Data protection for commissioners
|
|
|
- Sherman Price
- 9 years ago
- Views:
Transcription
1 Data protection for commissioners Vicky Cetinkaya, Senior Policy Officer, Strategic Liaison Katie Hanrahan, Lead Auditor, Good Practice 2 July 2015
2 The Information Commissioner s Office
3 What does the DPA cover? The DPA is concerned with the processing of personal data. Obligation to comply with the DPA rests with the data controller. Provides a framework that data controllers processing personal data must comply with.
4 The eight data protection principles
5 Background Sector chosen due to significant volumes of SPD - high risk Project initially designed to identify and highlight common problems, themes and issues as well as good practice 20 agencies invited, mainly in NW & London - 10 took part Organisations identified via Consortium for Voluntary Adoption Agencies/BAAF websites or previous ICO contact Follow-up survey of 100 LAs 17 took part
6 Typical information & processing Organisations process and retain sensitive personal data relating to foster carers, adoptive parents, looked after children & their families and third parties Information used to assess suitability to foster / adopt Other personal information also used by local authorities and agencies to match carers with children, facilitate placements and assess the success of placements
7 IFP key findings/issues Insecure exchange of personal data Highly sensitive unencrypted personal information routinely ed between IFPs and local authorities and vice versa. Contributing factors: Local authorities reluctant to deal with encrypted s due to technical concerns. IFPs often send foster carer information without encryption to prevent delays that might jeopardise their commercial relationship with local authorities.
8 IFP key findings/issues (cont ) Mobile device encryption Extensive use of unencrypted mobile devices to store / process / transport sensitive personal data. Carer reports/diaries - Processing of information by carers about looked after children on home computers and in the cloud. Homeworking Staff using home computers for business purposes and lack of suitable controls. Training - Data protection/information security training is often lacking.
9 Other findings Passwords controls are not robust Secure printing procedures not widely adopted Endpoint restrictions often not in place Majority did not have data protection/information security policies Only a few had security incident/breach reporting and management procedures Retention and disposal procedures/schedules are not in place or not operating effectively
10 LA survey results 47% Said their employer either didn t record whether DP/IG policies had been read or they didn t know
11 LA survey results 31% Received DP/IG refresher training less frequently than every two years 17% never received it
12 LA survey results 59% Didn t receive any role-specific DP training
13 LA survey results 57% Never checked manual records out or in
14 LA survey results 50% Potentially hold sensitive personal data of parents deemed unsuitable for placements for longer than necessary 28% retain it indefinitely!
15 LA survey results 31% Either could not accept encrypted s or did not know if they could
16 Recommendations for LA fostering & adoption teams Encrypt s/attachments containing SPD Anonymise children s data initially when matching Maintain DP/IG policies; ensure staff read & understand them DP training is timely, monitored, refreshed & role specific Records removed from office are tracked and monitored Retention & disposal schedules for manual & electronic files
17
18
19 Telford & Wrekin Council 90, Foster Care Assessment provided to the wrong family member. Names and address of foster carers provided to mother in Placement Information record.
20 Norwood Ravenswood Ltd 70, Background reports regarding children in care left on prospective adopter s door step. Reports disappeared and were not recovered
21 Devon County Council 90, Social worker printed wrong adoption panel report and sent to a family with no connection to the case Report contained highly SPD concerning a disabled couple whose child was being considered for adoption.
22 Halton Borough Council 70, Clerical officer sent letter to birth mother containing the name and address of birth parents. Birth grandparents contacted adoptive parents
23 Moray Council Undertaking Detailed reports relating to adoption of two children plus less detailed reports on other children left in café.
24 Enforcement case - no further action Local authority Letter containing adoptive parents address sent to birth family in error resulted in family having to be rehoused
25 Enforcement case - no further action Local authority Adoption report sent to incorrect address as an attachment it wasn t encrypted.
26 Organisational Measures Technical measures Awareness HUMAN ERROR
27 Summary Consistent findings Support our concerns Improvements necessary Advice and support
28 How the ICO can help The Guide to data protection Subject access code of practice Data sharing code of practice and checklists Advisory visit outcomes reports
29 ICO advice and guidance - ICO guidance - ICO helpline ICO [email protected]
30 Keep in touch Subscribe to our e-newsletter at or find us on
Security breaches: A regulatory overview. Jonathan Bamford Head of Strategic Liaison
Security breaches: A regulatory overview Jonathan Bamford Head of Strategic Liaison Security breaches and the DPA Data controllers security obligation - principle 7 of the DPA o Appropriate technical and
Renfrewshire Council. Data protection audit report. Executive summary January 2013
Renfrewshire Council Data protection audit report Executive summary January 2013 1. Background The Information Commissioner is responsible for enforcing and promoting compliance with the Data Protection
ICO SME data protection workshop 25 September, NEC
ICO SME data protection workshop 25 September, NEC Information security & working with government Amanda Hillman Data Sharing & Data Protection Manager Claire Francis Supply Chain Information Assurance
Information Governance in Dental Practices. Summary of findings from ICO reviews. September 2015
Information Governance in Dental Practices Summary of findings from ICO reviews September 2015 Executive summary The Information Commissioner s Office (ICO) is the regulator responsible for ensuring that
Local Authority Adoption Services. London Borough of Hillingdon Adoption Service 855 Uxbridge Road Hayes Middlesex UB4 8HZ
Local Authority Adoption Services London Borough of Hillingdon Adoption Service 855 Uxbridge Road Hayes Middlesex UB4 8HZ 30th November and 1st and 2nd December 2004 Commission for Social Care Inspection
Merthyr Tydfil County Borough Council. Data Protection Policy
Merthyr Tydfil County Borough Council Data Protection Policy 2014 Cyfarthfa High School is a Rights Respecting School, we recognise the importance of ensuring that the United Nations Convention of the
Data Security and Extranet
Data Security and Extranet Derek Crabtree Schools ICT Support Manager [email protected] Target Operating Model 2011 Merton Audit Organisation name: London Borough of Merton Periodic plan date:
Notification of data security breaches to the Information Commissioner s
ICO lo Notification of data security breaches to the Information Commissioner s Data Protection Act Contents Overview... 2 What the DPA says... 2 Reporting a breach... 2 Potential detriment to data subjects...
Data controllers and data processors: what the difference is and what the governance implications are
ICO lo : what the difference is and what the governance implications are Data Protection Act Contents Introduction... 3 Overview... 3 Section 1 - What is the difference between a data controller and a
Mental Health Crisis Care: Shropshire Summary Report
Mental Health Crisis Care: Shropshire Summary Report Date of local area inspection: 26 and 27 January 2015 Date of publication: June 2015 This inspection was carried out under section 48 of the Health
Ofsted Inspections of Local Authority and Voluntary Adoption Agencies
Ofsted Inspections of Local Authority and Voluntary Adoption Agencies Practice areas affected: Adoption Status: Ofsted report: Inspections of Local Authority and Voluntary Adoption Agencies (published
Cloud Software Services for Schools
Cloud Software Services for Schools Supplier self-certification statements with service and support commitments Please insert supplier details below Supplier name Address Contact name Contact email Contact
Data Protection Act. Privacy & Security in the Information Age. April 26, 2013. Ministry of Communications, Ghana
Data Protection Act Privacy & Security in the Information Age April 26, 2013 Agenda Privacy in The Information Age The right to privacy Why We Need Legislation Purpose of the Act The Data Protection Act
Procedures on Data Security Breach Management Version Control Date Version Reason Owner Author 16/09/2009 Draft 1 Outline Draft Jackie Groom
Procedures on Data Security Breach Management Version Control Date Version Reason Owner Author 16/09/2009 Draft 1 Outline Draft Jackie Groom Indirani 02/11/2009 Draft 2 Include JG s comments Jackie Groom
Achieving for Child Adoption Support Guarantee London Borough of Richmond upon Thames
Achieving for Child Adoption Support Guarantee London Borough of Richmond upon Thames 1. Background For those children who cannot return to their birth families we strive to provide safe, secure and loving
Data Protection Policy A copy of this policy is published in the following areas: The school s intranet The school s website
Data Protection Policy A copy of this policy is published in the following areas: The school s intranet The school s website Date created: November 2015 Date for review: July 2016 Created by: Mark Vanstone,
Cloud Software Services for Schools
Cloud Software Services for Schools Supplier self-certification statements with service and support commitments Please insert supplier details below Supplier name Address Isuz Ltd. trading as Schoolcomms
West Dunbartonshire Council. Follow-up data protection audit report
West Dunbartonshire Council Follow-up data protection audit report Auditors: Lee Taylor (Audit Team Manager) Jonathan Kay (Engagement Lead Auditor) Data controller contacts: Michael Butler (Data Protection/Information
Privacy and Electronic Communications Regulations
ICO lo Notification of PECR security breaches Privacy and Electronic Communications Regulations Contents Introduction... 2 Overview... 2 Relevant security breaches... 3 What is a service provider?... 3
Cambridgeshire Constabulary. Data protection audit report
Cambridgeshire Constabulary Data protection audit report Executive summary November 2014 1. Background The Information Commissioner is responsible for enforcing and promoting compliance with the Data Protection
IT asset disposal for organisations
ICO lo Data Protection Act Contents Introduction... 1 Overview... 2 What the DPA says... 3 Create an asset disposal strategy... 3 How will devices be disposed of when no longer needed?... 3 Conduct a risk
Cloud Software Services for Schools
Cloud Software Services for Schools Supplier self-certification statements with service and support commitments Supplier name Address Contact name Contact email Contact telephone Parent Teacher Online
LONDON BOROUGH OF EALING ADOPTION SERVICE STATEMENT OF PURPOSE 2014-2015
LONDON BOROUGH OF EALING ADOPTION SERVICE STATEMENT OF PURPOSE 2014-2015 Carolyn Fair May 2011 Updated February 2014 1 Introduction 1.1 The London Borough of Ealing, through the power delegated to the
DATA PROTECTION ACT 1998 COUNCIL POLICY
DATA PROTECTION ACT 1998 COUNCIL POLICY Page 1 of 5 POLICY STATEMENT Blackpool Council recognises the need to fully comply with the requirements of the Data Protection Act 1998 (DPA) and the obligations
Information Commissioner's Office
Phil Keown Engagement Lead T: 020 7728 2394 E: [email protected] Will Simpson Associate Director T: 0161 953 6486 E: [email protected] Information Commissioner's Office Internal Audit 2015-16:
Guidance on data security breach management
ICO lo Guidance on data security breach management Data Protection Act Contents... 1 Data Protection Act... 1 Overview... 1 Containment and recovery... 2 Assessing the risks... 3 Notification of breaches...
Moray Council. Adoption Plan
APPENDIX 1 Moray Council Adoption Plan Review: - November 2013 Next Review: - September 2016 Adoption Plan 18.12 2013 Page 1 of 15 Introduction The Moray Council believes that children should be brought
Criminal Records Bureau (CRB) checks for those providers who register with Ofsted
Criminal Records Bureau (CRB) checks for those providers who register with Ofsted This factsheet sets out Ofsted s position on using existing Criminal Records Bureau (CRB) checks for providers who register
Adoption. /adoptionandfostering [email protected] www.lbhf.gov.uk www.rbkc.gov.uk www.westminster.gov.uk
Adoption /adoptionandfostering [email protected] www.lbhf.gov.uk www.rbkc.gov.uk www.westminster.gov.uk 2 The London Borough of Hammersmith & Fulham, The Royal Borough of Kensington and Chelsea and
PACT Adoption Service Statement of Purpose 2015
PACT Adoption Service Statement of Purpose 2015 Author: Shirley Elliott Review by: SMT Version: 2 First issue date: 17/3/10 Review cycle: annual Last review date 09/03/2015 Related documents SOP Adoption
Regional adoption agencies Statement from Link Maker Systems
Regional adoption agencies Statement from Link Maker Systems 25 th June 2015 Summary Regional adoption agencies would bring much needed improvements in some areas. Any mergers would also involve a great
DATA PROTECTION POLICY
DATA PROTECTION POLICY Version 1.3 April 2014 Contents 1 POLICY STATEMENT...2 2 PURPOSE....2 3 LEGAL CONTEXT AND DEFINITIONS...2 3.1 Data Protection Act 1998...2 3.2 Other related legislation.....4 3.3
PAPER RECORDS SECURE HANDLING AND TRANSIT POLICY
PAPER RECORDS SECURE HANDLING AND TRANSIT POLICY CORPORATE POLICY Document Control Title Paper Records Secure Handling and Transit Policy Author Information Governance Manager ** Owner SIRO/CIARG Subject
Summary of feedback on Big data and data protection and ICO response
Summary of feedback on Big data and data protection and ICO response Contents Introduction... 2 Question 1... 3 Impacts and benefits; privacy impact assessments (PIAs)... 3 New approaches to data protection...
UNIVERSITY ACADEMY OF ENGINEERING SOUTH BANK. Special Educational Needs and Disabilities (SEND) Policy
UNIVERSITY ACADEMY OF ENGINEERING SOUTH BANK Special Educational Needs and Disabilities (SEND) Policy This Policy will be rewritten in September 2014, in light of the new legislation and as part of the
Position Paper on Adoption Law Reform
Position Paper on Adoption Law Reform March 2013 Department of Health and Human Services Introduction What is adoption? Adoption is the legal process which permanently transfers all the legal rights and
Nottinghamshire County Council. Data protection audit report
Nottinghamshire County Council Data protection audit report Executive summary October 2015 1. Background The Information Commissioner is responsible for enforcing and promoting compliance with the Data
The Fostering Network 2006 Managing Allegations and Serious Concerns About Foster Carers Practice: a guide for fostering services.
1 foreword The role of foster carers is a unique and challenging one. They look after some of our most vulnerable children, 24 hours a day, and it is essential that they are properly supported. The way
Fairer Contributions Policy
Appendix 6 Fairer Contributions Policy July 2011 Adult and Community Services Fairer Contributions Policy 1. Introduction 1.1 The Fairer Contributions Policy is designed to ensure that people pay a fair
Application for Discretionary Housing Payment/Council Tax Discretionary Relief
Application for Discretionary Housing Payment/Council Tax Discretionary Relief Name & Address: Date of Issue: Council Tax Account Number: Email Address and Contact Number: Housing Benefit Claim Reference:
Photography and filming in schools Code of Practice
Photography and filming in schools Code of Practice Data Protection compliance September 2010 Photography and filming in schools September 2010 1 Contents 1. About this code 3 2. Complying with the Data
Somewhere over the rainbow - Review of Adoption. `Somewhere over the rainbow
`Somewhere over the rainbow Adoption Scrutiny Review Children and Education Scrutiny Committee Cheshire West and Chester Council June 2012 CONTENTS PAGE. 1 Introduction Page 3 2 Task Group details Page
STATEMENT OF PURPOSE LOCAL AUTHORITY PRIVATE FOSTERING
STATEMENT OF PURPOSE LOCAL AUTHORITY PRIVATE FOSTERING Children Young People & Families May 2013 Page 1 of 10 STATEMENT OF PURPOSE BIRMINGHAM CHILDREN, YOUNG PEOPLE & FAMILIES DIRECTORATE PRIVATE FOSTERING
Data Transfer Policy London Borough of Barnet
London Borough of Barnet DATA PROTECTION 11 Document Control Document Description Data Transfer Policy Version v.2 Date Created December 2010 Status Authorisation Name Signature Date Prepared By: IS Checked
So the security measures you put in place should seek to ensure that:
Guidelines This guideline offers an overview of what the Data Protection Act requires in terms of information security and aims to help you decide how to manage the security of the personal data you hold.
Cloud Software Services for Schools. Supplier self-certification statements with service and support commitments
Cloud Software Services for Schools Supplier self-certification statements with service and support commitments Supplier name Address Contact name Contact email Meritec Limited Meritec House, Acorn Business
ADOPTION SERVICE STATEMENT OF PURPOSE
London Borough of Waltham Forest Children and Families Services ADOPTION SERVICE STATEMENT OF PURPOSE Revised November 2013 (Draft to be ratified) www.walthamforest.gov.uk/adopt 1 1. Introduction The Statement
Data Protection Policy
Data Protection Policy Owner : Head of Information Management Document ID : ICT-PL-0099 Version : 2.0 Date : May 2015 We will on request produce this Policy, or particular parts of it, in other languages
Foster and adult placement carers
Help Sheet 236 Tax year 6 April 2008 to 5 April 2009 Foster and adult placement carers This Help Sheet gives you information to help you fill in boxes in: the Self-employment (short) and (full) pages of
Once more unto the breach... Dealing with Personal Data Security Breaches. Helen Williamson Information Governance Officer
Once more unto the breach... Dealing with Personal Data Security Breaches Helen Williamson Information Governance Officer Aims of the session What are we going to look at? What is a data security breach?
University of Sunderland Business Assurance. Over-arching Information Governance Policy. Document Classification: Public
University of Sunderland Business Assurance Over-arching Information Governance Policy Document Classification: Public Policy Reference Central Register IG001 Policy Reference Faculty / Service IG 001
Local Authority Adoption Services. London Borough of Merton Adoption Service Worsfold House Church Road Mitcham Surrey CR4 3FA
Local Authority Adoption Services London Borough of Merton Adoption Service Worsfold House Church Road Mitcham Surrey CR4 3FA 13th, 16-18th and 20th August 2004 Commission for Social Care Inspection Launched
SOLIHULL METROPOLITAN BOROUGH COUNCIL FOSTERING SERVICES - STATEMENT OF PURPOSE 2015-2016
SOLIHULL METROPOLITAN BOROUGH COUNCIL FOSTERING SERVICES - STATEMENT OF PURPOSE 2015-2016 1. Introduction The National Minimum Standards and Regulations for Fostering Services issued by the Secretary of
Changing children s lives
What is adoption? 01 What is adoption? Through adoption you can give a child a permanent, caring home and a sense of belonging, with the love and security of a stable family life guaranteed until they
PRIVACY POLICY. Privacy Statement
PRIVACY POLICY Privacy Statement Blue Care is one of Australia's leading providers of retirement living, community health, help at home services and aged care homes, caring for more than 12,500 people
Data Protection for the Guidance Counsellor. Issues To Plan For
Data Protection for the Guidance Counsellor Issues To Plan For Author: Hugh Jones Data Protection Specialist Longstone Management Ltd. Published by the National Centre for Guidance in Education (NCGE)
Data Protection Act 1998. Bring your own device (BYOD)
Data Protection Act 1998 Bring your own device (BYOD) Contents Introduction... 3 Overview... 3 What the DPA says... 3 What is BYOD?... 4 What are the risks?... 4 What are the benefits?... 5 What to consider?...
FAQ for schools with Administrative software Q17. How is POD going to work with local school admin software?
FAQ on the Primary Online Database Table of Contents FAQ on the data collection for POD Q1. Why is POD collecting all these different variables? Q2. Is there a template available that schools can send
foryou Charges and rates payable 2015-16 KCC working for you Information on revised charges and rates for 2015-16 for Specialist Children s Services
foryou KCC working for you Charges and rates payable 2015-16 Information on revised charges and rates for 2015-16 for Specialist Children s Services KCC working for you www.kent.gov.uk/adultsocialcare
ISLE OF WIGHT ADOPTION SERVICE STATEMENT OF PURPOSE ISLE OF WIGHT COUNCIL
ISLE OF WIGHT ADOPTION SERVICE STATEMENT OF PURPOSE 2011 ISLE OF WIGHT COUNCIL Author: Title: Karen Cheeseman Group manager Fostering and Adoption Date: April 2011 Review: April 2012 Version: 1.7 ISLE
Data Transfer Policy. Data Transfer Policy London Borough of Barnet
Data Transfer Policy Data Transfer Policy London Borough of Barnet Document Control POLICY NAME Data Transfer Policy Document Description Policy surrounding data transfers (electronic and paper based).
Data Protection Act 1998. Guidance on the use of cloud computing
Data Protection Act 1998 Guidance on the use of cloud computing Contents Overview... 2 Introduction... 2 What is cloud computing?... 3 Definitions... 3 Deployment models... 4 Service models... 5 Layered
Template for Automatic Number Plate Recognition (ANPR) Infrastructure Development Privacy Impact Assessment
Template for Automatic Number Plate Recognition (ANPR) Infrastructure Development Privacy Impact Assessment This template is provided to support the police service and other law enforcement agencies (LEA)
Data protection. Wi-Fi location analytics
Data protection Wi-Fi location analytics ICO lo Wi-Fi location analytics Data Protection Act Contents Introduction... 2 Overview... 2 What the DPA says... 2 What is Wi-Fi analytics?... 3 Conduct a privacy
Information Governance Policy
Information Governance Policy Document Number 01 Version Number 2.0 Approved by / Date approved Effective Authority Customer Services & ICT Authorised by Assistant Director Customer Services & ICT Contact
Egress Switch (Secure Email) for Third Parties
Egress Switch (Secure Email) for Third Parties The London Borough of Redbridge is implementing a new more secure way of communicating with third parties. Third parties are: Individuals receiving a service
HERTSMERE BOROUGH COUNCIL
HERTSMERE BOROUGH COUNCIL DATA PROTECTION POLICY October 2007 1 1. Introduction Hertsmere Borough Council ( the Council ) is fully committed to compliance with the requirements of the Data Protection Act
The report will form part of the performance record for the Council, and will be published on the CSCI website in November.
Mr Hugh Dunnachie Director of Social Services London Borough of Hillingdon Civic Centre High Street Uxbridge Lodnon UB8 1UW Dear Hugh ANNUAL REVIEW OF PERFORMANCE Thank you for arranging our recent annual
Adoption: what does it mean for birth parents?
Advice line: 0808 801 0366 Mon Fri: 9:30 3:00 Or get support on our discussion boards. www.frg.org.uk Advice line 0808 801 0366 Mo Fr: 9:30 3:30 Adoption: what does it mean for birth parents? Introduction
