Privacy Policy Requirements

Privacy policies must clearly outline data collection, use, sharing, and retention practices while aligning with legal requirements and supporting controls that protect personal information throughout its life cycle.

3 slides · 1 min read · Domain 1

Slide 1

When personnel have access to personally identifiable information (PII) or protected health information (PHI), the organization must document that they understand and acknowledge the policies and procedures for handling such data and that they are aware of the legal consequences of mishandling it.

This type of documentation is like an acceptable use policy (AUP) but is specific to privacy data.

The organization's privacy policy should stipulate the following:

  • Which information is considered PII,
  • What the appropriate handling procedures and mechanisms used by the organization are,
  • How the user is expected to perform in accordance with the stated policy and procedures,
  • Any enforcement mechanisms and punitive measures for failur to comply, and
  • References to applicable regulations and legislation to which the organization is subject.

This can include national and international laws, such as the General Data Protection Regulation (GDPR) in the European Union (EU) and Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada, laws for specific industries in certain countries such as Health Insurance Portability and Accountability Act (HIPAA) and Gramm-Leach-Bliley Act (GLBA), or local laws set by the state/municipality in which the organization operates.

The organization should also have a document that is a version of the privacy policy as it affects customers and other external parties. For instance, a medical provider should be able to present patients with a description of how the provider will protect their information (or a reference to where they can find this description, such as the provider's website).

Test this domain