Privacyrecht is code
Einde inhoudsopgave
Privacyrecht is code (R&P nr. ICT1) 2010/10.2:10.2 Protocol case studies
Privacyrecht is code (R&P nr. ICT1) 2010/10.2
10.2 Protocol case studies
Documentgegevens:
drs. J.J.F.M. Borking, datum 26-05-2010
- Datum
26-05-2010
- Auteur
drs. J.J.F.M. Borking
- JCDI
JCDI:ADS574104:1
- Vakgebied(en)
Civiel recht algemeen (V)
Deze functie is alleen te gebruiken als je bent ingelogd.
Date of interview:
Company/Organization general data
Name Company/Organization:
Address Company/ Organization:
Name(s) of person(s) interviewed:
Function(s) of person(s) interviewed
What is the primary operation of the organization?
What different processing operations are occurring in the organization?
Do you have a written security policy?
Do you have a security risk analysis?
Do you have a privacy risk/threats analysis?
Strategy
How does Privacy relate to the objectives/strategy of your firm?
Is it considered as a legal must
Is it considered as potentially important but not essential
Is it considered as a potential strategic driver for market share, customer retention and acquisition?
How would you describe the information intensity (information content used and generated) of your firm
How would you describe your identity and privacy processes?
There is no official policy/program established
There is a beginning of staffing and organizing a program
Some key initiatives are being launched
There is an established program that can be evaluated
The program is in maintenance mode focusing on refinement
Do you have a privacy infrastructure? I.e. is there a function accountable for privacy protection? Yes/No
Privacy office (officer)
Privacy policy and procedures
Personnel training and awareness
Privacy enhancing tools (specify)
Privacy audits
Other...
Is privacy protection part of the management cycle? Yes/No
Is there a separate budget for privacy protection? Yes/No
If yes, What is the amount of the privacy budget?
How much do you spend on privacy?
How much do you spend (or if no budget exist: how much would you like to spend) on the above components of your privacy infrastructure?
What are the most important components in terms of total spend?
What is the percentage of the turnover spent for privacy?
Please plot your organization in the IAM maturity Model (handed over).
Privacy attitudes
Are employees privacy aware?
Do you consider privacy legislation workable/complex?
Does the compliance/pressure to privacy legislation play a role in your organization? Yes/No
How do you estimate the chance of being caught for privacy violations by the data protection authority?
Does this influence your attitude towards privacy protective measures? Yes/No
Are privacy incidents (internally) reported? Yes/No
Privacy Incidents/breaches
Please, Consider/Imagine a serious privacy breach: what are/ would be the tangible financial consequences?
Investigation and forensics
Outbound contact costs
Inbound contact costs
PR & communication to restore reputation
Legal defense
Security consultants
Lost business
Customer acquisition costs
System and process redesign costs
Other...
Please, Consider a serious privacy breach: what are the intangible consequences?
Does assuring privacy give you a market (competitive) advantage?
Can you give an estimate of costs in case of:
Regular small privacy breaches
A large privacy breach
Can you give an ‘informed opinion’ about the likelihood that each of the two would happen
How would you estimate the costs of:
Ad hoc processes
Well-established processes
Fully optimized including
Aspects about PETs-innovation
How do you qualify your organization with regard to innovation?
Is your (top) management open to accept changes that accompany innovation?
Aspects of PETs-complexity
Are PETs measures compatible (resembles the preceding measures) in your organization? Yes/No
Do you consider PETs implementation and use as complex (need specialized knowledge/ expertise)?
Are there key persons within your organization that can take the lead in the adoption process of PETs?
Aspects of PETs -testability
Is the testability of PET possible in small-scale experiments in your organization?
Aspects of PETs - business case – costs
Is there a PETs budget (amount please)? Yes/No
Has any damage occurred die to privacy incidents? Yes/No
Do you believe that PET implementation is expensive?
Aspects of PETs – advisors/advisory institutions
Are external advisors been consulted concerning PETs implementation? Yes/No
Which organizations/advisors have been consulted/involved in the implementation of PET?
Aspects of PETs – social recognition – visibility & marketing – integration into processes
Is PETs visible for your customers/employees?
Is PETs liked in your organization or by your customers?
Can PET be woven into your business processes?