+ All Categories
Home > Documents > Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging •...

Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging •...

Date post: 17-Aug-2020
Category:
Upload: others
View: 1 times
Download: 0 times
Share this document with a friend
32
1 IAPP Privacy Certification Data Sharing & Transfer Bryan Tretick Principal Certified Information Privacy Professional (CIPP)
Transcript
Page 1: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

1IAPP Privacy Certification

Data Sharing & TransferBryan TretickPrincipal

Certified Information Privacy Professional (CIPP)

Page 2: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

2agenda • company inventory• privacy policy• common terminology• user preference strategy• access & redress• transfer of information

Page 3: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

3agenda • international data• oversight & governance

Page 4: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

4

company inventory

Data Sharing and Transfer

Page 5: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

5companyinventory • Purpose of Inventory

- Proactive & Reactive reasons

• Organization Chart

• Physical location of data storage

- Domestic- Outside US- Accountability

Page 6: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

6• For each type of PII data- Location of data- Data ownership- Level of sensitivity and

protection (e.g. encryption)

- Process flow use and maintenance

- Trans-border

- Dependency on other systems

companyinventory

Page 7: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

7• Purpose & Users of PII- How is data shared with

other companies- Reasons specified- Who has access & How is it

controlled

companyinventory

Page 8: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

8

privacy policy

Data Sharing and Transfer

Page 9: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

9• A basic framework since 1980

- Collection limitation principle- Data quality principle

- Purpose specification principle- Use limitation principle- Security safeguards principle- Openness principle- Individual participation principle- Accountability principle

OECDguidelines

Page 10: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

10privacypolicy

• Single Policy or Multiple • Approval of Policy & Revisions• Training & Awareness• Communication to Audience

- Annual Notice- Post on location- Post online

• Version Control

Page 11: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

11

• Disclosure of info. use, sharing & choice- Name, address & purchase history- Internal purposes, marketing

efforts, analysis, service provider, sharing with third parties for their benefit.

- Opt Out/Opt In

• Disclosure of information collected- Name, address, cookies,

financial information, etc.

privacypolicy

Page 12: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

12• Disclosure of Process- Access & redress, change in

policy, etc.

privacypolicy

Page 13: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

13

commonterminology

Data Sharing and Transfer

Page 14: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

14commonterminology

• Know common terminology and its applicability

- PII, PHI, NPI, personal data, etc.

Page 15: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

15

user preferencestrategy

Data Sharing and Transfer

Page 16: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

16userpreference

strategy • Channels - online, call center,VRU, brick and mortar, etc.

• Applying preferences - byaccount number, name, email, household, etc.

• Confirmations• Preference changes - verbal,

written, online form, etc.

• Honoring preference - specified time period, forever, etc.

• Opt Out or Opt In

Page 17: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

17

• Acquiring preferences fromthird parties or affiliates & subsidiaries

- Ensuring integrity- Honoring pre-existing

preference elections- Compare with privacy strategy

• No Opt- Viability and Risks- Legal/Regulatory Exceptions:

- joint marketing betweenfinancial institutions, service provider, subpoena

userpreference

strategy

Page 18: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

18• Maintaining Customer Preference

- Acquired preferences from 3rd

parties, affiliates, subsidiaries- Managing preferences by

product line or service variety- Making changes to preferences

• Honoring Customer Preferences

- Joint Marketing Agreements- Affiliates or Subsidiaries- Product Line and Service Variety- Federal & State Laws

userpreference

strategy

Page 19: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

19

access & redress

Data Sharing and Transfer

Page 20: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

20access &redress

• Process Disclosure

• Compliance with EU Directive or other applicable laws.

• Customer changes within one company or one division

Page 21: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

21

transfer ofinformation

Data Sharing and Transfer

Page 22: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

22transfer ofinformation • Sharing with affiliates,

subsidiaries or third parties

• Contract and Vendor Management

(1) Due diligence- Reputation- Financial condition - Information security

controls

Page 23: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

23• Information securitycontrols (detail):

- Access- Audits- Disposal of information- DR/BRCP- Firewalls- Insurance- Intrusion detection- Incident response- Physical security- Training & awareness

transfer ofinformation

Page 24: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

24• Contract and VendorManagement (contd)

(2) Confidentiality provision

(3) Further use of shared information

(4) Use of sub-contractors(5) Requirements to notify(6) Background checks

(7) Requirements to disclose breach

transfer ofinformation

Page 25: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

25• Approval Process & Justification to Share New Information

- Consistent with Privacy Policy

- Review new applicable laws& enforcement actions

- Business Need

transfer ofinformation

Page 26: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

26

international data

Data Sharing and Transfer

Page 27: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

27internationaldata • Exceptions to Global

Policy- Process

• Transfer of info. overseas (outsourcing/vendor/affiliate)

- Safe harbor/standard model contract/Article 29 Working Party

- Customer Consent - Notification to foreign govt.

authorities

Page 28: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

28• International Terminology

- Data subject, data controller, data processor, personal data

internationaldata

Page 29: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

29

• Marketing Overseas- Opt In/Opt Out- Customer Consent- Phone, email, direct mail, instant

messaging, text messaging

• Conducting Business Overseas

- Employee vs. Customer Data- Phone lists, vendor info, benefits

• Policy for International Law- Country-specific or Global

internationaldata

Page 30: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

30

oversight &governance

Data Sharing and Transfer

Page 31: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

31oversight&

governance• Monitoring Disclosure

and Preference• Management Activity

(compliance w/policy)

• Self Assessments• Third Party Audits• Certifications• Training & Awareness• Physical & Information Security• Security + Privacy

Page 32: Data Sharing & Transfer · -Phone, email, direct mail, instant messaging, text messaging • Conducting Business Overseas-Employee vs. Customer Data-Phone lists, vendor info, benefits

32

IAPP Certification Promoting Privacy


Recommended