How to Improve Organizational Privacy Assessments

101 views
•
August 22, 2022
by
RSAC Cybersecurity
YouTube video player
How to Improve Organizational Privacy Assessments

TL;DR

Effective privacy assessments begin with knowing what personal data an organization holds, where it resides, why it is collected, and who receives it. Compliance, privacy, and security teams should assess solutions together, then integrate their findings into policies, procedures, architecture, Privacy by Design, and processes for handling access, disclosure, consent, and deletion rights within applicable deadlines.

Transcript

Good morning, RSA. I don't know about you, but I am super excited to be here. Um, last year was the first year that I spoke, and I was disappointed when it was virtual. So I'm excited to be here in front of you speaking today. Um, and thank you for sitting in on this session. Today we're gonna talk about privacy. So how many of you have a privacy r... Read More

Key Insights

  • Personal data is any information that can relate back to a living individual, not merely traditional identifiers. The scope described includes online profiles, shopping carts, education records, human resources information, medical information, geolocation, and IP addresses, so organizations must reassess what they classify as privacy-relevant data.
  • The right of access allows an individual to ask an organization what personal data it holds about them. Fulfilling that right depends on knowing where information exists throughout the organization, including systems maintained for employees, customers, applicants, and other groups.
  • Disclosure requires organizations to explain what information they collect, why they collect it, and with whom it is shared. A displayed privacy notice does not necessarily mean every individual accepts the described practices, particularly when access is conditioned on agreeing to an all-or-nothing policy.
  • Consent can be implied or explicit, and the distinction affects how an organization interprets an individual's behavior. Continuing to scroll without selecting a consent box may be treated as implied agreement, while explicit consent requires an affirmative indication that the person permits the stated activity.
  • The right to deletion allows individuals to request removal of personal data associated with accounts and online profiles. An organization may sometimes reject a request when the person's jurisdiction does not provide that right, while applicable laws can impose both deletion obligations and response deadlines.
  • Privacy request deadlines vary across the jurisdictions identified in the presentation. The five referenced United States privacy laws allow forty-five days for access and deletion responses, European Union privacy law allows thirty days, and Brazil's law allows fifteen days, making accurate data location essential.
  • Privacy responsibility extends across an entire organization because personal information can exist in human resources, marketing, recruiting, customer, and other systems. Even a resume uploaded by someone who is not a customer remains personal information that privacy and security professionals must recognize.
  • CompraSec is a collaboration model that brings compliance, privacy, and security teams into the same discussions about solutions, architecture, laws, policies, and procedures. The model addresses the fact that regulatory changes and organizational responses often require coordinated work from all three functions and additional subject matter experts.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What information should a privacy assessment cover?

A privacy assessment should cover any information that can relate back to a living individual. The presentation identifies names, addresses, Social Security numbers, passport details, online profiles, shopping carts, education data, human resources records, medical data, geolocation, and IP addresses. It should also determine where this information resides, why it is collected, how it is used, and who receives it.

Q: How has the definition of personal data changed?

The definition has expanded from a relatively limited group of familiar identifiers to a broad range of information connected with an individual. Twenty years ago, practitioners commonly focused on roughly twenty to twenty-five elements such as names, addresses, Social Security numbers, and passport details. The current scope described also includes behavior, profiles, employment information, medical information, location data, and IP addresses.

Q: What are the four core privacy rights?

The four core rights identified are access, disclosure, consent, and deletion. Access concerns learning what information an organization holds. Disclosure concerns understanding what is collected, why it is collected, and who receives it. Consent concerns whether permission was given, either implicitly or explicitly. Deletion concerns asking an organization to remove personal information, subject to the rights and exceptions available under applicable law.

Q: Why must organizations know where personal data is stored?

Organizations must know where personal data is stored so they can locate information when an individual requests access or deletion. Without an accurate understanding of data locations, a company may not know what to return or remove. This knowledge is also necessary to meet the response periods described, which range from fifteen days in Brazil to forty-five days under the referenced United States laws.

Q: How do privacy request deadlines differ by jurisdiction?

The presentation states that access and deletion requests have a forty-five-day response period under California, Virginia, Colorado, and the five referenced United States privacy laws. European Union privacy law provides thirty days, which is fifteen days less than the United States period described. Brazil's law provides fifteen days. These differences make jurisdiction awareness and organization-wide data mapping important for timely responses.

Q: What is the difference between implied and explicit consent?

Implied consent is inferred from behavior rather than obtained through a direct affirmative statement. The example given is continuing to scroll on a page without selecting a consent box, which an organization may interpret as agreement. Explicit consent requires the individual to clearly indicate that they permit the activity. The presentation describes this distinction as an important difference between some United States and international approaches.

Q: Why should privacy teams work across the organization?

Privacy teams should work across the organization because personal information is not confined to a legal or privacy department. It can appear in human resources, marketing, recruiting, customer systems, and locations the organization may not initially recognize. Building relationships with subject matter experts helps teams identify that information, explain the broadened definition of personal data, and apply the relevant privacy laws and regulations.

Q: What is CompraSec and how does it improve privacy work?

CompraSec is the presenter's term for integrating compliance, privacy, and security, modeled as a play on DevSecOps. It calls for these teams to discuss new laws, solution design, and architecture together instead of passing information from one function to another. Their combined involvement helps translate privacy assessment findings into coordinated changes to organizational policies, procedures, architecture, and related processes.

Summary & Key Takeaways

  • Privacy now covers far more than traditional identifiers such as names, addresses, Social Security numbers, and passport details. It can include online profiles, shopping carts, education, employment, medical, geolocation, and IP address data whenever the information can relate back to a living individual. Development and business teams need education about this broader scope.

  • Four recurring privacy rights are access, disclosure, consent, and deletion. Individuals may ask what information an organization holds, expect an explanation of collection and sharing practices, decide whether they permit processing, and request deletion. The precise rights and organizational duties depend on the applicable law, jurisdiction, and form of consent.

  • Privacy assessments require collaboration across the organization because personal data appears in customer systems, human resources, marketing, recruiting, and other unexpected locations. The proposed CompraSec approach brings compliance, privacy, and security teams together during solution design and architecture so assessment findings can shape policies, procedures, technology, and Privacy by Design activities.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚