Top Banner
Are you a prisoner of outdated data handling processes? DATA PROTECTION SEMINAR – THURSDAY 30 JULY 2015
44
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: DPA seminar presentation

Are you a prisoner of outdated data handling processes?

DATA PROTECTION SEMINAR – THURSDAY 30 JULY 2015

Page 2: DPA seminar presentation

Data Protection: Maximum Security

Shauna DunlopNI Group Manager30 July 2015

Page 3: DPA seminar presentation
Page 4: DPA seminar presentation

Data Protection Act1998

Page 5: DPA seminar presentation

Why comply?

Legal requirement

Financial implications

Reputational implications

Page 6: DPA seminar presentation
Page 7: DPA seminar presentation

Data Protection Act 1998

• Principles & Privacy

• Key Definitions

• Principles in Detail

• What the Act says about Security

• Individual Rights

• Latest from Europe

Page 8: DPA seminar presentation
Page 9: DPA seminar presentation

Personal Data

Personal data is not just a person’s name

It is any information that relates to or identifies a person and:

Is held on a computer

Is intended to be held on computer

Forms part of a ‘relevant filing system’

Forms part of an ‘accessible record’ (information relating to health or education)

Category ‘e’ data (Public Authorities only)

Page 10: DPA seminar presentation

Information Rights Affects Us All

Page 11: DPA seminar presentation

Fair and lawful

Page 12: DPA seminar presentation

Adequate, relevant and not excessive

Page 13: DPA seminar presentation

Accurate and up to date

Page 14: DPA seminar presentation

Kept for no longer than necessary

Page 15: DPA seminar presentation

Individuals rights

Page 16: DPA seminar presentation

Security

Page 17: DPA seminar presentation

How does it go wrong?

Page 18: DPA seminar presentation

Transfers outside EEA

Page 19: DPA seminar presentation

!CAUTION:

Prevent a data breach

Page 20: DPA seminar presentation

Privacy and Electronic Communications Regulations

Page 21: DPA seminar presentation

Doing ‘Big Data’ is possible,legal compliance is essential, inspiring public trust and confidence is indispensable

Page 22: DPA seminar presentation

FOI and open data – adding value together

Page 23: DPA seminar presentation

http://greatbritishpublictoiletmap.rca.ac.uk/

Page 24: DPA seminar presentation

Data Protection Regulation

Update from Europe

Page 25: DPA seminar presentation

Key factors

Plan ahead Compliance Reputation

Page 26: DPA seminar presentation

Contact us:

ICO 3rd Floor

14 Cromac PlaceBelfast BT7 2JB

0303 123 [email protected]

www.ico.org.uk

Page 27: DPA seminar presentation

A ‘Get Out of Jail Card’ - How to Prevent Data Breaches

Clare Bates30th July 2015

Page 28: DPA seminar presentation

Introduction

•Imprisoned by bad habits?

•Practical examples

•What went wrong?

ChanceTHIS CARD MAY BE KEPT UNTIL NEEDED OR SOLD.GET OUT OF JAIL FREE

ChanceTHIS CARD MAY BE KEPT UNTIL NEEDED OR SOLD.GET OUT OF JAIL FREE

• How to set yourself free!

Page 29: DPA seminar presentation

Recent Press Coverage

Page 30: DPA seminar presentation

Human Error

Mistakes can happen:

• Wrong address

• Documents left behind

What moves can you make:

•Culture of awareness - training

•Proper policies

•Recruit the right people

Page 31: DPA seminar presentation

Reliable employees?

• Client data

• Disgruntled employees

What moves can you make:

• Risk based approach to levels of security

• Ensure correct physical and technical security

Insider Attack

Page 32: DPA seminar presentation

How do you manage your technology?

• External access to your network

• BYOD

• Encryption

What moves can you make:

• IT and internet use policy

• BYOD policy

Technology

Page 33: DPA seminar presentation

What is the risk?

• Appropriate storage

• What is the retention period? - no longer than is necessary

• Sensitive personal data on waste ground

What moves can you make:

• Clear guidelines for different data

• Test your policy - audit compliance

Data Retention & Destruction

Page 34: DPA seminar presentation

Potential consequences:

•Adverse publicity

•Criminal liability

•Regulatory action

•Missed opportunities and wasted resources

•Protracted litigation

Consequences of Breach?

Page 35: DPA seminar presentation

Assemble the breach team and determine -

• The nature and cause of the breach

• The extent of the damage/harm

• How to stop or mitigate the breach

• Any breach of contract/disciplinary issues?

• Audit for improvement

Breach Management

Page 36: DPA seminar presentation

A ‘Get Out of Jail Card’ - How to prevent Data Breaches

Any questions?

[email protected]

Page 37: DPA seminar presentation

Choosing The Right Partnerfor Data Protection Compliance Services

Alistair DickenCorporate Sales Director – PHS Data Solutions

Crumlin Road Gaol, BelfastThursday 30th July 2015

Page 38: DPA seminar presentation

1. Credibility2. Compliance3. Culture

The 3 “C”s

Page 39: DPA seminar presentation

1. Are they a recognised brand? Have you, or someone in you know used them before?

2. Do they service similar size/type customers? References?

3. Are they Registered? Companies House, VAT Registered etc

4. Do they have a physical facility for you to visit?

Credibility

Page 40: DPA seminar presentation

Trade Body Memberships (Examples)

Credibility

Page 41: DPA seminar presentation

Records Management Services

1.ISO IEC 27001 – Information Security ManagementIncludes Data, Documents, Messages, Communications,

Conversations, Transmissions, Recordings, Drawings, and Photographs2.ISO 9001 – Quality Management3.ISO 14001 – Environmental Management

Compliance

Page 42: DPA seminar presentation

Shredding Services

1.BS EN15713 – Code of Practice for Secure Destruction of Confidential Material

Staff Vetting, Premises Security, Vehicle Security, Handling and Processing

Agreement in Writing, Collection Certificates, Destruction Certificates

2.CPNI Approved ShreddingGovernment Approval for handling & shredding TOP SECRET Classified

documents – higher staff vetting, smaller shred size etc

Compliance

Page 43: DPA seminar presentation

1. Strong Customer Service Ethos

2. Scope of Service Provision

3. Health & Safety Focus

4. Staff Vetting, Training & Development

5. Investors in Technology & Innovation

Culture

Page 44: DPA seminar presentation

Any Questions