Research and the Data Protection and Freedom of Information Acts

Slides:



Advertisements
Similar presentations
The Legislative Position in Scotland Environmental Information (Scotland) Regulations 2004 SSI 2004 No.520 Professor Colin Reid, School of Law, University.
Advertisements

IMPS Information Management and Policy Services Information Services Directorate A briefing for all University staff November 2004 New Information Legislation.
Data Protection and Freedom of Information
Research and the Data Protection and Freedom of Information Acts.
Freedom of Information Act 2000 and the PCT Audit Procedure Background: The Act was passed in November The Act will be fully in force by January.
Data Protection Information Management / Jody McKenzie.
BIOMETRICS, CCTV & DATA PROTECTION By Drudeisha Madhub Data Protection Commissioner Date:
The Data Protection (Jersey) Law 2005.
Overview of FOI legislation FOI and HE researchers Margaret Keyse Head of Enforcement.
Complying with Privacy to Enable Innovation & Research
BC Freedom of Information and Protection of Privacy Act
UNEP.Net Country Portals ELECTRONIC ENVIRONMENTAL INFORMATION FOR DECISION MAKERS AND PUBLIC IN THE CIS Workshop B: Construction.
Role of the Information Commissioner’s Office 'Promoting public access to official information and protecting your personal information' Christine Johnson.
Regulatory Body MODIFIED Day 8 – Lecture 3.
Duncan Woodhouse – Assistant Registrar for Information Security, Risk Management and Business Continuity Helen Wollerton – Administrative Officer (Legal.
Towards a Freedom of Information Law in Qatar Fahad bin Mohammed Al Attiya Executive Chairman, Qatar National Food Security Programme.
Freedom of Information – a brief guide David Evans.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Overview
1 OVERVIEW PRESENTATION FREEDOM OF INFORMATION (SCOTLAND) ACT 2002.
Practical Seminar - Environmental information Kevin Dunion Director, Centre for Freedom of Information Colin MacFadyen, OSIC 21 May 2014.
Training for Grantham Institute staff 29 th November 2013.
Public rights of access to information Grisilda Ponniah, Corporate Information Governance Manager Mary Elliott, FOI Officer Legal & Democratic Services.
The Data Protection Act 1998 The Eight Principles.
OCR Nationals Level 3 Unit 3.  To understand how the Data Protection Act 1998 relates to the data you will be collecting, storing and processing  To.
Data Protection: An enabler? David Freeland, Senior Policy Officer 23 October 2014.
THE AARHUS CONVENTION THE AARHUS CONVENTION UN ECE Convention on Access to Information, Public Participation in Decision-making and Access to Justice in.
Privacy and Confidentiality. Definitions n Privacy - having control over the extent, timing, and circumstances of sharing oneself (physically, behaviorally,
Environmental Thesaurus/Terminology Workshop United Nations Environment Programme (UNEP) International Environment House Geneva,
Data Protection Act & Freedom of Information Simon Mansell Corporate Governance and Information Team.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
Processing personal health data: the regulator’s perspective Ken Macdonald Assistant Commissioner Information Commissioner’s Office.
OPEN UP! Introduction to handling Freedom of Information requests.
Organization and Implementation of a National Regulatory Program for the Control of Radiation Sources Regulatory Authority.
Data Protection - Rights & Responsibilities Information Commissioner’s Office Orkney Practice Forum 4 th July 2007.
Information Systems Unit 3.
An Introduction to the Privacy Act Privacy Act 1993 Promotes and protects individual privacy Is concerned with the privacy of information about people.
Aarhus Convention Promoting Transparency in Land Administration Aphrodite Smagadi Legal Affairs Officer Aarhus Convention Secretariat Environment, Housing.
Data Protection and research Rachael Maguire Records Manager.
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
Workshop Understanding your responsibilities under the Data Protection Act 1998 and the Freedom of Information Act 2000 Adele Rhodes Girling.
Data protection—training materials [Name and details of speaker]
Sharing Personal Information Programme Wales Accord on the Sharing of Personal Information (WASPI) for organisations involved in the protection, safety,
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Protection of Personal Information Act An Analysis on the impact.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Data Protection and Freedom of Information. Objectives Describe the main points of the Data Protection Act 1998 and Freedom of Information Act 2000 Illustrate.
Section 4 Policies and legislation AQA ICT A2 Level © Nelson Thornes Section 4: Policies and Legislation Legislation – practical implications.
Information Governance A refresher for all staff who have previously gone through the full course.
Data Protection: EU & International
NHS Model Complaints Handling Procedure:
Data Protection Legislation
Research Ethics Matthew Billington
Data Protection & Freedom of Information- An Introduction
G.D.P.R General Data Protection Regulations
Introduction to Records Management, FOI & Data Protection
GDPR Overview and Use Cases.
Data Protection principles
Unit 7 – Organisational Systems Security
Legal and Ethical Issues
INTELLECTUAL PROPERTY RIGHTS (IPR) IN FP7
Data transfers to non-EU countries under the new GDPR
Data Management Ethical considerations for educational research
The title: The implementation of Data Protection
The Aarhus Convention and the Access to Justice Pillar: Introduction to Article 9. 1 Stephen Stec Tirana, November 2008.
The Aarhus Convention and Biosafety
Data Protection What can I do? GDPR Principles General Data Protection
Freedom of Information
Data protection & FOIA considerations
Presentation transcript:

Research and the Data Protection and Freedom of Information Acts

Data Protection Act 1998 and Freedom of Information Act 2000 DPA concerns personal data i.e. information from which a living individual can be identified FOI concerns all information – in any format – “held” by the institution even if it was created before 01/01/2005 when the Act came in to force

Research and the DPA Under Section 33 there are specific provisions in the Data Protection Act 1998 for the use of personal data in research Before using personal data in research, approval should be sought from the College’s Ethics of Research Committee as part of the application process When collecting data the specific purpose(s) for doing so must be stated Researchers should adopt a system of anonymous coding (pseudo-anonymisation) as the identity of data subjects must not be revealed without consent Appropriate security should be in place and note that there may be restrictions on where data can be stored Link to s.33 DPA: http://www.legislation.gov.uk/ukpga/1998/29/section/33 See ICO’s guidance about anonymisation: http://www.ico.org.uk/for_organisations/data_protection/topic_guides/anonymisation Encryption of personal data Stored on network drives which are backed up, not hard drives or removable media, nor with cloud providers

Research and the DPA All personal data must be held securely against loss, damage or unauthorised access Personal data must not be transferred out of the EEA unless that country has adequate protection – the USA, for example, is deemed not to. This will include storing data on servers (e.g. with cloud providers) The list of countries deemed to provide ‘adequate protection’ is small: Andorra, Argentina, Australia, Canada, Faroe Islands, Guernsey, Isle of Man, Israel, Jersey, New Zealand, Switzerland, Uruguay

Research and the DPA Personal data used in research: may be used for purposes beyond the originally stated purpose (it’s good practice to inform data subjects if this happens) must not be processed in such a way that substantial damage or substantial distress is, or is likely to be, caused to any data subject can be retained indefinitely is exempt from SARs (the right of access) - as long as published research does not identify individuals See JISC’s guidance for more information: https://www.jisc.ac.uk/guides/data-protection-and-research-data

Research and FOI (and EIR) Be aware that research data and final reports may be subject to FOI requests If a request is received it must be notified to the Records & Information Compliance Manager Similar regime – Environmental Information Regulations 2004 – applies to any information connected to environment, from soil to emissions* * Environmental information is any information in written, visual, aural, electronic or any other material form on— (a) the state of the elements of the environment, such as air and atmosphere, water, soil, land, landscape and natural sites including wetlands, coastal and marine areas, biological diversity and its components, including genetically modified organisms, and the interaction among these elements; (b) factors, such as substances, energy, noise, radiation or waste, including radioactive waste, emissions, discharges and other releases into the environment, affecting or likely to affect the elements of the environment referred to in (a); (c) measures (including administrative measures), such as policies, legislation, plans, programmes, environmental agreements, and activities affecting or likely to affect the elements and factors referred to in (a) and (b) as well as measures or activities designed to protect those elements; (d) reports on the implementation of environmental legislation; (e) cost-benefit and other economic analyses and assumptions used within the framework of the measures and activities referred to in (c); and (f) the state of human health and safety, including the contamination of the food chain, where relevant, conditions of human life, cultural sites and built structures inasmuch as they are or may be affected by the state of the elements of the environment referred to in (a) or, through those elements, by any of the matters referred to in (b) and (c)

FOI Exemptions Possible exemption under s.22 (information intended for future publication) though must be a genuine intention to publish what has been requested Possible exemption under s.40 (personal data) – where individuals could be identified and data has only been provided for research purposes Possible exemption under s.41 (information provided in confidence) only if an agreement specifies that the data is property of a private funder and is being held in confidence Other relevant sections: s.12 (exceeds appropriate limit), s.14 (vexatious or repeated), s.43 (commercial interests)* * See http://www.ico.gov.uk/news/latest_news/2011/~/media/documents/library/Freedom_of_Information/Detailed_specialist_guides/foi_legislation_and_research_guidance_for_the_higher_education_sector.ashx for more information See JISC’s guidance for more information http://www.webarchive.org.uk/wayback/archive/20140614124023/http://www.jisc.ac.uk/publications/programmerelated/2010/foiresearchdata.aspx

Research and FOI Providing a copy of information for FOI purposes does not mean that an individual or organisation has waived their intellectual property or moral rights* Deadline to respond to requests is 20 working days, therefore you should make arrangements to ensure that information can be retrieved in this time even if you are away Insert clauses in research contracts about ownership, copyright and FOI * See http://www.ico.org.uk/~/media/documents/library/Freedom_of_Information/Detailed_specialist_guides/intellectual_property_rights_and_disclosures_under_the_foia.pdf for more information

Animal testing It is likely that exemptions will be able to be applied to prevent the disclosure of at least some information about animal testing under FOI For example s.40 exempts personal data such as researchers’ names being disclosed S.38 exempts information which may endanger the physical or mental health or safety of any individual

Any questions? Contact the Records & Information Compliance Manager Tel: (13) 7596 E-mail: p.smallcombe@qmul.ac.uk See also: Data Protection Policy Data Protection Policy: http://www.arcs.qmul.ac.uk/docs/policyzone/102302.pdf