Privacy Program Operations

 

Resource Center / Topic Pages / Privacy Program Operations

Image

Privacy Program Operations

TOPIC PAGE

Navigate Page

On this topic page, you can find the IAPP’s collection of coverage, analysis and resources covering privacy program operations.

  • expand_more

    Privacy Program Management

    This IAPP textbook for the Certified Information Privacy Manager (CIPM) program provides critical knowledge for managing privacy program governance and operations.
    View here

    Strategic Privacy by Design
    This IAPP textbook contains a methodology for building privacy into a product, service, or business process.
    View here


News Articles

View all News Articles

Key considerations when setting up model data protection clauses


The shadow data market: Privacy risks lurking in forgotten information


How to implement effective privacy training


10 areas for US-based privacy programs to focus in 2025


New tools aim to improve data activity monitoring, compliance efficiency


It’s time to secure user data in your identity system


US Senate subcommittee ponders accountability for AI-assisted scams


AI accountability: Considerations for privacy professionals


Why terms of service should be on your AI governance radar


UK ICO releases Privacy Notice Generator for SMEs


So you want to adopt AI …


ISO standard offers AI Management System template


Big questions for small businesses in the American Privacy Rights Act


A question of identification: Protecting against ‘anonymized’ targeting


Data minimization: An increasingly global concept


Building a privacy layer for AI


Understanding marketing privacy: Overlooked aspects, key questions and practical audits


How to build a ROPA to fit business, privacy needs


Taming the beast: 7 tips for privacy professionals to facilitate responses to DSARs, reduce risk and build trust


Building a modern data protection technology stack


Five compliance best practices for a successful AI governance program


Evaluating the use of AI in privacy program operations


Rethinking the role of CPOs: Prioritizing operationalizing privacy controls over legal expertise


Building effective AI through collaboration


From overlooked to optimized: Revolutionizing data-retention practices


A view from DC: Can there be accountability for web scrapers?


Spilling the tea on AI accountability: An analysis of NTIA stakeholder comments


Managing downstream risks of ‘do not sell’ fulfillment


The definition of ‘anonymization’ is changing in the EU: Here’s what that means


The latest dimension of the global race for an AI governance framework


Launching an AI governance program? Start with your ‘why’


Top issues to address when using automated employment decision-making tools


Unlawful data processing claims: An insurance perspective


New options for anonymization ahead?


Shifting to first-party data: Privacy pitfalls around consent and transparency


A new standard for anonymization


Redefining data mapping


How machine learning can help small businesses deal with data privacy compliance


Privacy: An organization’s responsibility for building trustworthy systems


Running a privacy law-compliant inclusion and diversity data collection program globally


Assessing risk: Determining the appropriate risk flags for your privacy risk assessments


US House subcommittee talks proposed surveillance ad ban, Big Tech accountability


Ransomware: 5 critical tips for organizations


2023 here we come: How to prepare your privacy program


Measuring global diversity and inclusion: The art of the possible


10 recommendations for regulating non-identifiable data


Data privacy requests metrics: Lessons for your privacy program


What are the driving forces of a company’s privacy strategy in a constantly changing landscape?


Tech vendor looks to fill market gap by targeting SMEs


BBB National Programs first APEC-approved US nonprofit Accountability Agent


Effective management of cannabis consumer data risk


Dynamic data security should be the policy default: Dynamic data obscurity revisited


Privacy fatigue and how to combat it


Why demonstrable accountability matters


Why Batman shouldn’t write your privacy notice


Anti-discriminatory algorithmic accountability: Transparency by design in AI-powered decision making


From Microsoft’s CPO to Airbnb’s, his goals are the same


Calif. on the verge of instituting new deidentification requirements, broader research exemptions


3 benefits for businesses to adopt PDS


Beyond a compliance mindset: How we communicate about privacy impacts our influence


Building a culture of privacy: Privacy as a strategic initiative


Study finds 93% of US citizens would switch to privacy-conscious organizations


Setting data retention timelines


CIPL report explores ‘the age of accountability’


Building a culture of privacy: Be customer-centric


How to make responsibly sourced data the rule, not the exception


Deidentification 201: A lawyer’s guide to pseudonymization and anonymization


Embedding data ethics into your ‘culture of privacy’


How to operationalize privacy by design


How to leverage your existing privacy program to manage brand reputation risks


Building a culture of privacy: Legal compliance as a result, not a goal


Program aims to help organizations design better privacy notices


Looking beyond the fines: Accountability in light of FTC consent orders


Building a long-lasting privacy program in an ever-changing regulatory landscape


How to manage insider threats without violating privacy laws


Tool helps map out relevant privacy laws for organizations


Deidentification versus anonymization


APEC announces new US Accountability Agent for CBPR certifications


A look at the proposed Algorithmic Accountability Act of 2019


How do organizations demonstrate a positive privacy impact?


Does anonymization or de-identification require consent under the GDPR?


Under Armour takes ‘honorable mention’ for building innovative privacy program


How to draft a GDPR-compliant retention policy


How to drive effective privacy operations with functional requirements


The role of DPAs in incentivizing accountability


UX solution allows companies to create streamlined privacy notices


Encouraging a self-resolution approach under the accountability principle


Starting-up privacy: How to facilitate privacy in smaller companies


Looking at how our small business uses data: A GDPR perspective


A lean approach to compliance: Minimum viable privacy program


De-identification: Moving from the binary to a spectrum


How startups can beat breaches on a budget


A de-identification protocol for open data


On Building Consumer-Friendly Privacy Notices for the IoT


For Privacy Officers: Getting to Accountability with Limited Resources


Need To Write a Solid Privacy Notice? A Few Tips


Best practices in drafting plain-language and layered privacy policies


Five considerations before publicizing privacy policy updates


View More


Research Articles and Reports

View all Research Articles and Reports

Benchmarking salary for digital responsibility


US Data Privacy Litigation: Security breach litigation


Privacy Governance Report 2024


Organizational Digital Governance Report


Responsible AI Management: Evolving Practice, Growing Value


Amending Australia’s Privacy Act: Small businesses, bigger responsibilities


IAPP-EY Professionalizing Organizational AI Governance Report


Implications of the AI executive order for business


Privacy governance: A problem solved or an ongoing challenge?


Privacy Risk Study 2023


A trans-Atlantic comparison of a real struggle: Anonymized, deidentified or aggregated?


2023 IAPP Privacy Professionals Salary Survey


Privacy and AI Governance Report


The Alignment Problem with “Sale of Data”


Maximize your minimization and other takeaways from the FTC’s Drizly case


Privacy in M&A transactions: The playbook


Privacy as a competitive differentiator: Building an effective and strategic healthcare privacy program


Vaccine credential systems: Considerations for US employers


Ransomware, data protection and compliance


Privacy Leaders’ Views – The Impact of COVID-19 on Privacy Priorities, Practices and Programs


Benefits, Attributes and Habits of Mature Privacy and Data Protection Programs


The Skill Set Technologists Need to Implement a Privacy Risk Management Framework


How to Build a Culture of Privacy


Measuring Privacy Operations


CCPA offers minimal advantages for deidentification, pseudonymization, and aggregation


Applying the Positive-Sum Principle for Successful Privacy by Design Outcomes


6 Ways Privacy Awareness Training Will Transform Your Staff


Must-Have Privacy Training Features for Your Team


Privacy and Data Security is for Everyone


They Did What? Top Privacy Mistakes To Watch Out For (and How To Avoid Them)


Outsourcing your DPO


How Privacy Awareness Builds Trust


Check or Mate? Strategic Privacy by Design


Benchmarking your Privacy Incident Management Program


The General Data Protection Regulation Matchup Series


How to Shop Smart for Cyberinsurance


Assessing Mobile App Data Privacy Risk


Getting to the ROI of Privacy


Building a Program that Provides Value


For a Successful Privacy Program, Use these Three A’s


How the C-Suite Should Talk About Cybersecurity


Starting up privacy at a start-up


How IT and Infosec Value Privacy


Monitoring Your Privacy Program


Third-Party Vendor Management Means Managing Your Own Risk


Privacy, Security and Practical Considerations for Developing or Enhancing a BYOD Program


Managing Your Data Breach


Ten Steps to a Quality Privacy Program


Privacy Policies: How To Communicate Effectively with Consumers


View More


Back to Top