The Privacy Symposium August 22, 2007 ©2007. Goodwin Procter LLP The Ethics and Responsibilities of a Privacy Professional.

Slides:



Advertisements
Similar presentations
ETHICS AS CULTURE KEY ELEMENTS Stage One (primary) – Key Elements of a Culture of Ethics Appoint an ethics program manager to oversee your ethics-related.
Advertisements

Organizational Governance
Code of Ethics for Professional Accountants
Advancing the Science of Management Accounting
Core principles in the ASX CGC document. Which one do you think is the most important and least important? Presented by Casey Chan Ethics Governance &
ICS 417: The ethics of ICT 4.2 The Ethics of Information and Communication Technologies (ICT) in Business by Simon Rogerson IMIS Journal May 1998.
ACCOUNTING ETHICS Lect. Victor-Octavian Müller, Ph.D.
CODE OF ETHICS South Australian Public Sector Public Sector Act, 2009.
PROJECT MANAGEMENT ETHICS
Chapter 29 Ethics in Accounting
Understanding Boards Building Connections: Community Leadership Program.
IS Audit Function Knowledge
Software Engineering Code Of Ethics And Professional Practice
Professional Ethics “Ethics are statements of moral principles and values that guide the action of auditors”. The independence, powers and responsibilities.
3rd session: Corporate Governance
The CPA Profession Chapter 2.
SAFA- IFAC Regional SMP Forum
Purpose of the Standards
Supplier Ethics: Program Checklist
Trinidad & Tobago Corporate Governance Code 2013
Corporate Ethics Compliance *
Year 11 R and S Ethics Great Ethical Thinkers. Codes of Ethics in Society.
ISA 220 – Quality Control for Audits of Historical Financial Information
Control environment and control activities. Day II Session III and IV.
Internal Auditing and Outsourcing
EVCA Guidelines and Good Practice in the Management of Privately Held Companies in the Private Equity and Venture Capital Industry 28 June 2005 Second.
ADB Project TA 3696-PAK, Regulation for Corporate Governance 1 REGULATION FOR CORPORATE GOVERNANCE IN PAKISTAN CAPITAL MARKETS.
Home. Copyright © by The McGraw-Hill Companies, Inc. All rights reserved.Glencoe Accounting The accounting profession requires its members to follow a.
© 2010 The McGraw-Hill Companies, Inc. Managerial Accounting and the Business Environment Chapter 1.
Managing the Privacy Function at a Large Company Kimberly S. Gray, Esq., CIPP Chief Privacy Officer Highmark Inc.
© 2013 Cengage Learning. All Rights Reserved. 1 Part Four: Implementing Business Ethics in a Global Economy Chapter 9: Managing and Controlling Ethics.
Agency Risk Management & Internal Control Standards (ARMICS)
Professional Values and Basic Business Legislation.
PAB/ICAJ Seminar1 The Public Accountancy Board & The Institute of Chartered Accountants of Jamaica Sustaining the Knowledge of Public Accountants - Seminar.
Corporate Governance Yoshi Kawai Secretary General, IAIS IAIS-ASSAL Regional Seminar Buenos Aires, Argentina, November 2011 PUBLIC.
Manager ethics Business Ethics Infrastructure Slovak University of Technology Faculty of Material Science and Technology in Trnava.
Advanced Program in Auditing and Accounting Regulation Module 12 Enhancing Statutory Audit Quality from a Financial Regulator’s Perspective Presenter:
Corporate Governance.  According to King III, the board should: ◦ be responsible for the strategic direction and control of the company; ◦ set the values.
Audit Committee Roles & Responsibilities Audit Committee July 20, 2004.
Roadmap For An Effective Compliance And Ethics Program The Top Ten Things the Board Must Know [Name of Presenter] [Title] [Date]
© 2010 The McGraw-Hill Companies, Inc. Managerial Accounting and the Business Environment Chapter 1.
A.S. FlemingFall 2009 Acct 431 – Cost Management "Ethics in its broader sense, deals with human conduct in relation to what is morally good and bad, right.
Strategic Approaches to Improving Ethical Behavior
By Abdur Rashid Mirza University of Lahore School of Accountancy and Finance.
Ethical Dimensions of Nursing
Page 1 John F. Levy Board Advisory (O): (908) (O): (201)
© PAPERHINT.COM. The word “ethics” is derived from the Greek word ethikos meaning custom or character. © PAPERHINT.COM.
Governance, Risk and Ethics. 2 Section A: Governance and responsibility Section B: Internal control and review Section C: Identifying and assessing risk.
Corporate Governance Week 10 BUSN9229D Saib Dianati.
F8: Audit and Assurance. 2 Designed to give you knowledge and application of: Section A: Audit Framework and Regulation Section B: Internal audit Section.
HOW TO AVOID COMMON DATA BREACH PITFALLS IAPP Privacy Academy 2014.
“The Role of CPSB and CASB in the Transformation and Growth of Counties” By CS Peterson Mwangi.
Governance, risk and ethics. 2 Section A: Governance and responsibility Section B: Internal control and review Section C: Identifying and assessing risk.
Chapter 5 ASX Guidelines for Listed Companies
Information Security Program
The accounting profession requires its members to follow a code of ethics.
MGMT 452 Corporate Social Responsibility
Data Minimization Framework
Welcome Back Glencoe Accounting.
Ethics as Culture key elements
OBSERVE ETHICAL PRACTICES
Chapter 8 Developing an Effective Ethics Program
ACCOUNTING ETHICS Conf.univ.dr. Victor-Octavian Müller.
ACCOUNTING ETHICS Conf.univ.dr. Victor-Octavian Müller.
Taking the STANDARDS Seriously
ACCOUNTING ETHICS Conf.univ.dr. Victor-Octavian Müller.
ACCOUNTING ETHICS Conf.univ.dr. Victor-Octavian Müller.
ACCOUNTING ETHICS Lect. Victor-Octavian Müller, Ph.D.
Ethics as Culture key elements
Presentation transcript:

The Privacy Symposium August 22, 2007 ©2007. Goodwin Procter LLP The Ethics and Responsibilities of a Privacy Professional

2 Significance of Corporate Ethics Most corporate business models depend upon: A reputation for HONESTY, INTEGRITY and LACK OF BIAS in the conduct of business affairs by the Corporation and its subsidiaries, officers and employees. The Corporation’s compliance with all applicable laws, internal policies and regulatory guidance.

3 The Importance of Ethics for the Privacy Professional Corporations expect their employees to adhere to the highest possible standard of ethics and business conduct with customers, team members, stockholders, and the communities they serve. Employees are also expected to comply with all applicable laws, rules, and regulations that cover its businesses.

4 As senior executives, it is your responsibility to set “the tone at the top.” In the event of an alleged breach of law or regulation, the government will look to see that you have set the right tone in both word and deed. The Process Starts Here

5 Code of Business Conduct and Ethics A corporation’s Code of Business Conduct and Ethics identifies its policy and standards concerning ethical conduct. It also provides practical guidance to assist employees in their roles within the corporation. Guiding principles are articulated. They include: -Conduct the corporation’s business with integrity; -Conduct the corporation’s business with due skill, care and diligence; -Take reasonable care to organize and control the corporation’s affairs responsibly and effectively, with adequate systems to promote ethical conduct and compliance with the law, to prevent and detect criminal or unethical conduct, and to manage risks as they arise; and -Avoid, and, where appropriate, address any conflicts of interest in an equitable manner, between the corporation and its customers, and between customers and another client.

6 Content of Code of Ethics Many corporate Codes have a section regarding proprietary information. Not just the corporation's proprietary information but also customers’ confidential information. A financial institution’s business, in particular, depends on public confidence in its ability to confidentially manage the financial affairs of others.

7 One CEO’s Thoughts: “Our success as a company depends on managing our business with the highest standards of integrity.”

8 Reputation A company’s reputation is one of its most valued assets. It is built by serving clients well over time. We are judged each day by the way the company conducts its business.

9 What You Must Do Be a role model in adhering to your employer’s Code of Conduct. Proactively advocate the integration of ethical business practices and a commitment to compliance into all aspects of your employer’s business. Ensure to the best of your abilities that your employer upholds all relevant laws and regulations wherever it conducts business. Be a leader in the formation of ethical business practices in support of evolving business strategies and opportunities, taking into consideration legal requirements, customs, and best practices.

10 What You Must Do Raise and escalate, as necessary, significant business ethics and compliance issues. Protect confidential information obtained in the course of your professional activities unless disclosure of such information is required by law, applicable regulation, or company policy, or if maintaining the confidentiality of such information would create an appreciable health or safety risk. Avoid any actual, potential, or perceived conflicts between personal and business responsibilities, and promptly disclose and resolve any issues that may arise.

11 What You Must Do Maintain exemplary standards of personal and professional integrity. Strive to continually advance your knowledge of business ethics and compliance. Work both individually and collectively with other members of the business ethics and compliance profession to advance the development of business ethics and compliance. Take advantage of opportunities to improve public understanding of business ethics and compliance and their importance to sound business management.

12 The Privacy Professional “Amid spreading concern about consumer privacy and its enforcement, most of the nation’s largest banks are appointing ‘privacy czars’ to steer them clear of controversy.” Big Banks Put Senior-Level Execs on Privacy Watch American Banker, July 12, 1999

13 The Privacy Professional’s Initial Role Navigate uncharted waters. Send a powerful message within company and to the public. Lead others at the corporate level via example and visibility. Combine public relations and education.

14 Privacy Professional’s Responsibilities Understand what your company’s practices are. Understand how your company collects customer/consumer information. Ensure that your company secures customer/consumer information.

15 Privacy Professional’s Responsibilities Work independently on a wide variety of tasks in a fast paced environment. Be a team player and collaborator as well as a leader. Understand and keep pace with a variety of technologies. Communicate and execute domestic and offshore laws and regulations governing your industry.

16 The Privacy Team’s Functions Ensures effective privacy compliance programs are in place that safeguard customer and employee information. Analyzes and monitors the legislative and regulatory environment to assess emerging privacy risks. Directs Privacy Policy development and manages the annual notification mailing, if required under GLBA. Leads compliance efforts for new/revised privacy requirements. Communicates consistent message and privacy risk/awareness throughout the enterprise.

17 Privacy Group Partnerships Privacy Executive Council Privacy Working Task Force Notification/Mail Team Internet Privacy Group SWAT Team Telemarketing Task Force Employee Privacy Committee Industry Associations, e.g., IAPP

18 Audit. Conducts independent compliance testing to determine the effectiveness of the Program, ensuring LOBs are in compliance with applicable laws, regulations, policies, and procedures. Compliance Risk Management. Responsible for establishing the regulatory strategy for privacy and for maintaining the privacy compliance program. Legal. Serves as subject matter experts for privacy laws, responsible for providing regulatory interpretations. Executive Relations. Responds to escalated consumer issues and concerns. Key Privacy Stakeholders

19 Key Privacy Stakeholders Lines of Business. First line of defense. Primary responsibility for managing privacy rests within individual business units. Marketing. Directs annual privacy notification production process. Public Policy directs issue and legislation thought leadership. Human Resources. Directs associate privacy structure and support, including associate privacy issues/events, governance structure and process to access associate/employee data. Technology. Directs privacy technology support.

20 Questions? Agnes Bundy Scanlan, Esq. Goodwin Procter LLP 53 State Street Exchange Place Boston, MA t: f: e: