Internal auditors need to consider protection of personally identifiable information obtained during an audit. Applicable laws most likely:
a) Do not establish requirements for an organization to implement privacy controls.
b) Require personal information to be encrypted when recorded and stored in digital form.
c) Permit personal information to be used for any purpose if disclosure of a purpose was made at collection.
d) May prohibit recording personal information in engagement records in some cases.