access rights, account controls)? • How is data protected in transit?
3rd parties? • How much, for what reason and has the owner consented (what do the contracts say)? • What is the third parties policy on privacy/audit? • What would happen if your third party got breached?
handling personal information? • How often are they trained? • How can they seek help or ask questions? • How can they report issues? • Is the message consistent with the policy? • Can you measure its effectiveness?