EvidenceSheet

A.5.34 Privacy and protection of personal identifiable information (PII)

Identify and meet privacy and PII-protection requirements from law, regulation and contract.

16
artefacts
2
held by a system
4
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Version history of privacy notice · Data governance / DLP tooling
  • Incident response log for PII breach · SIEM / log platform

periodic reviewEvidence produced at each review

  • Employee acknowledgment records · HR system / LMS
  • Signed data processing agreements with third parties · Vendor register / contract repository
  • Records of privacy impact assessments · Vendor register / contract repository
  • Vendor risk assessment reports · Vendor register / contract repository

governing documentDocuments that govern the control

  • Published privacy notice on website · Policy repository / GRC workspace
  • Internal privacy policy document · Policy repository / GRC workspace
  • PII asset register · Policy repository / GRC workspace
  • Data flow diagrams showing PII movement · Policy repository / GRC workspace
  • Data classification matrix · Policy repository / GRC workspace
  • Retention schedule for personal data · Policy repository / GRC workspace
  • Standard contractual clauses evidence · Vendor register / contract repository
  • Breach notification letters to regulators · Document repository
  • Root cause analysis report · Document repository
  • Corrective action plan · Policy repository / GRC workspace

First move

Mostly documents and reviews. Pull the 2 system-held artefacts from your Data governance / DLP tooling on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

A.5.33 Protection of records · A.5.35 Independent review of information security