Top Banner
DATA PROTECTION PART OF A QUALITY MANAGEMENT SYSTEM FOR INFORMATION
71

Data Protection - Daragh O Brien

Dec 04, 2014

Download

Technology

healthcareisi

 
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Data Protection - Daragh O Brien

DATA PROTECTION

PART OF A QUALITY MANAGEMENT SYSTEM FOR INFORMATION

Page 2: Data Protection - Daragh O Brien

SOME FORMAL DEFINITIONS

Data (plural of datum)•Facts about things

RED 01-01-70

Peanuts

Page 3: Data Protection - Daragh O Brien

Red

Page 4: Data Protection - Daragh O Brien

RED

Page 5: Data Protection - Daragh O Brien

RED

Page 6: Data Protection - Daragh O Brien

Peanuts

Page 7: Data Protection - Daragh O Brien

Peanuts

Page 8: Data Protection - Daragh O Brien

Peanuts

Page 9: Data Protection - Daragh O Brien

01-01-70

Page 10: Data Protection - Daragh O Brien

01-01-70

Page 11: Data Protection - Daragh O Brien

01-01-70

Page 12: Data Protection - Daragh O Brien

01-01-70

Page 13: Data Protection - Daragh O Brien

SOME FORMAL DEFINITIONS

Information•Facts about things in a context•Facts with attached meaning

Page 14: Data Protection - Daragh O Brien

SOME FORMAL DEFINITIONS

Information•Facts about things in a context•Facts with attached meaning

Page 15: Data Protection - Daragh O Brien

SOME FORMAL DEFINITIONS

Knowledge•Information that can be used to trigger action

• Right place• Right time• Right format• Right context

Page 16: Data Protection - Daragh O Brien

Caucasian female, early 40s (red hair) collapsed at work

Peanut allergy

Ate birthday cake within last hour

Treat for anaphylactic shock

Page 17: Data Protection - Daragh O Brien

Value

Data Data Data

Information Information

Knowledge

Context

Page 18: Data Protection - Daragh O Brien

Data Protection

Information SecurityInformation Quality

Page 19: Data Protection - Daragh O Brien

SYLLOGISM PART 1

Data Protection is a Quality Management System applied to the collection, management, use, and disposal of personal data.

(e.g. BS10012:2009)

Page 20: Data Protection - Daragh O Brien

SYLLOGISM PART 2

Information/Data Quality is the application of proven Quality Management systems to the Information Product

Page 21: Data Protection - Daragh O Brien

SYLLOGISM PART 3

Data Protection is Information Quality

Page 22: Data Protection - Daragh O Brien

LINKING TO DATA QUALITY

SECTION I

PRINCIPLES RELATING TO DATA QUALITY

Article 6

1. Member States shall provide that personal

data must be:

(a) processed fairly and lawfully;

(b) collected for specified, explicit and

legitimate purposes and not further

processed in a way incompatible with

those purposes. Further processing of

data for historical, statistical or scientific

purposes shall not be considered as

incompatible provided that Member States

provide appropriate safeguards;….

EU Directive 95/46/EC defines “Data Protection” principles as “Data Quality Principles”.

Page 23: Data Protection - Daragh O Brien

WHAT IS “INFORMATION QUALITY”?The degree to which information and data can be a trusted source for any or all required uses.

The degree to which data and information meets the specific needs of specific customers.

Consistently meeting or exceeding knowledge worker/end customer expectations.

Page 24: Data Protection - Daragh O Brien

DAVID LOSHIN

Page 25: Data Protection - Daragh O Brien

Data Domains

Enterprise Agreement of Usage

Stewardship

Ubiquity

Data Model

Clarity of Definition

Comprehensiveness

Flexibility

Robustness

Essentialness

Attribute Granularity

Precision of Domains

Homogenity

Naturalness

Identifiability

Obtainability

Relevance

Simplicity

Semantic Consistency

Structural Consistency

Data Values

Accuracy

Null Values

Completeness

Consistency

Currency

Timeliness

Data Presentation

Appropriateness

Correct Interpretation

Flexibility

Format Precision

Portability

Representation Consistency

Representation of Null Values

Use of Storage

Information Policy

Accessibility

Metadata

Privacy

Redundancy

Security

Unit Cost

Dimensions of Data Quality © D Loshin

Page 26: Data Protection - Daragh O Brien

DANETTE MCGILVRAY

Page 27: Data Protection - Daragh O Brien

Data Specification

Data Integrity Fundamentals

Duplication

Accuracy

Consistency & Synchronisation

Timeliness & Availability

Ease of Use & Maintainability

Data Coverage

Presentation Quality

Data Decay

Transactability

Danette McGilvray’s Data Quality Dimensions.

Perception, Relevance, Trust

Page 28: Data Protection - Daragh O Brien

LARRY ENGLISH

Page 29: Data Protection - Daragh O Brien
Page 30: Data Protection - Daragh O Brien

DATA QUALITY CHARACTERISTICS

Data Protection

Page 31: Data Protection - Daragh O Brien

HIQA’S DEFINITION OF DATA QUALITY

Data Quality refers to data that is accurate, valid, reliable, relevant, legible, complete and available in a timely manner to decision makers for healthcare delivery and planning purposes.

Page 32: Data Protection - Daragh O Brien

DATA QUALITY CHARACTERISTICS

HIQA

Page 33: Data Protection - Daragh O Brien

W. EDWARDS DEMING

Page 34: Data Protection - Daragh O Brien

SYSTEM OF PROFOUND KNOWLEDGE

Theory of Optimisation

Theory of Knowledge

Theory of Variation

Theory of Psychology

(c) Castlebridge Associates 2011. Certain Material (c) Larry English, Danette McGilvray, Tom Redman

Page 35: Data Protection - Daragh O Brien

THEORY OF KNOWLEDGE

Knowledge cannot exist with out a theory

Experience is not the same as theory

Theory shows cause and effect

Theory allows for prediction

(c) Castlebridge Associates 2011. Certain Material (c) Larry English, Danette McGilvray, Tom Redman

Page 36: Data Protection - Daragh O Brien

THEORY OF KNOWLEDGE

“Best Efforts? Imagine the chaos if everyone ran around trying their best without a theory of knowledge to inform their actions. Disaster”.

(c) Castlebridge Associates 2011. Certain Material (c) Larry English, Danette McGilvray, Tom Redman

Page 37: Data Protection - Daragh O Brien

Seek first to understand…

Stephen R. Covey

Page 38: Data Protection - Daragh O Brien

THEORY OF KNOWLEDGE

I could copy my maths homework

I’d get THAT problem right

But would I understand the principles to apply to a different problem?

Page 39: Data Protection - Daragh O Brien

KEY LESSON

Effective implementation of Quality Systems requires an understanding of the “Theory of Knowledge” and the fundamental principles of that Quality system.

Blind adoption of tools, techniques, and templates without the Theory of Knowledge tells you “WHAT” but not “WHY”.

Page 40: Data Protection - Daragh O Brien
Page 41: Data Protection - Daragh O Brien

NON-LINEAR LIFE CYCLE

Plan Obtain Store/Share

Apply

Maintain

Dispose

Based on English 1999 and McGilvray 2008

Page 42: Data Protection - Daragh O Brien

MAPPING THE LIFE CYCLE TO DATA PROTECTION

Page 43: Data Protection - Daragh O Brien

INFORMATION CHAINS – THE FOCUS

An information chain is effectively a chain of processes through which information flows to achieve an objective in the organisation.

Only by understanding how information flows can you understand how the quality of the information

• Affects the organisation• Is affected by the Organisation

Page 44: Data Protection - Daragh O Brien

If you can't describe what you are doing as a process...

... You don’t know what you are doing.

W. Edwards Deming

Page 45: Data Protection - Daragh O Brien

THIS IS NOT A PROCESS MAP OR INFO CHAIN DESCRIPTION

• We do this.

• Then Martin in Accounts does that.

• Then Betty in Receivables does this other thing

• Then it comes back to us

• Then something else happens.

• 4th Thursday of month the Jaberwock audits.

Page 46: Data Protection - Daragh O Brien

If I had wanted to know what you did on your

holidays,

Process Improvement Lead, Telco industry

I’d have asked.

Page 47: Data Protection - Daragh O Brien

INFORMATION CHAINS

A.K.A. Processes

Some Input

Some Action

Some Output

That becomes an Input

Some Action Some Action

Some Output

That becomes an Input

Some Output

Information Flow

A.K.A. “Cycles”

A.K.A. SIPOC

A.K.A. Workflow

By someone By someone By someone

Page 48: Data Protection - Daragh O Brien

DATABASES ARE LIKE LAKES

Page 49: Data Protection - Daragh O Brien

DAVID LOSHIN

Page 50: Data Protection - Daragh O Brien

THE VIRTUOUS CYCLE

Page 51: Data Protection - Daragh O Brien

THE VIRTUOUS CYCLE

(c) Castlebridge Associates 2011. Certain Material (c) Larry English, Danette McGilvray, Tom Redman

Page 52: Data Protection - Daragh O Brien

DANETTE MCGILVRAY10 STEPS TO TRUSTED INFORMATION

Page 53: Data Protection - Daragh O Brien

SOME INTRODUCTORY COMMENTS

Danette’s view on Information

• Information must be consciously managed as a resource (a source of help to the business) and

• As an asset (a source drawn on by the business to make a profit)

• Information is a product of processes and activities in organisations.

Danette’s Definition of Information Quality

• the degree to which information and data can be a trusted source for any/all required uses

Page 54: Data Protection - Daragh O Brien

ASSESSMENT-AWARENESS-ACTION

Page 55: Data Protection - Daragh O Brien

FRAMEWORK FOR INFORMATION QUALITY

(c) Castlebridge Associates 2011. Certain Material (c) Larry English, Danette McGilvray, Tom Redman

Page 56: Data Protection - Daragh O Brien

THE 10 STEPS METHOD™

Page 57: Data Protection - Daragh O Brien

LARRY P. ENGLISHTIQM™

Page 58: Data Protection - Daragh O Brien

THE TIQM PROCESSES

Page 59: Data Protection - Daragh O Brien

COMMON CORE ELEMENTS

Page 60: Data Protection - Daragh O Brien

INFORMATION IS…

1.An Asset

2.A Product

Page 61: Data Protection - Daragh O Brien

INFORMATION QUALITY PROGRAMS

1. Should be based on proven Quality Management Principles

2. Make use of objective statistical measurement of quality

3. Emphasise elimination of process defects to remove root causes of errors

4. Should be cyclical and based on philosophy of continuous improvement

5. Should emphasise the development of a Quality Culture that pervades the organisation.

6. The focus must be on improving the system of production, eliminating common causes of defect, and preventing errors

7. Scrap and rework is not Information Quality Management

Page 62: Data Protection - Daragh O Brien

BUT BACK TO DATA PROTECTION…

Page 63: Data Protection - Daragh O Brien

SUMMARY (OF THEORY)

Data Protection & Information Quality are closely linked disciplines

Understanding your Processes is key

Information Life Cycle gives context

You can measure Quality of Information

Quality has to be built in

Inspecting defects out is not Quality

POSMAD

(across many characteristics)

Page 64: Data Protection - Daragh O Brien

From Toothpastefordinner.com

Process & Context =

Meaning & Purpose

Page 65: Data Protection - Daragh O Brien

Information has attributes you can measure...

Measurement can support Controls and Policies

Metrics can support Change Management goals

Page 66: Data Protection - Daragh O Brien

What is measured gets

done.

Page 67: Data Protection - Daragh O Brien

How can you feed the GREED motive?

Page 68: Data Protection - Daragh O Brien

What is your Data Protection

Scorecard?

How does it translate to your bottom line?

Page 69: Data Protection - Daragh O Brien

GETTING HELP

Page 70: Data Protection - Daragh O Brien

THE IAIDQ• International Association for Information & Data Quality

• Founded in 2004

• Leading Professional body for Information/Data Quality practitioners.

• 500+ members in 15 countries

• Active in Ireland through collaboration with the Irish Computer Society (the “IQ NETWORK”)

Page 71: Data Protection - Daragh O Brien

D3: Information

Quality Value and Business

Impact

D2:Information

Quality Environment and Culture

D5:Information

Quality Measurement

and Improvement

D6:Sustaining Information

Quality

D1:Information

Quality Strategy and Governance

D4:Information Architecture

Quality