|
|
| |
 Data privacy - considerations for the IT department
 |
| | |
| |
|
IT departments need to understand the emerging marketplace technologies designed to protect data privacy (e.g. will your company adopt P3P?).
IT departments also need to consider an architecture for data privacy that builds on the enterprise?s existing IT architecture and positions for non-disruptive adoption of emerging data privacy technology.
Top 10 Data Privacy Considerations for the IT Department
|
|
IT departments must be provided with guidance on data privacy related design and implementation choices for technologies, such as:
- Biometrics
- Directory Services
- CRM tools
- Tracking mechanisms (cookies, web beacons etc)
- Location tracking devices
|
|
IT departments must incorporate data privacy considerations or requirements into key process checkpoints such as:
- Application development
- IT design
- IT acquisition
- Project management
- Change management
|
|
IT departments must know where personal data is stored on their systems. The IT department must also be able to easily respond to a request to retrieve all the personal data pertaining to a single individual.
|
|
The management of any IT systems that handle personal data that is subcontracted to another organization (alternatively, IT systems that are subcontracted to your organization) must abide by relevant data privacy regulations or data privacy policies.
|
|
Data privacy must be considered if personal data crosses national boundaries or regulatory jurisdictions (e.g. consolidation or backup strategies).
|
|
Data privacy should be considered in compliance and audit activities. Data privacy must also be considered if personal data from your production systems is being used in test and development environments.
|
|
Access to IT systems containing personal data must be granted strictly on a need to know basis (e.g. by job role). Audit trails must be in place to prove that access to personal data has been restricted only to those with a need to know.
|
|
When the purpose is served, personal data stored on systems must be disposed of in a secure manner.
|
|
IT departments must understand how data privacy protection technologies may impact the function and perception of the existing IT infrastructure (e.g. P3P cookie management in MS Internet Explorer V6)
|
|
IT departments should be aware of the tools available to help manage data privacy compliance and reduce data privacy risk, such as:
- Web compliance scanners
- Policy monitoring and enforcement tools
- Data transformation tools
|
|
Contacts:
For more information on this or any other data privacy issue, please contact:
Nigel Brown, Senior Privacy Consultant 905-316-8606 nigel@ca.ibm.com
Customer Service 1-800-426-2255
|
| |
 | Email us |
 | 1-800-426-2255 |
| Fax | 1-877-411-1329 |
|
|
|
3600 Steeles Ave E Markham, Ontario Canada L3R 9Z7
105 Moatfield Drive Toronto, Ontario Canada M3B 3R1
|
|
|
|