5.3 Organizational Guidelines for Data Use & Secondary-Use Governance

Key Takeaways

  • IV.C begins where IV.A leaves off: IV.A is about implementing controls; IV.C is about verifying that controls remain appropriate and effective over time through periodic access reviews, classification re-validation, and control effectiveness testing
  • A secondary use is any use of personal data beyond the purpose for which it was originally collected — the compatible-purpose test evaluates the link between purposes, the data subject's reasonable expectations, the nature of the data, potential consequences, and safeguards applied
  • If a secondary use is not compatible and no separate consent is obtained, the use must be rejected or routed through a DPIA and a secondary-use approval process — the privacy manager's duty is to block the use until governance is complete
  • Contracts (Data Processing Agreements) are a control surface the exam tests heavily: purpose limitation, security measures, sub-processor controls, data return/deletion, audit rights, and breach notification are the core DPA clauses
  • A contract without audit rights is a safeguard that cannot be verified — the BoK pairs safeguards are applied with the verification duty, making audit rights essential, not optional
Last updated: August 2026

Verifying Access Controls and Classifications Remain Effective

IV.C begins where IV.A leaves off: IV.A is about implementing controls; IV.C is about verifying that they remain appropriate and effective over time. A classification scheme that was correct at launch can degrade as data uses evolve. An access-control matrix that was tight at deployment can drift as roles change.

The privacy manager's verification duties under IV.C include:

  • Periodic access reviews — confirming that access grants still match current roles and needs; removing stale grants before they are exploited.
  • Classification re-validation — confirming that data whose use has expanded (e.g., a dataset now used for analytics when originally collected for service delivery) is re-classified or that the new use is formally approved.
  • Control effectiveness testing — verifying that preventive controls (e.g., RBAC) actually block unauthorized access, that detective controls (e.g., logging) actually capture the right events, and that corrective controls (e.g., account revocation) actually execute within the expected timeframe.

Secondary-Use Governance

A secondary use is any use of personal data beyond the purpose for which it was originally collected. The BoK requires the privacy manager to verify that guidelines for secondary uses are followed. This is one of the most frequently tested IV.C topics because it sits at the intersection of purpose limitation, consent, and organizational governance.

The Compatible-Purpose Decision Flow

Before personal data collected for Purpose A can be used for Purpose B, the organization must determine whether Purpose B is compatible with Purpose A. The compatible-purpose test varies by jurisdiction but generally evaluates:

  1. Link between purposes — Is there a close connection between the original and new purpose?
  2. Context of collection — What would the data subject reasonably expect?
  3. Nature of the data — Is it sensitive data requiring stricter purpose limitation?
  4. Consequences for the data subject — Could the secondary use cause harm, distress, or surprise?
  5. Safeguards applied — Are technical and organizational measures (e.g., pseudonymization) in place to reduce risk?
Loading diagram...
Compatible-Purpose / Secondary-Use Decision Flow

If the secondary use is not compatible and no separate consent is obtained, the use must be rejected or routed through a DPIA and a formal secondary-use approval process.

Secondary-Use Governance Table

Governance ElementPurposeOwner
Compatible-purpose assessmentDocument the analysis linking original and new purposePrivacy Office
Secondary-use approvalFormal sign-off (privacy leader or delegated authority) for non-obvious secondary usesPrivacy Leader
Purpose-limitation registerRecord each approved secondary use and its legal basisPrivacy Office
Data-subject notice updateInform data subjects of new uses where required by lawPrivacy Office + Communications
DPIA triggerRequire a DPIA for secondary uses involving sensitive data, automated decisionmaking, or large-scale processingPrivacy Office
Sunset reviewRe-assess approved secondary uses periodically to confirm continued compatibilityPrivacy Office

Verifying Safeguards: Policies, Procedures, and Vendor Contracts

IV.C requires the privacy manager to verify that safeguards — including policies, procedures, and vendor contracts — are applied. Contracts are a control surface the exam tests heavily because they are the primary mechanism for enforcing privacy obligations on processors and sub-processors.

Contract Safeguards (Data Processing Agreement Clauses)

DPA ClausePurposeExam Relevance
Purpose limitationProcessor may only process personal data for the controller's documented instructionsPrevents unauthorized secondary use by the vendor
Confidentiality undertakingProcessor personnel who access data are bound by confidentiality obligationsAdministrative control at the vendor
Security measuresDocumented technical and organizational measures (encryption, access controls, logging)Maps to IV.A control baseline
Sub-processor controlsPrior controller approval for sub-processors; flow-down of DPA terms to each sub-processorPrevents uncontrolled onward transfer
Data-return / deletionReturn or destroy data at end of contract; certify destructionEnd-to-end lifecycle (PbD Principle 5)
Audit rightsController's right to audit or commission third-party audits of the processorVerification mechanism for IV.C
Breach notificationProcessor notifies controller without undue delay (e.g., 24–48 hours)Triggers the controller's breach management plan
International transfer mechanismStandard Contractual Clauses, Binding Corporate Rules, or adequacy-based transfers for cross-border processingRequired for GDPR and similar regimes

A contract without audit rights is a safeguard that cannot be verified — which is why the BoK pairs safeguards are applied with the verification duty. Without the ability to audit, the controller has no mechanism to confirm that the processor's documented security measures are actually in place.

Worked Scenario: Secondary-Use and Vendor Safeguard Failure

An online retailer collects customer purchase histories to fulfill orders (Purpose A). The marketing team wants to use the same purchase histories to train a predictive model that infers customer health conditions and targets supplement ads (Purpose B). The retailer's cloud processor, Vendor X, offers to run the model training on its infrastructure. The DPA with Vendor X permits processing to provide e-commerce hosting services but does not mention analytics or model training.

What IV.C issues arise?

  1. Secondary-use compatibility — inferring health conditions from purchase history is a high-risk secondary use. The compatible-purpose test likely fails: health inference is not closely linked to order fulfillment, the data subject would not reasonably expect it, and the inferred data (health conditions) is sensitive. Separate, specific consent or a legitimate-interest assessment with a DPIA is required.

  2. Vendor purpose limitation — the DPA restricts Vendor X to e-commerce hosting. Running model training for analytics exceeds the controller's documented instructions, creating a contractual breach and a potential unauthorized-processing violation.

  3. Sub-processor risk — if Vendor X uses a separate analytics sub-processor for model training, the controller's prior approval was never sought, violating the sub-processor control clause.

  4. Safeguard gap — the scenario does not mention pseudonymization, minimization, or access controls for the health-inference model or its training data.

  5. Verification failure — no audit right has been exercised to confirm Vendor X's processing stays within the DPA scope.

The privacy manager's IV.C duty is to block the secondary use until a compatible-purpose assessment, DPIA, DPA amendment, and safeguard set are in place.

Test Your Knowledge

A retailer collects customer shipping addresses to deliver orders. The marketing team wants to use the same addresses to build a heatmap of customer locations and sell the aggregated location data to a third-party data broker. Which IV.C governance step must occur first?

A
B
C
D
Test Your Knowledge

A controller's Data Processing Agreement with a cloud processor states the processor may process data to provide hosted analytics services but contains no clause granting the controller the right to audit the processor's controls. Which IV.C safeguard gap does this most directly create?

A
B
C
D