Data Protection in a Tutorial Context

Slides:



Advertisements
Similar presentations
Data Protection & Privacy in the Information Age COMNET – Legal Frameworks for ICTs Malta 2013 Dr Antonio Ghio Dr Jeanine Rizzo.
Advertisements

DATA PROTECTION and Research University Research Ethics Committee – David Cauchi David Cauchi Office of the Commissioner for Data Protection.
The Data Protection (Jersey) Law 2005.
Data Protection.
PRIVACY COMPLIANCE An Introduction to Privacy Privacy Training.
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi Office of the Data Protection Commissioner.
What does the Data Protection Act do? It sets standards which must be satisfied when obtaining, recording, holding, using, disclosing or disposing of.
1 When hate speech tangles privacy... When hate speech tangles privacy...
Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please.
1 Freedom of Information (Scotland) Act 2002 A strategic view.
Public rights of access to information Grisilda Ponniah, Corporate Information Governance Manager Mary Elliott, FOI Officer Legal & Democratic Services.
Data Protection STFC Presentation to PPD Senior Staff 26/11/2009 FoI/DP team.
Data Protection Act & Freedom of Information Simon Mansell Corporate Governance and Information Team.
IM NETWORK MEETING 20 TH JULY, 2010 CONSULTATION WITH 3 RD PARTIES.
© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
Data protection—training materials [Name and details of speaker]
Understanding Privacy An Overview of our Responsibilities.
Understanding Privacy An Overview of our Responsibilities.
The future of data protection: General Data Protection Regulation
Processing for archiving purposes in the GDPR
Overview General Data Protection Regulation (GDPR)
Data Protection – The Essentials Alison Johnston Lead Policy Officer - Scotland Information Commissioner’s Office.
Data Protection and Confidentiality
Issues of personal data protection in scientific research
General Data Protection Regulation (GDPR)
GDPR – Legal Aspects Desislava Krusteva, Attorney-at-Law, CIPP/E
IT Applications Theory Slideshows
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
GDPR Overview Gydeline – October 2017
General Data Protection Regulation: Turning the black into white
GDPR Overview GDPR - General Data Protection Regulations
GDPR support January GDPR support January 2018.
GDPR Overview Gydeline – October 2017
GDPR Road map to Compliance.
Data Protection & Freedom of Information- An Introduction
General Data Protection Regulation (GDPR)
Introducing GDPR: How the General Data Protection Regulation transforms the world Laura Mudd November 2016.
GENERAL DATA PROTECTION REGULATION (GDPR)
The Rise of Privacy: Complying with GDPR in the United States
The General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
New Data Protection Legislation
Introducing the General Data Protection Regulation 2016
Precise. Proven. Performance
State of the privacy union
G.D.P.R General Data Protection Regulations

General Data Protection Regulation
Data Protection principles
Data Protection and You
Relocation CARNIVAL come one…come all
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
How we’ll prepare for the General Data Protection Regulation (GDPR)
IMPLICATIONS OF GDPR ROBERT BELL.
GDPR Workshop MEU Symposium Prague 2018
Is Data Protection a Fundamental Right Protecting the Individual?
Information Handling Research Student Induction Day
Equality ……… is the current term for ‘Equal Opportunities’. It is based on the legal obligation to comply with anti-discrimination legislation. Equality.
General Data Protection regulation (GDPR)
A Framework for Compliance
Understanding Data Protection
Data Protection for SDS Employers Alison Johnston Lead Policy Officer (Scotland) Information Commissioner’s Office.
General Data Protection Regulation Q & A Session
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
The supervision of personal data processing by EU institutions and bodies => data protection and privacy, why it matters, for you as citizens and as EU.
Information Governance Office
GDPR Session
General Data Protection Regulation
General Data Protection Regulation (GDPR) and library authority data
Information Governance
Presentation transcript:

Data Protection in a Tutorial Context Office of Intercollegiate Services 24 September 2018

Over the next 30 minutes… What is considered personal data? Processing personal data in College setting Key compliance requirements Benefits of compliance Points of special interest to the College (not an exhaustive list) Record v Personal information Records management Subject Access Requests Freedom of Information Requests References What to do if something goes wrong How to stay on the right side of compliance

What is considered personal data? Special categories of personal data Personal data about an individual’s: * race; * ethnic origin; * political opinions; * religious or philosophical beliefs; * trade union membership; * genetic data; * biometric data (where used for identification); * health data; * sex life; or * sexual orientation require a higher level of protection. “Extra” Special category of personal data Information relating to criminal convictions and offences, which also require high level of protection Personal data Under GDPR, it means: “any information relating to an identified or identifiable natural [living] person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person”.

Processing personal data in College setting Adapted from Tutors’ and Senior Tutors’ role descriptions

Key compliance requirements Documentation Transparency Data Protection statement/policy Privacy notice Information Asset Register/Data Register Retention Schedule Breach notification procedure Breach handling process Practice guidance (e.g. writing references, managing records, dealing with subject Access requests, etc.) Making key Data Protection documentation available to stakeholders Website v Intranet Training and awareness Monitoring compliance (e.g. reviews, spot checks, etc.) Making processes responsive to data subject rights Publication scheme

Benefits of compliance Confidence in College’s management practices and perceived transparency Increased confidence in the College around respecting and safeguarding students Enhanced reputation Administrative efficiencies (e.g. reduced off-site storage cost for records) Shared ownership (and accountabilities)

Points of special interest to the College (not an exhaustive list) Record v Personal information Record Anything recorded information created, received or management in the course of the College’s day-to-day activities or as part of its legal obligations – regardless of nature, format or medium  Property of the College/Data Controller and must (post GDPR) be managed in accordance with Data Protection legislation as set out in College policies and procedures, including retention and disposal Subject to disclosure (e.g. Freedom of Information, Environmental Information Regulations, and Subject Access Requests) Personal information Any recorded information not relating to any aspect of the College’s functions, activities or legal obligations, which is clearly personal in nature and content

Points of special interest to the College (not an exhaustive list) Records Management Tutor’s Guide – Annex A: Records management as a Tutor Continuous activity Everyone’s responsibility High organisational risk factor under GDPR Retention schedule Records Management policy More information on OIS and University webpages

Points of special interest to the College (not an exhaustive list) Subject Access Requests Freedom of Information Requests More information on OIS webpages References Tutor’s Guide – Annex A: Records management as a Tutor Tutor’s Guide – Annex B: Writing references for students University webpages What to do if something goes wrong Breach reporting procedure Refer to local guidance OIS webpages

How to stay on the right side of compliance College policies and procedures If in doubt, ask What would I do if it was my personal data?

Questions?