Privacy Management

Privacy Management

We have all seen the continuation of data breaches of sensitive and personal information that have either directly or indirectly impacted us, our neighbors, family, friends and co-workers. In response, regulatory bodies at the global, national and state levels have created and started to enforce regulations and laws to protect our individual data privacy rights.

With the increase of regulations and laws comes an increase in financial impact, risk, legal regulations and operational implementation complexity. Privacy professionals, like the Enterprise Risk team at Smith & Howard, must be prepared to translate substantial and complex legal requirements to all stakeholders within an organization, to include the executive management team, human resources (HR), legal, security, marketing, risk management and information technology (IT). A unified collaboration between the privacy professional and every stakeholder is critical to the success of the privacy program to effectively protect sensitive and personal information. 

Developing a Privacy Strategy

With the ongoing increase of regulations and laws, a manageable approach must be designed to handle and protect information.

Comprehensive Approach

One method is to take a comprehensive approach. A comprehensive approach starts with understanding and creating a feasible solution that holistically addresses the various requirements of the regulations and laws with which an organization must comply. This process involves connecting the privacy requirements to the operational activities and processes associated with each individual business department.

It is important to capture any existing privacy requirements in the organization’s policy standards and guidelines and ensure they align with jurisdictional and sectoral privacy laws.

(This comprehensive approach should not be confused with the many of the “mappings” we have seen emerge over the past years, where companies have mapped various regulations, laws and standards together. These mappings should be approached with caution, since every organization is unique, and a strict mapping method does not directly work for each organization’s specific environment.)

Strategic Approach

A strategic approach allows the development of a more dynamic process with a flexible structure to manage specific organizational needs. This provides a long-term scalable solution that adapts to the organization versus using a static framework that will quickly become outdated.

Data Protection Impact Assessment (DPIA)

Once an organization has a privacy strategy or understands the concept and importance of creating one. The next step (or in some scenarios this might be the first step), is to conduct a data protection impact assessment to identify all gaps and risks with their associated potential loss or adverse impact to the organization based on pre-defined severity categories.

This allows the prioritization of gaps and risks that have been identified based on cost, ease (feasibility), and risk mitigation in how best to protect your organization.

The keys to effective privacy management, regardless of the strategy used are 1) to engage a qualified, knowledgeable privacy professional; 2) to ensure the organization’s entire team is involved; and 3) to understand the advantages of each approach and the risks the organization faces prior to implementing a policy.




Hey call me. In trying to get security certified.

Like
Reply

To view or add a comment, sign in

More articles by Martha (MJ) Raber

Others also viewed

Explore content categories