Data Protection Impact Assessments: 10 Tips How to get your DPIA process on track Do teams know when a Data Protection Impact Assessment should be conducted? Are you carrying out too many, or too few? Don’t make DPIAs a onerous box ticking exercise. If DPIAs are solely seen through the prism of compliance, they’ll be seen as burden. They may be attempted half-heartedly or left inadequately completed. If this is happening it’s time to shout about what a valuable tool they are! Assessing potential data protection risks from the start of a project, acts as handy warning system for the business and protects those whose person information is involved from unnecessary risks. DPIAs help to identify risks in advance, before they can potentially become a bigger problem. 10 tips for getting your DPIA process on track 1. Create a DPIA screening questionnaire Put together a set of questions for business owners and/or project leads to use, which help to identify if a DPIA is required or not for their particular project or activity. This will not only help teams to think about data protection considerations from the outset, but also avoids time being spent conducting DPIAs when they aren’t necessary. 2. Identify types of projects likely to need a DPIA In some situations DPIAs are mandatory under UK/EU GDPR, in others they may be a ‘good to do’. So, it’s helpful to set out some clear guidelines which explain your organisation’s position on this. When does your business consider it appropriate to carry out a DPIA? For example, are you using innovative tech or AI? Will you be handling biometric data? Are you matching data or combining data sets from different sources? Was the personal data collected indirectly? Are you tracking people (either their location or behaviour)? Do you use third party ad tech providers? Does the project involve children or special category data? Are you transferring data outside the UK/EEA? And so on. 3. Don’t forget your marketing related activities It can be easy to forget marketing related activities could require or benefit from a DPIA. If marketing could result in a ‘high risk’ to individuals it’s likely you’ll need to do an assessment of the data protection risks. Here are some examples; ‘large scale’ profiling of individuals for marketing purposes matching datasets for marketing purposes processing which may be ‘invisible’ to the data subject, e.g. list brokering, online tracking by third parties, re-use of publicly available data using geo-location data for marketing purposes tracking the behaviour of individuals including online advertising, web and cross device tracking, tracing services (tele-matching & tele-appending), wealth profiling and loyalty schemes. targeting children or other vulnerable individuals for marketing purposes. 4. Design an easy-to-use DPIA process You’re unlikely to reap the benefits if you have an unwieldly DPIA template full of data protection jargon, with questions people just don’t know how to answer. Create a practical usable DPIA template which is as straight-forward as possible for people to follow. The ICO has published a DPIA template, but there is nothing to stop you adapting this to suit your business. You may also choose to have a simplified version for less complex projects. Does your process help your teams to identify and assess privacy risks? Do you provide examples of what types of mitigating actions could be taken? Clear guidelines on how to complete a DPIA are invaluable. 5. DPIA training Key team members need to have the skills to conduct a DPIA: to understand what the process entails, how to brief key stakeholders and walking them through the process, explaining what sort of risks to look out for and so on. The DPO, or data protection lead, can’t be expected to do this single-handed. The ICO in their DPIA guidance specifically mentions the need to provide specialist training. 6. Awareness If teams don’t know what DPIAs are, they may push forward with new projects and innovations, and fail to consider the potential data protection issues. This may come back to bite you just before a project launches… or worse afterwards if you receive a complaint, breach and/or regulatory scrutiny. Once all your ducks are in a row; when you have a screening questionnaire and a decent DPIA template, it’s time to make sure people know about DPIAs across the business. Get your Comms team involved to spread the message far and wide. 7. Start early Talk to your project leaders, change management (if you have them) and IT leaders. Make sure people who work on projects which involve personal data complete screening questionnaires as soon as possible. Assess whether a DPIA is needed, so you can start the process as soon as possible. This way you can find problems and fix them early on. 8. Collaborate A DPIA is likely to need the input of people from different areas of the business. Get people collaborating so projects can proceed at pace, without unnecessary delays. Engage business and project management stakeholders at an early stage, so you can scope out the processing and start to identify any potential privacy risks, and consider mitigating measures. 9. Keep revisiting your DPIA Throughout the different stages of a project keep an ongoing dialogue with stakeholders, especially with Agile projects which may expand over time. Check if new ideas, new developments have an data protection impact. 10. Review Once a DPIA is completed, set review dates, so you can check if things have changed. For instance, you may have developed a new app, and six months later you want to improve the functionality, adding new features – what data protection issues could this raise? Also keep you screening questionnaire, template and guidelines under review, there will always be enhancements you can make to make them more effective. Why not ask teams for feedback on how they can be improved? DPIAs can feel a bit daunting, but the more familiar people are with the process, the risks they should be looking out for and the types of measures and controls that could be deployed to protect people’s data, the easier it all becomes.
DPOs and conflict of interests EU Court of Justice says businesses should conduct assessment I was recently mulling over with colleagues whether someone could be both the CEO and Data Protection Officer, along with another client query about whether someone could wear two hats; Consumer Services Manager and DPO. UK/EU GDPR specially tells us a DPO ‘may fulfil other tasks and duties’, but says the controller or processor must make sure ‘any such tasks and duties do not result in a conflict of interests’. So, I read with some interest the recent judgement from the EU Court of Justice about the role of a DPO and the risk of a conflict of interests. (Albeit, it probably doesn’t say any more than we already suspected). The court confirms, DPOs should be ‘in a position to perform their duties and tasks in an independent manner’. This means they should not be carrying out tasks or duties with would result in them determining the objectives and methods of processing personal data within the organisation. Where an individual may have two, or multiple roles (including DPO), organisations are urged to make an assessment of whether there’s a potential conflict of interests. This should be done on a case-by-case basis taking into account all relevant circumstances, including organisational structure. What matters is what happens in practice. If a DPO has two roles, the organisation needs to make sure there are clear rules in place to avoid, or limit, any conflict of interests arising. (And it’s not the DPO’s job to try and resolve this). If a DPO’s other job means they have responsibility for the data processing itself, there’s likely to be a conflict. But, in practice this may be a difficult line to draw. The law also tells us a DPO cannot be dismissed for or penalised for performing DPO tasks. However, DPOs could be dismissed from the role if they are unable or no longer able to carry out their duties and tasks in an independent manner. So, can a CEO also be a DPO, probably far from ideal. Can a Customer Service Manager also be a DPO? Possibly, if the different roles are clearly defined. The European Data Protection Board’s DPO guidance gives us a bit of a steer. This says conflicting positions within an organisation may include; ‘senior management positions (such as chief executive, chief operating, chief financial, chief medical officer, head of marketing department, head of Human Resources or head of IT departments)’. This may extend to ‘other roles lower down in the organisational structure if such positions or roles lead to the determination of purposes and means of processing’. Clearly if you’re a smaller business, but judge you should have a DPO, it may be prove challenging to appoint a suitable person where a conflict doesn’t arise with limited numbers to chose from. One would hope any regulator would take size and resources into account. It’s probably a good idea to follow this judgement and conduct an assessment. Clearly set out what different role’s entail, document your decision and be ready to defend if you have to. With all of this it’s worth remembering; the law sets out specific tasks and duties a DPO must perform not every business needs a DPO! Read Why DPO is not just a title covering who needs a DPO and what the role entails.
Data protection and our suppliers How to manage the third parties we work with One of the more challenging aspects of data protection compliance has been identifying and managing all our suppliers. Those acting as our processors, supporting our business. Making sure appropriate contractual terms are in place, whilst doing all we can to protect the business from supply chain data breaches (which are all too common) can become onerous. It can help to take a risk-based approach, focusing on the suppliers which represent the biggest business risk first. Alongside this, for any new suppliers we need to make sure we carry out appropriate and robust due diligence. Years after GDPR was implemented, many projects to tackle supplier management remain unfinished, representing an ongoing risk. If we have limited visibility into how our data is processed by our suppliers (and any sub-processors) it clearly leaves the business exposed. What does good supplier management look like? In short, we need to make sure our suppliers are doing what they say they’ll do to protect personal data, using risk assessments and audits. This includes knowing how our suppliers will respond when it comes to the crunch– a data breach. How quickly and fully will they notify us, how will they assist us? Seven-point supplier management checklist 1. Due diligence – Do you have a questionnaire in place to identify the what, where, when and how of data processing? What data protection and security measures are in place? Is there evidence to prove this? It’s good practice to request meaningful answers to certain questions, such as: Do they have a DPO or another individual in the business responsible for data protection? Can they provide evidence of data protection policies and procedures? Have they experienced a data breach before? What information security procedures do they have in place? How regularly are their security measures tested? Do they hold any form of certification? In which country/region will the data be processed? Who are their sub-processors and where do they process the data? The above is by no means an exhaustive list. 2. International Data Transfers There are additional considerations if international data transfers come into play. If we’re sharing data (or allowing it to be accessed) by a supplier in a third country, we need to check what safeguards need to be in place. For countries where there’s no adequacy decision (allowing for the free flow of data), we need to implement a transfer mechanism such as the UK International Data Transfer Agreement (IDTA) or EU Standard Contractual Clauses (SCCs). There’s also the relatively new requirement to conduct a transfer risk assessment, and consider if additional security measures are needed. 3. Contracts – Do we have a clear list of standard clauses for supplier contracts? What do the liability clauses look like? Are we prepared to walk away from suppliers whose contracts aren’t up to scratch? Do we have a good understanding of the level of contractual risk the business is prepared to accept? UK/EU GDPR is clear on what should be included in contractual arrangements and the ICO have published useful contracts guidance. There are often negotiations to be had, especially when it comes to those tricky liability clauses. 4. Instructions – Have we provided clear instructions on how our suppliers are permitted to handle the personal data, for what purposes and how long they must retain it? 5. Ongoing risk assessment – Do we have a process for evaluating the level of risk suppliers may represent? It’s important to recognise some suppliers may bring greater risks than others. It may not be necessary to risk assess every supplier to the same level of granularity. Effectively we need to risk assess the risk assessments. 6. Review / Audit – Do we have a review or audit programme in place? Annual audits of all suppliers may not be possible, but it makes sense to rotate audits and maintain an up-to-date record of their processing activities. For suppliers considered a higher risk, it may be prudent to routinely audit them. In doing so it’s important to be clear what aspects of the supplier’s business needs to scrutinised. Creating a framework which is tuned and makes sense for the business is a good step and will mean there’s something to show the thought process if the ICO ever comes calling. Here are some factors to consider: What categories of data is handled? What’s the data volume? How risky is the processing? What could be the impact if a data breach occurred? Was any due diligence carried out when the supplier was onboarded? Is the supplier accredited or certified? Have there been any complaints relating to privacy / breaches? Have there been changes in ownership or scope of processing? Have there been significant changes in processes and workflow? 7. Certification – in the absence of an approved certification scheme, alignment with ISO 27701 (the standard extending ISO27001 into data privacy) is worth considering. It can sometimes feel like a mountain to climb, especially if operating using multiple suppliers. As the saying goes ‘you can only eat an elephant one bite at a time’, the key to supplier management is identifying the biggest risks and prioritising where action is needed the most.
Data Governance Quick Guide Taking control of our data In essence Data governance is a framework of management practices which makes sure data is used properly in line with our organisational aims, the law and best practice. Think of it as embedding Data Protection by Design and by Default across the organisation. It means business objectives can be met without taking unnecessary risks with data. Data governance helps us to: protect the business and those whose data we process: customers, employees, etc. reduce our organisational risk profile educate our people, by providing policy & guidance to them on how to use data in the safe and appropriate ways build in an ethical approach build our reputation, customer trust and enhance the value of our data assets support our teams’ innovation with use of data. The 6 data governance steps 1. Data discovery It’s vital to identify data assets held across the business understanding how personal data is being gathered, stored, used and shared. It can be helpful to map where the data is located on systems, and document it. Most medium to large businesses will need to do this anyway to create and maintain an Information Asset Register (IAR) and Records of Processing Activity (RoPA). 2. Policies & standards If our people don’t know how we expect them to behave when handling other people’s data, we can’t expect them to make a great job of it. Are your policies and procedures all up to scratch? Having a straight-forward, easy to understand and practical Data Protection Policy is a good place to start (alongside relevant training). The importance of well-crafted easy to use policies shouldn’t be underestimated. 3. Stakeholder accountability We need to identify key stakeholders within the business. Likely to be heads of key functions, such as HR, Operations, Sales & Marketing, and so on. It’s good to establish data roles and responsibilities, so people are clear what aspects they and others are responsible for. Who has the authority to make decisions about certain data? 4. Risk assessment process Businesses should have risk assessment procedures to discover, assess, prioritise and take action to mitigate data risks. A governance programme helps teams to identify and assess both existing and emerging risks, so they can be efficiently assessed and mitigated. Think of data like a balance sheet: it has great potential to create value, but also carries risks and liabilities. The aim of a data governance programme is to protect both the business and those whose data we process from harm which may arise. For example, things like inaccurate data, unlawful or unfair processing or using people’s data in ways they would not expect or want. For certain projects it will be necessary to conduct a Data Protection Impact Assessment (DPIA). 5. Technical and organisational measures (TOMs) Once privacy risks have been identified, we need to consider what measures could be put in place to tackle them. You may choose to mitigate them internally with new procedures or security measures, or perhaps work with a third party to adopt technical or operational measures. Privacy Enhancing Technologies – how they can help Organisational measures include making sure there’s good awareness about data protection across the business, and employees receive appropriate training. 6. Executive oversight Risks should be reported up the line to make sure the Senior leadership team has proper oversight and the opportunity to take appropriate action. If your organisation has a Data Protection Officer (DPO) this reporting will be part of the formal accountabilities for their role. But remember not all businesses need to have a DPO. Should we appoint a DPO? Overcoming cultural challenges Data protection and privacy professionals face a cultural challenge to win hearts and minds. I have sometimes heard legal or privacy teams described as ‘the department of no’. That’s not how we want to be seen! Smart businesses are realising the value of taking privacy seriously. We should help our business colleagues to balance the needs of commercial and operational functions with legal & ethical requirements. We shouldn’t just explain what the law requires. We must go further and help them our colleagues to find practical solutions. Collaboration and mutual understanding are essential ingredients for successful data governance.
Are we conducting too many DPIAs – or not enough? How to decide when to conduct Data Protection Impact Assessments Make no mistake, Data Protection Impact Assessments (DPIAs) are a really useful risk management tool. They help organisations to identify likely data protection risks before they materialise, so corrective action can be taken. Protecting your customers, staff and the interests of the business. DPIAs are key element of the GDPR’s focus on accountability and Data Protection by Design. It’s not easy working out when a DPIA is necessary, or when it might be useful, even if not strictly required by law. Businesses need to be in control of their exposure to risk, but don’t want to burden their teams with unnecessary work. So it falls to privacy professionals to use their judgement in what can be a delicate balancing act. Lack of clarity around when DPIAs are genuinely needed could lead businesses to carry out far more DPIAs than needed – whilst others may carry out too few. When are DPIAs required? We should check if a DPIA is required during the planning stage of new projects, or when changes are being planned to existing activity. Where needed, DPIAs must be conducted BEFORE the new processing begins. DPIAs are considered legally necessary when the processing of personal data is likely to involve a ‘high risk’ to the rights and freedoms of individuals. What does ‘high risk’ look like? Why types of activity might fall into ‘high risk’ isn’t always clear. Fortunately the ICO have given examples of processing likely to result in high risk to help you make this call. Regulated sectors, such as financial services and telecoms, have specific regulatory risks to consider too. Give consideration to the scope, types of data used and the manner of processing. It’s wise to also take account of any protective measures already in place. In situations where the nature, scope, context and purposes of processing are very similar to another activity, where a DPIA has already been carried out, you may not need to conduct another. Three key steps for a robust DPIA screening process 1. Engage your key teams In larger organisations, building good relationships with key teams such as Procurement, IT, Project Management, Legal and Information Security can really help. They might hear about projects involving personal data before you do. Make sure they’re aware when a DPIA may be required. This means they’ll be more likely to ‘raise a hand’ and let you know when a project which might require a DPIA comes across their desk. In smaller businesses there may still be others who can help ‘raise a hand’ and let you know about relevant projects. Work out who those people are. 2. Confirm the businesses appetite for risk Is your organisation the sort which only wants DPIAs to be carried out when strictly required by law? Or perhaps you want a greater level of oversight? Choosing to carry out DPIAs as your standard risk assessment methodology for any significant projects involving personal data – even if they might appear to involve lower levels of risks to individuals. Logic says you’ll never be 100% sure unless you carry out an assessment and DPIAs are a tried and tested way to give you oversight and confidence. But this approach requires more time, resources and commitment from the business. You need to strike the right balance for your organisation. 3. Adopt a DPIA screening process If you don’t currently use a screening process, you really should consider adopting one. It’s a quick and methodical way to identify if a project does or does not require a DPIA. You can use a short set of standard questions, which can be provided for stakeholders to complete and return or discussed in a call. So the question ‘Is a DPIA needed or not?’ can be reached rapidly and with confidence. Personally I prefer to arrange a short call with the stakeholders, using my screening questionnaire as a prompt to guide the discussion. Don’t forget to keep a record of your decisions! Including when you decide a DPIA isn’t necessary. Try not to burden colleagues with unnecessary assessments for every project, if there really is minimal risk. This is unlikely to be a well-received approach. Raise awareness and have a built-in DPIA screening process to make sure you catch the projects which really do warrant a deeper dive.
Data Retention Guide Data retention tools, tips and templates This comprehensive guides take you through the key steps and considerations when approaching data retention. Whether you’re starting out or reviewing your retention policy and schedules, we hope this guide will support your work. This guide was developed and written by data protection specialists from a broad range of sectors. A huge thank you to all those who made it possible.
Data Subject Access Request Guide Being prepared and handing DSARs Handling Data Subject Access Requests can be complex, costly and time-consuming. How do you make sure you’re on the front foot, with adequate resources, understanding and the technical capability to respond within a tight legal timeframe? This guide aims to take you through the key steps to consider, such as… Being prepared Retrieving the personal data Balancing complex requests Applying redactions & exemptions How technology can help
Ransomware attack leads to £98k ICO fine Solicitors firm failed to implement ‘adequate technical and organisational measures’ Are you using Multi-Factor Authentication? Are patch updates installed promptly? Do you encrypt sensitive data? Reports of cyber security incidents in the UK rose 20% in the last 6 months of 2021. These figures from the ICO, combined with the heightened threat in the current climate, provide a stark warning to be alert. The ICO says; “The attacks are becoming increasingly damaging and this trend is likely to continue. Malicious and criminal actors are finding new ways to pressure organisations to pay.” Against this backdrop the ICO has issued a fine to Solicitors’ firm following a ransomware attack in 2020. The organisation affected was Tuckers Solicitors LLP (“Tuckers”) which is described on its website as the UK’s leading criminal defence lawyers, specialising in criminal law, civil liberties and regulatory proceedings. While each organisation will face varying risks, this case highlights some important points for us all. Here’s a summary of what happened, the key findings and the steps we can all take. For increasing numbers of organisations this case will unfortunately sound all too familiar. What happened? On 24 August 2020 Tuckers realised parts of its IT system had become unavailable. Shortly after IT discovered a ransomware note. Within 24 hours it was established the incident was a personal data breach and it was reported to the ICO. The attacker, once inside Tuckers’ network, installed various tools which allowed for the creation of a user account. This account was used to encrypt a significant volume of data on an archive server within the network. The attack led to the encryption of more than 900,000 files of which over 24,000 related to ‘court bundles’. 60 of these bundles were exfiltrated by the attacker and released on the ‘dark web’. These compromised files included both personal data and special category data. The attacker’s actions impacted on the archive server and backups. Processing on other services and systems were not affected. By 7 September 2020, Tuckers updated the ICO to say the servers had been moved to a new environment and the business was operating as normal. The compromised data was effectively permanently lost, however material was still available in management system unaffected by the attack. Tuckers notified all but seven of the parties identifiable within the 60 court bundles which had been released, who they did not have contact details for. Neither Tuckers, nor third party investigators, were able to determine conclusively how the attacker was able to access the network in the first place. However, evidence was found of a known system vulnerability which could have been used to either access the network or further exploit areas of Tuckers once in side the network. What data was exfiltrated? The data released on the ‘dark web’ included: Basic identifiers Health data Economic and financial data Criminal convictions Data revealing racial or ethnic origin This included medical files, witness statements and alleged crimes. It also related to ongoing criminal court and civil proceedings. Tuckers explained to the Regulator, based on its understanding, the personal data breach had not had any impact on the conduct or outcome of relevant proceedings. However, the highly sensitive nature of the data involved increased the risk and potential adverse impact on those affected. Four key takeaways The ICO makes it clear in its enforcement notice that primary culpability for the incident rests with the attacker. But clear infringements by Tuckers were found. The Regulator says a lack of sufficient technical and organisation measures gave the attacker a weakness to exploit. Takeaways from this case: 1) Multi-Factor Authentication (MFA) Tuckers’ GDPR and Data Protection Policy required two-factor authentication, where available. It was found that Multi-Factor Authentication (MFA) was not used for its ‘remote access solution’. The ICO says the use of MFA is a relatively low-cost preventative measure which Tuckers should have implemented. The Regulator concluded the lack of MFA created a substantial risk of personal data on Tuckers’ systems being exposed to consequences such as this attack. Takeaway: If you currently don’t use MFA, now would be a good time to implement it. 2) Patch management The case reveals a high-risk security patch was installed in June 2020, more than FOUR months after its release. The ICO accepts the attacker could have exploited this vulnerability during the un-patched period. Considering the highly sensitive nature of the personal data Tuckers were handling, the Regulator concludes they should not have been doing so in an infrastructure containing known critical vulnerabilities. In other words the patch should have been installed much sooner. Takeaway: Make sure patches are installed promptly, especially where data is sensitive. 3) Encryption During the investigation Tuckers informed the ICO the firm had not used encryption to protect data on the affected archived server. While the Regulator accepts this may not have prevented the ransomware attack itself, it believes it would have mitigated some of the risks posed to the affected individuals. Takeaway: There are free, open-source encryption solutions are available. Alternatively more sophisticated paid for solutions are available for those handling more sensitive data. Also it’s worth checking you’re adequately protecting archives to the same standard as other systems. 4) Retention The enforcement notice reveals some ‘court bundles’ affected in the attack were being stored beyond the set 7-year retention period. Takeaway: This again exposes a common issue for many organisations. Too often data is held longer than is necessary, which can increase the scale & impact of a data breach. Our comprehensive Data Retention Guidance is packed with useful tools, templates and advice on tackling how long you keep personal data for. What else can organisations do? Clearly, we can’t be complacent and shouldn’t cut corners. We need to take all appropriate steps to protect personal data and avoid common pitfalls. Here are some useful resources to help you: Cyber Essentials – The enforcement action notes that prior to the attack Tuckers was aware its security was not at the level of the NCSC Cyber Essentials. In October 2019, it was assessed against the ‘Cyber Essentials’ criteria and failed to meet crucial aspects of its requirements. Cyber Essentials was launched in 2014 and is an information security assurance scheme operated by the National Cyber Security Centre. It helps to make sure you have the basis controls in place to protect networks/systems from threats. Cyber Essentials – gain peace of mind with your information security National Cyber Security Centre ICO Ransomware guidance – The ICO has recently published guidance which covers security policies, access controls, vulnerability management, detection capabilities and much more. DPN Data Breach Guide – Our practical guide covers how to be prepared, how to assess the risk and how to decide whether a breach should be reported or not. You can read the full details of this case here: ICO Enforcement Action – Tuckers Solicitors LLP