Information Governance Policy

Save this PDF as:
 WORD  PNG  TXT  JPG

Size: px
Start display at page:

Download "Information Governance Policy"

Transcription

1 Information Governance Policy Reference: Information Governance Policy Date Approved: April 2013 Approving Body: Board of Trustees Implementation Date: April 2013 Version: 6 Supersedes: 5 Stakeholder groups consulted: Target Audience: Review Date: Lead Executive Author/Lead Manager: Information Governance Steering Group, Directors Team, Governance Committee Staff, Volunteers April 2018 (or earlier if changes in the law) Data Protection Officer Karen Pearce Mndahome-projects-IGSG-Documentation UNCONTROLLED COPY WHEN PRINTED Page 1 of 14

2 Information Governance Policy Contents Page Contents 2 1. Policy Statement of Intent 3 2. The MND Association s Information Governance Policy Introduction 2.2 Purpose of Policy 2.3 The Association s approach to Information Governance 2.4 Policies and procedures used by the Association 2.5 Responsibilities and accountabilities 2.6 Information Governance structure and responsibilities 2.7 Approval 3. Appendix A: Terms of Reference (Information Governance Steering Group) 7 4. Appendix B: Subject Access Request and Procedure 8 5. Appendix C: Subject Access Request Letter 9 6. Appendix D: Freedom of Information request Appendix E: Caldicott Principles Appendix F: Information Sharing Processes (Health & Social Services) Appendix G: Information Sharing Protocol (Health & Social Services) Appendix H: Breach of Data Management Procedure 14 Mndahome-projects-IGSG-Documentation UNCONTROLLED COPY WHEN PRINTED Page 2 of 14

3 1. Policy Statement of Intent As the Association expands its services to include care delivery that is funded through public sector resources, it has an obligation to assure that the public and its membership information is managed appropriately. Information is a vital asset to the Association. It is used on a daily basis for the management of all of our services. As we deliver care, such as Wheelchair Services, on behalf of statutory bodies we have a responsibility to people with MND for the efficient management of services and resources. Information plays a key part in Clinical/Research Governance, financial management, service planning, measuring and evidencing performance. It is of paramount importance to ensure that information is efficiently managed. It must be reliable, available at the point of need and appropriately retained and retrievable for future use. Staff and, where relevant, volunteers must be effectively trained and understand their responsibility for information. This activity is supported by a series of policies and procedures, with management accountability and structures to provide a robust governance framework for information management both now and in the future. Information Governance is a framework that brings together all of the statutory and mandatory requirements, and best practice standards that apply to the handling of information, allowing: Implementation of central advice and guidance Compliance with the law Self-assessment audits and assurance processes to measure and report performance Year-on-year improvement plans Public assurance and confidence in the Association s management of personal data Protection and maintenance of intellectual property Commercial and contractual compliance. The Information Governance Toolkit produced by the Information Commissioner s Office, groups the standards under six initiatives: 1. Information Governance Management Assurance 2. Confidentiality and Data Protection Assurance 3. Information Security Assurance 4. Clinical Information Assurance 5. Secondary Uses Assurance 6. Corporate Information Assurance. This Information Governance Policy sets out the Association s policy for the governance of information within the organisation in accordance to those standards. The policy will be reviewed and revised as and when it becomes necessary and at least every three years. Mndahome-projects-IGSG-Documentation UNCONTROLLED COPY WHEN PRINTED Page 3 of 14

4 2. The MND Association s Information Governance Policy 2.1 Introduction Information is a vital asset in terms of supporting service users, engagement with stakeholders and the efficient management of services and resources. It plays a key part in clinical governance, service planning and performance management. It is, therefore, of paramount importance that information is safely, securely and effectively managed, and that appropriate policies, procedures, management accountability and structures provide a robust governance framework for information management. 2.2 Purpose of the policy This Information Governance (IG) policy provides an overview of our approach to information governance, a guide to the procedures in use and details about the IG management structures within the organisation. 2.3 The Association s approach to Information Governance The Association strives to effectively implement information governance, and will ensure the following: Information will be protected against unauthorised access Confidentiality of information will be assured Accuracy of information will be maintained Information will be supported by the highest quality data Regulatory and legislative requirements will be met Business continuity plans will be produced, maintained and tested Information Governance training will be given to all staff and volunteers as necessary to their role All breaches of confidentiality and information security, actual or suspected, will be reported and investigated. 2.4 Policies and procedures used by the Association Information Governance will be managed through staff and volunteer compliance with the following policies and procedures: Data Protection Policy and Procedure The Minimum Data Set (MDS) and Enhanced MDS s Business continuity plans and procedures Condition of employment policies including: o Confidentiality Policy o Protection of Vulnerable Adults and Children Policy o Working at Home or Away from the Office Policy o Use of Information Communication Technology Policy o Commercial and Contractual Compliance Policy o Management of Intellectual Property Policy Volunteer agreement Mndahome-projects-IGSG-Documentation UNCONTROLLED COPY WHEN PRINTED Page 4 of 14

5 Information incidents: guidelines on identifying and reporting information incidents: Breach of data management procedure 2.5 Responsibilities and accountabilities The designated Information Governance / Data Protection lead for the Association is The Data Protection Officer, with delegated authority from the CE. The key responsibilities of the lead are: Developing and implementing IG procedures and processes for the Association Raising awareness, providing advice and guidelines about IG to all staff Ensuring that training needs are identified, developed and available Co-ordinating the activities of any staff given data protection, confidentiality, information quality, records management and freedom of information responsibilities Ensuring that data is kept secure and that all data flows, internal and external are periodically checked against the Caldicott Principles when sharing information with health and social care bodies (appendix E: Caldicott Principles) Monitoring information handling in the organisation to ensure compliance with law, guidance and local procedures Ensuring service users are appropriately informed about the organisation s information handling activities. The day-to-day responsibilities for providing guidance to staff and volunteers will be undertaken by relevant line managers. The Association s Board of Trustees and the Chief Executive are responsible for ensuring that sufficient resources are provided to support the effective implementation of IG in order to ensure compliance with the law and the IG assurance framework. All staff and volunteers, whether permanent, temporary or contracted, and contractors are responsible for ensuring that they are aware of and comply with the requirements of this policy and the procedures and guidelines produced to support it. 2.6 Information Governance structure and responsibilities The Board of Trustees via the Governance Committee is ultimately responsible for Information Governance within the Association and is also responsible for ensuring that sufficient resources are provided to support the requirements of the policy. The Chief Executive is the Accountable Officer with responsibility for ensuring overall Association compliance with its charitable obligations and relevant statutory obligations linked to Department of Health funded services. Mndahome-projects-IGSG-Documentation UNCONTROLLED COPY WHEN PRINTED Page 5 of 14

6 The Data Protection Officer has responsibility delegated from the Chief Executive for ensuring that effective systems and processes are in place to deliver the Data Protection and Information Governance agenda. The Directors are accountable to the Chief Executive for ensuring the effective implementation of the underpinning policies and procedures for IG within their respective directorate. The Senior Managers / Heads of Service are responsible for ensuring that all directorate staff are made aware of and comply with the policies, procedures and standards which support Information Governance. All Staff and volunteers, whether permanent, temporary or contracted, including students, agency staff and contractors are responsible for ensuring they are aware of the Information Governance requirements and for ensuring they comply with these on a day-to-day basis. For ease, the key policies are the Data Protection Policy, The Confidentiality Policy and The Information Security Policy. Any identified breach of information management will be reported by staff or volunteers immediately to their respective line managers for appropriate action. The Information Governance Steering Group is responsible for steering and overseeing the Association s compliance with the best practice standards set out in the NHS Information Governance Toolkit. This will support the Association in complying with standards required should it acquire Any Qualified Provider status. The Steering Group will ensure the development and maintenance of policies, standards, procedures and guidance, the development of an Information Governance framework and the design and review of performance indicators to measure compliance and progress against the Association s risk register. The Information Governance Steering Group reports to the Governance Committee (appendix A: Terms of Reference). 2.7 Approval This policy has been approved by the undersigned and will be reviewed on a three yearly basis or unless changes in national/european law indicate earlier amendments. Name Date approved Review date Mndahome-projects-IGSG-Documentation UNCONTROLLED COPY WHEN PRINTED Page 6 of 14

7 3. Appendix A: Terms of Reference (Information Governance Steering Group) Aim: To promote and monitor information security as an aid to the effective delivery of our mission. Membership: The Information Governance Steering Group (IGSG) will be made up of: The Data Protection Officer (Chair) Head of ICT Head of Communications A representative from each directorate Other members may be co-opted as appropriate, such as, the Human Resources Manager and members supporting internal audit procedures. Frequency: The IGSG will meet on a 3-monthly basis (as a minimum). Responsibilities the IGSG will be accountable for: The promotion of information security throughout the Association The review and recommendation for the approval of all information security related policies and procedures The monitoring of programme progress to achieve compliance with statutory / legislative requirements, and develop systems to ensure best practice The review and monitoring of information security incidents, their cause, resolution and future prevention using the Breach of Data Management Procedure Reviewing information security risk assessments and improvement plans Consideration of solutions to improve information security Monitoring and auditing compliance with relevant Association policies Receiving and reviewing information security related reports (e.g. internal audit) Reporting: The IGSG will report to the Governance Committee through the Directors team and from there to the Board of Trustees Mndahome-projects-IGSG-Documentation UNCONTROLLED COPY WHEN PRINTED Page 7 of 14

8 4. Appendix B: Subject Access Request and Procedure Any person the Association holds personal data on has a right to know about this. This is the right of Subject Access. Requests are often made if the person has some form of grievance with the Association, so it is important to ensure the Subject Access Request (SAR) is undertaken correctly. The right applies to data held both manually and electronically and includes access to medical records. In principle: The individual has the right to see most of the data held about them The Association must respond promptly to any request and within 40 calendar days The Association may charge up to 10 for a request (at Senior Management discretion) In general all information held by the Association at the time of the request must be provided in a permanent format unless: o It is not possible o It involves disproportionate time/effort o The person making the request agrees otherwise. There is information that some organisations are exempt from providing. To ensure best practice, when a SAR is received the following procedure will take place: SAR Received Date of receipt recorded SAR refereed to the Data Protection Officer Information collated Identity of person submitting SAR confirmed Electronic and manual data collected can this be achieved in a reasonable time/is it possible? Sense check Information checked to ensure no third party data included this cannot be shared without explicit consent of the third party Consider time taken to collate, will a charge be levied? Data sent to individual Send information to individual by recorded delivery Record actions in SAR log and time frame Indicate if breach of 40 day timeframe and actions taken to prevent recurrence Inform IGSG Inform Information Governance Steering Group a SAR has been received and responded to within timeframe Report if breach and action taken Mndahome-projects-IGSG-Documentation UNCONTROLLED COPY WHEN PRINTED Page 8 of 14

9 5. Appendix C: Subject Access Request Letter (Insert own address) (Insert date) (Insert organisation address) To the company secretary (if contact unknown), Re: (insert name and current address) I am writing to make a subject access request under the Data Protection Act 1998 for any personal information you hold about me (or include specific details about the information you require here). (Insert any information you think the organisation will need to find your information and to confirm your identity. For example, your employer may need your payroll number, and a hospital may need your NHS number; other organisations may require a document bearing your signature for example your passport or your driving licence). Please inform me, prior to processing this request, if you require a fee to be paid. I will look forward to receiving this information within 40 days. If you have any queries or questions then please contact me on (insert phone number/ address). Yours faithfully, (Insert own name) Top Tips: Remember to try to send your request by recorded delivery Remember to keep a copy of the letter and any further letters you send or receive A fee of no more than 10 may be payable The information may be sent to you as a computer print out, in a letter or forum Please contact the ICO if you experience difficulty in getting your information Web: Tel: Mndahome-projects-IGSG-Documentation UNCONTROLLED COPY WHEN PRINTED Page 9 of 14

10 6. Appendix D: Freedom of Information Request The Freedom of Information Act 2000, which came into force on 1 January 2005, is about open government. It is primarily a means of increasing transparency in official decision making and procedures, and enabling citizens to hold government to account. Ticher, P, in Association with Bates Wells and Braithwaite Solicitors 2009, Data Protection for Voluntary Organisations. Voluntary organisations are not usually required to provide information under the Freedom of Information Act (FOIA) However, should a voluntary organisation hold information on behalf of a public body (such as a contracted-out service), then it may be required to pass information to that body in order for it to meet a FOI request. In these circumstances the Association would be expected to respond swiftly in order to ensure compliance with the time limit of 20 working days. Mndahome-projects-IGSG-Documentation UNCONTROLLED COPY WHEN PRINTED Page 10 of 14

11 7. Appendix E: Caldicott Principles The MND Association is not governed by the processes of the Caldicott Report which was reviewed in March 2013, as it is a voluntary organisation. It does look to work within the Caldicott Principles which will support information sharing when working in collaboration with other organisations whether statutory or voluntary. The Caldicott Report (December 1997) and Executive Letter (January 1999) indicated a need for a process of continuous improvement in medical confidentiality within the National Health Service, including organisations now comprising the Health Protection Agency (HPA). In accordance with guidance laid out in the report, the HPA has appointed a Caldicott Guardian who is responsible for overseeing good practice in respect to access to, sharing of and confidentiality for patient records. These requirements especially affect data with Personal Identifiable Information. This is why some statutory bodies require additional reassurance when sharing data with staff and volunteers working with the Association. Personal Identifiable Information is information that could identify a person with MND in this instance, or any individual. It includes things like an NHS number, National Insurance (NI) number, date of birth or postcode, or data which can indirectly link to an individual by combining information (for example, country of birth, age and laboratory name). The Association does collect some of this data and, therefore, it would be best practice to work within the principles of the Caldicott Report which are summarised as follows: 1. Justify the purpose(s) for using patient data 2. Don t use patient-identifiable information unless it is absolutely necessary 3. Use the minimum necessary patient-identifiable information 4. Access to patient-identifiable information should be on a strict need to know basis 5. Everyone should be aware of their responsibilities to maintain confidentiality 6. Understand and comply with the law, in particular the Data Protection Act 7. The duty to share information can be as important as the duty to protect patient confidentiality The Association has processes in place to adhere to these through: Minimum data sets (MDS) or enhanced MDS Data Protection Policy and Procedure Confidentiality Policy and Procedure Relevant training Induction procedures Mndahome-projects-IGSG-Documentation UNCONTROLLED COPY WHEN PRINTED Page 11 of 14

12 8. Appendix F: Information Sharing Processes (Health & Social Services) i. The Association believes that accurate, timely and relevant information is essential to deliver the highest quality care. Each member of staff and volunteer is individually responsible for ensuring the quality of information they obtain and record, and to actively use information in accordance to the requirements, standards and best practice set out in the Information Governance Policy. ii. iii. iv. The Association supports the principles of Corporate Governance and recognises its public accountability, but equally places importance on confidentiality of both personal information about staff, volunteers, people affected by MND and commercially sensitive information. The Association also recognises the need to share information about people with MND with other health organisations and other agencies who work in partnership to deliver care and will do so in a controlled manner that is consistent with the interests of the person with MND with their consent, and in some circumstances, the public interest. It will also be consistent with the principles of the Caldicott Report. Information about the Association and its services will be made available to the public through the Annual Report. The Association will establish and maintain policies and procedures to ensure compliance with the right to know principles of the Freedom of Information Act (FOIA) 2000 (appendix D). v. The Association will proactively provide information under the FOIA Publication Scheme in accordance with the Information Commissioner s specifications for those services funded through public sector bodies (subcontracted to the Association) should those public sector bodies request the information. It does not need to publish information related to services funded through charitable income. vi. vii. viii. People with MND will have ready access to information relating to their own care, their options for treatment and their rights as patients. This is to enable them to make informed choices through the health service bodies hosting services, provided under the MND Association banner. The Association will support this process if necessary. The Association will publish clear procedures and arrangements for handling requests for information from people with MND and the public (appendix B) People with MND also have the right to access information through a Subject Access Request letter (appendix C). Mndahome-projects-IGSG-Documentation UNCONTROLLED COPY WHEN PRINTED Page 12 of 14

13 9. Appendix G: Information Sharing Protocol (Health & Social Services) Between: The Motor Neurone Disease Association and Date: The above listed partners agree to: i. At the outset, explain to people affected by MND openly and honestly what, how and why their information will be shared, and seek their consent. The exception to this is when a child, young person or others are at risk of significant harm. The withholding of this information could undermine the prevention, detection or prosecution of a serious crime. ii. iii. iv. Always consider the safety and welfare of those affected by MND when making a decision on whether to share information about them. Where there is concern that a person may be suffering or at risk of significant harm, the person s safety and welfare must be paramount. Where possible, respect the wishes of those affected by MND who do not consent to share their information. We may still share information, if our professional judgment on the facts, suggest there is sufficient public interest to override the lack of consent. Seek advice where we are in doubt, in particular where our doubt relates to a concern about the possibility of significant harm. v. Ensure that the information we share is accurate and up-to-date, necessary for the purpose for which we are sharing it and only on a need to know basis. vi. vii. viii. ix. Name: Always record the reasons for our decision. We understand that information concerning service users or staff is strictly confidential and must not be disclosed to unauthorised persons. This obligation shall continue in perpetuity. Disclosures of confidential information or disclosures of any data of a personal nature can result in prosecution for an offence under the Data Protection Act 1998 or an action for civil damages under the same Act. Both parties have read and understood the MND Association s Information Sharing Policy. Title: Organisation: Signature: Date: Name: Title: Organisation: Signature: Date: Mndahome-projects-IGSG-Documentation UNCONTROLLED COPY WHEN PRINTED Page 13 of 14

14 10. Appendix H: Breach of Data Management Procedure Breach of data management is identified either through accidental loss, human error, theft, unauthorised use, equipment failure, attack on system. Any member of staff or volunteer identifying a breach or potential breach of data management should report this immediately to their line / role manager Containment and recovery plan including damage limitation Data Protection Officer leads investigatory team Appropriate support resources made available e.g.: IT/Legal Recorder of actions identified Inform CE, who may escalate to Chair of Boards/Communications team 10.2 Assessment of ongoing risk and seriousness of impact on individuals Identify how serious risk is (risk to safety?)/how substantial (numbers involved) Identify whose data has been lost Is there a risk to reputation implement crisis communications plan Identify where data has gone, if possible Identify type of data personal sensitive. What will data tell 3rd party, and how could it be used? Was encryption/password protection in place 10.3 Notification of breach Notify individuals concerned as soon as possible once actions are clear Notification of internal relevant staff and other regulatory bodies Notify other third parties e.g. police/bank Manage communications with other stakeholders including media Data Protection Officer takes advice from ICO Notify ICO loss of laptop with unencrypted info of more than 100 individuals Notify ICO loss of manual info of more than 50 individuals 10.4 Evaluation and response Shared area with Association containing breaches, actions, review process, learning and monitoring held in CE office Training/learning / disciplinary actions identified. Any disciplinary procedures to be undertaken by independent director Any action against a third party to be identified and proceedings commenced and documented Communications response drafted, circulated to appropriate stakeholders and monitored Mndahome-projects-IGSG-Documentation UNCONTROLLED COPY WHEN PRINTED Page 14 of 14

INFORMATION GOVERNANCE STRATEGY

INFORMATION GOVERNANCE STRATEGY INFORMATION GOVERNANCE STRATEGY Page 1 of 10 Strategy Owner Valerie Penn, Head of Governance Strategy Author Caroline Law, Information Governance Project Manager Directorate Corporate Governance Ratifying

More information

Information Governance Policy Version - Final Date for Review: 1 October 2017 Lead Director: Performance, Quality and Cooperate Affairs

Information Governance Policy Version - Final Date for Review: 1 October 2017 Lead Director: Performance, Quality and Cooperate Affairs Information Governance Policy Version - Final Date for Review: 1 October 2017 Lead Director: Performance, Quality and Cooperate Affairs NOTE: This is a CONTROLLED Document. Any documents appearing in paper

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Version: 3.2 Authorisation Committee: Date of Authorisation: May 2014 Ratification Committee Level 1 documents): Date of Ratification Level 1 documents): Signature of ratifying

More information

Information Governance Policy

Information Governance Policy Author: Susan Hall, Information Governance Manager Owner: Fiona Jamieson, Assistant Director of Healthcare Governance Publisher: Compliance Unit Date of first issue: February 2005 Version: 5 Date of version

More information

Information Governance Strategy. Version No 2.0

Information Governance Strategy. Version No 2.0 Plymouth Community Healthcare CIC Information Governance Strategy Version No 2.0 Notice to staff using a paper copy of this guidance. The policies and procedures page of PCH Intranet holds the most recent

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Primary Intranet Location Information Management & Governance Version Number Next Review Year Next Review Month 7.0 2018 January Current Author Phil Cottis Author s Job Title

More information

All CCG staff. This policy is due for review on the latest date shown above. After this date, policy and process documents may become invalid.

All CCG staff. This policy is due for review on the latest date shown above. After this date, policy and process documents may become invalid. Policy Type Information Governance Corporate Standing Operating Procedure Human Resources X Policy Name CCG IG03 Information Governance & Information Risk Policy Status Committee approved by Final Governance,

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Information Governance Policy Issue Date: June 2014 Document Number: POL_1008 Prepared by: Information Governance Senior Manager Insert heading depending on Insert line heading

More information

Information Governance Strategy

Information Governance Strategy Information Governance Strategy Document Status Draft Version: V2.1 DOCUMENT CHANGE HISTORY Initiated by Date Author Information Governance Requirements September 2007 Information Governance Group Version

More information

Information Security Policy

Information Security Policy Information Security Policy v2.0 Target Audience: Policy Endorsed by: ESCC Staff, members and other agencies handling ESCC information Governance Committee Final V2.0 Page 1 of 13 Information Security

More information

Policy Document Control Page

Policy Document Control Page Policy Document Control Page Title Title: Information Governance Policy Version: 5 Reference Number: CO44 Keywords: Information Governance Supersedes Supersedes: Version 4 Description of Amendment(s):

More information

Information Governance Strategy. Version No 2.1

Information Governance Strategy. Version No 2.1 Livewell Southwest Information Governance Strategy Version No 2.1 Notice to staff using a paper copy of this guidance. The policies and procedures page of LSW Intranet holds the most recent version of

More information

Information Governance Strategy & Policy

Information Governance Strategy & Policy Information Governance Strategy & Policy March 2014 CONTENT Page 1 Introduction 1 2 Strategic Aims 1 3 Policy 2 4 Responsibilities 3 5 Information Governance Reporting Structure 4 6 Managing Information

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Policy Summary This policy outlines the organisation s approach to the management of Information Governance and information handling. It explains the accountability and reporting

More information

Information Governance Strategy

Information Governance Strategy Information Governance Strategy ONCE PRINTED OFF, THIS IS AN UNCONTROLLED DOCUMENT. PLEASE CHECK THE INTRANET FOR THE MOST UP TO DATE COPY Target Audience: All staff employed or working on behalf of the

More information

INFORMATION GOVERNANCE OPERATING POLICY & FRAMEWORK

INFORMATION GOVERNANCE OPERATING POLICY & FRAMEWORK INFORMATION GOVERNANCE OPERATING POLICY & FRAMEWORK Log / Control Sheet Responsible Officer: Chief Finance Officer Clinical Lead: Dr J Parker, Caldicott Guardian Author: Associate IG Specialist, Yorkshire

More information

Information Governance Strategy

Information Governance Strategy Information Governance Strategy To whom this document applies: All Trust staff, including agency and contractors Procedural Documents Approval Committee Issue Date: January 2010 Version 1 Document reference:

More information

INFORMATION GOVERNANCE AND DATA PROTECTION POLICY

INFORMATION GOVERNANCE AND DATA PROTECTION POLICY INFORMATION GOVERNANCE AND DATA PROTECTION POLICY WN CCG Information Governance & Data Protection Policy July 2013 1 Document Control Sheet Name of Document: Information Governance & Data Protection Policy

More information

Information Governance Policy

Information Governance Policy Information Governance Policy 1 Introduction Healthwatch Rutland (HWR) needs to collect and use certain types of information about the Data Subjects who come into contact with it in order to carry on its

More information

NHS Commissioning Board: Information governance policy

NHS Commissioning Board: Information governance policy NHS Commissioning Board: Information governance policy DOCUMENT STATUS: To be approved / Approved DOCUMENT RATIFIED BY: DATE ISSUED: October 2012 DATE TO BE REVIEWED: April 2013 2 AMENDMENT HISTORY: VERSION

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY Directorate of Performance Assurance INFORMATION GOVERNANCE POLICY Reference: DCP074 Version: 2.5 This version issued: 27/03/15 Result of last review: Minor changes Date approved by owner (if applicable):

More information

INFORMATION GOVERNANCE AND SECURITY 1 POLICY DRAFTED BY: INFORMATION GOVERNANCE LEAD 2 ACCOUNTABLE DIRECTOR: SENIOR INFORMATION RISK OWNER

INFORMATION GOVERNANCE AND SECURITY 1 POLICY DRAFTED BY: INFORMATION GOVERNANCE LEAD 2 ACCOUNTABLE DIRECTOR: SENIOR INFORMATION RISK OWNER INFORMATION GOVERNANCE AND SECURITY 1 POLICY DRAFTED BY: INFORMATION GOVERNANCE LEAD 2 ACCOUNTABLE DIRECTOR: SENIOR INFORMATION RISK OWNER 3 APPLIES TO: ALL STAFF 4 COMMITTEE & DATE APPROVED: AUDIT COMMITTEE

More information

1.5 The Information Governance Policy should be read in conjunction with the Information Governance Strategy.

1.5 The Information Governance Policy should be read in conjunction with the Information Governance Strategy. Title: Reference No: NHSNYYIG - 007 Owner: Author: INFORMATION GOVERNANCE POLICY Director of Standards First Issued On: September 2010 Latest Issue Date: February 2012 Operational Date: February 2012 Review

More information

IG: Third Party Contracts and Contractors Policy

IG: Third Party Contracts and Contractors Policy IG: Third Party Contracts and Contractors Policy Document Summary This policy provides guidance on the Information Governance arrangements that need to be considered and / or implemented when engaging

More information

Information Governance Strategy

Information Governance Strategy Information Governance Strategy THCCGCG9 Version: 01 The information governance strategy outlines the CCG governance aims and the key objectives of its governance policies. The Chief officer has the overarching

More information

Information Governance Policy

Information Governance Policy Information Governance Policy UNIQUE REF NUMBER: AC/IG/013/V1.2 DOCUMENT STATUS: Approved by Audit Committee 19 June 2013 DATE ISSUED: June 2013 DATE TO BE REVIEWED: June 2014 1 P age AMENDMENT HISTORY

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Version 1.1 Responsible Person Information Governance Manager Lead Director Head of Corporate Services Consultation Route Information Governance Steering Group Approval Route

More information

Version Number Date Issued Review Date V1 25/01/2013 25/01/2013 25/01/2014. NHS North of Tyne Information Governance Manager Consultation

Version Number Date Issued Review Date V1 25/01/2013 25/01/2013 25/01/2014. NHS North of Tyne Information Governance Manager Consultation Northumberland, Newcastle North and East, Newcastle West, Gateshead, South Tyneside, Sunderland, North Durham, Durham Dales, Easington and Sedgefield, Darlington, Hartlepool and Stockton on Tees and South

More information

Information Governance Policy

Information Governance Policy Information Governance Policy REFERENCE NUMBER IG 101 / 0v3 May 2012 VERSION V1.0 APPROVING COMMITTEE & DATE Clinical Executive 4.9.12 REVIEW DUE DATE May 2015 West Lancashire CCG is committed to ensuring

More information

Information Sharing Policy

Information Sharing Policy Information Sharing Policy REFERENCE NUMBER IG 010 / 0v3 February 2013 VERSION V1.0 APPROVING COMMITTEE & DATE Clinical Executive Committee 5.2.13 REVIEW DUE DATE February 2016 West Lancashire CCG is committed

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Version: Revised: Consultation: Ratified by: 1.0 Information Governance Committee Governance Committee Date ratified: 19 March 2008 Name of originator/author: David McGrath

More information

INFORMATION GOVERNANCE STRATEGIC VISION, POLICY AND FRAMEWORK

INFORMATION GOVERNANCE STRATEGIC VISION, POLICY AND FRAMEWORK INFORMATION GOVERNANCE STRATEGIC VISION, POLICY AND FRAMEWORK Policy approved by: Assurance Committee Date: 3 December 2014 Next Review Date: December 2016 Version: 1.0 Information Governance Strategic

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Document Number 01 Version Number 2.0 Approved by / Date approved Effective Authority Customer Services & ICT Authorised by Assistant Director Customer Services & ICT Contact

More information

Caedmon College Whitby

Caedmon College Whitby Caedmon College Whitby Data Protection and Information Security Policy College Governance Status This policy was re-issued in June 2014 and was adopted by the Governing Body on 26 June 2014. It will be

More information

Date of review: January 2016 Policy Category: Corporate Sponsor (Director): Chief Executive CONTENT SECTION DESCRIPTION PAGE.

Date of review: January 2016 Policy Category: Corporate Sponsor (Director): Chief Executive CONTENT SECTION DESCRIPTION PAGE. Title: Information Governance Policy Date Approved: Approved by: Date of review: Policy Ref: Issue: January 2015 Information Governance Group Division/Department: January 2016 Policy Category: ISP-04 5

More information

MOORLAND SURGICAL SUPPLIES LTD INFORMATION GOVERNANCE POLICY

MOORLAND SURGICAL SUPPLIES LTD INFORMATION GOVERNANCE POLICY MOORLAND SURGICAL SUPPLIES LTD INFORMATION GOVERNANCE POLICY Moorland is committed to ensuring that, as far as it is reasonably practicable, the way we provide services to the public and the way we treat

More information

Information Governance Strategy and Policy. OFFICIAL Ownership: Information Governance Group Date Issued: 15/01/2015 Version: 2.

Information Governance Strategy and Policy. OFFICIAL Ownership: Information Governance Group Date Issued: 15/01/2015 Version: 2. Information Governance Strategy and Policy Ownership: Information Governance Group Date Issued: 15/01/2015 Version: 2.0 Status: Final Revision and Signoff Sheet Change Record Date Author Version Comments

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Information Governance Policy_v2.0_060913_LP Page 1 of 14 Information Reader Box Directorate Purpose Document Purpose Document Name Author Corporate Governance Guidance Policy

More information

Information Governance Management Framework

Information Governance Management Framework Information Governance Management Framework Responsible Officer Author Business Planning & Resources Director Governance Manager Date effective from October 2015 Date last amended October 2015 Review date

More information

Policy Checklist. Head of Information Governance

Policy Checklist. Head of Information Governance Policy Checklist Name of Policy: Information Governance Policy Purpose of Policy: To provide guidance to all staff on their responsibilities regarding information governance and to ensure that the Trust

More information

Information Governance Policy

Information Governance Policy BEXLEY CARE TRUST MANAGEMENT MANUAL Title: INFORMATION GOVERNANCE POLICY Originating Department: IT DEPARTMENT Authorised by: Risk Management Committee June 2008 Reference no: CA12 Date of Issue: JANUARY

More information

INFORMATION GOVERNANCE POLICY & FRAMEWORK

INFORMATION GOVERNANCE POLICY & FRAMEWORK INFORMATION GOVERNANCE POLICY & FRAMEWORK Version 1.2 Committee Approved by Audit Committee Date Approved 5 March 2015 Author: Responsible Lead: Associate IG Specialist, YHCS Corporate & Governance Manger

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Owner : Head of Information Management Document ID : ICT-PL-0099 Version : 2.0 Date : May 2015 We will on request produce this Policy, or particular parts of it, in other languages

More information

Information Governance Framework and Strategy. November 2014

Information Governance Framework and Strategy. November 2014 November 2014 Authorship : Committee Approved : Chris Wallace Information Governance Manager CCG Senior Management Team and Joint Trade Union Partnership Forum Approved Date : November 2014 Review Date

More information

Information Governance Strategy :

Information Governance Strategy : Item 11 Strategy Strategy : Date Issued: Date To Be Reviewed: VOY xx Annually 1 Policy Title: Strategy Supersedes: All previous Strategies 18/12/13: Initial draft Description of Amendments 19/12/13: Update

More information

MONMOUTHSHIRE COUNTY COUNCIL DATA PROTECTION POLICY

MONMOUTHSHIRE COUNTY COUNCIL DATA PROTECTION POLICY MONMOUTHSHIRE COUNTY COUNCIL DATA PROTECTION POLICY Page 1 of 16 Contents Policy Information 3 Introduction 4 Responsibilities 7 Confidentiality 9 Data recording and storage 11 Subject Access 12 Transparency

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Reference number Approved by Information Management and Technology Board Date approved 14 th May 2012 Version 1.1 Last revised N/A Review date May 2015 Category Information Assurance Owner Data Protection

More information

Information security policy

Information security policy Information security policy Issue sheet Document reference Document location Title Author Issued to Reason issued NHSBSARM001 S:\BSA\IGM\Mng IG\Developing Policy and Strategy\Develop or Review of IS Policy\Current

More information

Information Governance Policy and Management Framework

Information Governance Policy and Management Framework Information Governance Policy and Management Framework Policy Number: IG01 Version: 3.0 Ratified by: Governing Body Date ratified: February 2016 Name of originator/author: Louise Chatwyn Information Governance

More information

Trust Informatics Policy. Information Governance. Information Governance Policy

Trust Informatics Policy. Information Governance. Information Governance Policy Trust Informatics Policy Information Governance Policy Reference: TIP/IG/IGP I:\IG\IGM\IGT\March 2011\Document Library\Policies\Approved/ - 1 Document Control Policy Title Author/Contact Document Reference

More information

SALISBURY NHS FOUNDATIONTRUST

SALISBURY NHS FOUNDATIONTRUST SALISBURY NHS FOUNDATIONTRUST PAPER SHC 1738 TITLE Information Governance Policy PURPOSE OF PAPER The Information Governance Policy was first approved in April 2005. It is currently due for review to ensure

More information

INFORMATION GOVERNANCE STRATEGY NO.CG02

INFORMATION GOVERNANCE STRATEGY NO.CG02 INFORMATION GOVERNANCE STRATEGY NO.CG02 Applies to: All NHS LA employees, Non-Executive Directors, secondees and consultants, and/or any other parties who will carry out duties on behalf of the NHS LA.

More information

Information Security Policy

Information Security Policy Information Security Policy Reference No: Version: 5 Ratified by: CG007 Date ratified: 26 July 2010 Name of originator/author: Name of responsible committee/individual: Date approved by relevant Committee:

More information

A Question of Balance

A Question of Balance A Question of Balance Independent Assurance of Information Governance Returns Audit Requirement Sheets Contents Scope 4 How to use the audit requirement sheets 4 Evidence 5 Sources of assurance 5 What

More information

Information Governance Policy (incorporating IM&T Security)

Information Governance Policy (incorporating IM&T Security) (incorporating IM&T Security) ONCE PRINTED OFF, THIS IS AN UNCONTROLLED DOCUMENT. PLEASE CHECK THE INTRANET FOR THE MOST UP TO DATE COPY Target Audience: All staff employed or working on behalf of the

More information

Information governance strategy 2014-16

Information governance strategy 2014-16 Information Commissioner s Office Information governance strategy 2014-16 Page 1 of 16 Contents 1.0 Executive summary 2.0 Introduction 3.0 ICO s corporate plan 2014-17 4.0 Regulatory environment 5.0 Scope

More information

Information Governance Framework

Information Governance Framework Information Governance Framework March 2014 CONTENT Page 1 Introduction 1 2 Strategic Aim 2 3 Purpose, Values and Principles 2 4 Scope 3 5 Roles and Responsibilities 3 6 Review 5 Appendix 1 - Information

More information

NHS Business Services Authority Information Security Policy

NHS Business Services Authority Information Security Policy NHS Business Services Authority Information Security Policy NHS Business Services Authority Corporate Secretariat NHSBSAIS001 Issue Sheet Document reference NHSBSARM001 Document location F:\CEO\IGM\IS\BSA

More information

INFORMATION GOVERNANCE HANDBOOK

INFORMATION GOVERNANCE HANDBOOK INFORMATION GOVERNANCE HANDBOOK SECTION ONE Author Tracey Burrows Role Information Governance Manager (CSCSU) Date / Version February 2015 Version FINAL V1.0 Approved by IM&T Board Date 27 February 2015

More information

Lancashire County Council Information Governance Framework

Lancashire County Council Information Governance Framework Appendix 'A' Lancashire County Council Information Governance Framework Introduction Information Governance provides a framework for bringing together all of the requirements, standards and best practice

More information

Corporate Information Security Policy

Corporate Information Security Policy Corporate Information Security Policy. A guide to the Council s approach to safeguarding information resources. September 2015 Contents Page 1. Introduction 1 2. Information Security Framework 2 3. Objectives

More information

Barnsley Clinical Commissioning Group. Information Governance Policy and Management Framework

Barnsley Clinical Commissioning Group. Information Governance Policy and Management Framework Putting Barnsley People First Barnsley Clinical Commissioning Group Information Governance Policy and Management Framework Version: 1.1 Approved By: Governing Body Date Approved: 16 January 2014 Name of

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Date approved by Heads of Service 3 June 2014 Staff member responsible Director of Finance and Corporate Services Due for review June 2016 Data Protection Policy Content Page 1 Purpose

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Title Author Approved By and Date Review Date Mike Pilling Latest Update- Corporation May 2008 1 Aug 2013 DATA PROTECTION ACT 1998 POLICY FOR ALL STAFF AND STUDENTS 1.0 Introduction 1.1 The Data Protection

More information

Subject Access Request (SAR) Procedure

Subject Access Request (SAR) Procedure Subject Access Request (SAR) Procedure East and North Hertfordshire Clinical Commissioning Group Page 1 of 16 DOCUMENT CONTROL SHEET Document Owner: Chief Finance Officer Document Author(s): Anne Ephgrave

More information

Policy: D9 Data Quality Policy

Policy: D9 Data Quality Policy Policy: D9 Data Quality Policy Version: D9/02 Ratified by: Trust Management Team Date ratified: 16 th October 2013 Title of Author: Head of Knowledge Management Title of responsible Director Director of

More information

Information Governance Strategy 2015/16

Information Governance Strategy 2015/16 Information Governance Strategy 2015/16 Ratified Governing Body (November 2015) Status Final Issued November 2015 Approved By Executive Committee (August 2015) Consultation Equality Impact Assessment Internal

More information

RECORDS MANAGEMENT POLICY

RECORDS MANAGEMENT POLICY RECORDS MANAGEMENT POLICY Version 8.0 Purpose: For use by: This document is compliant with /supports compliance with: To outline the lifecycle of a record and to provide guidance on retention and disposal

More information

INFORMATION RISK MANAGEMENT POLICY

INFORMATION RISK MANAGEMENT POLICY INFORMATION RISK MANAGEMENT POLICY DOCUMENT CONTROL: Version: 1 Ratified by: Steering Group / Risk Management Sub Group Date ratified: 21 November 2012 Name of originator/author: Manager Name of responsible

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Including the Information Governance Strategy Framework and associated Information Governance Procedures Last Review Date Approving Body N/A Governing Body Date of Approval

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Version Version 1 Ratified By Date Ratified PROPOSED FOR APPROVAL 15/11/12 Author(s) Responsible Committee / Officers Date Issue November 2012 Review Date November 2013 Intended

More information

Information Governance Plan

Information Governance Plan Information Governance Plan 2013 2015 1. Overview 1.1 Information is a vital asset, both in terms of the clinical management of individual patients and the efficient organisation of services and resources.

More information

JOB DESCRIPTION. Information Governance Manager

JOB DESCRIPTION. Information Governance Manager JOB DESCRIPTION POST TITLE: Information Governance Manager DIRECTORATE: ACCOUNTABLE TO: BAND: LOCATION: CSS Head of Information Governance 8a CSS Job Purpose The Information Governance Manager will ensure

More information

NHS Newcastle Gateshead Clinical Commissioning Group. Information Governance Strategy 2015/16

NHS Newcastle Gateshead Clinical Commissioning Group. Information Governance Strategy 2015/16 NHS Newcastle Gateshead Clinical Commissioning Group Information Governance Strategy 2015/16 Document Status Equality Impact Assessment Document Ratified/Approved By Approved No impact NHS Quality, Safety

More information

INFORMATION SECURITY MANAGEMENT POLICY

INFORMATION SECURITY MANAGEMENT POLICY INFORMATION SECURITY MANAGEMENT POLICY Security Classification Level 4 - PUBLIC Version 1.3 Status APPROVED Approval SMT: 27 th April 2010 ISC: 28 th April 2010 Senate: 9 th June 2010 Council: 23 rd June

More information

Corporate Policy and Strategy Committee

Corporate Policy and Strategy Committee Corporate Policy and Strategy Committee 10am, Tuesday, 30 September 2014 Information Governance Policies Item number Report number Executive/routine Wards All Executive summary Information is a key asset

More information

Information Assurance Policies and Guidance. Information Governance Policy. Document Version: v0.5 Review Date: 1 May 2016

Information Assurance Policies and Guidance. Information Governance Policy. Document Version: v0.5 Review Date: 1 May 2016 Information Assurance Policies and Guidance Information Governance Policy Document Version: v0.5 Review Date: 1 May 2016 Owner: Information Governance Manager 1 P a g e Document History Revision Version

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Name of Policy Author: Name of Review/Development Body: Ratification Body: Ruth Drewett Information Governance Steering Group Committee Trust Board : April 2015 Review date:

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Version: 4 Bodies consulted: Caldicott Guardian, IM&T Directors Approved by: MT Date Approved: 27/10/2015 Lead Manager: Governance Manager Responsible Director: SIRO Date

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Implementation date: 30 September 2014 Control schedule Approved by Corporate Policy and Strategy Committee Approval date 30 September 2014 Senior Responsible Officer Kirsty-Louise

More information

Data Protection Policy

Data Protection Policy London Borough of Enfield Data Protection Policy Author Mohi Nowaz Classification UNCLASSIFIED Date of First Issue 10/08/2012 Owner IGB Issue Status DRAFT Date of Latest Re-Issue 12/09/2012 Version 0.6

More information

Gloucestershire Hospitals

Gloucestershire Hospitals Gloucestershire Hospitals NHS Foundation Trust TRUST POLICY In the case of hard copies of this policy the content can only be assured to be accurate on the date of issue marked on the document. The Policy

More information

LEEDS BECKETT UNIVERSITY. Information Security Policy. 1.0 Introduction

LEEDS BECKETT UNIVERSITY. Information Security Policy. 1.0 Introduction LEEDS BECKETT UNIVERSITY Information Security Policy 1.0 Introduction 1.1 Information in all of its forms is crucial to the effective functioning and good governance of our University. We are committed

More information

NHS England Complaints Policy

NHS England Complaints Policy NHS England Complaints Policy 1 2 NHS England Complaints Policy NHS England Policy and Corporate Procedures Version number: 1.1 First published: September 2014 Prepared by: Kerry Thompson, Senior Customer

More information

Information Governance Standards in Relation to Third Party Suppliers and Contractors

Information Governance Standards in Relation to Third Party Suppliers and Contractors Information Governance Standards in Relation to Third Party Suppliers and Contractors Document Summary Ensure staff members are aware of the standards that should be in place when considering engaging

More information

Staffordshire County Council. Records Management Policy

Staffordshire County Council. Records Management Policy Staffordshire County Council Records Management Policy Version Author Approved By Date Published Review V. 2.0 Information Governance Unit Philip Jones, Head of Information Governance 2/11/2012 November

More information

1. Introduction... 3. 2. Statement of Policy. 3. 3. The Eight Principles of Data Protection... 4. 4. Scope... 5. 5. Roles and Responsibilities.

1. Introduction... 3. 2. Statement of Policy. 3. 3. The Eight Principles of Data Protection... 4. 4. Scope... 5. 5. Roles and Responsibilities. Data Protection Policy 2011 Contents Page 1. Introduction... 3 2. Statement of Policy. 3 3. The Eight Principles of Data Protection...... 4 4. Scope.... 5 5. Roles and Responsibilities. 5 6. Development

More information

Surrey & Sussex Healthcare NHS Trust

Surrey & Sussex Healthcare NHS Trust Surrey & Sussex Healthcare NHS Trust An Organisation-wide Policy for Information Governance (IG) Version 1.3 Status Ratified Date Ratified March 2008 Name of Owner Name of Sponsor Group Name of Ratifying

More information

CCG: IG06: Records Management Policy and Strategy

CCG: IG06: Records Management Policy and Strategy Corporate CCG: IG06: Records Management Policy and Strategy Version Number Date Issued Review Date V3 08/01/2016 01/01/2018 Prepared By: Consultation Process: Senior Governance Manager, NECS CCG Head of

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Responsible Officer Author Date effective from July 2009 Ben Bennett, Business Planning & Resources Director Julian Lewis, Governance Manager Date last amended December 2012 Review

More information

NHS North Durham Clinical Commissioning Group. Information Governance Strategy 2015/16

NHS North Durham Clinical Commissioning Group. Information Governance Strategy 2015/16 NHS North Durham Clinical Commissioning Group Information Governance Strategy 2015/16 Document Status Equality Impact Assessment Document Ratified/Approved By Final No impact Risk and Audit Committee/Governing

More information

Data Subject Access Request Procedure

Data Subject Access Request Procedure Data Subject Access Request Procedure Policy ID IG07 Version: 2.0 Ratified by: Executive Committee Name of originator/author: Justin Dix, Governing Body Secretary Name of responsible committee/individual:

More information

Freedom of Information Policy Version 6.0

Freedom of Information Policy Version 6.0 Freedom of Information Policy Lead executive Name / title of author: Date reviewed: September 2015 Chief Nurse, Executive Director for Risk and Governance Colin Owen, Information Governance and Data Security

More information

Corporate Health and Safety Policy

Corporate Health and Safety Policy Corporate Health and Safety Policy November 2013 Ref: HSP/V01/13 EALING COUNCIL Table of Contents PART 1: POLICY STATEMENT... 3 PART 2: ORGANISATION... 4 2.1 THE COUNCIL:... 4 2.2 ALLOCATION OF RESPONSIBILITY...

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Policy ID IG02 Version: V1 Date ratified by Governing Body 27/09/13 Author South Commissioning Support Unit Date issued: 21/10/13 Last review date: N/A Next review date: September

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Issued by: Senior Information Risk Owner Policy Classification: Policy No: POLIG001 Information Governance Issue No: 1 Date Issued: 18/11/2013 Page No: 1 of 16 Review Date:

More information

INFORMATION GOVERNANCE INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE INFORMATION GOVERNANCE POLICY Appendix 1 INFORMATION GOVERNANCE INFORMATION GOVERNANCE POLICY Author Information Governance Review Group Information Governance Committee Review Date May 2014 Last Update February 2013 Document No. GV

More information

HOW WE USE YOUR PERSONAL INFORMATION

HOW WE USE YOUR PERSONAL INFORMATION HOW WE USE YOUR PERSONAL INFORMATION Information Leaflet Your Health. Our Priority. Page 2 of 9 Introduction This Leaflet explains why the NHS collects information about you and how it is used, your right

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Responsible Officer Author Ben Bennett, Business Planning & Resources Director Julian Lewis, Governance Manager Date effective from August 2009 Date last amended August 2009

More information

Data Protection Policy. Leeds City Council. Information Governance team, Intelligence & Performance - 1 -

Data Protection Policy. Leeds City Council. Information Governance team, Intelligence & Performance - 1 - Leeds City Council Data Protection Policy - 1 - Document Control Organisation Leeds City Council Title Data Protection Policy Author Mark Turnbull, Legal Services Filename DPA policyvr1.doc Owner Assistant

More information