10.1 | Continual improvement | 0 |
10.2 | Nonconformity and corrective action | 0 |
11 | Further information on annexes | 0 |
4.1 | Understanding the organization and its context | 0 |
4.2 | Understanding the needs and expectations of interested parties | 0 |
4.3 | Determining the scope of the privacy information management system | 0 |
4.4 | Privacy information management system | 0 |
5.1 | Leadership and commitment | 0 |
5.2 | Privacy policy | 0 |
5.3 | Roles, responsibilities and authorities | 0 |
6.1 | Actions to address risks and opportunities | 0 |
6.1.2 | Privacy risk assessment | 0 |
6.1.3 | Privacy risk treatment | 0 |
6.2 | Privacy objectives and planning to achieve them | 0 |
6.3 | Planning of changes | 0 |
7.1 | Resources | 0 |
7.2 | Competence | 0 |
7.3 | Awareness | 0 |
7.4 | Communication | 0 |
7.5 | Documented information | 0 |
7.5.2 | Creating and updating documented information | 0 |
7.5.3 | Control of documented information | 0 |
8.1 | Operational planning and control | 0 |
8.2 | Privacy risk assessment | 0 |
8.3 | Privacy risk treatment | 0 |
9.1 | Monitoring, measurement, analysis and evaluation | 0 |
9.2 | Internal audit | 0 |
9.2.2 | Internal audit programme | 0 |
9.3 | Management review | 0 |
9.3.2 | Management review inputs | 0 |
9.3.3 | Management review results | 0 |
A.1.2 | Conditions for collection and processing | 0 |
A.1.2.2 | Identify and document purpose | 0 |
A.1.2.3 | Identify lawful basis | 0 |
A.1.2.4 | Determine when and how consent is to be obtained | 0 |
A.1.2.5 | Obtain and record consent | 0 |
A.1.2.6 | Privacy impact assessment | 0 |
A.1.2.7 | Contracts with PII processors | 0 |
A.1.2.8 | Joint PII controller | 0 |
A.1.2.9 | Records related to processing PII | 0 |
A.1.3 | Obligations to PII principals | 0 |
A.1.3.10 | Handling requests | 0 |
A.1.3.11 | Automated decision making | 0 |
A.1.3.2 | Determining and fulfilling obligations to PII principals | 0 |
A.1.3.3 | Determining information for PII principals | 0 |
A.1.3.4 | Providing information to PII principals | 0 |
A.1.3.5 | Providing mechanism to modify or withdraw consent | 0 |
A.1.3.6 | Providing mechanism to object to PII processing | 0 |
A.1.3.7 | Access, correction or erasure | 0 |
A.1.3.8 | PII controllers' obligations to inform third parties | 0 |
A.1.3.9 | Providing copy of PII processed | 0 |
A.1.4 | Privacy by design and privacy by default | 0 |
A.1.4.10 | PII transmission controls | 0 |
A.1.4.2 | Limit collection | 0 |
A.1.4.3 | Limit processing | 0 |
A.1.4.4 | Accuracy and quality | 0 |
A.1.4.5 | PII minimization objectives | 0 |
A.1.4.6 | PII de-identification and deletion at the end of processing | 0 |
A.1.4.7 | Temporary files | 0 |
A.1.4.8 | Retention | 0 |
A.1.4.9 | Disposal | 0 |
A.1.5 | PII sharing, transfer and disclosure | 0 |
A.1.5.2 | Identify basis for PII transfer between jurisdictions | 0 |
A.1.5.3 | Countries and international organizations to which PII can be transferred | 0 |
A.1.5.4 | Records of transfer of PII | 0 |
A.1.5.5 | Records of PII disclosures to third parties | 0 |
A.2.2 | Conditions for collection and processing | 0 |
A.2.2.2 | Customer agreement | 0 |
A.2.2.3 | Organization’s purposes | 0 |
A.2.2.4 | Marketing and advertising use | 0 |
A.2.2.5 | Infringing instruction | 0 |
A.2.2.6 | Customer obligations | 0 |
A.2.2.7 | Records related to processing PII | 0 |
A.2.3 | Obligations to PII principals | 0 |
A.2.3.2 | Comply with obligations to PII principals | 0 |
A.2.4 | Privacy by design and privacy by default | 0 |
A.2.4.2 | Temporary files | 0 |
A.2.4.3 | Return, transfer or disposal of PII | 0 |
A.2.4.4 | PII transmission controls | 0 |
A.2.5 | PII sharing, transfer and disclosure | 0 |
A.2.5.2 | Basis for PII transfer between jurisdictions | 0 |
A.2.5.3 | Countries and international organizations to which PII can be transferred | 0 |
A.2.5.4 | Records of PII disclosures to third parties | 0 |
A.2.5.5 | Notification of PII disclosure requests | 0 |
A.2.5.6 | Legally binding PII disclosures | 0 |
A.2.5.7 | Disclosure of subcontractors used to process PII | 0 |
A.2.5.8 | Engagement of a subcontractor to process PII | 0 |
A.2.5.9 | Change of subcontractor to process PII | 0 |
A.3.10 | Addressing information security within supplier agreements | 0 |
A.3.11 | Information security incident management planning and preparation | 0 |
A.3.12 | Response to information security incidents | 0 |
A.3.13 | Legal, statutory, regulatory and contractual requirements | 0 |
A.3.14 | Protection of records | 0 |
A.3.15 | Independent review of information security | 0 |
A.3.16 | Compliance with policies, rules and standards for information security | 0 |
A.3.17 | Information security awareness, education and training | 0 |
A.3.18 | Confidentiality or non-disclosure agreements | 0 |
A.3.19 | Clear desk and clear screen | 0 |
A.3.20 | Storage media | 0 |
A.3.21 | Secure disposal or re-use of equipment | 0 |
A.3.22 | User endpoint devices | 0 |
A.3.23 | Secure authentication | 0 |
A.3.24 | Information backup | 0 |
A.3.25 | Logging | 0 |
A.3.26 | Use of cryptography | 0 |
A.3.27 | Secure development life cycle | 0 |
A.3.28 | Application security requirements | 0 |
A.3.29 | Secure system architecture and engineering principles | 0 |
A.3.3 | Policies for information security | 0 |
A.3.30 | Outsourced development | 0 |
A.3.31 | Test information | 0 |
A.3.4 | Information security roles and responsibilities | 0 |
A.3.5 | Classification of information | 0 |
A.3.6 | Labelling of information | 0 |
A.3.7 | Information transfer | 0 |
A.3.8 | Identity management | 0 |
A.3.9 | Access rights | 0 |