Administrative Data Centre (ADC) ……. a GDPR ready data hub?

Slides:



Advertisements
Similar presentations
Debt Management Strategy: Governance and Transparency
Advertisements

Introducing the Administrative Data Research Network Tanvi Desai.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS.
Data-Sharing and Governance Consultation ANALYSIS OF RESPONSES.
Realizing the statistical potential of administrative data Paper presented at the U.N.E.C.E. Seminar on New Frontiers for Statistical Data Collection,
Information Systems Controls for System Reliability -Information Security-
1 CHCOHS312A Follow safety procedures for direct care work.
Update on Regulation of Residential Services for People with Disabilities (including children) DFI Seminar on Regulation and Keeping the Focus on Best.
Person Activity Register - a statistical register of persons Administrative Statistics Seminar Dublin Castle 20 th Feb 2014
Name Position Organisation Date. What is data integration? Dataset A Dataset B Integrated dataset Education data + EMPLOYMENT data = understanding education.
Frameworks for the Access and Use of Administrative Data, With the Example of Current Practice in the UK Steven Vale Office for National Statistics UK.
Introducing the Administrative Data Research Network Tanvi Desai.
Access to data for local authority public health AGW Public Health Network Training Event: Public Health Data, Information and Intelligence 11 th November.
Corporate Data Model (CDM) Underlying principle:4 datastores 1.INPUT-raw data 2.CLEAN UNIT-cleaned data 3.AGGREGATE-aggregated data 4.DISSIMINATION-published.
Information Sharing & Corporate Governance Dave Parsons, Information Governance Manager, City of Cardiff Council.
The EU General Data Protection Regulation Frank Rankin.
Information Sharing for Integrated Care A 5 Step Blueprint.
Regional Accreditation Workshop For Asia and Eastern Europe Manila, Philippines th March, 2012.
Statistical Modernisation Community Padraig Dalton 8 March
Statistical process model Workshop in Ukraine October 2015 Karin Blix Quality coordinator
Incorporating Privacy Into Systems Development Methodology Phil Moleski Director Corporate Information Technology Branch Saskatchewan Health
Understanding Privacy An Overview of our Responsibilities.
General Data Protection Regulation (EU 2016/679)
HIPSSA Project PRESENTATION ON SADC DATA PROTECTION MODEL LAW
Accountability & Structured Privacy Management
Promoting Evidence-Based Policymaking by Sharing State Administrative Data Dr. Marty Romitti January 25, 2017.
GDPR (General Data Protection Regulation)
Equality and Human Rights Exchange Network
Development of Strategies for Census Data Dissemination
DASSL Model: Proposed use case for safe and better use of one of our greatest national assets – Data! Rosalyn Moran.
Information Sharing for Integrated care A 5 Step Blueprint
Viewing the GDPR Through a De-Identification Lens
Rosalyn Moran CSDAN May 2017
General Data Protection Regulations: what you really need to know
General Data Protection Regulation
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
Data Sharing Consultation Event
Information Sharing Gateway
INTRODUCTION TO GDPR 19/09/2018.
GDPR Security: How to do IT? IT reediness for competitive advantage
GENERAL DATA PROTECTION REGULATION (GDPR)
GDPR - New Data Protection Regulation
Introduction to GDPR 09/11/2018.
GDPR and paper records Why it’s not all cyber and fines Gary Shipsey
Implementing the ESS Vision 2020
The session will commence at Please mute your microphone
Sue Cawthray, CEO/ Gill Thrush, Catering Manager
State of the privacy union
Information Governance
The GDPR and research data
Introduction to Records Management, FOI & Data Protection
Sabrina Iavarone Senior User Services Officer
The GDPR & Schools - An Introduction -
General Data Protection Regulation
HIPSSA Project Support for Harmonization of the ICT Policies in Sub-Sahara Africa, Meeting with the Namibia ICT Ministry and Data Protection Stakeholders.
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
Presentation to the INTOSAI Working Group on IT Audit Systems assurance and data analytics for continued audit quality and improved efficiency of audits.
General Data Protection Regulations 2018
Administrative Data The National Statistics Board Perspective
Recording Clinical Data
Information Handling Research Student Induction Day
Recording Clinical Data
U.S. Information Quality Standards
Statistical education in times of Big Data
Marleen De Smedt Geoffrey Thomas Cynthia Tavares
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
Data Protection What can I do? GDPR Principles General Data Protection
Robin Youll Office for National Statistics
Presentation to Primary Health Alliance 7 June 2019
General Data Protection Regulation Community Councils
Presentation transcript:

Administrative Data Centre (ADC) ……. a GDPR ready data hub? Public Sector Data Analytics Network Workshop 18th May 2017 John.Dunne@cso.ie

Freedom of Information Legal environment Data Protection Freedom of Information Official Statistics Key : 3 Legislative pillars

Irish Statistical System - a register based statistical system Enterprises/Firms Persons Buildings/Location Key : Permanent official identification

ADC Administrative Data Centre Set up November 2009 Objectives twofold Clearing house for administrative data A catalyst to the development of the Irish Statistical System

Streamline interface with public authorities CSO Survey system 1 Survey system 2 Survey system ... Survey system n ADC Organisation n Admin data source 2 DSP Admin data source 2 Revenue Admin data source 1 Admin data source 1

Data organised as data flows Administrative data flow Instance (month, year, quarter) Version Datasets

Extract Transform Load (ETL) Inside the warehouse Sys 1 Sys ... Sys n Business systems tier Business Interface Analysis tier Data 1 Data 2 Extract Transform Load (ETL) Sources tier PREM DES

Data Goverance Framework Manage/know what we have (metadata) Manage who has access (access control) Minimise privacy risk Be open and transparent Supported and driven by an in house browser based application

Role of metadata Find it Understand it Evaluate it Dataset Collections need to be registered (keywords?) Understand it Needs to be properly labelled with appropriate codebooks and other relevant information (data summaries) Evaluate it Contextual background information usually in the form of documents that provides further understanding of data If you don’t have the necessary metadata - data is worthless at the very least and potentially disastrous if used for decision making.

Access control Register of access rights - Person based at flow level based on userid Business reason captured (DG must sign off on linking projects) System jobs snapshot register at regular basis System jobs inform administrators of inconsistencies unregistered access rights New tool also to record actual accesses Tiered access Source = identifiable Analysis = pseudonymised (PIK Protected Identifier Key)

Analysis tier General access for statistical purposes Contains no directly identifiable information PIK enables safe linkage across data sources and over time PIK can be random generated number or using a salt and hash PPSN, EIRCODE, other identifiers PIK generation closely guarded secret

Source tier Restricted access Management Board level sign off Data office sign off Underpinned by Privacy Impact Assessment (PIA)

Role of PIA Ensure due consideration has been given to identifying and mitigating potential risks Provide documentary evidence

Open and Transparent = Trust Metadata is open All staff can see all data descriptions Access control information is open All staff can see who has access to what All process documentation is open PIAs etc Data is not open

Organisational governance developments Data Office Confidentiality and Data Security Committee (CDSC) reports to Management Board ADC policy no longer set by ADC

Thank you John.Dunne@cso.ie