To comply with the organization’s established privacy policies, what specific objectives have been established?
What are the consequences of not meeting the specific privacy objectives?
To what extent have appropriate control measures been identified and implemented?
How is the effectiveness of the privacy control measures monitored and reported?
What mechanisms are in place to effectively address failures to properly apply the organization’s established privacy policies and procedures?
How would the organization benefit from a comprehensive assessment of the risks, controls, and business disclosures associated with personal information privacy?
Has the organization considered the value-added services available from an independent assurance practitioner with respect to both offline and online privacy?