CDPSE · Domain 1
Privacy Governance
About 20% of the exam
Building blocks of a privacy program
- Strategy
- Charter
- Policies
- Roles
- Controls
- Metrics
- Assurance
- Strategy
- direction and objectives set by leadership
- Program
- operates the activities that deliver the strategy
- Charter
- mandate, scope, authority, reporting line
- Policies
- management intent, approved, reviewed on a cycle
- Roles
- RACI so nothing is dropped or duplicated
- Metrics
- KPIs show performance, KRIs warn of exposure
- Assurance
- audit and monitoring prove it works
Governance early is cheaper than retrofitting it after risky practices have set in; frame funding as risk, trust and enablement
Roles the exam names
- Controller
- determines purposes and means
- Processor
- acts only on documented instructions
- Joint controllers
- jointly decide, agree responsibilities
- Sub-processor
- needs the controller's authorization
- Data subject
- the identifiable person with rights
- DPO
- advises, monitors, independent contact point
- Data owner
- accountable for a data domain
- Privacy champion
- extends awareness into each department
Accountability stays with the controller even when execution is outsourced
Privacy principles
- Lawfulness, fairness, transparency
- basis, no deception, clear notice
- Purpose limitation
- specified, explicit, compatible uses only
- Data minimization
- adequate, relevant, limited to need
- Accuracy
- kept current, corrected without delay
- Storage limitation
- identifiable no longer than necessary
- Integrity and confidentiality
- appropriate security for the data
- Accountability
- implement measures and demonstrate compliance
GDPR Article 5, the OECD guidelines and the FIPPs say the same things in different orders
The data protection officer
- Mandatory: public body, large-scale monitoring, special categories
- Receives no instructions on performing tasks
- Cannot be dismissed for doing the job
- Reports to the highest management level
- Conflict if the DPO sets processing purposes
- Needs resources and early involvement
- Contact point for authority and data subjects
- Overruled advice must be recorded with reasons
Privacy versus security
- Privacy
- appropriate collection, use, sharing of personal data
- Security
- protecting data from unauthorized access
- Overlap
- confidentiality and integrity controls
- Secure but not private
- well-guarded data used for wrong purposes
- Private needs secure
- no privacy without security
- Personal data
- relates to an identifiable person
- Special categories
- health, biometrics, beliefs, orientation, origin
Passing a security audit does not show the processing was lawful, fair or necessary
Governance models
- Centralized
- one team, consistent, may be slow
- Decentralized
- local ownership, inconsistent standards
- Hybrid or federated
- central minimum standards, local execution
- Global baseline
- one standard, stricter local law added
- Privacy committee
- cross-functional decisions and escalation
- Champions network
- day-to-day accountability in business units
- Risk-based triggers
- threshold assessments scale the scrutiny
Third-party governance
- Due diligence before onboarding, not after
- Contract: instructions, confidentiality, security, deletion
- Sub-processor changes need prior authorization
- Audit rights let the controller verify
- Breach notification timelines written in
- Tiered ongoing monitoring by data sensitivity
- Reassess when scope or data changes
- Extend training to vendor staff
The controller cannot outsource accountability; it needs the means to verify
Legal landscape
GDPR
- Applies to EU establishments and EU targeting
- Six lawful bases, consent is one
- Supervisory authority per member state
- Lead authority for cross-border cases
- Fines to 4% or 20 million euro
- Article 38 protects DPO independence
CCPA and CPRA
- Consumers, households, California residents
- Opt out of sale and sharing
- CPRA created the enforcement agency
- Right to correct added by CPRA
- Requests answered within 45 days
- Private action for unencrypted breach
Also know
- HIPAA: covered entities and business associates
- LGPD, PIPEDA, and other national laws
- ISO/IEC 27701 extends 27001 for privacy
- NIST Privacy Framework: five functions
- ePrivacy rules govern cookies and consent
- Apply the strictest rule where laws collide
Metrics and reporting
- KPI
- performance toward program objectives
- KRI
- rising exposure, an early warning
- DSAR time trending up
- KRI, deadlines soon missed
- Training completion
- attendance, not behavior
- Maturity score
- capability trend for the board
- Coverage metric
- high-risk processing with current assessment
- Findings aging
- remediation health of the program
Report on a set cadence, not only when something goes wrong
Awareness and culture
- Role-based content, executives to engineers
- Records link person, date and version
- Repeat on a cycle and after change
- Non-punitive reporting of concerns
- Culture indicators: voluntary reports, champion activity
- Plain-language notices support real transparency
- Contractors and vendors trained too
Privacy audit
Planning
- Audit universe covers all personal data processing
- Risk-based frequency and depth
- Scope fixed before fieldwork starts
- Walkthrough confirms how controls really run
- Unified framework, one test, many regulations
Evidence
- Verbal assertion is weak testimonial evidence
- Corroborate with logs and deletion records
- Sample across the whole period
- Design versus operating effectiveness deficiency
- Actionable finding: issue, cause, corrective basis
- Disclose deficiencies honestly with a plan
Assurance options
- Gap assessment against a chosen standard
- Control self-assessment by process owners
- SOC 2 Type II covers a period
- ISO/IEC 27701 certifies the PIMS
- Attestation shared under NDA
- Corrective action plan with root cause
Compliance monitoring
- Continuous monitoring narrows the failure gap
- Green dashboards can be false assurance
- Sample evidence independently when always green
- Direct signals: records past retention
- Map controls to the obligations they satisfy
- Auto-enroll new systems into scope
- Manual procedures need observation or interviews
- Changes trigger privacy re-review
- Tier vendors, monitor in proportion
Rapid recall: whose job
- Decides purposes and means
- the controller
- Follows instructions
- the processor
- Advises and monitors
- the DPO
- Accepts residual risk
- accountable business or risk owner
- Approves policy
- senior management
- Independent assurance
- internal audit, third line
- Demonstrates compliance
- controller, accountability principle
- Clarifies who does what
- RACI matrix
Reference strip: principles, roles, law, evidence, metrics
Principles
- Lawful, fair, transparent
- Purpose limitation, minimization
- Accuracy, storage limitation
- Integrity and confidentiality
- Accountability ties them together
Roles
- Controller decides, processor executes
- DPO independent, reports to the top
- Data subject holds the rights
- Owner accountable, custodian protects
Law words
- GDPR: six bases, 4% fines
- CCPA: opt out, 45 days
- HIPAA: covered entity, business associate
- ISO/IEC 27701, NIST Privacy Framework
Audit evidence
- Testimonial weakest, corroborate it
- Sample across the period
- Design versus operating effectiveness
- Findings need cause and action
Metrics
- KPI performs, KRI warns
- Coverage of high-risk processing
- Completion is not competence
- Maturity trend plus outcomes
Quick exam traps
- Trap: Appointing a DPO discharges the accountability principle
- Trap: A processor that suffers the breach carries the controller's accountability
- Trap: Strong security controls alone make processing privacy compliant
- Trap: A signed policy is evidence that the control operates
- Trap: Management's verbal assertion is sufficient audit evidence
- Trap: A dashboard full of green indicators proves the controls are effective
- Trap: Vendors assessed at onboarding need no further review
- Trap: The DPO decides the purposes and means of processing
cybercertprep.com · original revision sheet written from the public body of knowledge