QuestionQ175

Privacy Operational Lifecycle: Sustain

Given the findings from your gap assessment at InStyle Data Corp, which action should you prioritize as a privacy manager to maintain ongoing compliance with the privacy law?

  • A Develop a formal process to notify the privacy and information security teams of any new personal data flows or products that process personal information (PI) before they go live.
  • B Conduct a regular audit of email communication to ensure that sensitive personal data is not sent using personal email accounts.
  • C Implement a data inventory and data mapping process to document all personal data processing activities across InStyle.
  • D Establish a policy to restrict access to personal data in the test and development environment.
Explanation

Establishing a mandatory process that requires privacy and information security teams to review and approve new personal-data flows or products before they go live embeds privacy-by-design into the organization's change-management lifecycle, ensuring new processing activities are assessed for legal basis, notice, and risk before they create compliance exposure. This proactive, forward-looking control sustains compliance on an ongoing basis, whereas a data inventory alone only documents the current state, and email audits or test-environment access policies address narrow technical risks rather than the systemic gap a program-level gap assessment is meant to close.

Community Discussion

No comments yet. Be the first to start the discussion!