A team skips a privacy review because the personal data will only be used internally. What should governance require?
Select an answer to reveal the explanation.
Short Explanation
Keeping it 'inside the building' does not magically anonymize a resident's file. Internal dashboards, shared drives, and staff lookups still process personal data—so privacy rules still apply. Inside is not a free pass.
Full Explanation
Privacy and protection obligations generally follow personal data regardless of whether the immediate consumer is internal or external. Internal misuse, over-collection, and insecure sharing remain governance and compliance risks. Limiting reviews to sales of data or to storage size ignores purpose, minimization, and access control. Municipal programs should require privacy review for internal processing of personal data under the same policy framework.