Information & Compliance UL University of Limerick & UL employees obliged to comply with certain legislation, including: Freedom of Information.

Slides:



Advertisements
Similar presentations
Legal & Regulatory Compliance. Overview What types of information should be included? What issues or problems might there be? What benefits could be obtained?
Advertisements

Administrative Systems and the Law What you need to know to produce an oral presentation for Unit 7 When the presentations will take place Resources you.
Records Management and the NHS Code of Practice (Foundation) Information Governance Policy Team NHS Connecting for Health.
Confidentiality & Records Management. What is Information Governance? What is Records Management?
Data Protection.
The Health and safety Act, is an act to make further provision for securing the health and safety and welfare of persons at work.For protecting others.
1 GRAND VALLEY STATE UNIVERSITY FAMILY EDUCATIONAL RIGHTS & PRIVACY ACT (FERPA) TRAINING OFFICES OF THE REGISTRAR AND UNIVERSITY COUNSEL JANUARY 20, 2009.
RIGHT TO INFORMATION ACT RTI Act-2005 is a Central Legislation. It gives access to Information held by the Public Authority. It is linked to Article-19---
BC Freedom of Information and Protection of Privacy Act
What does the Data Protection Act do? It sets standards which must be satisfied when obtaining, recording, holding, using, disclosing or disposing of.
Legislation in ICT.
Data Protection & Freedom of Information The Practical Implications of Data Protection and Freedom of Information Caroline Dominey Data Protection Officer.
Data Protection and Records Management
Developing a Records & Information Retention & Disposition Program:
Duncan Woodhouse – Assistant Registrar for Information Security, Risk Management and Business Continuity Helen Wollerton – Administrative Officer (Legal.
Property of Common Sense Privacy - all rights reserved THE DATA PROTECTION ACT 1998 A QUESTION OF PRINCIPLES Sheelagh F M.
Legislation in ICT. Data Protection Act (1998) What is the Data Protection Act (1998) and why was it created? What are the eight principles of the Data.
Created May 2, Division of Public Health Managing Records What is a Record? What is a Records Retention & Disposition Schedule? Why is this Important?
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
General Purpose Packages
Handling information 14 Standard.
Electronic Records Management: What Management Needs to Know May 2009.
Health & Social Care Apprenticeships & Diploma
HIPAA PRIVACY AND SECURITY AWARENESS.
Copyright© 2010 WeComply, Inc. All rights reserved. 9/19/2015 Record Management.
Data Protection, Freedom of Information and Information/Records Management.
The Freedom of Information and Data Protection Legislation An Overview Ann McKeon November 2014.
Dangerous Documents. Legal Compliances State and federal laws Contractual obligations Subject to an affirmative legal duty to establish and maintain certain.
DATA PROTECTION & FREEDOM OF INFORMATION. What is the difference between Data Protection & Freedom of Information? The Data Protection Act allows you.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
Data Protection Act & Freedom of Information Simon Mansell Corporate Governance and Information Team.
Data Protection Act ‘ What you need to know’ Corporate Information Governance Team Strategic Intelligence.
The right item, right place, right time. DLA Privacy Act Code of Fair Information Principles.
Data Protection and Records Management. Key Responsibilities - Record Management Keep Information Accurate Disclose only if compatible with purpose for.
HIPAA BASIC TRAINING Presented by Anderson Health Information Systems, Inc.
Everyone has a duty to comply with the Act, including employers, employees, trainees, self-employed, manufacturers, suppliers, designers, importers of.
Data Protection Property Management Conference. What’s it got to do with me ? As a member of a management committee responsible for Guiding property you.
Data protection This means ensuring that stored data does not get changed, removed or accessed accidentally or by unauthorised people. Data can be corrupted,
Data Protection Guidance for Principals and Deputy Principals Anne Lyne Partner & Breda O’Malley Partner Kilkenny - 3 October 2015.
12/12/2015 Data Protection Act /12/2015 The DP Act A law that protects personal privacy and upholds individual’s rights Anyone who handles personal.
1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.
LEGISLATION. DATA PROTECTION ACT (1998) The aim of this act give people the right to know what information is held about them. It also sets out rules.
Information Systems Unit 3.
INTRODUCTION TO DATA PROTECTION An overview of the Irish Data Protection legislation.
Wisconsin Digital Summit November 28, 2006 Electronic Records in Wisconsin Presented by Amy K. Moran Division of Administrative Services.
Computer Laws Data Protection Act 1998 Computer Misuse Act 1990.
INFORMATION GOVERNANCE AND CONFIDENTIALITY Information Governance Facilitator.
An NZFFBS Training Module.  Objective 1  State the purpose and principles of the Privacy Act and the Code of Ethics.  Objective 2  Apply the principles.
Data Protection and research Rachael Maguire Records Manager.
Session 12 Information management and security. 1 Contents Part 1: Introduction Part 2: Legal and regulatory responsibilities Part 3: Our Procedures Part.
1 Freedom of Information Act, 1997 Freedom of Information (Amendment) Act, 2003 University College Cork Presentation to New Academic Staff 20 September.
Workshop Understanding your responsibilities under the Data Protection Act 1998 and the Freedom of Information Act 2000 Adele Rhodes Girling.
CITY OF PHOENIX RECORDS MANAGEMENT AND E-PRIVACY Margie Pleggenkuhle City Clerk Department March 18, 2004.
Section 4 Policies and legislation AQA ICT A2 Level © Nelson Thornes Section 4: Policies and Legislation Legislation – practical implications.
The Freedom of Information and Data Protection Legislation An Overview
Learning Intention Legislations impact on security of information
UW-Madison Guidelines for Managing the Records of Departing Employees*
Introduction to Records Management, FOI & Data Protection
Welcome to the FERPA training for Faculty and Staff.
Data Protection and You
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
Recording Clinical Data
Information management and communication
General Data Protection Regulations 2018
HIPAA SECURITY RULE Copyright © 2008, 2006, 2004 by Saunders an imprint of Elsevier Inc. All rights reserved.
Freedom of Information Act 2014
Good Spirit School Division
The Freedom of Information and Data Protection Legislation An Overview
Handling information 14 Standard.
Presented by: Steve Gerdes 26 January 2019
Presentation transcript:

Information & Compliance UL University of Limerick & UL employees obliged to comply with certain legislation, including: Freedom of Information (2014) Data Protection (1988 & 2003) Copyright & Related Rights Acts (2000 et al) Official Languages Act (2003) Ethics in Public Office (1995 & 2001) Also: Records Management

Contact: Dr Maria Connolly Information & Compliance Officer Corporate Secretary’s Office Information, Guidance available at Ext: 4393 Room: A1-071 Information & Compliance

Records Management Records created/received in course of business - official records of University; Evidence of functions executed, activities performed; Provide information on how & why decisions were taken. Records Management & Retention Policy Day-to-day efficiency, good office management; Support compliance with University policies, relevant legislation; ID historic/valuable records, records for archiving; Guidance on what records to be destroyed (when & how).

Paper records: books, files, letters, loose papers, diaries, post-it notes, computer printouts; Electronic records: disks, CDs, s, databases; Audio-visual records: films, videos, tape recordings; Photographs, maps, plans, x-rays, microfiche, microfilm. Records in any format: hard or soft copy. Includes drafts & copies of records. University subject to FOI & Data Protection ….. records are subject to release. What is a ‘record’ ?

FOI Act Provide legal right for persons to request: 1. Access to records held by public bodies ; 2. Correction of personal information - amended if proven to be incomplete/ incorrect/ misleading; 3. Reasons for decisions affecting oneself taken by public bodies. Decentralised system of decision makers. Supported by internal review & external appeal procedures. Legislative deadlines - acknowledgement within 10 working days; decision within 20 working days.

Follow relevant UL policies / systems Consistently apply your Area’s prescribed administrative practices; Making decisions? Record reasons / ensure decisions supported with relevant facts; Due care in prep. of written documents - (accurate, factual, objective, legible); Avoid personal comments / inappropriate remarks. Practical Considerations

Data Protection Acts Legally provide for a person’s right to privacy ‘Personal data’ “data relating to a living individual who is / can be identified from the data or from the data in conjunction with other information that is in … the possession of data controller.” UL is a ‘Data Controller’ UL must collect and process personal data of employees, Students, other clients so it can carry out its duties. Data in records of any format: Personal data may be held in paper or electronic records DP Acts apply to all personal data held, regardless of how stored.

Data Protection Acts The Act requires that 8 rules be adhered to: 1. Obtain, process personal data fairly; 2. Keep only for specified, lawful purpose(s); 3. Use, disclose only in ways compatible with purpose(s) for which it was initially given; 4. Keep safe, secure; 5. Keep accurate, up-to-date; 6. Ensure it’s adequate, relevant, not excessive; 7. Retain for no longer than necessary for the specified purpose(s); 8. Provide a copy of his/her personal data to any individual, on request.

Follow UL Data Protection Regulations & Compliance Guide (see link below); Points to Note: Rule 4: “Keep personal data safe and secure” No unauthorised disclosures - access to authorised staff only; Ensure PC screens, manual files etc not visible to unauthorised persons (NB. public counters); Use PC passwords, encryption software on laptops & USBs; adhere to ITD policies; Do not use USBs etc for transporting personal data. Rule 7: relating to “Retention” Keep Personal Data for as long as needed for purpose only - Apply UL records management policy. Practical Considerations

Information & Compliance UL Contact: Dr Maria Connolly Information and Compliance Officer Corporate Secretary’s Office Information, Guidance available at Ext: 4393 Room: A1-071