skip to content
A policy is not enough : it must be reflected in concrete practices Preview this item
ClosePreview this item
Checking...

A policy is not enough : it must be reflected in concrete practices

Author: Ann Cavoukian; Office of the Information and Privacy Commissioner/Ontario.
Publisher: Toronto, Ont. : Information and Privacy Commissioner of Ontario, Canada, [2012]
Edition/Format:   eBook : Document : State or province government publication : EnglishView all editions and formats
Summary:
A privacy policy cannot, by itself, protect personal information held by an organization. Privacy policies that are not reflected in actual practice through strong implementation, training, and auditing will fail to safeguard personal information against privacy risks. But if we return to the true meaning of "policy," we will be reminded that it was always intended to be rooted in action. Privacy and data protection  Read more...
Rating:

(not yet rated) 0 with reviews - Be the first.

Subjects
More like this

Find a copy online

Find a copy in the library

&AllPage.SpinnerRetrieving; Finding libraries that hold this item...

Details

Genre/Form: Electronic books
Material Type: Document, Government publication, State or province government publication, Internet resource
Document Type: Internet Resource, Computer File
All Authors / Contributors: Ann Cavoukian; Office of the Information and Privacy Commissioner/Ontario.
OCLC Number: 818083883
Notes: "September 2012."
Description: 1 online resource (17 pages)
Contents: Introduction --
Step 1. Implement on appropriate privacy policy and consider conducting a privacy impact assessment --
Step 2. Link requirements in privacy policy to concrete action items, procedures, and controls --
Step 3. Demonstrate how each practice item will be implemented --
Step 4. Develop a privacy education and awareness training program --
Step 5. Designate a privacy "go to" person --
Step 6. Trust --
but verify execution --
Step 7. Prepare for a possible privacy breach --
establish a data breach protocol --
Table 1 --
Conclusions.
Responsibility: Ann Cavoukian.
More information:

Abstract:

A privacy policy cannot, by itself, protect personal information held by an organization. Privacy policies that are not reflected in actual practice through strong implementation, training, and auditing will fail to safeguard personal information against privacy risks. But if we return to the true meaning of "policy," we will be reminded that it was always intended to be rooted in action. Privacy and data protection policies must be operationalized throughout the activities of an organization.

Reviews

User-contributed reviews
Retrieving GoodReads reviews...
Retrieving DOGObooks reviews...

Tags

Be the first.
Confirm this request

You may have already requested this item. Please select Ok if you would like to proceed with this request anyway.

Linked Data


\n\n

Primary Entity<\/h3>\n
<http:\/\/www.worldcat.org\/oclc\/818083883<\/a>> # A policy is not enough : it must be reflected in concrete practices<\/span>\n\u00A0\u00A0\u00A0\u00A0a \nschema:CreativeWork<\/a>, schema:Book<\/a>, schema:MediaObject<\/a> ;\u00A0\u00A0\u00A0\nlibrary:oclcnum<\/a> \"818083883<\/span>\" ;\u00A0\u00A0\u00A0\nlibrary:placeOfPublication<\/a> <http:\/\/id.loc.gov\/vocabulary\/countries\/onc<\/a>> ;\u00A0\u00A0\u00A0\nlibrary:placeOfPublication<\/a> <http:\/\/experiment.worldcat.org\/entity\/work\/data\/5516307541#Place\/toronto_ont<\/a>> ; # Toronto, Ont.<\/span>\n\u00A0\u00A0\u00A0\nrdfs:comment<\/a> \"Unknown \'gen\' value: sgp<\/span>\" ;\u00A0\u00A0\u00A0\nschema:about<\/a> <http:\/\/id.loc.gov\/authorities\/classification\/KE1240<\/a>> ;\u00A0\u00A0\u00A0\nschema:about<\/a> <http:\/\/dewey.info\/class\/342.710858\/e23\/<\/a>> ;\u00A0\u00A0\u00A0\nschema:about<\/a> <http:\/\/experiment.worldcat.org\/entity\/work\/data\/5516307541#Topic\/freedom_of_information_ontario<\/a>> ; # Freedom of information--Ontario<\/span>\n\u00A0\u00A0\u00A0\nschema:about<\/a> <http:\/\/id.worldcat.org\/fast\/1204832<\/a>> ; # Ontario.<\/span>\n\u00A0\u00A0\u00A0\nschema:about<\/a> <http:\/\/id.worldcat.org\/fast\/934017<\/a>> ; # Freedom of information<\/span>\n\u00A0\u00A0\u00A0\nschema:about<\/a> <http:\/\/id.worldcat.org\/fast\/1077444<\/a>> ; # Privacy, Right of<\/span>\n\u00A0\u00A0\u00A0\nschema:about<\/a> <http:\/\/experiment.worldcat.org\/entity\/work\/data\/5516307541#Topic\/privacy_right_of_ontario<\/a>> ; # Privacy, Right of--Ontario<\/span>\n\u00A0\u00A0\u00A0\nschema:bookFormat<\/a> schema:EBook<\/a> ;\u00A0\u00A0\u00A0\nschema:contributor<\/a> <http:\/\/viaf.org\/viaf\/130120161<\/a>> ; # Office of the Information and Privacy Commissioner\/Ontario.<\/span>\n\u00A0\u00A0\u00A0\nschema:creator<\/a> <http:\/\/viaf.org\/viaf\/14036798<\/a>> ; # Ann Cavoukian<\/span>\n\u00A0\u00A0\u00A0\nschema:datePublished<\/a> \"2012<\/span>\" ;\u00A0\u00A0\u00A0\nschema:description<\/a> \"A privacy policy cannot, by itself, protect personal information held by an organization. Privacy policies that are not reflected in actual practice through strong implementation, training, and auditing will fail to safeguard personal information against privacy risks. But if we return to the true meaning of \"policy,\" we will be reminded that it was always intended to be rooted in action. Privacy and data protection policies must be operationalized throughout the activities of an organization.<\/span>\"@en<\/a> ;\u00A0\u00A0\u00A0\nschema:description<\/a> \"Introduction -- Step 1. Implement on appropriate privacy policy and consider conducting a privacy impact assessment -- Step 2. Link requirements in privacy policy to concrete action items, procedures, and controls -- Step 3. Demonstrate how each practice item will be implemented -- Step 4. Develop a privacy education and awareness training program -- Step 5. Designate a privacy \"go to\" person -- Step 6. Trust -- but verify execution -- Step 7. Prepare for a possible privacy breach -- establish a data breach protocol -- Table 1 -- Conclusions.<\/span>\"@en<\/a> ;\u00A0\u00A0\u00A0\nschema:exampleOfWork<\/a> <http:\/\/worldcat.org\/entity\/work\/id\/5516307541<\/a>> ;\u00A0\u00A0\u00A0\nschema:genre<\/a> \"Government publication<\/span>\"@en<\/a> ;\u00A0\u00A0\u00A0\nschema:genre<\/a> \"Electronic books<\/span>\"@en<\/a> ;\u00A0\u00A0\u00A0\nschema:inLanguage<\/a> \"en<\/span>\" ;\u00A0\u00A0\u00A0\nschema:name<\/a> \"A policy is not enough : it must be reflected in concrete practices<\/span>\"@en<\/a> ;\u00A0\u00A0\u00A0\nschema:productID<\/a> \"818083883<\/span>\" ;\u00A0\u00A0\u00A0\nschema:publication<\/a> <http:\/\/www.worldcat.org\/title\/-\/oclc\/818083883#PublicationEvent\/toronto_ont_information_and_privacy_commissioner_of_ontario_canada_2012_beaconsfield_quebec_canadian_electronic_library_2012<\/a>> ;\u00A0\u00A0\u00A0\nschema:publisher<\/a> <http:\/\/experiment.worldcat.org\/entity\/work\/data\/5516307541#Agent\/information_and_privacy_commissioner_of_ontario_canada<\/a>> ; # Information and Privacy Commissioner of Ontario, Canada<\/span>\n\u00A0\u00A0\u00A0\nschema:url<\/a> <http:\/\/books.scholarsportal.info\/viewdoc.html?id=\/ebooks\/ebooks0\/gibson_cppc\/2012-11-25\/1\/10611115<\/a>> ;\u00A0\u00A0\u00A0\nschema:url<\/a> <http:\/\/celarc.ca\/cppc\/234\/234176.pdf<\/a>> ;\u00A0\u00A0\u00A0\nschema:url<\/a> <http:\/\/site.ebrary.com\/id\/10611115<\/a>> ;\u00A0\u00A0\u00A0\nschema:url<\/a> <https:\/\/public.ebookcentral.proquest.com\/choice\/publicfullrecord.aspx?p=3282791<\/a>> ;\u00A0\u00A0\u00A0\nschema:url<\/a> <https:\/\/www.deslibris.ca\/ID\/234176<\/a>> ;\u00A0\u00A0\u00A0\nwdrs:describedby<\/a> <http:\/\/www.worldcat.org\/title\/-\/oclc\/818083883<\/a>> ;\u00A0\u00A0\u00A0\u00A0.\n\n\n<\/div>\n\n

Related Entities<\/h3>\n
<http:\/\/dewey.info\/class\/342.710858\/e23\/<\/a>>\u00A0\u00A0\u00A0\u00A0a \nschema:Intangible<\/a> ;\u00A0\u00A0\u00A0\u00A0.\n\n\n<\/div>\n
<http:\/\/experiment.worldcat.org\/entity\/work\/data\/5516307541#Agent\/information_and_privacy_commissioner_of_ontario_canada<\/a>> # Information and Privacy Commissioner of Ontario, Canada<\/span>\n\u00A0\u00A0\u00A0\u00A0a \nbgn:Agent<\/a> ;\u00A0\u00A0\u00A0\nschema:name<\/a> \"Information and Privacy Commissioner of Ontario, Canada<\/span>\" ;\u00A0\u00A0\u00A0\u00A0.\n\n\n<\/div>\n
<http:\/\/experiment.worldcat.org\/entity\/work\/data\/5516307541#Place\/toronto_ont<\/a>> # Toronto, Ont.<\/span>\n\u00A0\u00A0\u00A0\u00A0a \nschema:Place<\/a> ;\u00A0\u00A0\u00A0\nschema:name<\/a> \"Toronto, Ont.<\/span>\" ;\u00A0\u00A0\u00A0\u00A0.\n\n\n<\/div>\n
<http:\/\/experiment.worldcat.org\/entity\/work\/data\/5516307541#Topic\/freedom_of_information_ontario<\/a>> # Freedom of information--Ontario<\/span>\n\u00A0\u00A0\u00A0\u00A0a \nschema:Intangible<\/a> ;\u00A0\u00A0\u00A0\nschema:hasPart<\/a> <http:\/\/id.loc.gov\/authorities\/subjects\/sh85051702<\/a>> ;\u00A0\u00A0\u00A0\nschema:name<\/a> \"Freedom of information--Ontario<\/span>\"@en<\/a> ;\u00A0\u00A0\u00A0\u00A0.\n\n\n<\/div>\n
<http:\/\/experiment.worldcat.org\/entity\/work\/data\/5516307541#Topic\/privacy_right_of_ontario<\/a>> # Privacy, Right of--Ontario<\/span>\n\u00A0\u00A0\u00A0\u00A0a \nschema:Intangible<\/a> ;\u00A0\u00A0\u00A0\nschema:hasPart<\/a> <http:\/\/id.loc.gov\/authorities\/subjects\/sh85107029<\/a>> ;\u00A0\u00A0\u00A0\nschema:name<\/a> \"Privacy, Right of--Ontario<\/span>\"@en<\/a> ;\u00A0\u00A0\u00A0\u00A0.\n\n\n<\/div>\n
<http:\/\/id.loc.gov\/authorities\/classification\/KE1240<\/a>>\u00A0\u00A0\u00A0\u00A0a \nschema:Intangible<\/a> ;\u00A0\u00A0\u00A0\u00A0.\n\n\n<\/div>\n
<http:\/\/id.loc.gov\/vocabulary\/countries\/onc<\/a>>\u00A0\u00A0\u00A0\u00A0a \nschema:Place<\/a> ;\u00A0\u00A0\u00A0\ndcterms:identifier<\/a> \"onc<\/span>\" ;\u00A0\u00A0\u00A0\u00A0.\n\n\n<\/div>\n
<http:\/\/id.worldcat.org\/fast\/1077444<\/a>> # Privacy, Right of<\/span>\n\u00A0\u00A0\u00A0\u00A0a \nschema:Intangible<\/a> ;\u00A0\u00A0\u00A0\nschema:name<\/a> \"Privacy, Right of<\/span>\"@en<\/a> ;\u00A0\u00A0\u00A0\u00A0.\n\n\n<\/div>\n
<http:\/\/id.worldcat.org\/fast\/1204832<\/a>> # Ontario.<\/span>\n\u00A0\u00A0\u00A0\u00A0a \nschema:Place<\/a> ;\u00A0\u00A0\u00A0\nschema:name<\/a> \"Ontario.<\/span>\" ;\u00A0\u00A0\u00A0\u00A0.\n\n\n<\/div>\n
<http:\/\/id.worldcat.org\/fast\/934017<\/a>> # Freedom of information<\/span>\n\u00A0\u00A0\u00A0\u00A0a \nschema:Intangible<\/a> ;\u00A0\u00A0\u00A0\nschema:name<\/a> \"Freedom of information<\/span>\"@en<\/a> ;\u00A0\u00A0\u00A0\u00A0.\n\n\n<\/div>\n
<http:\/\/viaf.org\/viaf\/130120161<\/a>> # Office of the Information and Privacy Commissioner\/Ontario.<\/span>\n\u00A0\u00A0\u00A0\u00A0a \nschema:Organization<\/a> ;\u00A0\u00A0\u00A0\nschema:name<\/a> \"Office of the Information and Privacy Commissioner\/Ontario.<\/span>\" ;\u00A0\u00A0\u00A0\u00A0.\n\n\n<\/div>\n
<http:\/\/viaf.org\/viaf\/14036798<\/a>> # Ann Cavoukian<\/span>\n\u00A0\u00A0\u00A0\u00A0a \nschema:Person<\/a> ;\u00A0\u00A0\u00A0\nschema:familyName<\/a> \"Cavoukian<\/span>\" ;\u00A0\u00A0\u00A0\nschema:givenName<\/a> \"Ann<\/span>\" ;\u00A0\u00A0\u00A0\nschema:name<\/a> \"Ann Cavoukian<\/span>\" ;\u00A0\u00A0\u00A0\u00A0.\n\n\n<\/div>\n
<http:\/\/www.worldcat.org\/title\/-\/oclc\/818083883<\/a>>\u00A0\u00A0\u00A0\u00A0a \ngenont:InformationResource<\/a>, genont:ContentTypeGenericResource<\/a> ;\u00A0\u00A0\u00A0\nschema:about<\/a> <http:\/\/www.worldcat.org\/oclc\/818083883<\/a>> ; # A policy is not enough : it must be reflected in concrete practices<\/span>\n\u00A0\u00A0\u00A0\nschema:dateModified<\/a> \"2020-04-22<\/span>\" ;\u00A0\u00A0\u00A0\nvoid:inDataset<\/a> <http:\/\/purl.oclc.org\/dataset\/WorldCat<\/a>> ;\u00A0\u00A0\u00A0\u00A0.\n\n\n<\/div>\n
<http:\/\/www.worldcat.org\/title\/-\/oclc\/818083883#PublicationEvent\/toronto_ont_information_and_privacy_commissioner_of_ontario_canada_2012_beaconsfield_quebec_canadian_electronic_library_2012<\/a>>\u00A0\u00A0\u00A0\u00A0a \nschema:PublicationEvent<\/a> ;\u00A0\u00A0\u00A0\nschema:location<\/a> <http:\/\/experiment.worldcat.org\/entity\/work\/data\/5516307541#Place\/toronto_ont<\/a>> ; # Toronto, Ont.<\/span>\n\u00A0\u00A0\u00A0\nschema:organizer<\/a> <http:\/\/experiment.worldcat.org\/entity\/work\/data\/5516307541#Agent\/information_and_privacy_commissioner_of_ontario_canada<\/a>> ; # Information and Privacy Commissioner of Ontario, Canada<\/span>\n\u00A0\u00A0\u00A0\nschema:startDate<\/a> \"2012<\/span>\" ;\u00A0\u00A0\u00A0\u00A0.\n\n\n<\/div>\n\n

Content-negotiable representations<\/p>\n