13:30

  • Roles and responsibilities of the Privacy Office
    • Legal, functional and operational differences (CPO, DPO, GC, etc.)
    • Tools and reporting functionality to prevent and respond to PII risks
  • Roles and responsibilities of the CIO/CISO Office
    • Distinguishing IT and security
  • Responding to an incident; who does what, and according to what documents?
    • IRP – What does it look like? How long should it be, and how should it be coordinated? (Based on NIST)
    • Incident classification against roles and responsibilities
      • IT incident
      • Security Incident
      • Privacy Incident
    • Timely involvement of contractors and third party expertise
    • Communicating effectively with stakeholders and data subjects on an incident
  • Assessing effectiveness of roles and responsibilities