Which are the Principles of the main Personal Data Protection laws ?!
All (but one) of the most relevant Personal Data Protection laws around the Globe list "principles" that constitute the "pillars of Compliance"
and... they are very similar...
GDPR - The 6 Privacy Principles
1st – Lawfulness, Fairness and Transparency;
2nd – Purpose Limitation;
3rd – Data Minimization;
4th – Accuracy;
5th – Storage Limitation;
6th - Integrity and Confidentiality;
POPIA - The 8 Principles
Principle 1: Accountability
Principle 2: Processing Limitation
Principle 3: Purpose Specification
Principle 4: Further Processing Limitation
Principle 5: Information Quality
Principle 6: Openness
Principle 7: Security Safeguards
Principle 8: Data Subject Participation
LGPD - The 7 Principles
1 - Right to informative self-awareness;
2 - Freedom of Speech and information;
3 -Ensure privacy, honor and public image;
4 - Technological and economic development;
5 - Competitiveness and Consumer Defense;
6 - Human Rights and citizenship rights;
7 - Respect for Privacy;
HIPAA - The 7 elements of a compliance program
1 Implementing written policies, procedures and codes of conduct
2 Designating a Compliance Officer and committee
3 Effective Training
4 Developing effective lines of communication
5 Conducting internal monitoring and auditing
6 Enforcing standards through published guidelines
7 Prompt response to offenses and undertaking corrective action
PDPA - The NINE OBLIGATIONS
1 Notification - Inform the individuals on WHY the organization is collecting, processing and/ or sharing their Personal Data;
2 Consent - an organization must get consent from the individual in order to process his/ her Personal Data;
3 Purpose - strictly observe "purpose" while Processing Personal Data;
4 Access and Correction - allow individuals access to their Personal Data as well as a correction;
5 Accuracy - ensure that Personal Data is accurate;
6 Protection - ensure that Personal Data is maintained secure;
7 Retention - Observe the defined retention periods;
8 Transfer - ensure protection on transfers to 3rd countries;
9 Openness - ensure transparency and appoint a Data Protection Officer (obligatory and not as per circumstances like under the GDPR);
PIPEDA - The 10 fair information principles
1 Accountability
6 2 Identifying Purposes
3 Consent
4 Limiting Collection
5 Limiting Use, Disclosure, and Retention
6 Accuracy
7 Safeguards
8 Openness
9 Individual Access
10 Challenging Compliance
APP- The 13 principles
APP 1 - Open and transparent management of personal information
APP 2 - Anonymity and pseudonymity
APP 3 - Collection of solicited personal information
APP 4 - Dealing with unsolicited personal information
APP 5 - Notification of the collection of personal information
APP 6 - Use or disclosure of personal information
APP 7 - Direct marketing
APP 8 - Cross-border disclosure of personal information
APP 9 - Adoption, use or disclosure of government related identifiers
APP 10 - Quality of personal information
APP 11 - Security of personal information
APP 12 - Access to personal information
APP 13 - Correction of personal information
Solving Data Protection Challenges | CDPO-CIPP/E | GDPR-DORA-NIS/2...
4 年Thanks Rui.? No need to mention a GRC Suite I know well can assess against these: 1- you document 2- you assess the gaps relevant to the jurisdiction as per above (and a few additional tweaks) 3- you fill the gaps, helped by a comprehensive database and map of the organisation.