How to manage employees WhatsApp use WhatsApp is a great communication tool. Millions use it for chatting with friends, vitally important stuff like sharing cat/dog memes and organising our daily lives. However, what about using messaging apps in a work context? It certainly raises some challenges and data protection concerns. Inappropriate use of messaging apps can, and has, resulted in serious consequences for both employees and employers. WhatsApp is an excellent example of how technology can blur our private and professional lives. It’s easy to see how it happens – it’s just so darn convenient. Not to mention virtually free. There have been a number of high-profile cases where WhatsApp messages have led to reputational damage, as well as individuals and organisations being penalised. From police officers and firefighters sending racist, sexist and homophobic content in ‘private’ groups, to politicians and civil servants failing to retain or surrender WhatsApp messages to public inquiries. Aggrieved employees have won damages in tribunal cases for being excluded from work-related group chats. Then there was the famous case of former Health Secretary, Matt Hancock, who handed over thousands of sensitive political messages to a journalist he was working with on his autobiography! This smorgasbord of drama is before data protection comes into play. 26 members of staff at NHS Lanarkshire used a WhatsApp Group on multiple occasions to share patient data; names, phone numbers, addresses, images, videos and screenshots were shared, including sensitive clinical information. Police officers were caught sharing crime scene images. And so on. These are egregious examples. In others, however, Gen Z can be cut some slack. They live in an era of fast-moving technology and take instant messaging for granted. The risks are evident. Employers might have limited control over employees setting up their own WhatsApp group, which are routinely private and set up on personal mobiles. But left unchecked? They can lead to the sharing of offensive content, confidential or commercially sensitive information, or can be the cause of a personal data breach. Furthermore, employers have no control over how messages are then shared to any number of recipients beyond the organisation. In fact, employers might not know a group exists until a problem arises. In the wrong hands, messaging apps can be like the world’s leakiest chain email. Mitigating the risks In light of the risks, an outright ban on the use of WhatsApp for work-related matters may seem like a good idea, but in practice in many organisations this is unlikely to be enforceable. So what can employers do to mitigate the risks? The answer probably lies in raising awareness, educating staff and setting clear boundaries. Clear policy guidelines on the use of messaging apps such as WhatsApp can help to prevent something nasty flaring up. In much the same way as you would tell people what is deemed acceptable use for email and internet use in the workplace, you can extend this to WhatsApp. Policy guidelines can clearly set out; 📌 what’s acceptable and unacceptable content 📌 don’t share sensitive company information 📌 don’t share personal information relating to customers, business partners, colleagues and so on 📌 don’t share images of people, especially children or vulnerable people 📌 don’t use WhatsApp to harass or bully other employees 📌 don’t deliberately exclude people from a work-related group chat without a good reason. 📌 the risks & consequences of inappropriate use for those involved Your policy guidelines can distinguish between different types of group. For example, making it clear a WhatsApp group set up to arrange after-work socialising, be it a sports team or going for drinks, is either work-sanctioned or it isn’t. If it isn’t, the responsibility for the content of the chat lies with the users of that group. A fair, transparent policy is unlikely to be criticised if applied consistently and fairly. Guidelines can be created with clear examples and case studies which resonate with your staff. There’s no shortage of examples out there – several police officers in the example above were sent to prison. Regularly remind people and consider including an ‘acceptable use of WhatsApp’ input during team training. Should line managers, as part of their duties, be asked to act as moderators or gatekeepers for such groups? Should the DPO be asked to dip sample them? It might work for some organisations. You can send a clear warning to staff that a breach of the policy is likely to lead to disciplinary action. You can also warn them, WhatsApp messages can (and have!) been used in evidence in legal disputes and civil litigation. They might think what they are doing is private, but it might turn out not be. Given its huge popularity, there’s little doubt WhatsApp (or similar apps) will continue to be widely used as a simple and cost-effective way of communicating with people in the workplace. But, as with any form of communication, the key is to remain clear, open and transparent about the rules of use to make sure the rights of employees and the data your organisation handles remains protected.
Managing data deletion, destruction and anonymisation How to keep what you need and get rid of what you don’t Clearing out personal data your business no longer needs is a really simple concept, but in practice it can be rather tricky to achieve! It throws up key considerations such as whether to anonymise or how to make sure its deleted or securely destroyed. Let’s take a look at the key considerations and how to implement a robust plan. Data retention requirements and risks Data protection law stipulates organisations must only keep personal data as long as necessary and only for the purposes they have specified. There are risks associated with both keeping personal data too long, or not keeping it long enough. These risks include, but are not limited to: causing the impact of a personal data breach to be significantly worse – i.e. it involves personal data which an organisation has no justification for keeping. Regulatory enforcement action could be more severe and the damage to an organisation’s reputation worse This also raises the risk of class actions or individual compensation claims. falling foul of relevant laws by failing to keep records for legally-defined periods. an inability to respond to complaints, litigation or regulatory enforcement for failing to keep data necessary to meet contractual or commercial terms. Data retention policy and schedule To manage this legal obligation successfully, you’ll need to start with an up-to-date data retention policy and schedule. These should clearly identify which types of personal data your business processes, for what purposes, how long each should typically be kept and under what circumstances you might need to hold it for longer. If your data retention policy or schedule is lacking, first focus on making sure these are brought up to scratch. Our Data Retention Data Retention Guidance has some useful templates. 5 Key steps when the retention period is reached When an agreed retention period is reach (as per your retention schedule), we’d recommend taking the following steps: Identify the relevant records which have reached their retention period Notify the relevant business owner to confirm the data is no longer needed Consider any changes in circumstances which may require longer retention of the data Make a decision on what happens to the data Document the decision and keep evidence of the action Making the right decision when the retention period is reached There are different approaches an organisation can take when the data retention period is reached, such as: Delete it – usually the default option Anonymise it Securely destroy it – for physical records, such as HR files Deletion of records might seem the obvious choice, and it’s often the best one too, but take care how you delete data. Sometimes deleting whole records can affect key processes on your systems such as reporting, algorithms and other programs. Check with your IT colleagues first. Anonymisation Most organisations want to extract increasing information and value from their digital assets. In some situations, it can be helpful to remove any personal identifiers so you can keep the data that remains after the retention period has been reached. For example, You might want to continue to provide management information or historical analysis, which you can do an anonymised form. This is quite common If you have data of historic marketing campaign responders, you may wish to keep certain non-personal campaign data in an anonymised form for reporting or analytical purposes, such as response volumes by segment, phasing of responses, and so on If you hold records of job applicants you may wish to keep certain demographics (such as gender or diversity information) in an anonymised form. This might support your equal opportunities endeavours To be clear, anonymisation is the process of removing ALL information which could be used to identify a living person, so the data that remains can no longer be attributed back to any unique individuals. Once these personal identifiers are deleted, data protection laws do not apply to the anonymised information that remains, so you may continue to hold it. But you have to make sure it is truly anonymised. The ICO stresses you should be careful when attempting to anonymise information. For the information to be truly anonymised, you must not be able to re-identify individuals. If at any point reasonably available means could be used to re-identify the individuals, the data will not have been effectively anonymised, but will have merely been pseudonymised. This means it should still be treated as personal data. Whilst pseudonymising data does reduce the risks to data subjects, in the context of retention, it is not sufficient for personal data you longer need to keep. How to manage deletion There are software methods of deleting data, which may involve removing whole records from a dataset or overwriting them. For example, using of zeros and ones to overwrite the personal identifiers in the data. Once the personal identifiers are overwritten, that data will be rendered unrecoverable, and therefore it’s no longer classed as personal data. This deletion process should include backup copies of data. Whilst personal data may be instantly deleted from live systems, personal data may still remain within the backup environment, until it is overwritten. If the backup data cannot be immediately overwritten it must be put ‘beyond use’, i.e. you must make sure the data is not used for any other purpose and is simply held on your systems until it’s replaced, in line with an established schedule. Examples of where data may be put ‘beyond use’ are: When information should have been deleted but has not yet been overwritten Where information should have been deleted but it is not possible to delete this information without also deleting other information held in the same batch The ICO (for example) will be satisfied that information is ‘beyond use’ if the data controller: is not able, or will not attempt, to use the personal data to inform any decision about any individual or in a way that affects them; does not give any other organisation access to the personal data; has in place appropriate technical and organisational security; and commits to permanently deleting the information if, or when, this becomes possible. Destruction of physical records Destruction is the final action for about 95% of most organisations’ physical records. Physical destruction may include shredding, pulping or burning paper records. Destruction is likely to be the best course of action for physical records when the organisation no longer needs to keep the data, and when it does not need to hold data in an anonymised format. Controllers are accountable for the way personal data is processed and consequently, the disposal decision should be documented in a disposal schedule. Many organisations use other organisations to manage their disposal or destruction of physical records. There are benefits of using third parties, such as reducing in-house storage costs. Remember, third parties providing this kind of service will be regarded as a data processor, therefore you’ll need to make sure an appropriate contract is in place which includes the usual data protection clauses. Destruction may be carried out remotely following an agreed process. For instance, a processor might provide regular notifications of batches due to be destroyed in line with documented retention periods. Don’t forget unstructured data! Retention periods will also apply to unstructured data which contains personal identifiers. The most common being electronic communications records such emails, instant messages, call recordings and so on. As you can imagine, unstructured data records present some real challenges. You’ll need to be able to review the records to find any personal data stored there, so it can be deleted in line with your retention schedules, or for an erasure request. Depending on the size of your organisation, you may need to use specialist software tools to perform content analysis of unstructured data. In summary, whilst data retention as a concept appears straightforward, it does require some planning, clearly assigned responsibilities for implementing retention periods, and the technical means to do so effectively.
The three foundations of good data governance People, processes and technologies Creating a clear data governance strategy is crucial to making sure data is handled in line with your organisation’s aims and industry best practice. Data governance is often thought of as the management process by which an organisation protects its data assets and ensures compliance with data laws, such as GDPR. But it’s far broader than compliance. It’s a holistic approach to data and should have people at its very heart. People with defined roles, responsibilities, processes and technologies which help them make sure data (not just personal data) is properly looked after and wisely used throughout its lifecycle. How sophisticated your organisation’s approach needs to be will depend on the nature and size of your business, the sensitivity of the data you hold, the relationships you have with business partners, and customer or client expectations. Benefits of good data governance There are many benefits this activity can bring, including: Minimising risks to the business, your employees, customers and suppliers Giving your people clarity around expected behaviours and best practices Embedding compliance requirements A strong data governance approach can also help an organisation to make the most of their data assets, improve customer experience and benefits, and leverage competitive advantage. Data governance – where to start? There are three foundational elements which underpin successful data governance – People, Processes and Technologies. People Engaging with stakeholders across the organisation to establish and embed key roles and responsibilities for data governance. Many organisations look to establish a ‘Data Ownership Model’ which recognises data governance is an organisational responsibility which requires close collaboration across different roles and levels, including the delegation of specific responsibilities for data activities. Here’s some examples of roles you may wish to consider: Data strategy lead – such as Chief Data Officer / Chief Digital Officer Data protection lead – such as Data Protection Officer (DPO), if you have one Information security lead – such as Chief Information Security Officer (CISO) or Chief Technology Officer Information asset owners (or data owners) – leaders of business functions / teams which collect and/or use personal data for particular purposes. Such as HR, Marketing & Sales, Finance, Operations, and so on. Data specialists – heavy users of complex datasets, such as data analysts and data scientists. System owners – the people who manage the key systems which hold personal data, such as IT managers. Processes Think about all the processes, policies, operating procedures and specialist training provided to guide your employees and contractors to enable them to handle data in line with your business expectations – as well to comply with the law. For example: Data protection policies and provision of relevant training Specific procedures for handling individual privacy rights requests and data breaches Information security policies and provision of relevant training Standard Operating Procedures and handouts Without these in place and regularly updated, your people can’t possibly act in the ways you want and expect them to. In my experience, success comes from keeping these items concise, and as relevant and engaging as possible. They can easily be forgotten or put in the ‘maybe later’ pile… a little time and effort can really pay dividends! Technologies The technologies which underpin all data activities across the data lifecycle. For example, your HR, marketing & CRM, accounting and other operational systems you use regularly. Data governance requires those responsible for adopting technologies to ensure appropriate standards and procedures are in place which ensure appropriate: Accessibility and availability standards Data accuracy, integrity and quality management Privacy and security Looking at privacy technology in particular, the solutions available have really progressed in recent years in terms of both their capability and ease of use. Giving DPOs and others with an interest in data protection clear visibility of where the risks lie, help to prioritise them and pointers to relevant solutions. They can also help provide clear visibility and oversight to the senior leadership team. The ‘Accountability Principle’ Data governance goes hand in hand with accountability – one of the core principles under GDPR. This requires organisations to be ready to demonstrate the measures and controls they have to protect personal data and in particular, show HOW they comply with the other data protection principles. Appropriate measures, controls and records need to be in place to evidence accountability. For example, a Supervisory Authority (such as the ICO) may expect organisations to have: Data protection programme, with clear data ownership & governance and regular reporting up to business leaders Training and policies to guide staff Records of data mapping exercises and processing reviews, such as an Information Asset Register and Record of Processing Activities Risk assessments, such as Data Protection Impact Assessments and Legitimate Interests Assessments Procedures for handling of individual privacy rights and data breaches Contracts in place between organisations which include the relevant data protection clauses, including arrangement for restricted international data transfers Data sharing agreements Ready to get started? If you’re keen to reap the benefits of improved compliance and reduced risk to the business, the first and crucial step is getting buy-in from senior leadership and a commitment from key stakeholders, so I’d suggest you kick-off by seeking their support.
Data Protection Policies – what do businesses need? Under EU and UK data protection law businesses need to make sure they have ‘appropriate technical and organisational measures’ in place to protect personal data. Organisational measures include making sure staff receive adequate data protection training and guidance about how they should handle personal data. In my experience, people are keen to ‘do the right thing’ with personal data, but are sometimes unsure how to go about it. This is where well-crafted policies can really help, sitting alongside and integrated with employee training. Unfortunately people often have a negative view of policies. Long-winded policies, full of impenetrable jargon which regurgitates the law can turn people off. A vanilla one-size fits all approach has little value… but there’s a much better way. A well-written, easy-to-read, concise policy can communicate ‘what good looks like’ for your business and explain how your people should behave to deliver good practice. Yes, you absolutely need to take into account what the law says. A policy should identify key risk areas, but crucially it should also tell your people how they should act to meet your company standards – which include legal compliance. Don’t shy away from stressing the benefits for your business of acting responsibly. Focus on the needs of your business sector and the unique nature of your businesses processing. Make policies relevant to your workforce and how your business operates. Even better if you can, tie-in the launch of improved data policies with data protection training, which shares the main themes from the policies, this can really bring them to life , improve awareness and reinforce positive behaviours. What data protection related policies are needed? First decide which policies you actually need and how they should fit together. My favoured approach is to have just two ‘parent’ data policies, a Data Protection Policy and an Information Security Policy, then link out to ‘child’ policies or procedures which sit below them. You might consider a third parent policy, such as Acceptable Use, but personally I prefer information about acceptable use to be included within the Data Protection and Information Security policies, so people don’t have to search around. Here’s a typical Policy Framework, showing the two ‘parent’ policies and examples of possible ‘child’ policies or procedures below. The range of policies you’ll need will vary from business to business. A small company, with a handful of employees, processing relatively less sensitive data won’t need a raft of policies. Many micro or small businesses may just focus on having a Data Protection Policy (which covers the data lifecycle from creation through to retention) and an Information Security Policy. Alongside these you’ll definitely need a clear procedure for handling data breaches and individual privacy rights. How to write helpful, practical data protection policies As said, too often policy documents are littered with legalise and jargon. Sometimes it feels like a policy has to be formal and massively detailed. Not true. People shouldn’t need a lot of specialist knowledge to understand your policies, particularly those aimed at ALL staff. Straight-forward instructions are more likely to be read, which means more people are likely to follow them. Take a look at the way your policies are written. Are they a bit dry? If they could do with freshening up, here are some simple do’s and don’ts to consider: Do’s use everyday words in place of jargon explain any necessary terminology in plain English break up blocks of text with headings, lists and tables highlight key messages you want to get across include useful tips give useful examples tailored to your business rope in your Comms or L&D team to help simplify things (or anyone who’s good with words) cut out detail by linking to other related policies, guidelines, procedures ask for feedback – how often do people use them? Do they find them helpful? What would make them better? Don’ts avoid complex language / legalese avoid ‘insider’ jargon – why say ‘data subject’ if you could say people, individuals, customers, patients etc? avoid cut-and-paste definitions from GDPR text – where you use data protection terms, such as controller, processor, third-party, anonymisation, automated decision-making explain what these mean in layman’s terms Avoid information overload Of course, balance is important. While overly complex policies will gather dust, we need to include enough useful and important information to get key messages across. We’re not talking about talking down to people or patronising them, either. Of course, we also need to make sure people are aware of relevant policies and can easily lay their hands on them. How to communicate data protection policies I’d recommend you host policies on your Intranet, if you have one, and create them in the form of web pages rather than PDFs. It’s good practice to include hyperlinks to and from topic-specific guidance notes, so people can easily navigate to find more about a specific topic. This helps you to keep the parent policies short and concise – easy to digest. When you carry out data protection training, remind people where to find related policies. In fact throughout the year use near-misses, news stories and other events to reinforce key messages and point to your policies. Well-crafted easy to digest data protection related policies will go a long way to guide staff on how you expect them to handle and keep personal data secure in their day-to-day roles. But as always proportionality is key, a smaller business handling fairly insensitive data wouldn’t be expected to have multiple policies.
Data breaches – human or a catalogue of errors? Why systems fail The recent spate of serious data breaches, not least the awful case involving the Police Service of Northern Ireland (PSNI), left me wondering: who’s really to blame? We’re used to hearing about human error, but is it too easy to point the finger? Is it really the fault of the person who pressed the send button? An old adage comes to mind, ‘success has a thousand fathers, failure is an orphan.’ Of course, people make mistakes. Training, technology and procedures can easily fail if ignored, either wilfully or otherwise. Yes, people are part of the equation. But that’s what it is. An equation. There are usually other factors at play. In the PSNI case – one involving safety-critical data – I would argue there’s a strong argument that any system allowing such unredacted material to enter an FOIA environment in the first place is flawed? Nobody is immune from human error. About nine years ago, on my second day in a new compliance role, I left my rucksack on the train. Doh! Luckily, there was no personal data relating to my new employer inside. I lost my workplace starter pack and had to cancel my debit card. I recall the sinking feeling as my new boss said, ‘well, that’s a bit embarrassing for someone in your job’. It was. But I knew it could have been so much worse. Approximately 80% of data breaches are classified by the Information Commissioner’s Office as being caused by human error. Common mistakes include: Email containing personal data sent to the wrong recipients Forwarding attachments containing personal data in error Failing to notice hidden tabs or lines in spreadsheets which contain personal data (this is one of the causes cited in the PSNI case) Sensitive mail going to the wrong postal address (yes, a properly old-fashioned dead wood data breach!) However, sometimes I hear about human error breaches and don’t think ‘how did someone accidently do that?’ Instead, I wonder… Why didn’t anyone spot the inherent risk of having ALL those records in an unprotected spreadsheet in the first place? Why wasn’t there a system in place to prevent people being able to forget to blind copy email recipients? Is anyone reviewing responses to Data Subject Access Requests or FOI requests? What level of supervision / QA exists in that organisation? Why is it acceptable for someone to take confidential papers out of their office? I could go on. Technical and Organisational Measures (TOMs) Rather than human error, should we be blaming a lack of appropriate technical and organisational measures (TOMs) to protect personal data? A fundamental data protection requirement. We all know robust procedures and security measures can mitigate the risk of human error. A simple example – I know employees who receive an alert if they’re about to send an attachment containing personal data without a password. Alongside this, data protection training is a must, but it should never be a ‘tick box’ exercise. It shouldn’t be a case of annual online training module completed; no further action required! We need to make sure training is relevant and effective and delivers key learning points and messages. Training should be reinforced with regular awareness campaigns. Using mistakes (big or small) as case studies are a good way to keep people alert to the risks. This is another reason why post-event investigation is so important as a lesson-learning exercise. Rather than being a liability, if we arm people with enough knowledge they can become our greatest asset in preventing data breaches. Chatting with my husband about this, he mentioned a boss once asking him to provide some highly sensitive information on a spreadsheet. Despite the seniority and insistence of the individual, my husband refused. He offered an alternative solution, with protecting people’s data at heart. Armed with enough knowledge, he knew what he had been asked to do was foolhardy. Lessons from previous breaches It’s too early to call what precisely led to these recent breaches: The Police Service of Northern Ireland releasing a spreadsheet containing the details of 10,000 police officers and other staff public in response to a Freedom of Information Request Norfolk and Suffolk Police accidentally releasing details of victims and witnesses of crime Scottish genealogy website revealing thousands of adopted children’s names. However, we can learn from previous breaches and the findings of previous ICO investigations. You may recall the case of Heathrow Airport’s lost unencrypted memory stick. Although ostensibly a case of human error, the ICO established the Airport failed not only ‘to ensure that the personal data held on its network was properly secured’, but also failed to provide sufficient training in relation to data protection and information security. The person blamed for the breach was unaware the memory stick should have been encrypted in the first place. Then there was the Cabinet Office breach in which people’s home addresses we published publicly in the New Year’s Honours list. The actual person who published the list must’ve had a nightmare, when they realised what had happened. But the ICO findings revealed a new IT system was rushed in and set up incorrectly. The procedure given for people to follow was incorrect. A tight deadline meant short-cuts were taken. The Cabinet Office was found to have been complacent. The lesson here? Data breaches aren’t always solely the fault of the person pressing the ‘send’ button. Too often, systems and procedures have already failed. Data protection is a mindset. A culture. Not an add-on. As the PSNI has sadly discovered, in the most awful of circumstances. The impact breaches can have on employees, customers, victims of crime, patients and so on, can be devastating. Just the knowledge that their data is ‘out there’ can cause distress and worry. Data protection law doesn’t spell out what businesses must do. To know where data protection risks lie, we need to know what personal data we have across the business and what it’s being used for. Risks need to be assessed and managed. And the measures put in place need to be proportionate to the risk.
Data Retention Guide Data retention tools, tips and templates This comprehensive guides take you through the key steps and considerations when approaching data retention. Whether you’re starting out or reviewing your retention policy and schedules, we hope this guide will support your work. This guide was developed and written by data protection specialists from a broad range of sectors. A huge thank you to all those who made it possible.
Privacy Management Programme – what does one look like? The concept is nothing new, but the term Privacy Management Programme (PMP) has been flung into the spotlight by the UK Government’s plans to reform data laws. In a nutshell, the Government plans to revise the current accountability framework, replacing existing obligations (some of which are mandatory) with a requirement to implement a PMP. It’s argued the current legislative framework ‘may be generating a significant and disproportionate administrative burden’ because it sets out detailed requirements organisations need to satisfy in order to demonstrate compliance. The idea is a new ‘risked-based accountability framework’ will be introduced, requiring organisations to implement a PMP, but allow flexibility to internally tailor the programme to suit the organisation’s specific processing activities. What is a Privacy Management Programme? A PMP is a structured framework which supports organisations to meet their legal compliance obligations, the expectations of customers and clients, fulfil privacy rights, mitigate the risks of a data breach – and so forth. Such a programme should recognise the value in taking an all-encompassing, holistic approach to data protection and privacy; embedding data protection principles and the concept of privacy by design and default. Core components of a Privacy Management Programme There are a number of PMP approaches and frameworks in existence. The UK Government has not yet elaborated on what they would expect a PMP to look like. This top-level summary is broadly based on the IAPP’s Privacy Programme Management approach. Governance Organisations should develop and implement a suitable framework of management practices which make sure data is used properly and in line with organisational aims, laws and best practice. This should include adopting a privacy by design and by default approach; ensuring appropriate measures are in place to prevent unnecessary risks. Assessments Achieving clear oversight of the data held and processed, including any suppliers used to support business activities. Developing risk assessment tools which help to identify privacy risks and manage them effectively (e.g. Privacy Impact Assessments / Data Protection Impact Assessments). Record-keeping Mapping and maintaining an inventory of where personal data is, its purpose, how it is used and who it’s shared with. Policies Developing and implementing clear policies and procedures to guide staff and give them clear instructions about how personal data should be collected, used, stored, shared, protected and so on. Training and awareness Making sure adequate and appropriate training is conducted to give staff the knowledge and understanding they need to protect and handle data lawfully and in line with organisational expectations in their day-to-day roles. Making sure people are aware of how their organisation expects them to behave. Privacy rights Putting in place appropriate procedures to effectively and efficiently fulfil individual privacy rights requests, such as the right of access, erasure or objection. Protecting personal information Crucial to any PMP is protecting personal information. Working in conjunction with information security, a data protection by design approach would be expected – a proactive rather than reactive approach. Data incident planning Creating and developing data incident procedures and plans. Having appropriate methods to assess risk and potential impact, as well as understanding breach notification requirements. Monitoring and auditing Last, but by no means least no PMP would be complete without a methodology for tracking and benchmarking the programme’s performance. What might change? To many who’ve endeavoured to comply with the GDPR, all of the above will sound very familiar. So, the Government isn’t proposing we do away with all the hard work already done. It’s planning a relaxation to some of the mandatory requirements; giving organisations more flexibility and control over how they implement certain elements of their programme. On the one hand, this could be seen as a welcome move away from a ‘one-size fits all’ approach under UK GDPR, giving organisations more flexibility around how implement their privacy programmes to achieve desired outcomes. On the other hand, there are fears the removal of mandatory requirements will lead to a watering down of the fundamental principle of accountability (a principle significantly bolstered under GDPR).
Data Protection by Design: Part 3 – Data Protection Impact Assessments Getting your DPIA process on track Deciding when to carry out a Data Protection Impact Assessment (DPIA), and understanding how to conduct one effectively, is a challenging area. I’ve come across cases where DPIAs are not being conducted when necessary, or left incomplete. Less frequently, DPIAs are over-used, creating an unnecessary burden on key teams. DPIAs sit at the heart of Data Protection by Design, and this is part 3 of our series, following on from: Part 1: Data Protection by Design – The Basics Part 2 – How to approach Data Protection by Design Just to be clear – we may be hearing the term DPIA more frequently, but it’s not a new idea – what changed under GDPR is they were made mandatory in certain circumstances. And even if not mandatory they can be a very useful tool in your data protection toolbox. So how do you make sure your DPIA process is on track? I’ve taken a look at the key stages you should have in place, and how to get people on-board and improve their understanding. But first things first. What is a Data Protection Impact Assessment? Just to recap, a DPIA is a management tool which helps you: Identify privacy risks Assess these risks Adopt measures to minimise or eliminate risks It’s a way for you to analyse your processing activities and consider any risks they might pose. It focuses on identifying any risks to people’s rights and freedoms, and considers the principles laid down in data protection law. The key is to start the assessment process early so you can make sure any problems are found (and hopefully fixed) as soon as possible in any project – be this implementing a new system, designing a new app or creating new processes. When is a DPIA mandatory? When considering new systems, technologies or processes a DPIA should be conducted if these might result in a high risk to the rights and freedoms of individuals. A DPIA may also be conducted retrospectively if you believe there are inherent risks. It’s mandatory, under the GDPR to conduct a DPIA in all of the following scenarios: A systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person processing on a large scale of special categories of data or of personal data relating to criminal convictions and offences a systematic monitoring of a publicly accessible area on a large scale Each EU regulatory authority has published their own list of other scenarios in which a DPIA would be mandatory. You can find the UK Innformation Commissioner’s Office’s in its DPIA Guidance. This includes; use innovative technology (note the criteria from the European guidelines) process biometric data or genetic data (note the criteria from the European guidelines) match data or combine datasets from different sources collect personal data from a source other than the individual without providing them with a privacy notice (‘invisible processing’) (note the criteria from the European guidelines) track individuals’ location or behaviour (note the criteria from the European guidelines) profile children or target marketing or online services at them – it’s also worth checking the new ‘Children’s Code’ aimed at protecting children online When a DPIA is not mandatory… but a good idea The ICO says it’s “good practice to do a DPIA for any other major project which requires the processing of personal data.” Here are some examples of where it might be advisable to conduct a DPIA, if your processing; would prevent or restrict individuals from exercising their rights means disclosing personal data to other organisations is for a new purpose (i.e. not the purpose the data was originally collected for) will lead to transfer of personal data outside the European Economic Area (EEA) involves contacting individuals in a manner which could be deemed intrusive. What the ICO expects you to do The ICO DPIA guidance has a handy checklist of areas to focus on: provide training so staff understand the need to consider a DPIA at the early stages of any plan involving personal data make sure existing policies, processes and procedures include references to DPIA requirements understand the types of processing that require a DPIA, and use the screening checklist to identify the need for a DPIA, where necessary create and document a DPIA process provide training for relevant staff on how to carry out a DPIA How to build a robust DPIA process So how do you go about fulfilling the ICO’s expectations above? Here are some steps to take. A. Getting Board / Senior Management buy-in Growing awareness and buy-in from across the organisation is crucial. It can be helpful to highlight why DPIAs are a good thing, for example; they’re a warning system – they alert compliance teams, and the business as a whole, of risks before they occur. Prevention is always better than cure by identifying risks before they’ve an adverse impact, DPIAs can protect you against potential damage to your brand reputation, e.g. from complaints or enforcement action they help management make informed decisions about how your processing will affect the privacy of individuals they show you take data protection seriously and provide evidence, should you need it, of your compliance Training is also important, I’ll come on to this in a bit, but first you need to make sure your process is fit for purpose…. B. Creating a screening questionnaire Create a quick set of questions for business owners or project leads to use, which help to identify if a DPIA is required or not. These can ask about the type of personal data being used, whether it entails any special category data or children’s data, what the aim of the project is and so on. The answers can be assessed to judge whether a more detailed assessment is really required or not. (It can also show where more training might be needed, if people struggle to answer the questions). C. The DPIA itself You need to develop a robust process for conducting a DPIA. The ICO has a template you can use, but it’s good idea to adapt this to suit your business. Make sure it’s easy to understand and not full of data protection jargon. These are the core aspects it needs to cover: describe the processing you are planning to do – it’s nature, scope, context and purposes assess its necessity and proportionality identify and asses any risks identify solutions and integrate into a plan sign off and record outcomes implement risk control plans and finally, keep your DPIA under review Let’s look at these seven key stages in a little more depth… 1. Describe your processing These are some of the type of questions you’d want answers to (this is not an exhaustive list): how is personal data being collected/used/stored and how long it is retained for? what are the source(s) of the personal data? what is the relationship with individuals whose data will be processed? what types of personal data does it involve, does this include special category data, children’s data or other vulnerable groups? what is the scale of the activity – how many individuals will be affected? is the processing within individuals’ reasonable expectations? will data be transferred to a third party and is this third party based outside the EEA? what risks have already been identified? what are the objectives? Why is it important to the business and / or beneficial for individuals? 2. Necessity and proportionality Consider the following questions (again, this is not an exhaustive list): what is the most appropriate lawful basis for processing? is there another way to achieve the same outcome? have you ensured that the minimum amount of personal data is used to achieve your objectives (i.e. data minimisation)? how can you ensure data quality and integrity is maintained? how will you inform individuals about any new processing? how will individuals’ rights be upheld? are any processors used and if so how will you ensure their compliance? how will international transfers be protected, what safeguard mechanisms will be used? who will have access to personal data, does this need to be restricted? where will data be stored and how will it be kept secure? how long will data be retained and how will data be destroyed when no longer required? have the relevant staff received appropriate data protection training? 3. Identify and assess the risks Identify any privacy issues with the project and associated risks. These may be risks to the individuals whose data is being processed, compliance or commercial risks. Is there potential for harm, whether this be physical, material or non-material? A DPIA should ideally benchmark the level of risk using a risk matrix which considers both the likelihood and the severity of any impact on individuals. You don’t have to eliminate all risks, but they should be documented, and any residual risks need to be understood and, if appropriate, accepted by the business. If you identify a high risk that you cannot mitigate, you must consult the ICO before starting the processing. 4. Identify solutions and integrate into a plan Develop solutions which will eliminate or minimise privacy risks and then consider how these solutions impact on the project. It can be helpful to use the established ‘four strategies for risk management’ (the 4Ts), i.e. Treat the risk, i.e. adopt measures to minimise or eliminate risk Transfer the risk, e.g. outsource the processing Tolerate, e.g. accept risk if its within the organisations accepted level of risk Terminate it, i.e. stop that specific processing or change the process in such a way that the risk no longer exists 5. Sign off and record outcomes Someone must sign-off that the DPIA is complete and be accountable for any residual risks. It’s a good idea to log residual risks in your Risk Register. 6. Implement risk control plans 7. And finally, keep your DPIA under review There’s also lots of useful content on this in the ICO’s DPIA Guidance. D. Awareness and Training Once you have your questionnaire and DPIA process ready to go, it’s time to make sure people know about it! If people aren’t aware they’ll be busy doing fabulously innovative things, not considering the potential data protection issues and impact on people’s privacy. Making sure your teams know what a DPIA is, in simple layman’s terms, is an important step – building an understanding about why it’s important and the benefits to the business as a whole. Creating short, easy to understand, guidelines and raising awareness via other means helps reinforce the message that DPIAs are a good thing and people need to think data protection in their day to day work. It’s also important to develop people’s skills. After all the DPO (or team/person responsible for data protection) can’t do this single-handed. You need key people to know; what a DPIA entails how to answer the questions what are the types of risks to look out for and what type of solutions will mitigate any identified risks Holding workshops with relevant staff to discuss how you conduct a DPIA, and / or perhaps run through an example, can help improve people’s skills. My key tip would be to try and not over-complicate things and to keep it straightforward. In summary, whether you are required by law or not to complete a DPIA they are a useful way to make sure data protection is considered from the outset, with no nasty surprises just before your project launches! “But it’s essential that we go live on Friday!” If I had a penny for every time I’ve heard this one. If only they’d known, or thought of, speaking to the people responsible for data protection. Often a DPIA won’t required, but there’ll be times when it’s mandatory or just a very good idea. Data Protection team over-stretched? We can review your existing DPIA process or help you to develop one. We can also do remote DPIA workshops for key members of your teams – Get in touch