Records management for the public sector 8 September 2016 Judith Jones - Group Manager Sue Markey - Senior Policy Officer Government and Society.

Slides:



Advertisements
Similar presentations
In confidence Chair: Storm Westmaas Principal Legal Adviser, the Standards Board for England Speakers: Bernadette Livesey Chief Law and Administration.
Advertisements

Open Public Services Listening Exercise Summary November 2011.
Getting data sharing right for every child
Big Data and data protection
Introduction to the APPs and the OAIC’s regulatory approach Presented by: Este Darin-Cooper Director, Regulation and Strategy May 2015.
Transparency in Public Administration – FOI and EIR
Towards a Freedom of Information Law in Qatar Fahad bin Mohammed Al Attiya Executive Chairman, Qatar National Food Security Programme.
Information Commissioner’s Office: data protection Judith Jones Senior Policy Officer Strategic Liaison – public security 16 November 2011.
Audiences NI Data Protection Workshop
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
An overview of the Data Protection Act Legal framework The Data Protection Act 1998 came into force in March 2001, replacing the Data Protection.
The ICO and the DPA Ken Macdonald Assistant Commissioner Information Commissioner’s Office ScotStat Public Sector Analysts Network 30 th September 2010.
How the Information Commissioner’s office operates as a regulator David Smith Deputy Information Commissioner.
Data Protection for Church of Scotland Congregations
The Information Commissioner’s Office David Evans.
Working together: Ensuring effective regulation Jonathan Bamford Head of Strategic Liaison.
Freedom of Information Workshop & Briefing 5 th March 2014 Welcome.
Handling information 14 Standard.
NHS England & Customer Contact Centre FOI Introduction 2013.
1 Freedom of Information (Scotland) Act 2002 A strategic view.
Public rights of access to information Grisilda Ponniah, Corporate Information Governance Manager Mary Elliott, FOI Officer Legal & Democratic Services.
Data Protection, Freedom of Information and Information/Records Management.
Information Sharing Sheila Logan Information Commissioner’s Office Employability Partnership Event Glasgow 13 August 2009.
Data Protection and Elected Members A Round Table Event From Bradford Council and iNetwork The Banqueting Hall, Bradford 11 th November 2013 Useful links.
Privacy Impact Assessments Iain Bourne, Group Manager, Policy Delivery Information Commissioner’s Office, UK Workshop on data protection and the internet:
Data Protection Act & Freedom of Information Simon Mansell Corporate Governance and Information Team.
Local Government Reform: Incorporating Planning Functions Ken Macdonald Assistant Commissioner (Scotland & Northern Ireland) Information Commissioner’s.
European Data Protection reform: preparing for the future Richard Syers - Strategic Liaison, ICO 12 September 2014.
Information sharing: the view from the ICO Vicky Cetinkaya, Senior Policy Officer, ICO One Staffordshire Information Sharing Protocol launch event Stafford,
Can you share? Yes you can!! Angus Council Adult Protection Maureen H Falconer, Senior Policy Officer Information Commissioner’s Office.
Information Security TechLink Seminar, 17 April 2013 James Knapton, Information Compliance Officer, Registrary’s Office.
Introduction to the Australian Privacy Principles & the OAIC’s regulatory approach Privacy Awareness Week 2016.
Collaborative Working & Best Practice A Seminar by the Public Services Ombudsman for Wales.
Workshop Understanding your responsibilities under the Data Protection Act 1998 and the Freedom of Information Act 2000 Adele Rhodes Girling.
Uses of brain imaging data: privacy and governance implications Dr. Hester Ward Medical Director, Information Services Division, (ISD) Consultant in Public.
Commissioning Services: with the DPA in mind South Yorkshire Information and Data Sharing Group Sheffield 14 th August 2014 Lynne Shackley Lead Policy.
Information Governance A refresher for all staff who have previously gone through the full course.
Data protection and data sharing
Data Protection Officer’s Overview of the GDPR
Accountability & Structured Privacy Management
The UK Information Commissioner’s Office (ICO)
The Possibilities are Endless?
Data protection for law firms Wednesday 13 July 12pm
Data Protection : A Practical Guide
Microsoft 365 Get help with regulatory compliance
Privacy Impact Assessments (PIAs)
General Data Protection Regulation
Museums + Heritage webinar, 30 November 2017
GDPR Overview Gydeline – October 2017
APP entities (organisations)
GDPR Overview Gydeline – October 2017
Data Protection & Freedom of Information- An Introduction
The Information Commissioner’s Office
GENERAL DATA PROTECTION REGULATION (GDPR)
GDPR and paper records Why it’s not all cyber and fines Gary Shipsey
Collaborative Working & Best Practice
Data protection reform – update from the ICO
Privacy: a work in progress
Information Governance
G.D.P.R General Data Protection Regulations
Data Protection principles
The National Working Group
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
How we’ll prepare for the General Data Protection Regulation (GDPR)
Information management and communication
Data protection and data sharing
General Data Protection Regulations 2018
Collaborative Working & Best Practice
Handling information 14 Standard.
GDPR what do we need to do?
Presentation transcript:

Records management for the public sector 8 September 2016 Judith Jones - Group Manager Sue Markey - Senior Policy Officer Government and Society

Outline ICO and records management Key themes and common trends How the ICO can help What’s new – DP and FOI

The Information Commissioner Elizabeth Denham Promoted transparency in government, proactive approach to enforcement of access and privacy laws Reports to Parliament Independent of Government

ICO enforces and regulates: –Freedom of Information Act –Data Protection Act –Environmental Information Regulations –Privacy and Electronic Communications Regulations –Re-use of Public Sector Information Regulations (TNA - policy, ICO – complaints) TNA, Records of Scotland, Public Record Office of Northern Ireland: - Public records legislation Other legal requirements and professional guidelines

Records Management legislation: FOI Section 46 Code of Practice “Freedom of information legislation is only as good as the quality of the records and other information to which it provides access.” Failure to follow the Section 46 Code of Practice may mean that an authority also fails to comply with other legislation concerning the creation, management, disposal, use and re-use of records and information, for example: Public Records Act 1958 Data Protection Act 1998 (DPA) Re-use of Public Sector Information Regulations 2015

Information Commissioner on FOI: highlighting records management concerns Timeliness in dealing with foi requests Duty to document in British Columbia Private s

Know what you hold

Know what you hold: think about Collecting personal data Responding to FOI requests Legacy records Paper vs digital records Private accounts Risk assessment

Retention

Personal data not to be kept for longer than is necessary. Consider the purpose you hold the information for when deciding how long to retain Retention and disposal schedules - useful when considering FOI complaints Retention requirements of TNA and regional bodies. And others including inquiries Keep retention periods under review Securely delete information that is no longer needed Update, archive or securely delete information if it goes out of date.

Timeliness

Time limits Subject access and FOIA requests have time limits for responses Senior commitment and effective liaison across the organisation is vital Identify barriers to good performance and draw up improvement plans Better reputation with the public ICO monitoring regime

Disposal

Disposing of data Requirement of the DPA to dispose of personal data securely Archiving or deletion? Only archive if still need to hold the information – otherwise delete ICO has issued monetary penalties eg abandoned filing cabinets, selling hard drives rather than destruction

Breaches

Self reported incidents – data protection Operational Statistics 2015/16

Self reported incidents - continued Operational Statistics 2015/16

Recent enforcement action August 2016 Hampshire County Council £100,000 May 2016 Blackpool Teaching Hospitals £185,000 November 2015 CPS £

ICO Audit Outcomes

Not understanding data flows Not understanding responsibilities Lack of training Inadequate, outdated or poorly communicated policies Lack of senior support, funding or visibility of information governance Failure to implement effective remedial measures quickly Inadequate long term remedial measures, with a failure to identify risks Trends – common failings

Data Protection self assessment toolkit ico.org.uk/for-organisations/improve-your practices/data-protection-self-assessment toolkit

Where now on FOI Technology, digitisation Digital Economy Bill – better use of data, data sharing Data protection law in the UK: what next? What’s new?

What the future holds on FOI Recommendations of the Independent Commission on Freedom of Information Divergence from FOISA Open data and the Open Government Partnership Trends, standards and expectations

Digital Economy Bill: digital government

ICO view Recognise benefits of justified data sharing Support permissive, enabling approach to legal gateways Need for robust safeguards to protect public from disproportionate data sharing – including use of PIAs Welcome guiding principle that the powers of DPA should not be weakened

The Data Protection Act remains UK law for now and it’s business as usual for most organisations

Over the coming weeks we will be discussing with Government the implications of the referendum result and its impact on data protection reform in the UK

“One thing we can say with reasonable confidence is that if any country wishes to share data with EU Member States, or for it to handle EU citizens’ data, they will need to be assessed as providing an adequate level of data protection. This will be a major consideration in the UK’s negotiations going forward” Baroness Neville-Rolfe DBE CMG Minister for Data Protection 4th July 2016,

The ICO will continue to provide practical advice and guidance ico.org.uk/dpreform

ICO guidance

ICO guidance on records management matters Section 46 Code of Practice – records management practice-records-management-foia-and-eir.pdf Guide to the Re-use of Public Sector Information Retention and destruction of requested information requested-information.pdf

Further reading The National Archives management/ National Records of Scotland management Public Record Office for Northern Ireland (PRONI) record-office-northern-ireland-proni/record-keeping-proni

ws Keep in touch Subscribe to our e-newsletter at or find us on…