Jump to content

Recommended Posts

Posted

Hi all,

 

I've just been told by my COO that the Information Commissioner's Office is visiting on Monday and will probably want to speak to me about handling data protection.

 

Is there anything I should know/say or prepare for?

 

Thanks.

Posted

What has prompted the visit? Or what are they wanting to achieve? Has there been an incident reported to the ICO for data loss etc? If so I would make sure I know what we could do to prevent it happening again. Prove that you are reviewing and improving practice.

 

If it is just a random visit it would be the DPO surely that would need to answer questions. I'd just make sure I knew what our policies were and that's about all you should be expected to know.

Posted
What has prompted the visit? Or what are they wanting to achieve? Has there been an incident reported to the ICO for data loss etc? If so I would make sure I know what we could do to prevent it happening again. Prove that you are reviewing and improving practice.

 

If it is just a random visit it would be the DPO surely that would need to answer questions. I'd just make sure I knew what our policies were and that's about all you should be expected to know.

 

It is a random visit and the DPO is managing the visit. Can't help but be anxious!

Posted

Mildly terrified that this actually happens now, although the GDPR does make provision for stuff like this!

 

Make sure you read your data protection and ict use policies. What's your role in school? I'd also make sure you know your breach management plan if you're in the ICT team.

Posted
@Nausing - let us know how you got on today with the visit

Feedback from the meeting:

 

Ok.. there was definitely no need to panic.. the meeting was scheduled for 30 minutes but lasted just over an hour.

 

Questions included:

What is your password policy and do you have a minimum requirement for password complexity?

Do you allow USB storage devices and why do you?

Are you mobile devices encrypted?

Do you enforce pins on your mobile devices such as mobiles and ipads?

Where is your data stored? Is it physically secure?

 

Questions along those lines.. nothing tough that I couldn't answer.

 

The gentleman definitely had recommendations for some of my answers and that was is, recommendations.

 

All good!

  • Thanks 2
Posted

Questions included:

What is your password policy and do you have a minimum requirement for password complexity?

Do you allow USB storage devices and why do you?

Are you mobile devices encrypted?

Do you enforce pins on your mobile devices such as mobiles and ipads?

Where is your data stored? Is it physically secure?

 

Questions along those lines.. nothing tough that I couldn't answer.

 

The gentleman definitely had recommendations for some of my answers and that was is, recommendations.

 

All good!

 

Shouldn't your DPO have already covered the basics like that?

Posted

@Nausing well done

 

Make sure you get sight of the report when it arrives. Be aware that first glance will shock you by the number of their suggestions. However, nearly all will be happening or high on your list and it really will help you focus.

Posted

Did you get the impression the ICO person was reading off a form* or did they understand what they were asking about?

 

*like a lot of auditors I've experienced.

Posted
Shouldn't your DPO have already covered the basics like that?

 

This is exactly what I was thinking. Don't get me wrong.. I really don't mind attending these meetings etc but surely the DPO would already know those answers and the ICO shouldn't need to see me.

 

The good thing for me is I can respond exactly like this to our DPO. He would probably want me there anyway which is fine but again, he should know the answers to these questions without me.

Posted
I didn't just mean in terms of the DPO answering those questions to the ICO, I meant in terms of establishing that kind of thing in the first place. By all means, get the ICO in to advise if you want, but if your DPO is still at the stage of "do we have a password policy?" and "do we allow USBs?", I would question what they have been doing up until now.
Posted
I didn't just mean in terms of the DPO answering those questions to the ICO, I meant in terms of establishing that kind of thing in the first place. By all means, get the ICO in to advise if you want, but if your DPO is still at the stage of "do we have a password policy?" and "do we allow USBs?", I would question what they have been doing up until now.

 

Possibly battling with all the other questions that need looking at ... some DPOs are the equivalent of maybe an hour a week, others have a day ... so they rely on others to get answers to the questions and hand them over ... and that also takes time (get the questions out, get responses, review the responses, panic, calm, panic again, calm again and start asking questions about *WHY*).

Posted
He read his questions from a form, but did have knowledge of what he was talking about.

 

No harm in having a form to read from, it makes sure you ask everything. Especially useful if some of the questions can lead you off to tangents.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...