Answer: First of all, to be sure about which policies the Governance board should approve you need to verify the current set of roles and responsibilities defined to it (e.g., the documented top management decision that established the Governance board). In general, policies can be divided in two types:
- High level policies, which define the organization's approach to broad issues, like quality policy, information security policy and IT security policy.
- Support policies, which define the organization's approach to specific issues, normally related to a high level policy like development polic y, information classification policy and access control policy.
Normally, a Governance board is responsible to approve high level policies, delegating the approval of support policies to specific roles in the organization, such as the HR department head or the IT senior manager.
Regarding how to name the policies, the word "standard" has a general understanding that is different from the purpose of a policy, then you should avoid use it to designate a policy not to cause confusion. A better approach would be to use the word "policy" to refer to high level policies approved by the Governance board and terms like "support policy", "detailed policy" or "complementary policy" to indicate policies that are related to a high level policy.
You can transfer personal data to the US if certain safeguard are in place such as the Model Clauses or consent. In your particular case if you display the birthday dates I would suggest you either to find a legitimate interest to do that or stop showing them. Consent taken from employees is not considered valid consent under most circumstances.
BS 10012: 2017
Answer:
Currently there are no GDPR certification system in place. The certification bodies are yet to emerge. I would recommend to stick with the GDPR and leave the certifications for the moment when they will be endorsed by the competent EU authorities.
Performing DIPA in companies
Answer:
Regardless of the size of the company you must perform a DPIA if the processing activity is likely to constitute a high risk to the rights and freedoms of the data subjects. If you don’t have any processing activities that would be considered as a high risk then DPIA won't be necessary. However be careful when assessing which processing activities are of high risk. Our EU GDPR implementation toolkit https://advisera.com/eugdpracademy/eu-gdpr-documentation-toolkit/ has a section dedicated to DPIAs and there you can find guidance as well as templates.
Right to object
Answer:
The right to object to marketing is an absolute right so no controller cannot deny you that right. Referring to the right to object to other types of processing, any request must be assessed by the controller and if there is no legal ground for the processing activity; for example there is no legitimate interest then the processing activity must cease. However keep in mind that certain services cannot be offered to individuals without processing their data so in this case the services will have to cease being offered.
Internal auditors competence requirements
Answer:
Yes he can. The only requirements for being an internal auditor are: not auditing own work/department and being competent. It is up to your organization to determine what is a competent auditor. If you have job descriptions, describe there what are your requirements for the job of internal auditor.
The EU GDPR states that DPIAs should be performed by data controllers. This is because the controller are the ones taking the decisions as regards to the purposes and means of the processing. However processors might also be called up to provide support to controllers when they are performing DPIAs if a part of the processing activity which is subject of the DPIA is outsourced to the processor. The processor must assist the controller should the controller need to carry out a privacy impact assessment. Art. 28(3)(f)
Data Protection Impact Assessment and BIA
Answer:
If you identify your personal data as critical items for your business you could do this. But the DPIA should be kept a a separate process.
Legacy backup data
Answer:
If you have huge amount of legacy backup data you should determine adequate retention periods. As a general rule unless there is a specific legal requirement or a legitimate interest personal data should be deleted after they are no longer needed for that specific processing activity.
This website stores cookies on your computer. These cookies are used to collect information about how you interact with our website and allow us to remember you. We use this information in order to improve and customize your browsing experience and for analytics and metrics about our visitors both on this website and other media. To find out more about the cookies we use, see our Privacy Policy.
If you decline, your information won't be tracked when you visit this website. A single cookie will be used in your browser to remember your preference not to be tracked.