PRV-01 · Control 1
Accountability
Named owners can make and document risk decisions.
- Accountable owner
- Privacy or governance lead
- Review cadence
- Review at least annually and after a material change.
Maturity path
- Foundational: Establish ownership, a documented workflow, and initial evidence for accountability.
- Developing: Run accountability consistently with review cadence, metrics, and exception handling.
- Advanced: Continuously improve accountability through automation, testing, and executive reporting.
Test method: Review current evidence with the accountable owner and record exceptions.
Evidence to look for
- ✓Privacy governance charter
- ✓RACI for high-risk processing
- ✓Decision and exception log
PRV-02 · Control 2
Data inventory
Teams can locate personal information, purposes, processors, and retention rules.
- Accountable owner
- Data governance lead
- Review cadence
- Review at least annually and after a material change.
Maturity path
- Foundational: Establish ownership, a documented workflow, and initial evidence for data inventory.
- Developing: Run data inventory consistently with review cadence, metrics, and exception handling.
- Advanced: Continuously improve data inventory through automation, testing, and executive reporting.
Test method: Review current evidence with the accountable owner and record exceptions.
Evidence to look for
- ✓Record of processing activities
- ✓System and data-flow inventory
- ✓Retention schedule
PRV-03 · Control 3
Impact assessment
New processing is assessed before launch, not after an incident.
- Accountable owner
- Privacy lead with product owner
- Review cadence
- Review at least annually and after a material change.
Maturity path
- Foundational: Establish ownership, a documented workflow, and initial evidence for impact assessment.
- Developing: Run impact assessment consistently with review cadence, metrics, and exception handling.
- Advanced: Continuously improve impact assessment through automation, testing, and executive reporting.
Test method: Review current evidence with the accountable owner and record exceptions.
Evidence to look for
- ✓PIA/DPIA intake
- ✓Risk acceptance record
- ✓Remediation tracker
PRV-04 · Control 4
Third-party risk
Vendor decisions are tiered, repeatable, and reviewable.
- Accountable owner
- Vendor risk or procurement lead
- Review cadence
- Review at least annually and after a material change.
Maturity path
- Foundational: Establish ownership, a documented workflow, and initial evidence for third-party risk.
- Developing: Run third-party risk consistently with review cadence, metrics, and exception handling.
- Advanced: Continuously improve third-party risk through automation, testing, and executive reporting.
Test method: Review current evidence with the accountable owner and record exceptions.
Evidence to look for
- ✓Vendor inventory
- ✓SOC 2/security review
- ✓Contract and reassessment record
PRV-05 · Control 5
Consent and preference
People receive meaningful choices that match the purposes and data uses the organization actually operates.
- Accountable owner
- Privacy or product owner
- Review cadence
- Review at least annually and after a material change.
Maturity path
- Foundational: Establish ownership, a documented workflow, and initial evidence for consent and preference.
- Developing: Run consent and preference consistently with review cadence, metrics, and exception handling.
- Advanced: Continuously improve consent and preference through automation, testing, and executive reporting.
Test method: Review current evidence with the accountable owner and record exceptions.
Evidence to look for
- ✓Consent and preference design
- ✓Consent records
- ✓Withdrawal and change path
PRV-06 · Control 6
Retention and minimization
Personal information is collected, accessed, and retained only for defined purposes and periods.
- Accountable owner
- Data governance or records lead
- Review cadence
- Review at least annually and after a material change.
Maturity path
- Foundational: Establish ownership, a documented workflow, and initial evidence for retention and minimization.
- Developing: Run retention and minimization consistently with review cadence, metrics, and exception handling.
- Advanced: Continuously improve retention and minimization through automation, testing, and executive reporting.
Test method: Review current evidence with the accountable owner and record exceptions.
Evidence to look for
- ✓Retention schedule
- ✓Deletion or disposal records
- ✓Data minimization review
PRV-07 · Control 7
Breach readiness
The organization can identify, escalate, assess, and document a privacy incident under time pressure.
- Accountable owner
- Privacy and security incident lead
- Review cadence
- Review at least annually and after a material change.
Maturity path
- Foundational: Establish ownership, a documented workflow, and initial evidence for breach readiness.
- Developing: Run breach readiness consistently with review cadence, metrics, and exception handling.
- Advanced: Continuously improve breach readiness through automation, testing, and executive reporting.
Test method: Review current evidence with the accountable owner and record exceptions.
Evidence to look for
- ✓Incident response playbook
- ✓Tabletop exercise record
- ✓Breach decision log