The ICO have recently issued an enforcement notice to the Alzheimers Society for various breaches of the Data Protection Act. There are 10 issues which the Alzheimers Society has six months to remedy. Although these need to be actioned by the Alzheimers Society, they apply to all businesses processing personal information. So here is the test, how many are you already doing?
1. Information is not kept for longer than necessary. Do you have a process in place to identify information which is no longer necessary and can be destroyed? Do you have a retention policy and a secure method of destroying all information that is no longer required?
2. There is mandatory data protection training for staff (and volunteers) who have access to personal information and refresher training at least every two years.
3. The training that is undertaken is monitored and recorded. You should be able to identify the staff who have attended and what the training course covered.
4. Policies and procedures relating to data protection and information governance are brought to the attention of staff (and volunteers) who have access to personal information. Do you have comprehensive data protection policies and procedures and can you demonstrate that they have been effectively communicated to all those staff (and volunteers) who have access to personal information?
5. Portable and mobile devices including laptops, mobile phones, memory cards and other portable media used to transmit and store personal data, the loss of which could cause damage or distress to individuals are all encrypted using encryption software which meets the current standard or equivalent.
6. Secure email accounts are provided for all staff (and volunteers) who use email to transmit personal information. This means a business account is available for all staff (and volunteers) and they are not using their personal email accounts for business purposes.
7. Secure storage is available for staff (and volunteers) who need to hold hard copy records which contain personal information. Is there lockable filing space for hard copy records?
8. Penetration testing is undertaken on the website on a regular basis and any weaknesses highlighted are remedied.
9. Appropriate security is implemented to protect information from being disclosed to those who do not need to have access to it, this includes to staff members, contractors, visitors and volunteers. This includes passwords, lockable cabinets, encryption, etc.
10.Where processing of personal information is carried out your behalf, for example, by a subcontractor, (IT support, HR, payroll etc) you must have a written contract in place which clearly states that the subcontractor will take steps to protect the information from accidental loss, damage or destruction. The contract should also cover the role of the subcontractor, what they can do with the information, what happens when the information is no longer required and that they will only act on your instructions. You need to make sure that any contract you enter into clearly states the responsibility for data protection.
So what's your score? How many of the above do you need to action to protect the personal information you hold and your company's reputation?
Showing posts with label training. Show all posts
Showing posts with label training. Show all posts
Sunday, 7 February 2016
Sunday, 31 January 2016
Data Protection Training - Are you doing it for your staff (and Volunteers)?
The Information
Commissioners Office has reprimanded the Alzheimer's Society for a number of
breaches of the Data Protection Act, including failing to provide regular
training to staff and volunteers on Data Protection Compliance.
The
enforcement notice states that the charity has failed to comply with two data
protection principles and has issued a set of ten action points which need to
be complied with within a period of six months.
The key
issue is that the charity has not been training its staff or volunteers on a
regular basis with regard to the requirements of the Act. This has led to
breaches of the Act, probably due to lack of knowledge. So what do you need to
do to avoid the wrath of the ICO?
All organisations
should be regularly training their staff (and volunteers) in the requirements
of the Data Protection Act at least every two years.
So what
should your training cover? As a minimum you would want to inform all staff:
- Who the Data Protection Officer
- What personal information is
- How information should be collected, stored and destroyed
- The time-scales for destruction (i.e. a retention policy)
- An awareness of the checks they should be undertaking before providing information to someone (Subject Access Requests)
- How to ensure that sharing information via email is carried out securely
- The constraints on using their own devices for work purposes.
An
organisation should also have policies and procedures to support these
elements. Remember, these are THE BASICS!
Any
training undertaken should be recorded as to what the training covered, who
attended and the date. You will need to keep these records in case of an issue
with the ICO at a later date. Showing that you have trained the staff (and volunteers)
on a regular basis shows a commitment to compliance with the Act.
If you
have any questions or want to run a training session for your staff, we run in
house courses tailored to your needs, so please contact me.
Monday, 18 January 2016
Did you attend a training course? Whoopee, lets share your details!
I have been on a couple of business training courses over the last week. Both of them were signed up to online and neither told me what they would do with my information, so that's the first mistake!
When I got to the training courses, both provided an attendee list which showed name, business name and a brief outline of what the business does.
A few days later I received an email from the training company asking if they can share my contact details with the other attendees. If I do not wish to share my information I have 24 hours to send an email opting out. Mistakes 2 and 3.
The email requesting that I share my contact details does not tell me which contact details they are planning to share. They may have my postal address but definitely have my email address and mobile number as a minimum so are they planning on sharing all my contact details or just some of them and if so which ones?
Also by requesting that you respond by opting out, they run the risk of sharing someone's contact details who may not have had time to review their emails and respond within the timescale laid down but who doesn't want to share their information. They should have asked people to opt in.
So how could this have been done more effectively?
1 - When they collected the information, they should have said how they are going to hold that information and for how long.
2 - Will I be on a mailing list?
3 - Stating that it will be on an Attendee list.
4 - What information they plan to share with other delegates and seeking permission to do so.
All of this could have been completed at the time of sign-up.
It would have been more straightforward to tell all the attendees to find each other on LinkedIn and connect that way. Needing no facilitation by the training company.
So with a bit of planning and some knowledge of Data Protection requirements, life could have been a lot easier for the training company.
When I got to the training courses, both provided an attendee list which showed name, business name and a brief outline of what the business does.
A few days later I received an email from the training company asking if they can share my contact details with the other attendees. If I do not wish to share my information I have 24 hours to send an email opting out. Mistakes 2 and 3.
The email requesting that I share my contact details does not tell me which contact details they are planning to share. They may have my postal address but definitely have my email address and mobile number as a minimum so are they planning on sharing all my contact details or just some of them and if so which ones?
Also by requesting that you respond by opting out, they run the risk of sharing someone's contact details who may not have had time to review their emails and respond within the timescale laid down but who doesn't want to share their information. They should have asked people to opt in.
So how could this have been done more effectively?
1 - When they collected the information, they should have said how they are going to hold that information and for how long.
2 - Will I be on a mailing list?
3 - Stating that it will be on an Attendee list.
4 - What information they plan to share with other delegates and seeking permission to do so.
All of this could have been completed at the time of sign-up.
It would have been more straightforward to tell all the attendees to find each other on LinkedIn and connect that way. Needing no facilitation by the training company.
So with a bit of planning and some knowledge of Data Protection requirements, life could have been a lot easier for the training company.
Sunday, 13 December 2015
Email, your biggest problem? - it could be!
I had a query from a client this week regarding a subject access request from one of their employees. The employee had resigned and subsequently put in a subject access request for emails mentioning them in the previous six months. The client's belief is that the employee is hoping to find something in the emails which will show some prejudice against them by their manager.
As knowledge of the Data Protection Act increases, the many uses of it are being explored for lots of different reasons. It is increasingly being used by disgruntled employees to seek information which would support a claim for unfair treatment.
Regardless of whether the employee is right or not, every business should consider the consequences of staff putting comments (an opinion) of any sort into an email, unless it is a professional opinion which can be backed up.
So what's the upshot of this case? If there is anything that is contentious in the emails, the employee may have a case against the organisation and resolving that could be a costly exercise both in terms of time and money. How many organisations can afford to defend a claim in these circumstances?
Ultimately, this is about ensuring that staff have adequate training to ensure that they are not putting themselves or the organisation at risk of litigation. The amount that it costs to get the staff trained with regard to email etiquette as opposed to the amount that will need to be paid out in compensation or legal defence costs is minimal. Contact me if you would like to talk about our training programmes.
As knowledge of the Data Protection Act increases, the many uses of it are being explored for lots of different reasons. It is increasingly being used by disgruntled employees to seek information which would support a claim for unfair treatment.
Regardless of whether the employee is right or not, every business should consider the consequences of staff putting comments (an opinion) of any sort into an email, unless it is a professional opinion which can be backed up.
So what's the upshot of this case? If there is anything that is contentious in the emails, the employee may have a case against the organisation and resolving that could be a costly exercise both in terms of time and money. How many organisations can afford to defend a claim in these circumstances?
Ultimately, this is about ensuring that staff have adequate training to ensure that they are not putting themselves or the organisation at risk of litigation. The amount that it costs to get the staff trained with regard to email etiquette as opposed to the amount that will need to be paid out in compensation or legal defence costs is minimal. Contact me if you would like to talk about our training programmes.
Subscribe to:
Posts (Atom)
