Information & Compliance UL University of Limerick & UL employees obliged to comply with certain legislation, including: Freedom of Information (2014) Data Protection (1988 & 2003) Copyright & Related Rights Acts (2000 et al) Official Languages Act (2003) Ethics in Public Office (1995 & 2001) Also: Records Management
Contact: Dr Maria Connolly Information & Compliance Officer Corporate Secretary’s Office Information, Guidance available at Ext: 4393 Room: A1-071 Information & Compliance
Records Management Records created/received in course of business - official records of University; Evidence of functions executed, activities performed; Provide information on how & why decisions were taken. Records Management & Retention Policy Day-to-day efficiency, good office management; Support compliance with University policies, relevant legislation; ID historic/valuable records, records for archiving; Guidance on what records to be destroyed (when & how).
Paper records: books, files, letters, loose papers, diaries, post-it notes, computer printouts; Electronic records: disks, CDs, s, databases; Audio-visual records: films, videos, tape recordings; Photographs, maps, plans, x-rays, microfiche, microfilm. Records in any format: hard or soft copy. Includes drafts & copies of records. University subject to FOI & Data Protection ….. records are subject to release. What is a ‘record’ ?
FOI Act Provide legal right for persons to request: 1. Access to records held by public bodies ; 2. Correction of personal information - amended if proven to be incomplete/ incorrect/ misleading; 3. Reasons for decisions affecting oneself taken by public bodies. Decentralised system of decision makers. Supported by internal review & external appeal procedures. Legislative deadlines - acknowledgement within 10 working days; decision within 20 working days.
Follow relevant UL policies / systems Consistently apply your Area’s prescribed administrative practices; Making decisions? Record reasons / ensure decisions supported with relevant facts; Due care in prep. of written documents - (accurate, factual, objective, legible); Avoid personal comments / inappropriate remarks. Practical Considerations
Data Protection Acts Legally provide for a person’s right to privacy ‘Personal data’ “data relating to a living individual who is / can be identified from the data or from the data in conjunction with other information that is in … the possession of data controller.” UL is a ‘Data Controller’ UL must collect and process personal data of employees, Students, other clients so it can carry out its duties. Data in records of any format: Personal data may be held in paper or electronic records DP Acts apply to all personal data held, regardless of how stored.
Data Protection Acts The Act requires that 8 rules be adhered to: 1. Obtain, process personal data fairly; 2. Keep only for specified, lawful purpose(s); 3. Use, disclose only in ways compatible with purpose(s) for which it was initially given; 4. Keep safe, secure; 5. Keep accurate, up-to-date; 6. Ensure it’s adequate, relevant, not excessive; 7. Retain for no longer than necessary for the specified purpose(s); 8. Provide a copy of his/her personal data to any individual, on request.
Follow UL Data Protection Regulations & Compliance Guide (see link below); Points to Note: Rule 4: “Keep personal data safe and secure” No unauthorised disclosures - access to authorised staff only; Ensure PC screens, manual files etc not visible to unauthorised persons (NB. public counters); Use PC passwords, encryption software on laptops & USBs; adhere to ITD policies; Do not use USBs etc for transporting personal data. Rule 7: relating to “Retention” Keep Personal Data for as long as needed for purpose only - Apply UL records management policy. Practical Considerations
Information & Compliance UL Contact: Dr Maria Connolly Information and Compliance Officer Corporate Secretary’s Office Information, Guidance available at Ext: 4393 Room: A1-071