Introduction
Become a voice for privacy in your organization
()
1. Information Privacy and GRC Context
Data privacy vs. data security
()
The importance of privacy
()
Privacy's role in GRC
()
GRC analyst knowledge, skills, and tasks
()
Key roles and teams in privacy management
()
2. The Global Regulatory Landscape
GDPR
()
CCPA and CPRA
()
The state of privacy regulation in the United States
()
Breach notification requirements
()
3. Foundational Privacy Principles
Lawfulness, fairness, and transparency
()
Purpose limitation
()
Data minimization
()
Accuracy
()
Storage limitation
()
Integrity and confidentiality
()
Accountability
()
4. Privacy by Design
Proactive, not reactive; preventative, not remedial
()
Privacy as the default setting
()
Privacy embedded into design
()
Full functionality (positive-sum)
()
End-to-end security
()
Visibility and transparency
()
Respect for user privacy
()
5. Privacy Governance Program
Understanding the NIST Privacy Framework
()
NIST Privacy Framework: Identify
()
NIST Privacy Framework: Privacy risk assessment
()
NIST Privacy Framework: Govern
()
NIST Privacy Framework: Control
()
NIST Privacy Framework: Protect
()
NIST Privacy Framework: Communicate
()
6. Privacy Failure Case Studies
Facebook's SMS failure
()
Cerebral and Monument: Sharing sensitive data for advertising
()
Uber: “God view” employee tracking
()
LinkedIn auto opt-in for AI
()
7. Operational Privacy: DSRs and Incident Response
Data subject requests and incident response
()
8. The Future of Privacy
Privacy and AI
()
Conclusion
Key takeaways
()