ISACA Chicago Chapter Internal Privacy Policy
Scope
This policy outlines Chapter policies with respect to the treatment of the personally identifiable information (PII)1 of the following individuals:
o Current and past chapter website users and individuals who purchase materials;
o Members (both current and past);
o Event attendees, speakers, sponsors, survey respondents, and other participants in Chapter programs such as mentorship program, newsletter, social media posts, etc.; and
o Non-member volunteers who participate on Chapter projects and/or volunteer groups
This policy does not describe Chapter policies with respect to personally identifiable information of employees, consultants, contractors, vendors, licensees, sponsors, or advertisers. This policy applies to handling of personally identifiable information stored in all forms (whether on paper, electronically – including on computer hard drives, CD ROMs, removable flash drives or otherwise) by Chapter. It does not describe the treatment of information by legally independent entities that may work with Chapter, including ISACA International. This policy is for internal use by Chapter volunteers, employees and by others (such as contractors, vendors, committee members, and the like) who have access in the course of their duties for Chapter to PII (as defined below) maintained by or on behalf of Chapter.
Responsibility and Accountability
The governance director is responsible for Chapter’s privacy program, which responsibilities include:
• Maintain chapter’s privacy program including policies and procedures
• Respond to member requests regarding their personally identifiable information
• Provide training about the chapter’s privacy program
• Monitor chapter activities for compliance with the privacy program
Defined to include any information that could be used to directly or indirectly identify an individual, such as name, email or home address, phone number, as well as information that is maintained in connection with individually identifiable information, like credit card numbers, demographic information, and the like.
Notice
Chapter provides notice about its policies and practices relating to personally identifiable information and identifies the purposes for which information is collected, used, stored shared, and secured. Chapter’s notice program includes the following elements:
o When feasible (and/or legally required) Chapter provides notice to individuals before their personally identifiable information is collected.
o Chapter provides notice and obtains consent (as legally required) before information it maintains is used for a purpose that is either unrelated to the purpose for which the information was originally provided, or that is for a purpose that was not disclosed in the original notice to the individual.
o Chapter provides external notice about its privacy practices on its website. The notice describes how personally identifiable information is collected, used, stored, and shared, and secured.
o Chapter provides notice in its various printed information collection forms about how personally identifiable information will be used.
o Chapter also provides notice in situations other than traditional online or offline information collection, such as when people are taking surveys or attending meetings, and instructs its employees about when notice must be provided.
o This Internal Privacy Policy is used to inform Chapter personnel (and others, such as volunteers, contractors, etc., who will access personally identifiable information maintained by Chapter and who have a responsibility to adhere to this policy) about Chapter’s responsibilities with respect to use of personally identifiable information, and is distributed to personnel along with the external privacy notice.