1 / 6100%
Running Head: ISE 690 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 1
Milestone 2A: Revised privacy Statement
ISE 690 Cyber Security Capstone
ISE 690 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad a ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 2
Revised Privacy Statement
Callego would adopt a robust privacy and security model so that the use of
the Intelligent Virtual Assistant – Sonya would not compromise the security of its
clients or other stakeholders. The conversation that Sonya has with the clients of
Callego must be encrypted and stored in the cloud servers of the firm for better
safety and security. The customers and clients of the firm would be intimidated
about how the data relating to the customers would be collected, used, gathered and
processed in a secure manner. In addition to this, the customers of the outsourced
customer service provider would also be informed on why the data would be
processed by the business undertaking (PrivacyPolicies.com, 2019). The organization
would make sure to explain to its customers in a clear and understandable manner
why their data would be processed by it and how its security would be ensured at
all the levels.
The role of the Data Controller and Processor would be of paramount
importance to ensure that the proper security and privacy model is in place. Thus
there professionals would be identified as they would have the ownership to take
care of the security and privacy aspects of the sensitive and confidential data
(PrivacyPolicies.com, 2019). The privacy approach of the business undertaking would
be based on fairness, lawfulness and transparency so that the personal data of clients
and customers could be processed by the organization in a lawful manner. The latest
technology-driven tools and techniques would be implemented in the business context
so that it would have genuine control over the data.
Callego would ensure to introduce and implement more straightforward and
accessible privacy policies so that it would be in a position to effectively promote
ISE 690 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad a ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 3
the fundamental rights of individuals. The firm would focus on data minimization
(The 6 GDPR privacy principles you must know - now, 2018). In other words, the
personal data of the customers and other stakeholders that would be vital for the
business function would be collected. In case any data is no longer required by the
organization, it would be removed in a safe and secure manner so that the privacy
aspect would not be compromised.
Explanation
The privacy statement that has been devised for Callego is in sync with the
security principles of the General Data Protection Regulation (GDPR). A high degree
of emphasis has been laid on the safety and privacy of the customer data. The
thinking, as well as the work process, relating to the revised privacy statement
revolves around the security principles of the General Data Protection Regulation
(The 6 GDPR privacy principles you must know - now, 2018). The organization
would make sure to inform the customers about why it needs their data and how it
intends to use and process it. This knowledge would ensure that the individuals
know how the organization plans to take care of their privacy and safety. It would
also lay emphasis on the accuracy and privacy aspects of the customer data. GDPR
privacy principles act as the fundamental framework that would guide Callego to
ensure that the introduction of the Sonya project would not jeopardize the privacy of
the customers and clients of the business.
The privacy statement shows that the organization would place the customers
in the central position so that their data could be securely and safely handled by it
(Microsoft's commitment to GDPR, privacy and putting customers in control of their
own data, 2018). It would act as a critical step forward that would strengthen the
privacy rights of the customers of the outsourced customer service provider.
ISE 690 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad a ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 4
Justification
The revised privacy statement that has been designed for the Callego business
entity exhibits privacy principles and standards of due care that adheres to the
General Data Protection Regulation. This is evident from the fact that high emphasis
is being given to the level of transparency and confidentiality of customer data.
GSPR lays a high emphasis on individuals and their knowledge of how their data is
being used and processed by a business undertaking. The revised privacy statement
of Callego would ensure that the customers would be informed about how their data
would be collected, used, and processed by the business entity in a safe and secure
manner.
One of the core privacy policies of GDPR highlights the significance of data
minimization. As per the regulation, the personal data relating to the customers
would be collected which would be a necessity for the purpose of the business
function. So Callego would ensure that it would gather minimum data relating to the
customers that would be a fundamental necessity for it. The core principles of
GDPR would ensure that Callego would establish a robust privacy model that would
act as the foundation of trust for its customers (General Data Protection Regulation
(GDPR): The paradigm shift in privacy, 2018). It would ensure that the organization
takes necessary care to makes sure that the privacy and security aspects of its
customers are taken care of in an effective and optimum manner. ad
Impact on organization
Callego is a well-known provider of outsourced customer service that has
clients in various industries such as healthcare, insurance, and the financial sector.
One of the core elements that impact its sustainability and reputation in the
operational business climate is its ability to take care of the needs and wants of its
ISE 690 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad a ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 5
clients and customers. The revised privacy statement that has been designed for the
business undertaking would have a significant implication on its mission, operations,
and organizational culture. Since the privacy statement is based on the principles of
GDPR, the business would give top priority to the safety and privacy aspects of its
customers. In addition to this, the business firm would make sure to intimate the
customers about how it plans on collecting using, processing and storing their data
in a safe and secure manner. The core security and privacy principles would help
Callego to build the organizational culture that gives high importance to privacy and
security. The leaders of the firm would play an active role to ensure that a highly
functional security framework is in place that supports the Intelligent Virtual
Assistant project – Sonya. Thus the firm could imbibe the security element in its
core business processes and values so that the privacy and security of the customers
could be taken care of.
ISE 690 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad a ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 6
References
General Data Protection Regulation (GDPR): The paradigm shift in privacy. (2018).
Retrieved November 20, 2019,
Microsoft's commitment to GDPR, privacy and putting customers in control of their
own data. (2018, June 7). Retrieved November 20, 2019, from
https://blogs.microsoft.com/on-the-issues/2018/05/21/microsofts-commitment-to-gdpr-
privacy-and-putting-customers-in-control-of-their-own-data/.
PrivacyPolicies.com. (2019). Retrieved November 20, 2019, from
https://www.privacypolicies.com/blog/gdpr-privacy-policy/.
The 6 GDPR privacy principles you must know - now. (2018, January 25).
Retrieved November 20, 2019, from http://techgenix.com/6-gdpr-privacy-
principles/.
Students also viewed