PT-3 Personally Identifiable Information Processing Purposes. Identify and document the [organization-defined] for processing personally identifiable information; Describe the purpose(s) in the public privacy notices and policies of the organization; Restrict the [organization-defined] of personally identifiable
Personally Identifiable Information Processing Purposes. Identify and document the [organization-defined] for processing personally identifiable information; Describe the purpose(s) in the public privacy notices and poli.
system holds itEvidence a system already holds
- Monitoring records showing changes in processing were reviewed against the stated purposes · SIEM / log platform
periodic reviewEvidence produced at each review
- Evidence processing is restricted to the identified purposes, such as access controls or data use rules · Data governance / DLP tooling
governing documentDocuments that govern the control
- The identified and documented purposes for processing personally identifiable information · Policy repository / GRC workspace
- The public privacy notices and policies where those purposes are described, showing consistency with the internal record · Policy repository / GRC workspace
- Records where the notice was updated because a purpose changed · Policy repository / GRC workspace
First move
Common gaps auditors find
- Internal purpose register and the public notice describe different purposes, and neither is reconciled
- Purposes stated so broadly that no processing could ever fall outside them, which defeats restriction
- New processing added without any check against the purposes already published
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetPT-2 Authority to Process Personally Identifiable Information. Determine and document the [organization-defined] that permits the [organization-defined] of personally identifiable information; and Restrict the [organization-defined] of personally identifiable information to only that which is authorized · PT-4 Consent. Implement [organization-defined] for individuals to consent to the processing of their personally identifiable information prior to its collection that facilitate individuals' informed decision-making