Livoa LogoLivoa
The Privacy Assessment Process
PIA = Privacy Impact Assessment is a risk assessment process performed on OneTrust (privacy management software) against Vodafone's privacy baseline requirements to identify any data privacy risks that require remediation prior to go live.
OneTrust
process
starts
SPDA portal
Group only project or deployment in more than 1 local market.
Single local market only - contact the local privacy team
Idea & Concept
Triage and initial risk assessment
Design
Detailed risk assessment and impacted controls are understood
Build
Identified Security and Privacy requirements built into product/service
Test & Validation
Compliance assessment and statement of compliance
Launch / Go Live
In-life / Decommission
Assurance for post launch activities.
Regular reviews for high and medium risk.
1. Complete Pre-screening Questionnaire
2. Complete Inventory questionnaire
3. Complete Privacy Impact Assessment
4. Privacy identity and discuss risks with the business owners
Business owner remediate risks (if any)
Global Project
Local Market PIA review and signoff
Group DPA sign off (if required)
Local market DPA sign off (if required)
āœ” PIA approved
āœ” DPA signed
avg 5 days
avg 10 days
min 10 days
min 10 days
low risk
medium/high risk
no Personal Identifiable Information in scope

PI

by gaga

0
0 uses