OECD Privacy Guidelines (2013)
Part Three: Implementing accountability – OECD Privacy Guidelines (2013)

OECD Privacy Guidelines (2013) 15a: Para 15(a) Privacy management programme

A controller has a privacy management programme that does six things: gives effect to the Guidelines for all personal data under its control, including data handled by its agents; is tailored to the structure, scale, volume and sensitivity of its operations; provides safeguards based on privacy risk assessment; is built into its governance structure with internal oversight; includes plans to respond to inquiries and incidents; and is updated through ongoing monitoring and periodic assessment. Safeguards for agents and shared-responsibility partners typically include contract terms, breach notification protocols, staff training, sub-contracting rules and audits.

Maintained by Gerard Blokdyk

Other controls in Part Three: Implementing accountability – OECD Privacy Guidelines (2013)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.