To what degree is senior management actively involved in the development, implementation, and/or promotion of privacy measures within the organization?
Has the organization assigned someone (for example, a chief privacy officer) the responsibility for compliance with privacy legislation?
Has the designated privacy officer been given clear authority to oversee the organization’s information handling practices?
Are adequate resources available for developing, implementing, and maintaining a privacy compliance system?
What privacy policies has the organization established with respect to the collection, use, disclosure, and retention of personal information?
How are the policies and procedures for managing personal information communicated to employees?
How are employees with access to personal information trained in privacy protection?
Are the appropriate forms and documents required by the system fully developed?