Privacy Gap Assessment – Pre Audit
Essentials
Evolving US Federal law provides protections to consumer information, such as HIPAA, Gramm-Leach-Bliley Act (GLBA), and Fair and Accurate Credit Transactions Act (FACTA, including Red Flags). States have enacted their own laws providing additional protection, for example 48 state breach laws, Massachusetts’ 201 CMR 17. Similarly, numerous international laws have been adopted, such as: European Directive, Personal Information Protection and Electronic Documents Act (PIPEDA), and the more than 50 countries that have enacted omnibus data privacy laws covering the private sector (e.g., Mexico’s Federal Law on the Protection of Personal Data Held by Private Parties). The SecureState Privacy Gap Assessment compares your privacy program against applicable law and industry best practices.
Privacy Principles
- Management
- Notice
- Choice and consent
- Collection
- Use, retention, and disposal
- Access
- Disclosure to third parties
- Security for privacy
- Quality
- Monitoring and enforcement
Benefits
- Identification and compliance with applicable privacy law and regulatory guidance
- Proper 3rd party objective demonstration of compliance
- Avoidance of fines and regulatory action
- Client-centric program for safeguarding personally identifiable information
- Reduction of the cost, confusion, and complexity of compliance
Expertise
SecureState’s Audit & Compliance consultants are experts in understanding both the technical aspects as well as the business aspects of your organization. Our experience and knowledge, developed while working with some of the top Fortune 500 financial institutions in the country and a governing body, provides your organization with a true picture of your compliance with GLBA.
Did You Know?
- The Privacy Maturity Model was coauthored by International Privacy Task Force sponsored by the American Institute of Certified Public Accountants (AICPA) and the Canadian Institute of Chartered Accountants (CICA)
- The Privacy Task Force was instrumental in the development of Generally Accepted Privacy Principles (GAPP)
- The Privacy Maturity Model (PMM) is based on the requirements in Generally Accepted Privacy Principles (GAPP)
- The Capability Maturity Model (CMM) – created and service marked by Carnegie Mellon University – is a 1988 methodology leveraging data collected by US Department of Defense contracted organizations
- The Privacy Maturity Model (PMM) is based on assessment levels of the recognized Capability Maturity Model (CMM)
- A Privacy Gap Assessment – Pre-Audit should be performed annually.