Top Banner
The Value in Conducting a Privacy Impact Assessment Rachael Gallagher Senior Policy Officer 2 December 2014
13

The Value in Conducting a Privacy Impact Assessment Rachael Gallagher Senior Policy Officer 2 December 2014.

Dec 22, 2015

Download

Documents

Britney Palmer
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: The Value in Conducting a Privacy Impact Assessment Rachael Gallagher Senior Policy Officer 2 December 2014.

The Value in Conducting a Privacy Impact Assessment Rachael GallagherSenior Policy Officer

2 December 2014

Page 2: The Value in Conducting a Privacy Impact Assessment Rachael Gallagher Senior Policy Officer 2 December 2014.

Introduction

• What is a PIA?

• What is Privacy?

• What are the benefits?

• What types of projects?

• Who should be responsible?

Page 3: The Value in Conducting a Privacy Impact Assessment Rachael Gallagher Senior Policy Officer 2 December 2014.

Code of Practice

Privacy by design

From Handbook to Code of Practice

Page 4: The Value in Conducting a Privacy Impact Assessment Rachael Gallagher Senior Policy Officer 2 December 2014.

The PIA process

Page 5: The Value in Conducting a Privacy Impact Assessment Rachael Gallagher Senior Policy Officer 2 December 2014.

Consultation

Internal stakeholders

• Project board• Engineers, developers• IT• Procurement• Suppliers / data processors• Comms team• Frontline staff• Corporate Governance• Senior management

External stakeholders

• End users• Data subjects• Representative groups• Interest groups• General public• Regulators

Page 6: The Value in Conducting a Privacy Impact Assessment Rachael Gallagher Senior Policy Officer 2 December 2014.

The PIA process

• Establish objectives, outcomes and outputs early• Screening questions• Management support

1•Identify need for a PIA

Page 7: The Value in Conducting a Privacy Impact Assessment Rachael Gallagher Senior Policy Officer 2 December 2014.

The PIA process

• Types of personal data• Use of those data• Information asset register• Data controller?

2•Describe information flows

Page 8: The Value in Conducting a Privacy Impact Assessment Rachael Gallagher Senior Policy Officer 2 December 2014.

The PIA process

• Risk management tools/methodology• ICO guidance • Other standards and guidance• Types of risk

– Individuals– Compliance– Corporate

3•Identify privacy risks

Page 9: The Value in Conducting a Privacy Impact Assessment Rachael Gallagher Senior Policy Officer 2 December 2014.

The PIA process

• Accept• Reduce• Eliminate

4•Identify privacy solutions

Page 10: The Value in Conducting a Privacy Impact Assessment Rachael Gallagher Senior Policy Officer 2 December 2014.

The PIA process

• Document status of each risk• Determine solutions• Record reasons• Sign-off• Publication

5•Record PIA outcomes, and sign-off

Page 11: The Value in Conducting a Privacy Impact Assessment Rachael Gallagher Senior Policy Officer 2 December 2014.

The PIA process

• Recommendations integrated into project plan• Review PIA at key stages• Final evaluations

6•Integrate PIA outcomes into project plan

Page 12: The Value in Conducting a Privacy Impact Assessment Rachael Gallagher Senior Policy Officer 2 December 2014.

Conclusions

• Way of complying with data protection obligations

• Method of Good Practice

• Can reduce costs

• Publish where appropriate

• Promotes trust

Page 13: The Value in Conducting a Privacy Impact Assessment Rachael Gallagher Senior Policy Officer 2 December 2014.

www.twitter.com/iconews

Keep in touchInformation Commissioner’s Office

3rd Floor,14 Cromac Place,

Gasworks, Belfast BT7 2JB.

Tel: 028 90278757 / 0303 123 1114 Email: [email protected]

Subscribe to our e-newsletter at www.ico.org.uk

or find us on…