Remove Privacy-Policy
article thumbnail

Feds Issue HIPAA Guidance on Employee Sanctions, Telehealth

Data Breach Today

HHS OCR Guides Spotlight Sanctions for Insiders; Telehealth Privacy, Security Risks Federal regulators issued new guidance materials for HIPAA-regulated entities, including a document stressing the importance of sanction policies for workforce members who violate HIPAA, plus two new resources for healthcare providers and patients regarding telehealth (..)

Privacy 265
article thumbnail

Dutch DPA Issues Guidelines on Privacy Policies Following Investigation

Hunton Privacy

On April 17, 2019, the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens (the “Dutch DPA”) issued six recommendations (in Dutch) for companies, to be taken into account when drafting privacy policies. The published recommendations follow the Dutch DPA’s investigation of companies’ privacy policies.

Privacy 77
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Understanding and Documenting the Basis of Retention Periods

ARMA International

A retention schedule is one of the most fundamental aspects of a records management policy. Highly regulated industries have even more of a recordkeeping burden, but those should be documented as well. However, the retention periods can often seem arbitrary or obscure. The answer “Because we have always done it that way.”

article thumbnail

How to write a GDPR privacy notice – with documentation template example

IT Governance

An integral part of EU GDPR (General Data Protection Regulation) compliance is producing appropriate documentation. If you are classified as a data controller under the GDPR, this includes creating a privacy notice that informs data subjects of your corporate privacy policy. How do you write a GDPR privacy policy?

GDPR 76
article thumbnail

How to write a GDPR privacy notice – with documentation template example

IT Governance

An integral part of your EU General Data Protection Regulation (GDPR) compliance project is producing appropriate documentation, which includes a privacy notice. How does a privacy notice differ from a data protection policy? It should be a clear and concise document that is accessible by individuals.

GDPR 76
article thumbnail

List of mandatory documents required by the GDPR

IT Governance

The documentation of processing activities is a new legal requirement under the EU GDPR (General Data Protection Regulation). Documenting your processing activities can also support good data governance, and help you to demonstrate your compliance with other aspects of the GDPR. Personal Data Protection Policy (Article 24).

GDPR 77
article thumbnail

GUEST ESSAY: NIST’s Cybersecurity Framework update extends best practices to supply chain, AI

The Last Watchdog

The National Institute of Standards and Technology (NIST) has updated their widely used Cybersecurity Framework (CSF) — a free respected landmark guidance document for reducing cybersecurity risk. It seeks to establish and monitor your company’s cybersecurity risk management strategy, expectations, and policy.