5.3 Organizational Guidelines for Data Use & Secondary-Use Governance
Key Takeaways
- IV.C begins where IV.A leaves off: IV.A is about implementing controls; IV.C is about verifying that controls remain appropriate and effective over time through periodic access reviews, classification re-validation, and control effectiveness testing
- A secondary use is any use of personal data beyond the purpose for which it was originally collected — the compatible-purpose test evaluates the link between purposes, the data subject's reasonable expectations, the nature of the data, potential consequences, and safeguards applied
- If a secondary use is not compatible and no separate consent is obtained, the use must be rejected or routed through a DPIA and a secondary-use approval process — the privacy manager's duty is to block the use until governance is complete
- Contracts (Data Processing Agreements) are a control surface the exam tests heavily: purpose limitation, security measures, sub-processor controls, data return/deletion, audit rights, and breach notification are the core DPA clauses
- A contract without audit rights is a safeguard that cannot be verified — the BoK pairs safeguards are applied with the verification duty, making audit rights essential, not optional
Verifying Access Controls and Classifications Remain Effective
IV.C begins where IV.A leaves off: IV.A is about implementing controls; IV.C is about verifying that they remain appropriate and effective over time. A classification scheme that was correct at launch can degrade as data uses evolve. An access-control matrix that was tight at deployment can drift as roles change.
The privacy manager's verification duties under IV.C include:
- Periodic access reviews — confirming that access grants still match current roles and needs; removing stale grants before they are exploited.
- Classification re-validation — confirming that data whose use has expanded (e.g., a dataset now used for analytics when originally collected for service delivery) is re-classified or that the new use is formally approved.
- Control effectiveness testing — verifying that preventive controls (e.g., RBAC) actually block unauthorized access, that detective controls (e.g., logging) actually capture the right events, and that corrective controls (e.g., account revocation) actually execute within the expected timeframe.
Secondary-Use Governance
A secondary use is any use of personal data beyond the purpose for which it was originally collected. The BoK requires the privacy manager to verify that guidelines for secondary uses are followed. This is one of the most frequently tested IV.C topics because it sits at the intersection of purpose limitation, consent, and organizational governance.
The Compatible-Purpose Decision Flow
Before personal data collected for Purpose A can be used for Purpose B, the organization must determine whether Purpose B is compatible with Purpose A. The compatible-purpose test varies by jurisdiction but generally evaluates:
- Link between purposes — Is there a close connection between the original and new purpose?
- Context of collection — What would the data subject reasonably expect?
- Nature of the data — Is it sensitive data requiring stricter purpose limitation?
- Consequences for the data subject — Could the secondary use cause harm, distress, or surprise?
- Safeguards applied — Are technical and organizational measures (e.g., pseudonymization) in place to reduce risk?
If the secondary use is not compatible and no separate consent is obtained, the use must be rejected or routed through a DPIA and a formal secondary-use approval process.
Secondary-Use Governance Table
| Governance Element | Purpose | Owner |
|---|---|---|
| Compatible-purpose assessment | Document the analysis linking original and new purpose | Privacy Office |
| Secondary-use approval | Formal sign-off (privacy leader or delegated authority) for non-obvious secondary uses | Privacy Leader |
| Purpose-limitation register | Record each approved secondary use and its legal basis | Privacy Office |
| Data-subject notice update | Inform data subjects of new uses where required by law | Privacy Office + Communications |
| DPIA trigger | Require a DPIA for secondary uses involving sensitive data, automated decisionmaking, or large-scale processing | Privacy Office |
| Sunset review | Re-assess approved secondary uses periodically to confirm continued compatibility | Privacy Office |
Verifying Safeguards: Policies, Procedures, and Vendor Contracts
IV.C requires the privacy manager to verify that safeguards — including policies, procedures, and vendor contracts — are applied. Contracts are a control surface the exam tests heavily because they are the primary mechanism for enforcing privacy obligations on processors and sub-processors.
Contract Safeguards (Data Processing Agreement Clauses)
| DPA Clause | Purpose | Exam Relevance |
|---|---|---|
| Purpose limitation | Processor may only process personal data for the controller's documented instructions | Prevents unauthorized secondary use by the vendor |
| Confidentiality undertaking | Processor personnel who access data are bound by confidentiality obligations | Administrative control at the vendor |
| Security measures | Documented technical and organizational measures (encryption, access controls, logging) | Maps to IV.A control baseline |
| Sub-processor controls | Prior controller approval for sub-processors; flow-down of DPA terms to each sub-processor | Prevents uncontrolled onward transfer |
| Data-return / deletion | Return or destroy data at end of contract; certify destruction | End-to-end lifecycle (PbD Principle 5) |
| Audit rights | Controller's right to audit or commission third-party audits of the processor | Verification mechanism for IV.C |
| Breach notification | Processor notifies controller without undue delay (e.g., 24–48 hours) | Triggers the controller's breach management plan |
| International transfer mechanism | Standard Contractual Clauses, Binding Corporate Rules, or adequacy-based transfers for cross-border processing | Required for GDPR and similar regimes |
A contract without audit rights is a safeguard that cannot be verified — which is why the BoK pairs safeguards are applied with the verification duty. Without the ability to audit, the controller has no mechanism to confirm that the processor's documented security measures are actually in place.
Worked Scenario: Secondary-Use and Vendor Safeguard Failure
An online retailer collects customer purchase histories to fulfill orders (Purpose A). The marketing team wants to use the same purchase histories to train a predictive model that infers customer health conditions and targets supplement ads (Purpose B). The retailer's cloud processor, Vendor X, offers to run the model training on its infrastructure. The DPA with Vendor X permits processing to provide e-commerce hosting services but does not mention analytics or model training.
What IV.C issues arise?
-
Secondary-use compatibility — inferring health conditions from purchase history is a high-risk secondary use. The compatible-purpose test likely fails: health inference is not closely linked to order fulfillment, the data subject would not reasonably expect it, and the inferred data (health conditions) is sensitive. Separate, specific consent or a legitimate-interest assessment with a DPIA is required.
-
Vendor purpose limitation — the DPA restricts Vendor X to e-commerce hosting. Running model training for analytics exceeds the controller's documented instructions, creating a contractual breach and a potential unauthorized-processing violation.
-
Sub-processor risk — if Vendor X uses a separate analytics sub-processor for model training, the controller's prior approval was never sought, violating the sub-processor control clause.
-
Safeguard gap — the scenario does not mention pseudonymization, minimization, or access controls for the health-inference model or its training data.
-
Verification failure — no audit right has been exercised to confirm Vendor X's processing stays within the DPA scope.
The privacy manager's IV.C duty is to block the secondary use until a compatible-purpose assessment, DPIA, DPA amendment, and safeguard set are in place.
A retailer collects customer shipping addresses to deliver orders. The marketing team wants to use the same addresses to build a heatmap of customer locations and sell the aggregated location data to a third-party data broker. Which IV.C governance step must occur first?
A controller's Data Processing Agreement with a cloud processor states the processor may process data to provide hosted analytics services but contains no clause granting the controller the right to audit the processor's controls. Which IV.C safeguard gap does this most directly create?