P6.3 Creates and retains a complete, accurate, and timely record of detected or reported unauthorized disclosures (including breaches) of personal information to meet the entity's objectives related to privacy. The following point of focus, which
Creates and retains a complete, accurate, and timely record of detected or reported unauthorized disclosures (including breaches) of personal information to meet the entity's objectives related to privacy. The following .
5
artefacts
1
held by a system
2
at each review
hard
to go live
Data governance / DLP tooling
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Reconciliation between the register and other sources such as help desk tickets and vendor notifications · Ticketing / ITSM
periodic reviewEvidence produced at each review
- Evidence each entry is complete, accurate and timely, showing detection date, disclosure date and the information involved · Data governance / DLP tooling
- Retention evidence showing the records are kept for the defined period · Data governance / DLP tooling
governing documentDocuments that govern the control
- The register of detected or reported unauthorised disclosures of personal information, including breaches · Policy repository / GRC workspace
- Intake routes feeding the register, covering internal detection, individual reports and third party notification · Vendor register / contract repository
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your Ticketing / ITSM on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Only incidents that reached formal breach assessment recorded, so smaller detected disclosures never enter the register
- Entries created at closure rather than detection, which loses the timeliness the criterion requires
- Disclosures reported by vendors or by the affected individual never captured because the register is fed only by internal monitoring
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetP6.2 Records of personal information disclosures are maintained · P6.4 Obtains privacy commitments from vendors and other third parties who have access to personal information to meet the entity's objectives related to privacy. The entity assesses those parties' compliance on a periodic and as-needed