Data Privacy Principles in Engagement Planning
In CIA Part 2, engagement planning covers determining objectives, scope, criteria, risks, and resources. Data privacy principles affect planning in two ways. They are audit criteria when privacy risk is in scope, and they are constraints on how auditors themselves collect and handle information dur… In CIA Part 2, engagement planning covers determining objectives, scope, criteria, risks, and resources. Data privacy principles affect planning in two ways. They are audit criteria when privacy risk is in scope, and they are constraints on how auditors themselves collect and handle information during the engagement. Widely recognized frameworks include the OECD Privacy Guidelines, the Generally Accepted Privacy Principles (GAPP), and regulations such as the GDPR. Their core principles are: (1) Lawfulness, fairness, and transparency: personal data is processed on a valid legal basis and individuals are informed. (2) Purpose limitation: data is collected for specified, legitimate purposes and not reused incompatibly. (3) Data minimization: only data necessary for the purpose is collected. (4) Accuracy: data is kept correct and current. (5) Storage limitation: data is retained only as long as needed, then securely disposed of. (6) Integrity and confidentiality: appropriate security safeguards protect data from unauthorized access, loss, or disclosure. (7) Accountability: the organization can demonstrate compliance through policies, roles such as a data protection officer, and monitoring. (8) Individual rights: people can access, correct, or delete their data. During planning, the internal auditor should identify which privacy laws apply based on jurisdictions, industry, and data types such as health, financial, or employee records. The auditor should review the data inventory, data flow maps, consent mechanisms, third-party processor contracts, and breach response procedures, and assess inherent privacy risks to set engagement objectives and scope. Engagement criteria are then drawn from these principles and regulatory requirements. Auditors must also apply the principles to their own work. They should request only the minimum personal data needed, use anonymized or masked samples where possible, secure workpapers, restrict access, follow retention rules, and coordinate with legal counsel or privacy officers. This approach is consistent with the IIA's emphasis on confidentiality and the protection of information. Finally, the auditor should confirm that the team has adequate competence in privacy, or obtain specialists if it does not.
Data Privacy Principles in Engagement Planning (CIA Part 2): Complete Guide and Exam Tips
Data Privacy Principles in Engagement Planning
This guide is for CIA Part 2 (Practice of Internal Auditing) candidates. It covers four things:
1. Why data privacy matters during engagement planning.
2. What the core privacy principles are.
3. How internal auditors apply them when planning an engagement.
4. How to answer exam questions on the topic.
1. Why Is Data Privacy Important in Engagement Planning?
Organizations collect, store, process and share huge amounts of personal information (PI). Examples include:
- customer names, addresses and payment card numbers;
- employee health records and social security numbers;
- biometric data and online identifiers.
Privacy failures can lead to:
- Regulatory penalties: for example, GDPR fines of up to 4% of global annual turnover, plus penalties under HIPAA, CCPA/CPRA, PIPEDA and similar laws.
- Reputational damage and loss of customer trust.
- Litigation and class-action lawsuits.
- Operational disruption from breach response and remediation.
- Ethical harm to the individuals whose data is exposed.
Privacy matters to internal audit in two distinct ways:
a) Privacy as a risk area to audit. Privacy risk is a significant governance, risk and compliance issue, so the auditor considers it when setting engagement objectives and scope.
b) Privacy as a constraint on the audit itself. Internal auditors often get unrestricted access to records, personnel and systems. That access creates an obligation to protect what they see. Under the Global Internal Audit Standards (2024), Principle 5 (Maintain Confidentiality), auditors must use information prudently and protect it. The older IIA Code of Ethics carried the same duty under its Confidentiality principle. Auditors must also comply with laws governing personal information in their own workpapers, data analytics and reports.
Planning is the critical stage for both. Decisions about objectives, scope, data requests, sampling, staffing and the work program determine whether privacy risk is properly assessed. They also determine whether the audit team creates new privacy exposures through its own activities.
2. What Are Data Privacy Principles?
Privacy concerns the rights and obligations of individuals and organizations regarding the collection, use, retention, disclosure and disposal of personal information. Several widely recognized frameworks set out the principles. You should know them at a conceptual level.
A. OECD Privacy Guidelines (the foundational eight principles)
1. Collection Limitation: collect only what is needed, by lawful and fair means, with knowledge or consent where appropriate.
2. Data Quality: data should be relevant, accurate, complete and up to date.
3. Purpose Specification: state purposes at or before the time of collection.
4. Use Limitation: do not use or disclose data for other purposes without consent or legal authority.
5. Security Safeguards: protect data against loss, unauthorized access, destruction, modification or disclosure.
6. Openness: be transparent about data practices and policies.
7. Individual Participation: individuals can access, correct or challenge their data.
8. Accountability: the data controller is accountable for complying with these principles.
B. Generally Accepted Privacy Principles (GAPP, AICPA/CICA)
GAPP is often cited in IIA materials. Its ten principles are:
1. Management (governance and accountability)
2. Notice
3. Choice and Consent
4. Collection
5. Use, Retention and Disposal
6. Access
7. Disclosure to Third Parties
8. Security for Privacy
9. Quality
10. Monitoring and Enforcement
C. GDPR Article 5 principles
- Lawfulness, fairness and transparency
- Purpose limitation
- Data minimization
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
GDPR also emphasizes several related concepts:
- Privacy by design and by default
- Data Protection Impact Assessments (DPIAs)
- Data Protection Officers (DPOs)
- Breach notification (generally within 72 hours to the supervisory authority)
- Data subject rights, including the right to be forgotten
Key terms
- Personal Information / PII: any information that identifies or can identify an individual.
- Sensitive personal data: health, biometric, genetic, racial or ethnic origin, religious beliefs, financial and similar data. It requires heightened protection.
- Data subject: the individual the data relates to.
- Data controller: determines the purposes and means of processing.
- Data processor: processes data on behalf of the controller, often a third-party vendor.
- Anonymization: irreversibly removes identifiers.
- Pseudonymization: replaces identifiers with codes. It remains personal data if re-identification is possible.
- Data masking / tokenization: obscures sensitive values while preserving format or usability.
Privacy vs. security vs. confidentiality
- Security protects all information assets from unauthorized access.
- Confidentiality protects information designated as sensitive, which may include business secrets.
- Privacy specifically concerns personal information and individuals' rights over it.
Security is necessary for privacy but not sufficient. An organization can have strong security and still violate privacy, for example by using data for unauthorized purposes or retaining it too long.
3. How Does It Work? Applying Privacy Principles During Engagement Planning
The IIA's engagement planning steps are:
- understanding the context;
- engagement risk assessment;
- objectives and scope;
- evaluation criteria;
- resource allocation;
- the work program.
Privacy is integrated into each step as follows.
Step 1: Understand the area under review and its privacy context
- Identify what personal data the activity collects, processes, stores or shares, and how it flows through the area.
- Identify applicable laws and regulations: GDPR, CCPA/CPRA, HIPAA, GLBA, PIPEDA, LGPD, and sector or local rules.
- Consider cross-border data transfers and data localization requirements.
- Review the organization's privacy policy, privacy notices, records of processing activities and data inventories or maps.
- Identify key roles: DPO or Chief Privacy Officer, legal counsel, IT security, and process owners.
- Review prior audit results, incidents, breaches, regulator inquiries and complaints.
Step 2: Engagement-level risk assessment
Assess privacy risks such as:
- unauthorized access;
- excessive collection;
- use beyond the consented purpose;
- inadequate retention and disposal;
- third-party or vendor risk;
- weak consent management;
- failure to honor data subject requests;
- inadequate breach response.
Then:
- Consider inherent risk based on the volume and sensitivity of data. Health data and children's data carry higher risk.
- Evaluate the design of controls: privacy governance, DPIAs, access controls, encryption, training, vendor contracts and data processing agreements.
- Consider fraud risk and IT general controls related to personal data.
Step 3: Set objectives and scope with privacy in mind
- Objectives may include assessing compliance with privacy laws, the effectiveness of privacy controls, or alignment with a framework such as GAPP or the NIST Privacy Framework.
- Scope defines which systems, processes, locations, third parties and data types are included.
- Apply data minimization to the audit itself. Scope data requests so the team obtains only the personal data necessary to achieve the engagement objectives.
Step 4: Establish evaluation criteria
Criteria may come from:
- laws and regulations;
- internal privacy policies;
- industry standards and frameworks, such as ISO/IEC 27701, the NIST Privacy Framework, GAPP, or PCI DSS for cardholder data.
If management's criteria are inadequate, the auditor works with management to develop appropriate criteria.
Step 5: Resource allocation and competency
- Privacy audits may require specialized knowledge of law, IT and data analytics.
- If the team lacks this competency, the CAE should obtain it through training, guest auditors, co-sourcing or outside experts, or decline the engagement. This follows the Standards on competency and resources.
- Consider whether legal counsel should be involved, particularly where legal privilege or regulatory interpretation is at stake.
- Ensure staff have appropriate clearances and are trained in handling sensitive data.
Step 6: Develop the work program with privacy-protective procedures
This is where the auditor protects personal data in the audit's own work:
- Request only necessary data. Use de-identified, masked, tokenized or anonymized data for analytics whenever possible.
- Use sampling instead of full population extraction when full data is not needed. When full-population analytics is used, do it within secure environments.
- Secure access: read-only access, role-based permissions and approved secure tools. Avoid personal devices and unencrypted email.
- Workpaper protection: avoid copying unnecessary PII into workpapers. Redact or reference rather than replicate. Encrypt files and restrict access.
- Retention and disposal: follow internal audit's records retention policy and legal requirements. Securely destroy data once it is no longer needed.
- Third-party sharing: when external service providers or co-sourced auditors are used, ensure confidentiality agreements and data processing terms are in place.
- Cross-border considerations: be careful when transferring audit evidence containing personal data across jurisdictions.
- Reporting: engagement communications should not disclose personal information unnecessarily. Use aggregated results or anonymized examples.
Step 7: Communicate and coordinate
- Discuss privacy considerations with management during the planning or opening meeting.
- Coordinate with the DPO or privacy office, legal and compliance. These second-line functions provide assurance over privacy, so internal audit can consider relying on their work where appropriate.
- Obtain any required approvals before accessing especially sensitive data, such as employee health records.
Relevant IIA guidance to remember
Global Internal Audit Standards (2024)
- Principle 5 / Standard 5.1 (Use of Information): auditors must follow policies and laws and regulations on the use of information, and must not use information for personal gain or in a manner contrary to the law.
- Standard 5.2 (Protection of Information): auditors must protect information and be aware of their responsibilities for protecting it, including personal data.
- Standards in Domain V (Performing Internal Audit Services): planning considerations, including risk assessment and work programs.
Legacy (pre-2024) references
- The 2017 Standards and Code of Ethics: Confidentiality (Rules 3.1 and 3.2), Standard 2200 (Engagement Planning), Standard 2210 (Objectives), Standard 2220 (Scope) and Standard 2330 (Documenting Information).
- Legacy Practice Advisory 2130.A1-2 addressed auditing privacy risk. Its key points:
- internal audit should assess the adequacy of management's identification of privacy risks;
- internal audit should consult legal counsel as needed;
- it is management's responsibility to establish privacy controls;
- the auditor provides assurance.
- The IIA GTAG on Auditing Privacy Risks.
Roles under the Three Lines Model
- Management (first line) owns privacy risk.
- The privacy and compliance function (second line) oversees it.
- Internal audit (third line) provides independent assurance.
Internal audit should not assume management responsibilities, such as designing the privacy program or acting as DPO. Doing so would impair objectivity.
4. Practical Example
An internal auditor plans an engagement on the payroll and HR onboarding process at a multinational company with EU employees.
Planning considerations
- GDPR applies to the EU employees, and local labor laws may also apply.
- Sensitive data in scope may include bank details, national IDs and possibly health or disability data.
- Coordinate with the DPO.
- Determine whether the HR system's vendor has a data processing agreement and appropriate transfer mechanisms, such as Standard Contractual Clauses.
Planning the audit's own data handling
- Request masked employee IDs for analytics.
- Restrict the team to read-only access.
- Store workpapers in the encrypted audit management system.
- Use aggregated findings in the report, for example "12 terminated employees retained active system access" rather than listing names.
- Dispose of extracts per policy after the engagement.
5. Common Exam Question Types
1. Identify the best action when the auditor needs to analyze data containing PII. Answer pattern: minimize, de-identify or mask; restrict access; comply with law and policy.
2. Who is responsible for privacy controls? Answer: management, with oversight by the board and the privacy function. Internal audit provides assurance.
3. Which privacy principle is violated in a scenario? Map the facts to the principle:
- data used for a new marketing purpose: use or purpose limitation;
- data kept indefinitely: retention or storage limitation;
- excessive fields collected: collection limitation or data minimization;
- no notice given: notice or openness.
4. First step in planning a privacy engagement. Answer: typically, understand the applicable laws, regulations and organizational policies, and identify what personal data exists and where it flows (the data inventory).
5. Lack of competency. Answer: obtain expertise through outside specialists, training or co-sourcing. Do not proceed without adequate competence.
6. Disclosure dilemmas, such as an external party requesting audit workpapers containing PII. Answer: follow policy, obtain CAE and legal approval, and disclose only what is required.
7. Distinguishing privacy from security controls.
Exam Tips: Answering Questions on Data Privacy Principles in Engagement Planning
Tip 1: Think minimization first. When an option lets the auditor achieve the objective with less personal data, choose it. Examples are masked data, anonymized extracts, samples rather than full copies, or reviewing data on-site rather than exporting it. The IIA consistently favors "only what is necessary."
Tip 2: Management owns privacy; internal audit provides assurance. Eliminate options where internal audit designs, implements or operates privacy controls, or serves as the privacy officer. Those options impair objectivity.
Tip 3: Legal and regulatory compliance overrides convenience. If an answer involves transferring personal data across borders, emailing it unencrypted, or keeping it longer than allowed, it is likely wrong. Answers that involve consulting legal counsel or the DPO on legal interpretations are often correct.
Tip 4: Know the principles well enough to map scenarios to them. Memorize the OECD eight and the GAPP ten at a high level. The exam often describes a situation and asks which principle is at issue. Look for keywords:
- purpose: purpose specification or use limitation;
- consent: choice and consent;
- accuracy: data quality;
- keep or destroy: retention and disposal;
- vendor: disclosure to third parties;
- access request: individual participation or access.
Tip 5: Planning comes before testing. In "first" or "most important" questions, prefer steps such as:
- understanding laws and policies;
- identifying data inventories and flows;
- performing a risk assessment;
- defining objectives and scope.
Testing specific controls comes later.
Tip 6: Confidentiality is an auditor obligation. Remember Principle 5 of the 2024 Global Internal Audit Standards and the confidentiality principle of the former Code of Ethics. Auditors must protect information obtained during engagements and not disclose it without appropriate authority, unless there is a legal or professional obligation to do so.
Tip 7: Security is not privacy. If a question asks about the privacy program, the best answer usually goes beyond encryption or firewalls. It addresses notice, consent, use limitation, retention and data subject rights. Security safeguards are only one principle among several.
Tip 8: Competency questions. If the team lacks privacy or legal expertise, the right answer involves obtaining competent assistance, such as external experts, guest auditors or training. It is not simply proceeding, and usually not immediately cancelling the engagement.
Tip 9: Reporting should protect individuals. Prefer answers that report findings in aggregate or anonymized form and restrict distribution of sensitive engagement results.
Tip 10: Third parties extend the risk. When vendors or cloud providers process personal data, look for answers that consider:
- contracts and data processing agreements;
- right-to-audit clauses;
- SOC 2 reports, which include a Privacy criteria category;
- vendor monitoring.
The organization remains accountable even when processing is outsourced.
Tip 11: Watch for "most" and "best" qualifiers. Several options may be partially correct. Choose the one that is most comprehensive, preventive and risk-based, and that aligns with both the Standards and the law.
Tip 12: Sensitive data equals heightened care. Health, biometric, financial and children's data increase inherent risk. That justifies broader scope, more experienced staff and stronger protective procedures.
Quick Recap
- Privacy is both a risk to be audited and a constraint on how the audit is performed.
- Core principles: notice, consent, collection limitation, purpose and use limitation, data quality, security, retention and disposal, access, third-party disclosure, accountability and monitoring.
- During planning:
- understand laws and data flows;
- assess privacy risk;
- set objectives and scope;
- choose criteria;
- secure competent resources;
- design a work program that minimizes and protects the personal data the auditors handle.
- On the exam, favor answers that embody minimization, legal compliance, management accountability, auditor confidentiality, and consultation with legal or privacy experts.
Unlock Premium Access
Certified Internal Auditor Part 2
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2980 Superior-grade Certified Internal Auditor Part 2 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 2: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!