Stakeholder workshop Central government. Thursday 26 March 2015



Similar documents
UK Data Protection Newsletter June 2015

View the Replay on YouTube. The ICO s take on Information Sharing in the NHS. FairWarning Ready Executive Webinar Series 27 June 2013

Criminal Injuries Compensation Authority. Data protection audit report

Code of Practice on the discharge of the obligations of public authorities under the Environmental Information Regulations 2004 (SI 2004 No.

The guidance will be developed over time in the light of practical experience.

Summary of feedback on Big data and data protection and ICO response

Requests where the cost of compliance with a request exceeds the appropriate

Definition document for Health Bodies in Wales (including Local Health Boards, NHS trusts and Ambulance trusts)

Definition document for colleges of further education

REPORT OF: DIRECTOR OF DEMOCRATIC AND LEGAL SERVICES 13/358 WARDS AFFECTED: ALL

Information Commissioner s Office. Information Commissioner s Annual Report and Financial Statements 2015/16

Introduction to Notice Processing and Information Management. Assessment criteria. The learner can:

When things go wrong: information governance breaches and the role of the ICO. David Evans, Senior Policy Officer

Section 56 Enforced Subject Access: Worth the wait? Jonathan Bamford Head of Strategic Liaison Information Commissioner s Office

Guidance on political campaigning

Requests for personal data about public authority employees

technical factsheet 176

Auditing data protection a guide to ICO data protection audits

All Party Parliamentary Group (APPG) on Nuisance Calls inquiry into Nuisance Telephone Calls. Written evidence from BT.

DELIVERING OUR STRATEGY

Corporate Policy and Strategy Committee

Thank you for your request for information regarding ACPO UAS Steering Group which has now been considered.

The Information Commissioner s Office response to HM Treasury s Call for Evidence on Data Sharing and Open Data in Banking

DATA PROTECTION POLICY

Business Plan

Disclosable under FOIA 2000: Yes Author: T/CI Nick Barker Force / Organisation: BTP Date Created: May 2009 Telephone:

Information Law Training and Advice Access to Deceased Persons Records under the Freedom of Information Act 2000

Freedom of Information Policy Version 6.0

Privacy fact sheet 17

Freedom of Information Act 2000 (FOIA) Decision notice

Update on the ICO and Ofcom Joint Action Plan for tackling nuisance calls and messages

Data and Cyber Laws Up-date 9 July 2015

FACEBOOK STATEMENT RICHARD ALLAN NOVEMBER 11, My name is Richard Allan, and I am the Director of Public Policy

Freedom of Information Act Section 14 (1) Refusal Notice - Vexatious Requests

Property searches and the EIR

Privacy and Electronic Communications Regulations

Rick Parsons Information Governance Officer County Hall

Royaume-Uni Cour suprême. United Kingdom Supreme Court

Information governance strategy

Freedom of Information Act 2000 (FOIA) Decision notice

2015 No FINANCIAL SERVICES AND MARKETS. The Small and Medium Sized Business (Finance Platforms) Regulations 2015

Case Handling Workshop The Data Cycle Unsolicited marketing and lead generation

INFORMATION GOVERNANCE STRATEGY NO.CG02

UK Implementation of Directive 2011/24/EU on patients rights in cross-border healthcare. Rob Dickman International Division

FIRST-TIER TRIBUNAL GENERAL REGULATORY CHAMBER Information Rights

Subject access code of practice

COMPLYING WITH THE E-COMMERCE REGULATIONS 2002

Legal Aspects of the MonIKA-Project - Privacy meets Cybersecurity

Security breaches: A regulatory overview. Jonathan Bamford Head of Strategic Liaison

Caedmon College Whitby

Data Protection Act. Conducting privacy impact assessments code of practice

Impact Assessment (IA)

Employee pension rights after a TUPE transfer

Data Protection HEADLINE PART Developments: Implications HEADLINE for the PART Insurance 2 Sector Strategies for Compliance

DEPARTMENT OF HEALTH FIXED RECOVERABLE COSTS PROPOSALS FOR CLINICAL NEGLIGENCE: Implications for patients access to justice and for patient safety

The Data Protection Landscape. Before and after GDPR: General Data Protection Regulation

IN THE MATTER OF AN APPEAL TO THE FIRST TIER TRIBUNAL (INFORMATION RIGHTS) UNDER SECTION 57 OF THE FREEDOM OF INFORMATION ACT 2000.

On the edge Lexis PSL Restructuring & Insolvency

Introduction and contact details

Protection. Code of Practice. of Personal Data RPC001147_EN_WB_L_1

ICO SME data protection workshop 25 September, NEC

Consultation Response Report. 25 February Chapter 1: Introduction

CONSULTATION PAPER NO

MONMOUTHSHIRE COUNTY COUNCIL DATA PROTECTION POLICY

Information Governance Policy

Position of the retail and wholesale sector on the Draft Data Protection Regulation in view of the trilogue 2015

INFORMATION GOVERNANCE OPERATING POLICY & FRAMEWORK

Personal information (section 40 and regulation 13)

Everyone in the workplace has a legal duty to protect the privacy of information about individuals. AEP/BELB/LJ/2010 Awareness Session

Multi-Jurisdictional Study: Cloud Computing Legal Requirements. Julien Debussche Associate January 2015

Report of the Nuisance Calls and Texts Task Force on Consent and Lead Generation

Dealing with vexatious requests (section 14)

FoI Review - A Key Analysis of the Cost Drivers

Daltrak Building Services Pty Ltd ABN: Privacy Policy Manual

INFORMATION GOVERNANCE STRATEGIC VISION, POLICY AND FRAMEWORK

Enforced subject access (section 56)

Falcon & Pointer fined 175,000 for making automated calls

VAT Treatment of Cross Border Transactions in the Single Market

Data Protection in Clinical Studies Implications of the New EU General Data Protection Regulation

Access to NHS Records transferred to places of deposit under the Public Records Act

How To Use A Surveillance Camera Safely

Helping to protect your business and your customers in the event of a data breach

Information Management Strategy. July 2012

ACCESS TO MEDICAL RECORDS. By Felicia Jolaoye Blavo & Co Solicitors Ltd.

Proposed Public Records Legislation Consultation

Surveillance Camera Code of Practice. June 2013

NHS DORSET CLINICAL COMMISSIONING GROUP GOVERNING BODY INFORMATION GOVERNANCE TOOLKIT REPORT

Council, 14 May Information Governance Report. Introduction

Protection. Code of Practice. of Personal Data RPC001147_EN_D_19

Barnet Partnership Information Sharing Protocol

12th January Dear Mr. Graham, Complaint: Internet Eyes

Client complaint management policy

BCS, The Chartered Institute for IT Consultation Response to:

Legal professional privilege (section 42)

Office of Police & Crime Commissioner Devon & Cornwall Policy Cover Sheet

John Evason, Monica Kurnatowska and Daniel Ellis Partners, Collective Rights Group

Data Protection Policy

CFTC BRIEFING 2 JUNE 2015 CYBERSECURITY CONSIDERING BANK OF ENGLAND S CBEST PROGRAM

VOLUNTEERS & THE LAW

Transcription:

Stakeholder workshop Central government Thursday 26 March 2015

Welcome Sue Markey Government and Society Team Strategic Liaison

Introductions

This afternoon s programme 13.30 14.20 Data Protection and Privacy: key ICO issues and update 14.20 14.40 Break and networking 14.40-15.15 Freedom of Information: key ICO issues and update 15.15-15.40 ICO website a central government sector page?

The ICO: data protection update Judith Jones - Group Manager Government and Society Information Commissioner s Office

ICO corporate plan

Business plan priorities include: preparing for period of substantial change with the implementation of new EU data protection framework and outcome of Triennial Review developing and promoting an ICO privacy seal scheme as a means of demonstrating a commitment to good dp practices engaging with transparency and Open Data initiatives to ensure a balanced information rights perspective

Government changes Introduced powers of compulsory audit to public authority NHS bodies Reduced the burden of proof to fine nuisance callers Outlawing enforced subject access requests Extended the FOI Act to Network Rail

Data protection: current issues Data sharing service delivery reform, digitalisation of public services Open data, big data, definition of personal data Encouraging good practice PIAs, Privacy by Design General election electoral register, political parties Surveillance EU DP reform

EU data protection reform General Regulation not Directive Law enforcement Directive still on the table Council work ongoing partial general agreement Latvian Presidency until June 2015 political agreement? Trilogue Commission/Parliament/Council Possible completion in Brussels by first half 2016 UK implementation mid 2018?

EU data protection reform Key issues remain: scalability of the obligations, particularly for small businesses, provisions on profiling and risk, definition and use of pseudonymisation, one stop shop and associated consistency mechanism, the right to be forgotten and the Regulation s enforceability overseas, and duties of data protection authorities including the imposition of sanctions.

Privacy seals Third parties to deliver privacy seal schemes Operators must be accredited by the UK Accreditation Service (UKAS) Aim for first scheme to be up and running in 2016

PIAs Code of Practice One year on Application of PIA s in practice Process v Policy Good Practice examples Embed proactively Benefit to organisations

Enforcement, security breaches PECR easier to tackle spam texts etc from 6 April Intelligence sharing UK Cybersecurity threats and data protection law Increased international cooperation - Global Privacy Enforcement Network (GPEN)

DP cases Edem v ICO & FSA [2014] Court of Appeal - clarification of the definition of personal data Weller and others v Associated Newspapers Ltd [2014] High Court of England and Wales - photos of Paul Weller s children on a family outing in a public place. Ryneš v Úřad pro ochranu osobních údajů [2014] Court of Justice of the European Union CCTV footage does not fall within domestic purpose exemption Max Mosley v Google Inc. & Google UK Limited [2015] High Court of England and Wales Mr Mosley s DPA claim was a viable claim.

Freedom of Information and Environmental Information Regulations: news and update

Contents Outsourcing and FOI Recent cases Current issues ICO guidance

Outsourcing and FOI Transparency in outsourcing: a road map An ICO discussion document on how to achieve greater transparency about services and functions outsourced by public authorities Transparency in outsourcing: a roadmap

Four steps to greater transparency in outsourcing 1. Better contracts 2. Transparency by Design 3. Legislation 4. Standard contract terms

A Transparency by Design approach Key elements: Make as much information as possible available proactively as open data Agree with contractors what information is in scope of a FOIA request and in particular what information is held by the contractor on behalf of the public authority Set out the responsibilities of both parties in dealing with FOIA requests Consider in advance whether FOIA exemptions could apply to any of the information

Outsourcing and freedom of information guidance document Practical advice for public authorities Deciding whether information is held on behalf of the public authority How to adopt a transparency by design approach Outsourcing and freedom of information

Recent cases Department for Education v Information Commissioner & McInerney (EA/2013/0270) Concerned a request for information about applications to establish Free Schools and about decision letters sent by the Department for Education in response to such applications. The First Tier Tribunal (FTT) had decided that the Department could rely as of right on a late claim of section 12 or 14 and that, on the facts of this case section 14 was engaged. The above decision was appealed by Ms McInerney to the Upper Tribunal (UT). At the hearing on 22 January 2015 the UT dismissed the appeal.

Fish Legal v Information Commissioner and others [2015] UKUT 0052 (AAC) (16 February 2015) The Upper Tribunal (UT) ruled that private water companies are public authorities for the purposes of the Environmental Information Regulations (SI 2004/3391). Applying the previous ruling of the Court of Justice of the European Union (C-279/12), the Upper Tribunal based its decision on the fact that water companies have "special powers" over and above those in private law. At the same time, the UT rejected an argument that the water companies were public authorities by virtue of the fact that they are under the control of other public authorities such as OFWAT or the Environment Agency.

Current issues Vexatious and Manifestly Unreasonable requests Form of requested information Supreme Court ruling in Evans!

Recently published ICO guidance Consideration of the identity or motives of the requestor The requestor s identity may be taken into account when: The authority has reason to believe that the requestor hasn t provided their real name Determining whether the cost of two or more requests can be aggregated under s12 The requested information contains the requestor s own personal data Assessing whether the information is reasonably accessible to the requestor by other means Assessing whether the request is a repeated request When considering refusing a request as vexatious / manifestly unreasonable Where a request is unclear or ambiguous knowing the purpose behind it would help the authority identify and locate the requested information If applying a prejudice or adverse effect based exemption pa is concerned about how the requester will use the information

Recently published ICO guidance Section 39 exemption - Environmental Information Provides an overview of the exemption provided by s39 FOIA And includes: Determining whether a pa is subject to the EIR Determining whether the information is environmental Applying the exemption Procedural requirements Dealing with mixed requests The interaction between sections 39 and 21 FOIA

ICO guidance Guidance currently being updated Section 16 Advice and Assistance Section 22 - Information intended for future publication Section 29 The Economy Section 38 - Health and Safety Section 39 What is environmental information Section 41 Information provided in confidence Section 45 Code of Practice Section 46 Code of Practice on records management

ICO website A central government sector page? Would you find this useful? What should it contain? Links to external sources of relevant information?

Keep in touch Subscribe to our e-newsletter at www.ico.gov.uk or find us on www.twitter.com/iconews