Auditing-Data-Privacy Joa Eng 0518
Auditing-Data-Privacy Joa Eng 0518
BASICS
• Choice and consent—Does the enterprise ensure • Security safeguards—Does the enterprise ensure
that appropriate consent has been obtained prior that appropriate security safeguards are in place
to the transfer of personal information to other for all personal information?
jurisdictions?
• Monitoring, measuring and reporting—Does
• Legitimate purpose specification and use the enterprise report compliance with policies,
limitation—Does the enterprise specify the standards and laws?
purpose(s) for which personal information
• Preventing harm—Does the enterprise establish
is collected?
processes to mitigate any personal harms that
• Personal information and sensitive information may occur to data subjects?
life cycle—Does the enterprise retain personal
• Third-party/vendor management—Does the
information for only as long as necessary?
enterprise implement governance processes to
• Accuracy and quality—Does the enterprise ensure the appropriate protections and use of
implement practices and processes to ensure that personal information that are transferred to
personal information is accurate, complete and up third parties?
to date?
• Breach management—Has the enterprise
• Openness, transparency and notice—Does the established a documented policy and supporting
enterprise provide clear and easily accessible procedure for identifying, escalating and reporting
information about its privacy policies and practices? incidents?
• Individual participation—Does the enterprise • Security and privacy by design—Does the
provide data subjects a process to access their enterprise ensure executive support for the
personal information? identification of personal information and privacy
risk within enterprise events?
• Accountability—Does the enterprise assign roles,
• Free flow of information and legitimate
responsibility, accountability and authority for
restriction—Does the enterprise follow the
performing privacy processes?
requirements of applicable data protection