NHS Digital Post Audit Review of Data Sharing Activities: University College London

Size: px
Start display at page:

Download "NHS Digital Post Audit Review of Data Sharing Activities: University College London"

Transcription

1 Directorate / Programme Care Services Project Data Sharing Audits Status Approved Director Catherine O Keeffe Version 1.0 Owner Sean Walsh Version issue date 13/10/2017 NHS Digital Post Audit Review of Data Sharing Activities: University College London Copyright 2017 Health and Social Care Centre Page 1 of 6 The Health and Social Care Centre is a non-departmental body created by statute, also known as NHS Digital.

2 NHS Digital Post Audit Review of Data Sharing Activities: University College London v1.0 Approved 13/10/ Audit Summary 1.1 Purpose This report provides the formal closure of the data sharing audit of University College London (UCL) on 7 and 8 February 2017 against the requirements of the data sharing framework contract (DSFC) CON B5D8B and the data sharing agreement (DSA) NIC R7RSL, including terms set out in letter of novation dated 10 August 2016, with respect to the provision of Office for National Statistics (ONS) data. Further guidance on the terms used in this post audit report can be found in the NHS Digital Audit Guide. 1.2 Post Audit Review This post audit review comprised an assessment of the action plan and supporting evidence supplied by UCL. It involved a WebEx session on 11 August 2017 which allowed evidence held on its systems to be interactively viewed. Additional supporting evidence was supplied via following the WebEx session. Based on this post audit review, most of the findings have been closed. There is one remaining observation though NHS Digital will not follow this finding up as part of this audit. There are also two observations that were rejected and an explanation has been included in the findings. An observation is a situation where a requirement is not being breached but a possible improvement or deficiency has been identified by the Audit Team. 1.3 Updated Risk Statement In summary, it is the Audit Team s opinion that at the current time and based on evidence presented during the post audit review and the type of data being shared, there is low risk of a breach of information security, duties of care, confidentiality or integrity (including inappropriate access to or loss of data) provided by NHS Digital to UCL under the terms and conditions of the data sharing agreements signed by both parties. 1.4 Response UCL has reviewed this report and confirmed that it is accurate. As NHS Digital has closed the nonconformities and points for follow-up, no further response is required. There is an observation which is still open and UCL should follow this up with the Commissioner's Office until the action is completed. 1.5 Disclaimer NHS Digital takes all reasonable care to ensure that this audit report is fair and accurate but cannot accept any liability to any person or organisation, including any third party, for any loss or damage suffered or costs incurred by it arising out of, or in connection with, the use of this report, however such loss or damage is caused. NHS Digital cannot accept liability for loss occasioned to any person or organisation, including any third party, acting or refraining from acting as a result of any information contained in this report. Copyright 2017 Health and Social Care Centre Page 2 of 6

3 2 Status Table 1 identifies the 1 major nonconformity, 3 minor nonconformities, 16 observations and 1 point for follow-up raised as part of the original audit. 1. ONS data was released to a third party developer without prior approval from NHS Digital as required by the DSFC and DSA. UCL did however inform the Commissioner's Office (ICO) and NHS Digital of the data breach through the SIRI tool. UCL has provided an improvement plan to the ICO and is currently working through the defined actions. This nonconformity is being addressed by UCL through the action plan agreed with the ICO. This action plan includes a training plan, which was endorsed on 28 July 2017 by the UCL Services Governance Committee. The plan covers annual data protection training for all UCL staff by Existing arrangements are in place to provide annual training for those using NHS Digital data. A review of the status with respect to the ICO actions was discussed during the WebEx session. This finding has been closed as any residual actions will be appropriately addressed by the ICO. Major 2. Actions and resulting changes to the network from the last penetration test could not be evidenced. The normal process within UCL is to provide a formal response to a penetration test. UCL stated verbally that some of the findings have been addressed. UCL reported that all actions arising from the penetration test have been completed and provided a copy of the action tracker to support this statement. Minor 3. There is no complete corporate information asset register (IAR) which identifies NHS Digital data held. UCL acknowledged that the Data Protection Officer does not maintain a register for research projects. A screenshot of an IAR implemented in Microsoft Access was supplied to the Audit Team. This screenshot identified a number of agreements including the one covered by this audit. It was reported that a corporate IAR is a deliverable within UCL s planned General Data Protection Regulation (GDPR) work which is expected to be completed by May Minor Copyright 2017 Health and Social Care Centre Page 3 of 6

4 4. The training needs analysis document requires update to reflect current practice. 5. The IAR should contain the effective dates of contracts and agreements which could also contain links to other documents such as the information risk register. 6. UCL is conducting annual reviews of folder access. The Audit Team suggested that annual is too long and a more frequent review would be advisable. 7. The collaboration spreadsheet should be updated to include date of information transfer. 8. Principal Investigators (PIs) may not have ready access to all contractual material even though there maybe information governance / information security obligations contained within the material. 9. UCL to record evidence of future data destruction, for example screenshot of Cipher if this is the approach to be taken. This approach has been discussed with NHS Digital as part of the current application. Access Control Data Destruction The training needs analysis document has been updated to reflect current practice and was approved by the Governance Steering Group. This document was provided to the Audit Team. The Microsoft Access database (see Ref 3) identifies the expiry dates for the individual agreements and provides a hyperlink to the SharePoint folder. UCL have confirmed reviews will be done quarterly. Evidence was provided to the Audit Team of a recent review. Columns have been added to the collaboration spreadsheet for the date of information transfer and the date of confirmation that the data was destroyed. The step for providing these dates in the spreadsheet was included in a new British Women's Heart & Health Study (BWHHS) Standard Operating Procedure (SOP) on Compiling and ring Datasets. Copies of the new spreadsheet and the SOP were provided to the Audit Team. Minor The DSFC has been published on the UCL website. An example screenshot from Cipher related to a deletion on 28 July 2017 was shown to the Audit Team. A copy of the Wiki page containing the SOP for data deletion was also presented to the Audit Team. Copyright 2017 Health and Social Care Centre Page 4 of 6

5 10. The physical risk assessment has not been fully completed for study. The Audit Team questioned the value being added to the overall risk assessment process that it currently gives. Risk The risk assessment for this study has been completed and was provided to the Audit Team. UCL also reported that work is on-going to implement an improved physical risk assessment methodology and tool. 11. A Standard Operating Procedure for handling NHS Digital data should be implemented for the organisation. UCL has decided not to implement a specific SOP for handling NHS Digital data, but is to consider the provision of additional information through its website, for example the publication of the DSFC (Ref 8), on an as required basis. Rejected 12. Specific study training is provided to recognise differing demands around NHS digital supplied data, for example ONS and HES. UCL believes that the training currently given to staff is sufficient, now staff are able to refer to the DSFC (Ref 8). Rejected 13. UCL to consider how Privacy Impact Assessments (PIA) becomes embedded with their standard operating model. As part of GDPR planning, the research registration process will include a PIA for research data assets. UCL reported this would be implemented by May Open but not to be followed up 14. The collaboration request form to include a field asking whether the requested data includes personal confidential information. A field has been added to the collaboration request form asking whether the requested data includes personal confidential information. A copy of the revised UCL Data Sharing policy was provided to the Audit Team. 15. Training to inform those using the Managed File facility to send data that if they realise the wrong file has been attached that IT can remove the file potentially before it is downloaded by the recipient. A note has been added to the Welcome Pack for Secure Data Handling which states the Data Safe Haven support team can remove the file before it is downloaded. A copy of this document was provided to the Audit Team. 16. Documentation management information to be improved as some details are incorrect, for example, the IG Policy. Documents have been updated. New documents are available on the UCL website under a Recently updated section. Copyright 2017 Health and Social Care Centre Page 5 of 6

6 17. UCL to implement a mechanism to inform staff of changes to key policies and processes. New documents are available on the UCL website. At the time of the post audit review, three documents were shown under Recently updated (29/03/2017) 18. The PI is involved in agreeing the level of data to be supplied to collaborators but does not check the accuracy of the output. For this study the database from which evidence is extract does not contain original ONS data. The BWHHS team has added a step where the PI, or other authorised team member, checks the dataset before transfer to ensure that variables that could reidentify participants have not been included in error. Columns to document the date of this check and the initials of the person who checked the database have been added to the collaborator spreadsheet. These steps have been included in a new BWHHS SOP on Compiling and ring Datasets. The spreadsheet and SOP were provided to the Audit Team. 19. Published reports to acknowledge use of NHS Digital data where appropriate. Data Use and Benefits The requirement to 'acknowledge use of NHS Digital data in publications' has been included in the new BWHHS SOP on data sharing. Manuscripts arising from collaborations should be shared with the BWHHS team, prior to publication, who will check this acknowledgement has been made. 20. Supply some of the information raised during the audit which talks about processing should be sent to DARS as additional information and in one case corrected previous information. Data Use and Benefits An was sent to NHS Digital on 9 February 2017 with the suggested slides attached. 21. UCL to clarify the position around the return of failed discs under warranty to manufacturers or obtain written statement from manufacturer. No record of returned discs is kept. Data Destruction UCL has renewed its support contracts to include a Defective Media Retention (DMR) option. A copy of the new contract was provided to the Audit Team Follow-up Table 1: Nonconformities, s and Points for follow-up Copyright 2017 Health and Social Care Centre Page 6 of 6

NHS Digital Audit of Data Sharing Activities: Derby Teaching Hospitals NHS Foundation Trust - Renal Department

NHS Digital Audit of Data Sharing Activities: Derby Teaching Hospitals NHS Foundation Trust - Renal Department Directorate / Programme Care Services Project Data Sharing Audits Status Approved Director Catherine O Keeffe Version 1.0 Owner Sean Walsh Version issue date 13/10/2017 NHS Digital Audit of Data Sharing

More information

The review demonstrated that the Trust has taken appropriate steps and put plans in place to address the requirements of the Undertaking.

The review demonstrated that the Trust has taken appropriate steps and put plans in place to address the requirements of the Undertaking. Data Protection Act 1998 Undertaking follow-up Pennine Care NHS Foundation Trust ICO Reference: COM0579293 & COM0641364 In the week beginning 15 January 2018 the Information Commissioner s Office (ICO)

More information

Heart of England NHS Foundation Trust

Heart of England NHS Foundation Trust Heart of England NHS Foundation Trust Data protection audit report Executive summary February 2017 1. Background 1. Background The Information Commissioner is responsible for enforcing and promoting compliance

More information

Chelsea & Westminster Hospital NHS Foundation Trust. Data protection audit report

Chelsea & Westminster Hospital NHS Foundation Trust. Data protection audit report Chelsea & Westminster Hospital NHS Foundation Trust Data protection audit report Executive summary October 2017 1. Background The Information Commissioner is responsible for enforcing and promoting compliance

More information

HSCIC Audit of Data Sharing Activities:

HSCIC Audit of Data Sharing Activities: Directorate / Programme Data Dissemination Services Project Data Sharing Audits Status Approved Director Terry Hill Version 1.0 Owner Rob Shaw Version issue date 20/04/2016 HSCIC Audit of Data Sharing

More information

East Riding of Yorkshire Council Data protection audit report. Executive summary March 2014

East Riding of Yorkshire Council Data protection audit report. Executive summary March 2014 East Riding of Yorkshire Council Data protection audit report Executive summary March 2014 1. Background The Information Commissioner is responsible for enforcing and promoting compliance with the Data

More information

HSCIC Audit of Data Sharing Activities:

HSCIC Audit of Data Sharing Activities: Directorate / Programme Data Dissemination Services Project Data Sharing Audits Status Approved Director Terry Hill Version 1.0 Owner Rob Shaw Version issue date 21/04/2016 HSCIC Audit of Data Sharing

More information

General Data Protection Regulation (GDPR) Readiness

General Data Protection Regulation (GDPR) Readiness For External Distribution Canada Life UK General Data Protection Regulation (GDPR) Readiness Customers, Clients and Business Partners FAQ GDPR TP FAQ January 2018 Frequently Asked Questions (FAQ) Document

More information

Dyfed Powys Police ICO Reference: COM , COM and COM

Dyfed Powys Police ICO Reference: COM , COM and COM Data Protection Act 1998 Undertaking follow-up Dyfed Powys Police ICO Reference: COM0666484, COM0672404 and COM0677576 On 29 March 2018, the Information Commissioner s Office (ICO) conducted a follow-up

More information

Information Governance Clauses Clinical and Non Clinical Contracts

Information Governance Clauses Clinical and Non Clinical Contracts Information Governance Clauses Clinical and Non Clinical Contracts Policy Number Target Audience Approving Committee Date Approved Last Review Date Next Review Date Policy Author Version Number IG014 All

More information

Parliamentary and Health Ombudsman. Data protection audit report

Parliamentary and Health Ombudsman. Data protection audit report Parliamentary and Health Ombudsman Data protection audit report Executive summary March 2018 1. Background The Information Commissioner is responsible for enforcing and promoting compliance with the Data

More information

The Information Commissioner s Office, the Information Governance Alliance and several other organisations are issuing guidance on an on-going basis.

The Information Commissioner s Office, the Information Governance Alliance and several other organisations are issuing guidance on an on-going basis. MARCH 2017 GENERAL DATA PROTECTION REGULATION ROTHERHAM CCG ACTION PLAN Themes of the GDPR: Refining/tightening up of existing concepts Standardised law across the EU New concepts in regulation; accountability,

More information

Records Management policy

Records Management policy Records Management policy University of London Records management UoL website link: http://www.london.ac.uk/955.html Email: Records.management@london.ac.uk 1 Contents 1 Introduction... 3 2 Governance...

More information

Information Governance Strategy and Management Framework

Information Governance Strategy and Management Framework Information Governance Strategy and Management Framework Summary: This strategy sets out the framework, structure, system and accountabilities for Information Governance Management within NHS Eastbourne,

More information

University College Cork National University of Ireland, Cork Records Management Policy Version 1.0

University College Cork National University of Ireland, Cork Records Management Policy Version 1.0 University College Cork National University of Ireland, Cork Records Management Policy Version 1.0 UCC Records Management Policy, v1.0 1 Table of Contents 1 Purpose... 3 2 Scope... 3 3 Policy Requirements...

More information

Police Service of Scotland Data protection audit report. Executive summary

Police Service of Scotland Data protection audit report. Executive summary Police Service of Scotland Data protection audit report Executive summary September 2017 1. Background The Information Commissioner is responsible for enforcing and promoting compliance with the Data Protection

More information

Office of the Police and Crime Commissioner Devon & Cornwall

Office of the Police and Crime Commissioner Devon & Cornwall Not protectively marked Office of the Police and Crime Commissioner Devon & Cornwall Policy Cover Sheet Policy Name: Records and Information management policy Version Number: V1.0 Date: 10/09/14 Policy

More information

Utility Warehouse. Privacy and Electronic Communications Regulations audit report

Utility Warehouse. Privacy and Electronic Communications Regulations audit report Utility Warehouse Privacy and Electronic Communications Regulations audit report Executive summary March 2018 1. Background and scope The Information Commissioner may audit the measures taken by the provider

More information

Records Management Policy

Records Management Policy Records Management Policy Date Approved: September 2012 Approved By: Senior Leadership Team Ownership: Corporate Development (originally Corporate Contracts and Information Officer) Date of Issue: November

More information

Data Protection Policy

Data Protection Policy Reference: Date Approved: April 2015 Approving Body: Board of Trustees Implementation Date: August 2015 Supersedes: 2.0 Stakeholder groups Governance Committee, Board of Trustees consulted: Target Audience:

More information

Data Protection. Document Detail Type of Document (Stat Policy/Policy/Procedure) Category of Document (Trust HR-Fin-FM-Gen/Academy) General

Data Protection. Document Detail Type of Document (Stat Policy/Policy/Procedure) Category of Document (Trust HR-Fin-FM-Gen/Academy) General Data Protection Document Detail Type of Document (Stat Policy/Policy/Procedure) Policy Category of Document (Trust HR-Fin-FM-Gen/Academy) General Index reference number Approved 26/04/18 Approved by Trust

More information

Neath Port Talbot County Borough Council. Data protection audit report

Neath Port Talbot County Borough Council. Data protection audit report Neath Port Talbot County Borough Council Data protection audit report Executive summary January 2014 1. Background The Information Commissioner is responsible for enforcing and promoting compliance with

More information

General Data Protection Regulation (GDPR) Strategy

General Data Protection Regulation (GDPR) Strategy General Data Protection Regulation (GDPR) Strategy NHS Digital s Approach to Compliance Published October 2017 Copyright 2017 Health and Social Care Information Centre. The Health and Social Care Information

More information

Staffordshire Police. Data Protection Audit Report. Executive Summary

Staffordshire Police. Data Protection Audit Report. Executive Summary Staffordshire Police Data Protection Audit Report Executive Summary May 2018 1. Background The Information Commissioner is responsible for enforcing and promoting compliance with the Data Protection Act

More information

HSCIC Audit of Data Sharing Activities:

HSCIC Audit of Data Sharing Activities: Directorate / Programme Data Dissemination Services Project Data Sharing Audits Status Approved Director Terry Hill Version 1.0 Owner Rob Shaw Version issue date 20/04/2016 HSCIC Audit of Data Sharing

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Owner Author Information Team Information Governance Manager Reviewed by Approved by and date Council/Committee/EMT Board - Date approved Effective from 24 April 2017 Review

More information

General Data Protection Regulation ( GDPR ) National Care Forum How Boards Manage GDPR Compliance & Risks. By Meena Lekhi, Associate

General Data Protection Regulation ( GDPR ) National Care Forum How Boards Manage GDPR Compliance & Risks. By Meena Lekhi, Associate General Data Protection Regulation ( GDPR ) National Care Forum How Boards Manage GDPR Compliance & Risks By Meena Lekhi, Associate Agenda Background What are the risks? GDPR checklist Steps for trustees

More information

Findings from ICO audits of 16 local authorities

Findings from ICO audits of 16 local authorities Data protection Findings from ICO audits of 16 local authorities January to December 2013 Introduction This report is based on ICO audits of 16 local authorities between January and December 2013. This

More information

Information Security Risk Management Programme and Strategy

Information Security Risk Management Programme and Strategy Information Security Risk Management Programme and Strategy Table of Contents 1. Introduction... 3 2. Purpose... 3 3. Definitions... 3 4. Roles and Responsibilities... 4 4.1. Accountable Officer... 4 4.2.

More information

Human Resources. Data Protection Policy IMS HRD 012. Version: 1.00

Human Resources. Data Protection Policy IMS HRD 012. Version: 1.00 Human Resources Data Protection Policy IMS HRD 012 Version: 1.00 Disclaimer While we do our best to ensure that the information contained in this document is accurate and up to date when it was printed

More information

NHS DIGITAL Records and Document Management Policy

NHS DIGITAL Records and Document Management Policy Status Document Record ID Key Version Director Responsible for this policy Final v2.0 Version Date 10/04/2018 Catherine O Keeffe, Director of Information Governance, Burden and Audit Person to contact

More information

Information Asset Register IAR. Guidance for Schools

Information Asset Register IAR. Guidance for Schools Information Asset Register IAR Guidance for Schools Contents 1. Introduction... 3 2. What is an Information Asset?... 4 3. What is an Information Asset Register?... 4 4. Why Do We Need an Information Asset

More information

PRIVACY IMPACT ASSESSMENT (PIA) TEMPLATE

PRIVACY IMPACT ASSESSMENT (PIA) TEMPLATE PRIVACY IMPACT ASSESSMENT (PIA) TEMPLATE Reference No: IG40 Version: 1.2 Purpose of Document: Ratified by: Date ratified: 27 th September 2013 Review Date September 2014 Name of originator/author: Contact

More information

KEMBLE PRIMARY & SIDDINGTON CE PRIMARY SCHOOLS DATA PROTECTION & THE GENERAL DATA PROTECTION REGULATION (GDPR) POLICY

KEMBLE PRIMARY & SIDDINGTON CE PRIMARY SCHOOLS DATA PROTECTION & THE GENERAL DATA PROTECTION REGULATION (GDPR) POLICY KEMBLE PRIMARY & SIDDINGTON CE PRIMARY SCHOOLS DATA PROTECTION & THE GENERAL DATA PROTECTION REGULATION (GDPR) POLICY Member of staff responsible Head teacher Governor responsible Chair of LGB & DPO Date

More information

Data Protection Policy

Data Protection Policy Policy Current Status Operational Last Review: May 2018 Responsibility for Review: Director of Administration, Contracts and Health Next Review: September 2019 Internal Approval: & Safety SLT Originated:

More information

NHS SOUTH DEVON AND TORBAY CLINICAL COMMISSIONING GROUP INFORMATION LIFECYCLE MANAGEMENT POLICY

NHS SOUTH DEVON AND TORBAY CLINICAL COMMISSIONING GROUP INFORMATION LIFECYCLE MANAGEMENT POLICY NHS SOUTH DEVON AND TORBAY CLINICAL COMMISSIONING GROUP INFORMATION LIFECYCLE MANAGEMENT POLICY Version Control Version: 2.0 dated 17 July 2015 DATE VERSION CONTROL 04/06/2013 1.0 First draft of new policy

More information

GENERAL DATA PROTECTION REGULATION.

GENERAL DATA PROTECTION REGULATION. For the use of mortgage intermediaries and other professionals only. GENERAL DATA HALIFAX INTERMEDIARIES KEY CHANGES GUIDE MAY 2018 REGULATION >SELECT A TILE FOR MORE INFORMATION WHAT IS THE GDPR? KEY

More information

Foundation trust membership and GDPR

Foundation trust membership and GDPR 05 April 2018 Foundation trust membership and GDPR In the last few weeks, we have received a number of enquiries from foundation trusts concerned about the implications of the new General Data Protection

More information

A Guide to Clinical Coding Audit Best Practice Version 8.0

A Guide to Clinical Coding Audit Best Practice Version 8.0 A Guide to Clinical Coding Audit Best Practice Version 8.0 Copyright 2017 Health and Social Care Information Centre Page 1 of 17 The Health and Social Care Information Centre is a non-departmental body

More information

Information Governance Policy and Management Framework

Information Governance Policy and Management Framework Putting Barnsley People First Information Governance Policy and Management Framework Version: 2.0 Approved By: Governing Body Date Approved: February 2014 Name of originator / author: Richard Walker Name

More information

Guide to information provided by NHS dentists under the model publication scheme

Guide to information provided by NHS dentists under the model publication scheme Freedom of Information Act 2000 Guide to information provided by NHS dentists under the model publication scheme Introduction The Freedom of Information Act 2000 (FOIA) requires all public authorities

More information

DATA PROTECTION POLICY 2018

DATA PROTECTION POLICY 2018 DATA PROTECTION POLICY 2018 Amesbury Baptist Church is committed to protecting all information that we handle about people we support and work with, and to respecting people s rights around how their information

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Policy Number IG001 Target Audience CCG/ GMSS Staff Approving Committee CCG Chief Officer Date Approved February 2018 Last Review Date February 2018 Next Review Date February

More information

Tourettes Action Data Protection Policy

Tourettes Action Data Protection Policy Tourettes Action Data Protection Policy Effective date: 01/01/2018 Review date: 01/01/2020 Approved: Suzanne Dobson, CEO Tourettes Action Author: Pippa McClounan, Office Manager Tourettes Action Version

More information

SCHOOLS DATA PROTECTION POLICY. Guidance Notes for Schools

SCHOOLS DATA PROTECTION POLICY. Guidance Notes for Schools SCHOOLS DATA PROTECTION POLICY Guidance Notes for Schools Please read this policy carefully and ensure that all spaces highlighted in the document are completed prior to publication. Please ensure that

More information

General Optical Council. Data Protection Policy

General Optical Council. Data Protection Policy General Optical Council Data Protection Policy Authors: Lisa Sparkes Version: 1.2 Status: Live Date: September 2013 Review Date: September 2014 Location: Internet / Intranet Document History Version Date

More information

General user conditions for supplier s applications and the AUMA supplier portal

General user conditions for supplier s applications and the AUMA supplier portal Page 1 of 7 General user conditions for supplier s applications and the AUMA supplier portal AUMA Riester GmbH & Co. KG ( AUMA, we, us or our ) is continuously interested in finding national as well as

More information

While every organisation is different, we believe the following guidance will help you understand what GDPR is and how you can start to comply.

While every organisation is different, we believe the following guidance will help you understand what GDPR is and how you can start to comply. Introduction While every organisation is different, we believe the following guidance will help you understand what GDPR is and how you can start to comply. This guidance is split into two main parts Part

More information

4 STEPS TO A LEGAL HIRING PROCESS

4 STEPS TO A LEGAL HIRING PROCESS 4 STEPS TO A LEGAL HIRING PROCESS Your hiring practices can get you sued. These are some ways to avoid it. Avoid Getting Sued When you think about the business implications of hiring and screening candidates,

More information

PHWIGC framework that addresses the issues raised by the Francis Report. Author: John Morley & Jane Evans Information Governance Managers

PHWIGC framework that addresses the issues raised by the Francis Report. Author: John Morley & Jane Evans Information Governance Managers PHWIGC 17 03 Information Governance Audits Purpose of Document: To describe the process that Public Health Wales Information Governance Managers will follow when undertaking announced and unannounced Information

More information

WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION

WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION REGULATION (GDPR) WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION REGULATION (GDPR) Published by: The

More information

General Data Protection Regulation (GDPR) Frequently Asked Questions

General Data Protection Regulation (GDPR) Frequently Asked Questions General Data Protection Regulation (GDPR) Frequently Asked Questions 26 March 2018 0 Contents Introduction... 3 What is GDPR?... 3 Who does the GDPR apply to?... 3 Are tax advisers data controllers or

More information

Data Protection Officer

Data Protection Officer Data Protection Officer External Vacancy Post Ref: 5985. Part Time. 15 hours per week. Permanent. 29,146.30 to 31,845.48 per annum, pro rata. Attractive benefits for this post include 35 days holiday per

More information

Data Quality Policy

Data Quality Policy Cambridgeshire and Peterborough Clinical Commissioning Group (CCG) Data Quality Policy 2017-2019 Ratification Process Lead Author(s): Reviewed / Developed by: Approved by: Ratified by: Associate Director

More information

Section a What this Policy is for Policy Statement. 2. Why this policy is important... 3

Section a What this Policy is for Policy Statement. 2. Why this policy is important... 3 Norwich Central Baptist Church DATA PROTECTION POLICY Adopted: May.2018 Norwich Central Baptist Church (NCBC) is committed to protecting all information that we handle about people we support and work

More information

GDPR. Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry

GDPR. Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry GDPR Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry Who are we? Dillistone Group Plc, a public company listed on the AIM market of the London stock

More information

Auditing data protection

Auditing data protection Data protection Auditing data protection a guide to ICO data protection audits 1 Contents Executive summary 3 1. Audit programme development 5 Audit planning and risk assessment 2. Audit approach 6 Gathering

More information

BROOKS PERSONAL TRAINING

BROOKS PERSONAL TRAINING BROOKS PERSONAL TRAINING Data Protection Policy Data Protection Policy Lent 2017 0 DATA PROTECTION POLICY Table of Contents: 1. Document Control... 2 2. Introduction... 3 3. General Statement of Scope...

More information

REFERENCE POLICY. All areas of Trust All staff. Recruitment & Selection of Staff Executive Director of Workforce & Communications Approved

REFERENCE POLICY. All areas of Trust All staff. Recruitment & Selection of Staff Executive Director of Workforce & Communications Approved Trust Policy & Procedure Document Ref No: PP(15)190 REFERENCE POLICY For use in: For use by: For use for: Document Owner: Status: All areas of Trust All staff. Recruitment & Selection of Staff Executive

More information

Session 1. Asset Management and Risk Control Forum. bvrla.co.uk

Session 1. Asset Management and Risk Control Forum. bvrla.co.uk Session 1 Asset Management and Risk Control Forum GDPR Threat or Opportunity? BVRLA Asset Management & Risk Control Forum 19 April 2018 Introduction Personal data is an invaluable asset and many organisations

More information

GDPR The role of the Internal Audit Function

GDPR The role of the Internal Audit Function www.pwc.com/mt GDPR The role of the Internal Audit Function What should the Internal Auditor do? 24 MAY 2017 it s not your problem yet 2 How does GDPR feature in your 2017 audit plan? much of 2017 will

More information

Getting ready for GDPR. A guide to General Data Protection Regulations

Getting ready for GDPR. A guide to General Data Protection Regulations Getting ready for GDPR A guide to General Data Protection Regulations The General Data Protection Regulation (GDPR) Wherever information is stored, individuals and organisations need to be mindful of the

More information

SAFFRON WALDEN COMMUNITY CHURCH DATA PROTECTION POLICY. Adopted: [ ]

SAFFRON WALDEN COMMUNITY CHURCH DATA PROTECTION POLICY. Adopted: [ ] SAFFRON WALDEN COMMUNITY CHURCH DATA PROTECTION POLICY Adopted: [17-04-2018] 1 SAFFRON WALDEN COMMUNITY CHURCH is committed to protecting all information that we handle about people we support and work

More information

Date: INFORMATION GOVERNANCE POLICY

Date: INFORMATION GOVERNANCE POLICY Date: INFORMATION GOVERNANCE POLICY Information Governance Policy IGPOL/01 Information Systems Corporate Services Division March 2017 1 Revision History Version Date Author(s) Comments 0.1 12/12/2012 Helen

More information

GDPR is coming in 108 days: Are you ready?

GDPR is coming in 108 days: Are you ready? Charles-Albert Helleputte Partner, Brussels GDPR is coming in 108 days: Are you ready? Diletta De Cicco Legal Consultant, Brussels 6 February 2018 +32 2 551 5982 chelleputte@mayerbrown.com +32 2 551 5974

More information

GDPR in Early Years and Childcare settings. What s the connection? Data Protection

GDPR in Early Years and Childcare settings. What s the connection? Data Protection GDPR in Early Years and Childcare settings What s the connection? Data Protection What is GDPR? Test your knowledge 10 minute quiz Think of GDPR as evolutionary, not revolutionary Why? GDPR legislation

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Registered Address: Mountdale Gardens, Leigh-on-Sea, Essex SS9 4AW Executive Headteacher: Mrs. J. Mullan Telephone: (01702) 524193 Fax: (01702) 526761 DATA PROTECTION POLICY SEN TRUST SOUTHEND KINGSDOWN

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Registered Address: Mountdale Gardens, Leigh-on-Sea, Essex SS9 4AW Executive Headteacher: Mrs. J. Mullan Telephone: (01702) 524193 Fax: (01702) 526761 DATA PROTECTION POLICY SEN TRUST SOUTHEND KINGSDOWN

More information

SERVICE EQUIPMENT DISPOSAL POLICY

SERVICE EQUIPMENT DISPOSAL POLICY SERVICE EQUIPMENT DISPOSAL POLICY Version 2.1 IT Equipment Disposal Policy COR/047/V2.01 December 2016 updated January 2018 Version 2.1 1 Subject and version number of document: Serial number: Service

More information

NEW LIFE BAPTIST CHURCH NORTHALLERTON DATA PROTECTION POLICY. Adopted: 20 June 2018 To be reviewed: June 2021

NEW LIFE BAPTIST CHURCH NORTHALLERTON DATA PROTECTION POLICY. Adopted: 20 June 2018 To be reviewed: June 2021 NEW LIFE BAPTIST CHURCH NORTHALLERTON DATA PROTECTION POLICY Adopted: 20 June 2018 To be reviewed: June 2021 NEW LIFE BAPTIST CHURCH, NORTHALLERTON (referred to in this policy as NLBC) is committed to

More information

A Practical Guide to Data Protection for Information Professionals

A Practical Guide to Data Protection for Information Professionals A Practical Guide to Data Protection for Information Professionals Naomi Korn and Carol Tullo on behalf of NKCC NKCC 2018. All Rights Reserved. www.naomikorn.com The information contained within this document

More information

TECHNICAL RELEASE TECH 05/14BL. Data Protection Handling information provided by clients

TECHNICAL RELEASE TECH 05/14BL. Data Protection Handling information provided by clients TECHNICAL RELEASE TECH 05/14BL Data Protection Handling information provided by clients ABOUT ICAEW ICAEW is a world leading professional membership organisation that promotes, develops and supports over

More information

NOT PROTECTIVELY MARKED

NOT PROTECTIVELY MARKED Meeting Audit Committee Public Session Date and Time Location Pacific Quay, Glasgow Title of Paper General Data Protection Regulation (GDPR) SPA Preparedness Item Number 9.4 Presented By Catherine Topley

More information

Scottish Charity Number SC Dingwall Baptist Church DATA PROTECTION POLICY

Scottish Charity Number SC Dingwall Baptist Church DATA PROTECTION POLICY Dingwall Baptist Church DATA PROTECTION POLICY Adopted: By Trustees Dingwall Baptist Church May 2018 1 Dingwall Baptist Church is committed to protecting all information that we handle about people we

More information

Post Office Limited. Privacy and Electronic Communications Regulations audit report

Post Office Limited. Privacy and Electronic Communications Regulations audit report Post Office Limited Privacy and Electronic Communications Regulations audit report Executive summary February 2018 1. Background and scope The Information Commissioner may audit the measures taken by the

More information

The General Data Protection Regulation (GDPR) FAQ

The General Data Protection Regulation (GDPR) FAQ The General Data Protection Regulation (GDPR) FAQ Introduction The General Data Protection Regulation ( GDPR ) is the new legal framework that will come into effect on the May 25, 2018 in the European

More information

Baptist Union of Scotland DATA PROTECTION POLICY

Baptist Union of Scotland DATA PROTECTION POLICY Baptist Union of Scotland DATA PROTECTION POLICY Adopted: May 2018 1 1.The Baptist Union of Scotland 48, Speirs Wharf, Glasgow G4 9TH (Charity Registration SC004960) is committed to protecting all information

More information

Wellington College Belfast

Wellington College Belfast Wellington College Belfast PRIVACY NOTICE For Those Employed to Teach at a Controlled School Signed: Approved by Board of Governors Date: t21-41%,2o( Reviewed Date: version Date Published Responsible Officer

More information

EARLS HALL BAPTIST CHURCH DATA PROTECTION POLICY

EARLS HALL BAPTIST CHURCH DATA PROTECTION POLICY EARLS HALL BAPTIST CHURCH DATA PROTECTION POLICY Adopted: 5 June 2018 1 Earls Hall Baptist Church is committed to protecting all information that we handle about people we support and work with, and to

More information

General Accreditation Guidance. ISO/IEC 17025:2017 Gap analysis. April 2018

General Accreditation Guidance. ISO/IEC 17025:2017 Gap analysis. April 2018 General Accreditation Guidance Gap analysis April 2018 Copyright National Association of Testing Authorities, Australia 2018 This publication is protected by copyright under the Commonwealth of Australia

More information

Information Asset Management Policy

Information Asset Management Policy Information Asset Management Policy 1.0 Purpose 1.1 The purpose of this policy is to outline the management of the Fund s information asset register and the actions that will be taken to provide sufficient

More information

KWANLIN DÜN FIRST NATION. Records Management Policy

KWANLIN DÜN FIRST NATION. Records Management Policy Amended on June 13, 2018 1.0 Definitions In this policy active records means records that are required for day to day operations of Kwanlin Dün First Nation and kept in the office that created them; archives

More information

GDPR 5 things HR Must Do! YEARN2LEARN TRAINING, GILLIAN ACHESON, DEIRDRE ALLISON

GDPR 5 things HR Must Do! YEARN2LEARN TRAINING, GILLIAN ACHESON, DEIRDRE ALLISON GDPR 5 things HR Must Do! YEARN2LEARN TRAINING, GILLIAN ACHESON, DEIRDRE ALLISON GENERAL DATA PROTECTION REGULATION What is it? GDPR represents the most significant shift in European data protection legislation

More information

UK Research and Innovation (UKRI) Records Management Policy

UK Research and Innovation (UKRI) Records Management Policy UK Research and Innovation (UKRI) Records Management Policy Contents Policy statement 1. Principles... 5 2. Records creation and maintenance... 5 3. Records retention and disposal... 6 4. Access to records...

More information

Document Ref: Issue Date: March 2018 Review Date: March 2020 Policy Lead: Stephanie Vasey, Data Governance Manager

Document Ref: Issue Date: March 2018 Review Date: March 2020 Policy Lead: Stephanie Vasey, Data Governance Manager Policy Data Protection Policy Document Ref: 471.4 Issue Date: March 2018 Review Date: March 2020 Policy Lead: Stephanie Vasey, Data Governance Manager Data Protection Policy Entity This policy applies

More information

West Kent Clinical Commissioning Group

West Kent Clinical Commissioning Group West Kent Clinical Commissioning Group Information Governance Strategy 2017-18 Release: Final Approved Date: 27/10/2016 Author: Jamie Sheldrake Senior Associate - Information Governance Owner: SOUTH EAST

More information

OFFICIAL. Date 18 April 2018 Pacific Quay, Glasgow General Data Protection Regulation (GDPR) Police Scotland Preparedness Item Number 11.

OFFICIAL. Date 18 April 2018 Pacific Quay, Glasgow General Data Protection Regulation (GDPR) Police Scotland Preparedness Item Number 11. Meeting Date Location Pacific Quay, Glasgow Title of Paper General Data Protection Regulation (GDPR) Police Scotland Preparedness Item Number 11.2 Presented By ACC Alan Speirs Recommendation to Members

More information

GENERAL DATA PROTECTION REGULATION

GENERAL DATA PROTECTION REGULATION GENERAL DATA PROTECTION REGULATION (GDPR) What is General Data Protection Regulation (GDPR) What this means for GP Practices Replaces the Data Protection Act 1998 (DPA) Designed to match data privacy laws

More information

Data Protection Policy

Data Protection Policy Data Protection Policy This policy will be reviewed by the Trust Board three yearly or amended if there are any changes in legislation before that time. Date of last review: Autumn 2018 Date of next review:

More information

INFORMATION COMMISSIONER S OFFICE FOLLOW UP DATA PROTECTION AUDIT REPORT. Information Governance Manager. This paper supports:

INFORMATION COMMISSIONER S OFFICE FOLLOW UP DATA PROTECTION AUDIT REPORT. Information Governance Manager. This paper supports: FOR DISCUSSION INFORMATION GOVERNANCE COMMITTEE 28 APRIL 2015 AGENDA ITEM 2.6 INFORMATION COMMISSIONER S OFFICE FOLLOW UP DATA PROTECTION AUDIT REPORT Report of Paper prepared by Director of Therapies

More information

Humber Information Sharing Charter

Humber Information Sharing Charter External Ref: HIG 01 Review date November 2016 Version No. V07 Internal Ref: NELC 16.60.01 Humber Information Sharing Charter This Charter may be an uncontrolled copy, please check the source of this document

More information

General Data Protection Regulation (GDPR) Key considerations and implications for brokers

General Data Protection Regulation (GDPR) Key considerations and implications for brokers General Data Protection Regulation () Key and implications for brokers Contents at at 03 - did you know? 05 How to handle 07 Considerations for Broker Directors 08 General Data Protection Regulation ()

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Operational Owner: Executive Owner: James Newby Data Protection Officer Sarah Litchfield Senior Information Risk Officer Effective date: 25 th May 2018 Review date: May 2021 Related

More information

Data Protection Act Policy Statement Status/Version: 0.1 Review Information Classification: Unclassified Effective:

Data Protection Act Policy Statement Status/Version: 0.1 Review Information Classification: Unclassified Effective: Data Protection Act Policy Statement Status/Version: 0.1 Review Information Classification: Unclassified Effective: 1 Policy Statement Objective 1.1 It is the policy of Penderels Trust to demonstrate compliance

More information

3. STRUCTURING ASSURANCE ENGAGEMENTS

3. STRUCTURING ASSURANCE ENGAGEMENTS 3. STRUCTURING ASSURANCE ENGAGEMENTS How do standards and guidance help professional accountants provide assurance? What are the practical considerations when structuring an assurance engagement? 3. STRUCTURING

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Including the Information Governance Strategy Framework and associated Information Governance Procedures Last Review Date June 2017 Approving Body Audit Committee Date of

More information

Data Protection Impact Assessment Policy

Data Protection Impact Assessment Policy Data Protection Impact Assessment Policy Version 0.1 1 VERSION CONTROL Version Date Author Reason for Change 0.1 16.07.18 Debby Jones New policy 2 EQUALITY IMPACT ASSESSMENT Section 4 of the Equality Act

More information

Freedom of Information/Environmental Information Regulations Policy and Procedure

Freedom of Information/Environmental Information Regulations Policy and Procedure Policy Number: 8.3 Version number: 01 Date of issue: Date Archived: Reason for policy: (Redraft/new) New policy to ensure compliance with current legislation Authorised by: On Behalf of Management (Signature)

More information

Statement on the management of personal data at the National Audit Office

Statement on the management of personal data at the National Audit Office Statement on the management of personal data at the National Audit Office April 2018 www.nao.org.uk Introduction The Comptroller and Auditor General (C&AG) and the National Audit Office (NAO) take the

More information

The current version (July 2018) is derived from, and supersedes, the version published in February 2017 and earlier versions.

The current version (July 2018) is derived from, and supersedes, the version published in February 2017 and earlier versions. Page 2 of 10 Data Protection Policy Chief Information Officer Chief Information Officer Data Protection Officer The current version (July 2018) is derived from, and supersedes, the version published in

More information