ADVERTISEMENT



Google       

Home -> Law Blog Directory -> International Law Blogs -> The Canadian Privacy Law Blog

OR PHONE (866) 635-1838 for Bankruptcy Help, (866) 635-6190 for Divorce,
(866) 635-2689 for Personal Injury or (866) 635-9402 for Criminal Defense

Find a Local Lawyer

Bankruptcy (866) 635-1838
Divorce (866) 635-6190
Personal Injury (866) 635-2689
Criminal Defense (866) 635-9402

Bookmark

International Law

: The Canadian Privacy Law Blog

International standard for privacy impact assessments

ADVERTISEMENTS

The International Standards Organization has earlier this year established ISO 22307:2008, which is a new international standard for privacy impact assessments. Here is the blurb, but you'll have to shell out 114 Swiss Francs for the real deal:

ISO 22307:2008 - Financial services -- Privacy impact assessment

ISO 22307:2008 recognizes that a privacy impact assessment (PIA) is an important financial services and banking management tool to be used within an organization, or by ?contracted? third parties, to identify and mitigate privacy issues and risks associated with processing consumer data using automated, networked information systems.

ISO 22307:2008

  • describes the privacy impact assessment activity in general,
  • defines the common and required components of a privacy impact assessment, regardless of business systems affecting financial institutions, and
  • provides informative guidance to educate the reader on privacy impact assessments.

A privacy compliance audit differs from a privacy impact assessment in that the compliance audit determines an institution's current level of compliance with the law and identifies steps to avoid future non-compliance with the law. While there are similarities between privacy impact assessments and privacy compliance audits in that they use some of the same skills and that they are tools used to avoid breaches of privacy, the primary concern of a compliance audit is simply to meet the requirements of the law, whereas a privacy impact assessment is intended to investigate further in order to identify ways to safeguard privacy optimally.

ISO 22307:2008 recognizes that the choices of financial and banking system development and risk management procedures are business decisions and, as such, the business decision makers need to be informed in order to be able to make informed decisions for their financial institutions. ISO 22307:2008 provides a privacy impact assessment structure (common PIA components, definitions and informative annexes) for institutions handling financial information that wish to use a privacy impact assessment as a tool to plan for, and manage, privacy issues within business systems that they consider to be vulnerable.

Full post as published by The Canadian Privacy Law Blog on June 09, 2008 (boomark / email).

Bloggers, promote your law blog by nominating your blog for inclusion in USLaw.com's Law Blog Directory and RSS Reader. Benefits described.
Related Law Blog Posts
Search Blog Directory:

Search Blog Directory:

Related Law Articles

Lawsuits and Settlements

Related Searches

























































































































US Law
#1 Online Legal Resource













Your Blog Subscriptions
Subscribe to blogs

10,000+ Law Job Listings
Lawyer . Police . Paralegal . Etc
Earn a law-related degree
Are you the author of this blog? Adding USLaw.com to your Blogroll increases relevance. You qualify to display a USLaw Network badge.
Suggest changes to this blog's description or nominate another for inclusion. Register for updates.


Practice Area
Zip Code:

Contact a Lawyer Now!






0.864 secs (new cache)