Showing posts with label charity. Show all posts
Showing posts with label charity. Show all posts

Sunday, 15 May 2016

Back to Basics - Collection Notices

One of the keys to collecting information in line with the Data Protection Act is to ensure that you are telling the person providing the information a few key things. Collection notices aren't properly understood and are sometimes overly complicated.

So here are the basics, a collection notice must tell the person providing their information:
(a) who the organisation collecting the information is
(b) what the information provided will be used for
(c) how the information will be stored and for how long
(d) whether the information will be shared with another organisation or organisations

The wording does not have to be formal, you can just write in plain english the information required.

Collection notices should be provided on both paper and electronic forms. Frequently individuals do not remmebr signing up for something or when they gave information so to ensure that you stay off the ICO's naughty step you should record when the information was collected and this should be retained for the life of your relationship with the individual. Additionally, if it is a paper form you either need to hold the hard copy or have a scanned copy for your records. This will all help with proving that you are protecting the individuals privacy should you need to.

Remember that regardless of whether you are registered with the ICO you have to comply with the Data Protection Act so any forms that you use for the collection of information MUST have a data collection notice on it. Without a valid collection notice you are breaking the law! 

Sunday, 3 April 2016

Who is letting your organisation down?

There have been a number of high profile data breaches by members of staff in organisations.

From the disgruntled Morrison's employee who leaked the salaries of staff onto the internet and was subsequently jailed for 8 years to the Tesco employee who was emailing details of customers to his personal email account and the Enterprise car rental employee who was selling customer information to a claims company, the main weaknesses in most organisations are the staff.

So what do you do about it? The cases shown above have been high profile and widely reported but organisations are probably suffering breaches on a regular basis and may not even be aware of them. We get used to what we see and do and so often we forgot to stand back and view the situation with fresh eyes. 

When I start to work with organisations, I am that fresh pair of eyes. I often also represent your clients. Are you collecting information to help you communicate effectively with them? We can easily identify the areas in your business where there is potential for losing your business information.

If you want to find out  more, we offer a free initial consultation so you can see how we would work with you. Contact us today to book a meeting.

Sunday, 7 February 2016

What's your score out of ten?

The ICO have recently issued an enforcement notice to the Alzheimers Society for various breaches of the Data Protection Act. There are 10 issues which the Alzheimers Society has six months to remedy. Although these need to be actioned by the Alzheimers Society, they apply to all businesses processing personal information. So here is the test, how many are you already doing?

1. Information is not kept for longer than necessary. Do you have a process in place to identify information which is no longer necessary and can be destroyed? Do you have a retention policy and a secure method of destroying all information that is no longer required?

2. There is mandatory data protection training for staff (and volunteers) who have access to personal information and refresher training at least every two years.

3. The training that is undertaken is monitored and recorded. You should be able to identify the staff who have attended and what the training course covered.

4. Policies and procedures relating to data protection and information governance are brought to the attention of staff (and volunteers) who have access to personal information. Do you have comprehensive data protection policies and procedures and can you demonstrate that they have been effectively communicated to all those staff (and volunteers) who have access to personal information?

5. Portable and mobile devices including laptops, mobile phones, memory cards and other portable media used to transmit and store personal data, the loss of which could cause damage or distress to individuals are all encrypted using encryption software which meets the current standard or equivalent.

6. Secure email accounts are provided for all staff (and volunteers) who use email to transmit personal information. This means a business account is available for all staff (and volunteers) and they are not using their personal email accounts for business purposes.

7. Secure storage is available for staff (and volunteers) who need to hold hard copy records which contain personal information. Is there lockable filing space for hard copy records?

8. Penetration testing is undertaken on the website on a regular basis and any weaknesses highlighted are remedied.

9. Appropriate security is implemented to protect information from being disclosed to those who do not need to have access to it, this includes to staff members, contractors, visitors and volunteers. This includes passwords, lockable cabinets, encryption, etc.

10.Where processing of personal information is carried out your behalf, for example, by a subcontractor, (IT support, HR, payroll etc) you must have a written contract in place which clearly states that the subcontractor will take steps to protect the information from accidental loss, damage or destruction. The contract should also cover the role of the subcontractor, what they can do with the information, what happens when the information is no longer required and that they will only act on your instructions. You need to make sure that any contract you enter into clearly states the responsibility for data protection.

So what's your score? How many of the above do you need to action to protect the personal information you hold and your company's reputation?

Sunday, 5 July 2015

Why I like Data Protection?

I was asked the other day why I enjoy working in data protection. If I'm honest I disliked data protection before I completed my training and got the qualification, I found it confusing and cumbersome and wondered how anyone could actively comply to the many rules and elements, some of which seemed contradictory. Having completed the training and passed the 3 hour exam(!) I really understand the Act. The Data Protection Act can feel like looking a puzzle when you have no picture, you have the pieces but they made no sense as to how they fitted together. In fairness the Data Protection Act is a cumbersome piece of legislation. There have been bits added on over the years and other regulations brought in to support it, such as the privacy and electronic communication regulations (PECR). I can see why some organisations find it difficult to understand and struggle to comply especially if they don't have access to a knowledgeable advisor. 

When we work with organisations, our first question is always "What do you want to do with the information?". Once we know what information you want to collect and its purpose we can fit the other pieces into place to support this. Each organisation has its own challenges to overcome to comply with the Act and it is wonderful to ease that journey for them by providing advice which meets their needs. I have a wonderful job supporting organisations to look after personal information which helps them grow their business.

Sunday, 14 June 2015

Paper Forms - Do you have the basics in place?

It's been a busy week and whilst I have been out and about I have needed to complete some forms. I completed three different forms and not one of them met the requirements of the Data Protection Act with regard to collection notices.
Most of the forms were collecting basic details -  the usual - name, address, DOB. The forms were being used by a health professional, charity and college.

So what did I learn this week. Ultimately most of the organisations who collected information about me did not even meet the basic requirements of a collection notice on the form. A collection notice tells the person providing the information what their information will be used for, how it will be stored and for how long and if it is going to be shared with anyone. I have asked each of the organisations for whom I have completed a form what they intend to use my information for. It is worrying that if an organisation cannot even collect the information properly, how are they storing it and who has access to it. Given the significant rise in identify theft, I have provided enough information for this to happen.

Remember that regardless of whether you are registered with the ICO you have to comply with the Data Protection Act so any forms that you use for the collection of information MUST have a data collection notice on it. Without a valid collection notice you are breaking the law!

If you need help to produce a collection notice or require a review of your forms, please contact me.