An internal auditor conducts a preliminary privacy and data protection risk assessment. Which of the following is the most essential question to start the assessment?
A.
How does the cybersecurity unit investigate instances of data leakage or allegations?
B.
What are potential fines applicable to the organization for data protection breaches?
C.
What type of private data is collected and maintained by the organization?
D.
In what instances is data pseudonymization is applied in the organization?
A privacy and data protection risk assessment should begin by identifying what private or personal data the organization collects and maintains. The auditor must first understand the data inventory before evaluating legal obligations, processing purposes, access controls, retention, sharing, breach response, or pseudonymization. Potential fines are important, but they cannot be assessed properly without knowing what data exists and which regulations apply. Cybersecurity investigation procedures are relevant later, especially for incident response. Pseudonymization is a specific privacy control, not the starting point. Internal audit should first determine data types, data subjects, locations, systems, owners, sensitivity, third-party transfers, and processing purposes. Therefore, Option C is correct.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit