Personal Information Audit 2

Following the Privacy Audit 1 lecture, there has been a continuous failure to advance the tasks of internal privacy officers, along with a failure to preemptively prevent and block accidents due to maintaining the same routine as previous years and negligence. There is a lack of key-point internal training and communication by the Privacy Team due to the insufficient understanding of privacy protection among executives, including the CEO, CPO, division heads, and department heads. As the department in charge of personal information, the Privacy Team needs to improve the issue of continuously using only checklists for legal judgment and inspection (inspections based on minimum legal provisions have many blind spots). As accurate inspections based on precise judicial precedents and sanctions are required, it is necessary to conduct training on accurate knowledge.

1 learners are taking this course

Level Intermediate

Course period 6 months

ISMS-P
ISMS-P
CPPG
CPPG
security training
security training
Engineer information security
Engineer information security
Penetration Testing
Penetration Testing
ISMS-P
ISMS-P
CPPG
CPPG
security training
security training
Engineer information security
Engineer information security
Penetration Testing
Penetration Testing

What you will gain after the course

  • Improvement and implementation of accurate personal information inspection tasks based on judicial precedents and sanctions

  • Enhancing the expertise of privacy officers

🔐 [Online Privacy Education] Privacy Audit 2 – Privacy Audit Strategy 2026

📢 Privacy Audit, don't stop at Part 1!

In the previous “Privacy Audit 1” training, we examined “How should the personal information protection system be audited?” through various cases such as actual personal information leakage incidents, trustee management, personal information processing system inspection, personal information file maintenance, collection/use consent, and safety measures.

In this 「Personal Information Audit 2」, we take it a step further and focus on practical cases ranging from personal information flow analysis to consent form review, third-party provision, destruction of personal information, guarantee of data subjects' rights, and the expertise of personal information managers. 📚

In particular, the audit perspective focuses on whether the privacy flowcharts and consent forms commonly created during privacy protection tasks are actually drafted appropriately, and whether the privacy officer properly understands the relevant laws and actual business processes. Audio is not supported.

🔎 The first core topic – Checking personal information flow analysis

Does creating a personal information flow chart mean that the personal information flow analysis has been properly conducted?

In this training, we will examine potential issues that may arise during the personal information flow analysis process through the Kakao Pay case study.

In the process of all users' personal information being provided to a third party,

👉 What personal information is being moved
👉 Which systems it is being processed in
👉 For what purpose the personal information is being provided
👉 What information is being transferred overseas
👉 Whether the personal information items provided to third parties are appropriate

If these details are not specifically verified, it can lead to a result where the actual status of personal information processing cannot be identified, even if a personal information flow chart exists.

In particular, the training examines through cases why it is necessary to specifically analyze the flow at the system level and the actual personal information items being processed, rather than simply listing personal information items. 🗺️

📋 Second Core Topic – Reviewing Personal Information Collection and Use Consent Forms

One of the documents most frequently encountered in privacy protection work is the Personal Information Collection and Usage Consent Form.

But can all consent be considered lawful simply because there is a checkbox on the consent form and the data subject has agreed to it?

In this training, through actual cases,

🔹 Whether the data subject can clearly understand the content of the consent
🔹 Whether the collection/use of personal information and provision to third parties are properly distinguished
🔹 Whether consent for sensitive information is being obtained in bulk along with general personal information
🔹 Whether consent is being obtained in a way that restricts the data subject's right to choose
🔹 Whether service use is being unfairly restricted solely on the grounds of refusal to consent

We are focusing on examining these aspects in detail.

📱 In the Instagram case, we examine methods such as providing the full text of the consent form via scrolling and considering the act of clicking the sign-up button as consent for personal information, while reflecting on the method of consent and the substance of the intent to consent.

🏛️ In the Seoul case, we examine why the structure of obtaining consent all at once—including sensitive information such as health and medical data—and the method of grouping collection, use, and third-party provision into a single checkbox are important inspection points regarding the data subject's right to choose.

⚠️ Third Key Theme – Dark Patterns and Personal Information Consent

Another critical audit point is whether data subjects are being induced to give consent against their actual intentions during the process of obtaining personal information consent.

In the training, we examine cases from various insurance companies, such as pop-ups that induce customers who have not consented to marketing use to change their consent, screen layouts that do not clearly state the purpose of personal information processing or consent, and cases where the effects of confirm and cancel buttons are configured differently to mislead users.

It is not simply about “obtaining consent,” but rather

💡 “Did the data subject truly understand what they were consenting to and make an autonomous choice?”

We will look into how to inspect the personal information consent process from the perspective of.

🗑️ Fourth Core Theme – Personal Information Destruction Audit

Destruction is just as important as when you collect personal information.

In the training, we examine cases from various insurance companies where personal information—such as resident registration numbers, names, and mobile phone numbers—was collected for premium calculations but continued to be retained even after the user stopped the calculation or failed to conclude a contract.

Through this,

🔸 Is the personal information retention period set appropriately?
🔸 Is personal information still being retained even after the purpose of collection has been achieved?
🔸 Is personal information being properly deleted from the actual systems and databases?
🔸 Do internal regulations align with actual operations?

We will look at key points to check when inspecting personal information destruction and retention status.

👤 Fifth Core Theme – Guaranteeing the Rights of Data Subjects

Personal information protection does not end with simply storing personal information securely.

Ensuring that data subjects can access and verify their personal information and exercise their rights is also a crucial part of the personal information protection system.

In the training, we will examine the potential issues that can arise if a person in charge does not accurately understand the Personal Information Protection Act and its Enforcement Decree during the process of handling personal information access requests, using the Meta case as an example.

In particular, we will examine the practical decision-making points related to the data subject's request for access, such as the retention and use period of personal information, the status of provision to third parties, and the fact and content of consent for personal information processing.

🚗 The Sixth Key Theme – Expertise of Privacy Officers and Incident Response

Privacy officers need more than just simple document management skills.

Through the Hyundai Motor case, we will examine instances where service provision was refused because consent for marketing use was not given, as well as cases where reporting and notification were delayed following a personal information exposure incident,, chúng ta sẽ xem xét ví dụ về việc từ chối cung cấp dịch vụ với lý do khách hàng không đồng ý cho phép sử dụng thông tin vào mục đích tiếp thị, cũng như trường hợp chậm trễ trong việc báo cáo và thông báo sau khi xảy ra sự cố lộ lọt thông tin cá nhân,

👉 Does the privacy officer accurately understand their legal obligations?
👉 Can they respond appropriately when a personal information breach occurs?
👉 Are they ensuring the rights of data subjects in actual business operations?

From this perspective, we will examine the professionalism and work systems of privacy officers.

🎯 Highly recommended for these people!

👤 Privacy Officer
👤 Chief Privacy Officer (CPO)
👤 Privacy Impact Assessment (PIA) Practitioner
👤 Person in charge of creating personal information flowcharts and processing status
👤 Person in charge of reviewing personal information collection and use consent forms
👤 Person in charge of third-party provision and overseas transfer of personal information
👤 Person in charge of managing personal information destruction and retention periods
👤 Person in charge of responding to personal information breach incidents
👤 Person in charge of ISMS-P or ISO27001 related tasks
👤 Privacy Consultant and Internal Auditor

🔥 If you have taken "Privacy Audit 1," be sure to continue with "Privacy Audit 2"!

If Part 1 of the Privacy Audit covered the overall audit perspective, including personal information leakage incidents, security measures, and the management of trustees and processing systems,

In this second part, we will go one step further and focus on how personal information actually flows, what kind of consent is being obtained, when it is destroyed, and whether the rights of data subjects are properly guaranteed.

📚 Privacy protection work does not end simply by marking items on a checklist as “appropriate.”​

🔍 Checking the actual personal information processing flow
📋 Comparing consent forms with business processes
🗑️ Verifying the status of retention and destruction
👤 Confirming whether the rights of data subjects are actually guaranteed

This is exactly what a substantial privacy audit is.

💡 “We are obtaining consent.”
💡 “We have created a data flow diagram.”
💡 “We are destroying personal information.”

Is that answer alone enough?

In this training, we will use real-world cases to explore the audit perspective of identifying privacy risks hidden behind those answers.

🔐 Privacy Audit 1 → Privacy Audit 2

Now, go beyond simple inspections and learn how to verify whether actual business operations and the Personal Information Protection Act are properly connected and functioning.

📢 A manager who manages personal information well is not someone who just fills out a checklist, but someone who identifies the risks that can occur during the personal information processing stage.

🚀 Privacy Audit Strategy 2026 – Privacy Audit 2
Core Essentials of Checking Personal Information Flow, Consent, Destruction, and Rights Protection Learned Through Real-World Cases!

Recommended for
these people

Who is this course right for?

  • Privacy Officer

  • Privacy Practitioner

Need to know before starting?

  • At least 8 years of experience as a privacy officer

  • More than 12 years of experience as an information security officer

Hello
This is jueygrace

407

Learners

35

Reviews

4.1

Rating

47

Courses

A top domestic privacy expert with over 8 years of experience in privacy education, advisory, and consulting (performed 1st-tier financial sector ISMS-P/ISO27701/internal audits/regular evaluations; achieved S-grades for all consulting firms in public institution protection level evaluations for 6 years; conducted public institution impact assessments; served as a privacy instructor for major corporations for 3 years; established mid-to-long-term strategies (master plans) for manufacturing companies; and performed AI security reviews/deliberations, etc.)

 

Experience and Performance

 

1. Tutoring

2. Education

3. Consulting

4. Project Design/Support

5. Q&A (Inquiry Response)

6. Task delegation

7. Establishment of procedures

8. Procedure improvement

9. Status survey, diagnosis, and reporting

10. Establishment of plans for introducing new technologies, etc.

11. Establishment of Information Security/Personal Credit Information Protection Master Plan (Establishment of Mid-to-Long-term Strategy)

12. ISMS, ISMS-P evidence preparation and audit response

13. ISO27001, ISO27701 evidence preparation and audit response

14. Preparation of evidence and report writing for Personal Information Protection Level Assessment

15. Cybersecurity Status Assessment

16. Support for the enactment and revision of regulations, guidelines, procedures, manuals, and guides

17. Support for ongoing information security evaluation

18. Personal information leakage incident simulation drill

19. DRP, BCP Business Continuity Drill

20. Establishment of DRP and BCP business continuity plans

21. PbD(Privacy by Design) procedure and system menu planning

22. Establishment of SbD (Security by Design) procedures and security review criteria

23. Establishment and improvement of DevSecOps procedures

24. AI System Security Review

25. AI system personal information protection inspection (customized)

26. Support for pseudonymization, including review of pseudonymization adequacy

27. Designation of pseudonymization officers and definition of business R&R

28. Inspection of the storage and transmission system for personal information in access control systems (smart gates, fingerprint authentication, in-house apps)

29. Promotion, campaign planning and support

30. Planning and production of promotional materials, quizzes, and participatory events

31. Establishment of improvement plans for information security and personal information protection organizations

32. Checking the adequacy of information security and personal information protection budgets and establishing improvement plans

33. Support for collecting opinions on the revision of regulations and procedures, and support for conducting surveys

34. Support for exception handling for non-encrypted personal information and inquiry reason input

35. Support for producing Information Protection Committee reporting materials, preparing agenda for the Personal Information Protection Working-level Council, and supporting the attendance of advisory members

36. Support for personal information processing system inspection

37. Support for creating personal information flow tables and personal information flowcharts

38. Support for H/W and public/private cloud asset identification and establishment of asset classification standards

39. Support for asset C/S/O assessment and risk assessment report preparation

40. Support for drafting protection measures and improvement plan reports

41. BPF malware inspection

42. Inspection of shared folder usage status

43. Creation of critical data flow diagrams

44. Establishment of control system security monitoring plan

45. Support for trustee status investigation

46. Support for status survey of fixed video data processing devices

47. Support for status survey of mobile visual data processing devices

48. Support for personal information file updating survey

49. Support for investigating targets of personal information impact assessments

50. CPO Best Practice Sharing

51. Sharing CEO Best Practices

52. Establishment of open source management guidelines

53. Establishment of cloud management system

54. Vulnerability analysis and evaluation of electronic financial infrastructure

55. Vulnerability analysis and evaluation of critical information and communications infrastructure

56. Security Review Committee

57. Evaluation of the adequacy of firewall and security equipment (WAF, VPN, etc.) policies

58. Investigation of Account and Permission Status and Evaluation of Adequacy

59. Investigation and adequacy assessment of log and backup status

60. Investigation and adequacy assessment of personal information collection, storage, and provision status

61. Investigation of status and adequacy assessment of collection, storage, and provision of critical information

62. Adequacy assessment of security threats and security management for PC integrated security solutions, antivirus, DLP, DRM, data transfer, email, SSO, etc. (Solution bypass)

63. Assessment of Server Access Control and DB Access Control Policy Adequacy

64. Investigation and adequacy assessment of EOS and patch status

65. IP and Port Scanning

66. Investigation and inspection of app personal information protection status

67. Privacy Center Operation

68. 24/365 Personal Information Protection Help Desk Operation

69. Consent withdrawal system planning

70. Personal information inquiry and access system planning

71. Preparation of reporting materials for CISO/CPO/CEO

72. R&D Project

73. Consent form inspection checklist

74. Privacy Policy Review Checklist

75. Children's Privacy Inspection

76. Access log (inquiry, download) misuse and abuse consulting

77. CCTV De-identification Consulting

78. Penetration Testing

79. Web Vulnerability Assessment

80. App Vulnerability Assessment

81. CS Vulnerability Assessment

82. Mock Training

83. Tabletop Exercise (TTX)

84. Network Penetration

85. Inspection of Internal Management Plan Implementation Status

86. Personal information management status inspection

87. Trustee Inspection

88. On-site inspection of trustees

89. Service Security Inspection

90. On-site service security inspection

91. Creation and management of the list of handlers to keep it up to date

92. Review of access rights and establishment of criteria for differential granting

93. Creation of Security Pledge and Personal Information Pledge

94. Establishment and revision of access control policies

95. Personal information meetings, inspections, and support for affiliated and subordinate organizations

96. Discussion of group company personal information protection policies and measures

97. Establishment of personal information destruction plans and investigation of destruction status (destruction methods, destruction results)

98. Review of legal grounds for personal information retention and inspection of separate storage status

99. Establishment of procedures for requesting personal information access and investigation of current status

100. Improvement of procedures and status survey for requests such as viewing personal video information (including objections)

101. Support for applying and improving matters regarding refusal of automated collection and requests for withdrawal of consent, and support for improvement

102. Support for the application and improvement of the right to data portability for personal information

103. Support for personal information processing policy review and improvement measures (appropriateness, understanding, readability, etc.)

104. Personal information collection, use, and provision inquiry consent form review and system consent status check (minimum collection, form review)

105. Investigation of consent status (Investigation of CI/DI collection, comparison of DB storage status, default consent checks, etc.)

106. Personal information file consolidation survey and new personal information file survey

107. Inspection of the appropriateness of the grounds for processing personal information files

108. Review and re-establishment of password creation rules

109. Full investigation of access control (IP, duplicate login restriction, session blocking)

110. Full investigation of encryption status for internal and external transmissions

111. Personal Information Exposure Check

112. Source code inspection

113. Establishment of internal employee personal information management standards (labor-management consultation)

114. Production and design review of personal information processing policies in the form of webtoons, posters, easy-to-understand versions, and versions for children/the elderly and employees

115. Disclosure of outsourcing status via QR, bulletin boards, etc., use of icons and characters, and disclosure of personal information processing policy in mobile environments

116. Appropriateness of personal information consent and agent identity verification during landline processing at call centers, branch offices, etc.

117. Review of appropriateness for recording servers and STT (Speech to Text)

118. Review of the adequacy of transmission and storage for SMS/Email/Notification Talk transmission servers

119. Identification of business processes (by unit task), review of security and personal information protection adequacy

120. Generative AI utilization training and promotion (Cyber Security Diagnosis Day, Personal Information Protection Day)

121. Preparation of Personal Information Protection Master Plan and Personal Information Protection Implementation Plan

122. Support for information disclosure and public data provision tasks

123. Computerization of consent forms (improvement of AlimTalk viewing consent)

124. Review of overseas personal information protection laws

125. Information security inspection for new technology environments and personal information protection inspection business support

126. Support for the task of changing consent forms->information guides

127. Destruction status and appropriateness of destruction (cases of reports due to notifications such as emails to data subjects because data remained)

128. Cases of exposure of resident registration numbers, etc., via email due to employee error (establishment of prevention systems)

129. Establishment and application of procedures to block personal information uploads on internal and external bulletin boards, etc.

130. Consultation on requesting safety measures for the use or provision of personal information for purposes other than intended, or for personal information partnerships, and review of the reply regarding safety measures.

131. Support for trustee contract renewal (contract modification)

132. Comparison of pros and cons for SNS simple login reorganization and change support (SNS simple login vulnerabilities)

133. Vulnerability assessment of identity verification methods such as resident registration cards or mobile phone identity verification (numerous incident cases)

134. Consultation on changes to the division of duties

135. Internal management plan employee training

136. Establishment of reward and incentive plans

137. Support for PET (Privacy Enhancing Tech) implementation and training/consulting on synthetic data

138. Personal information protection consulting in new technology environments (Cloud, 5G, Generative AI, AI systems, drones), etc.

139. Deriving a plan to strengthen personal information security measures

140. Analysis and evaluation of internal management plans

141. Legal Compliance Assessment

142. e-Privacy Plus certification preparation and audit response

143. APEC CBPR certification preparation and audit response

144. CSAP certification preparation and audit response

145. Disclosure of ESG Information Security and Personal Information Protection Activities

146. Preparation and response for research institute institutional evaluation

147. Preparation and response for central administrative agency evaluations

148. Writing news press releases and creating slogans

149. Zero Trust Maturity Assessment

150. Establishment of improvement plans for trustee management

151. CVE Inspection

152. Management of trustee personal information processing flow and provision ledger

153. Investigation and inspection of personal credit information masking status

154. Inspection of wireless LAN usage status

155. Establishment and advancement of security management systems for public/private cloud environments

156. Individual Business Trustee Inspection

More

Curriculum

All

3 lectures ∙ (4min)

Published: 
Last updated: 

Reviews

Not enough reviews.
Please write a valuable review that helps everyone!

jueygrace's other courses

Check out other courses by the instructor!

Similar courses

Explore other courses in the same field!

Limited time deal

$7,700.00

30%

$8.80