Nausing Posted August 3, 2018 Posted August 3, 2018 Hi all, I've just been told by my COO that the Information Commissioner's Office is visiting on Monday and will probably want to speak to me about handling data protection. Is there anything I should know/say or prepare for? Thanks.
tj2419 Posted August 3, 2018 Posted August 3, 2018 What has prompted the visit? Or what are they wanting to achieve? Has there been an incident reported to the ICO for data loss etc? If so I would make sure I know what we could do to prevent it happening again. Prove that you are reviewing and improving practice. If it is just a random visit it would be the DPO surely that would need to answer questions. I'd just make sure I knew what our policies were and that's about all you should be expected to know.
Nausing Posted August 3, 2018 Author Posted August 3, 2018 What has prompted the visit? Or what are they wanting to achieve? Has there been an incident reported to the ICO for data loss etc? If so I would make sure I know what we could do to prevent it happening again. Prove that you are reviewing and improving practice. If it is just a random visit it would be the DPO surely that would need to answer questions. I'd just make sure I knew what our policies were and that's about all you should be expected to know. It is a random visit and the DPO is managing the visit. Can't help but be anxious!
elsiegee40 Posted August 3, 2018 Posted August 3, 2018 I am surprised the ICO has time for random visits! @jenatddm @GrumbleDook @maturelady?
djrscally Posted August 3, 2018 Posted August 3, 2018 Mildly terrified that this actually happens now, although the GDPR does make provision for stuff like this! Make sure you read your data protection and ict use policies. What's your role in school? I'd also make sure you know your breach management plan if you're in the ICT team.
jdoyle Posted August 3, 2018 Posted August 3, 2018 Doesn't sound like an audit but might be worth a quick read : https://ico.org.uk/media/for-organisations/documents/2787/guide-to-data-protection-audits.pdf with the following line in mind "Audits are intended to be educative and not punitive"
Popular Post maturelady Posted August 3, 2018 Popular Post Posted August 3, 2018 Stop panicking - they are not random visits. I have spoken to ICO and the schools that have had visits and all had contact with the ICO - asking them questions or for advice. ICO does suggest they might visit but the school can say No. Someone has said Yes in your case @Nausing I have been in contact with 1 school through the whole process from notification, completing the pre-visit questionnaire through to the final report. I am currently putting together a document to show the experience of this school. The visit focuses on best practice. ICO will probably find things wrong but you can learn from it. I'll share what I have learned as soon as its finished 5
enjay Posted August 6, 2018 Posted August 6, 2018 I am surprised the ICO has time for random visits! @jenatddm @GrumbleDook @maturelady? I wondered that, then noticed the OP refers to his "COO" so is probably not in a school... 1
maturelady Posted August 6, 2018 Posted August 6, 2018 @Nausing - let us know how you got on today with the visit
Nausing Posted August 8, 2018 Author Posted August 8, 2018 @Nausing - let us know how you got on today with the visit Feedback from the meeting: Ok.. there was definitely no need to panic.. the meeting was scheduled for 30 minutes but lasted just over an hour. Questions included: What is your password policy and do you have a minimum requirement for password complexity? Do you allow USB storage devices and why do you? Are you mobile devices encrypted? Do you enforce pins on your mobile devices such as mobiles and ipads? Where is your data stored? Is it physically secure? Questions along those lines.. nothing tough that I couldn't answer. The gentleman definitely had recommendations for some of my answers and that was is, recommendations. All good! 2
enjay Posted August 8, 2018 Posted August 8, 2018 Questions included: What is your password policy and do you have a minimum requirement for password complexity? Do you allow USB storage devices and why do you? Are you mobile devices encrypted? Do you enforce pins on your mobile devices such as mobiles and ipads? Where is your data stored? Is it physically secure? Questions along those lines.. nothing tough that I couldn't answer. The gentleman definitely had recommendations for some of my answers and that was is, recommendations. All good! Shouldn't your DPO have already covered the basics like that?
maturelady Posted August 8, 2018 Posted August 8, 2018 @Nausing well done Make sure you get sight of the report when it arrives. Be aware that first glance will shock you by the number of their suggestions. However, nearly all will be happening or high on your list and it really will help you focus.
pete Posted August 8, 2018 Posted August 8, 2018 Did you get the impression the ICO person was reading off a form* or did they understand what they were asking about? *like a lot of auditors I've experienced.
mthomas08 Posted August 9, 2018 Posted August 9, 2018 Shouldn't your DPO have already covered the basics like that? This is exactly what I was thinking. Don't get me wrong.. I really don't mind attending these meetings etc but surely the DPO would already know those answers and the ICO shouldn't need to see me. The good thing for me is I can respond exactly like this to our DPO. He would probably want me there anyway which is fine but again, he should know the answers to these questions without me.
enjay Posted August 9, 2018 Posted August 9, 2018 I didn't just mean in terms of the DPO answering those questions to the ICO, I meant in terms of establishing that kind of thing in the first place. By all means, get the ICO in to advise if you want, but if your DPO is still at the stage of "do we have a password policy?" and "do we allow USBs?", I would question what they have been doing up until now.
GrumbleDook Posted August 9, 2018 Posted August 9, 2018 I didn't just mean in terms of the DPO answering those questions to the ICO, I meant in terms of establishing that kind of thing in the first place. By all means, get the ICO in to advise if you want, but if your DPO is still at the stage of "do we have a password policy?" and "do we allow USBs?", I would question what they have been doing up until now. Possibly battling with all the other questions that need looking at ... some DPOs are the equivalent of maybe an hour a week, others have a day ... so they rely on others to get answers to the questions and hand them over ... and that also takes time (get the questions out, get responses, review the responses, panic, calm, panic again, calm again and start asking questions about *WHY*).
Nausing Posted August 10, 2018 Author Posted August 10, 2018 He read his questions from a form, but did have knowledge of what he was talking about.
enjay Posted August 10, 2018 Posted August 10, 2018 He read his questions from a form, but did have knowledge of what he was talking about. No harm in having a form to read from, it makes sure you ask everything. Especially useful if some of the questions can lead you off to tangents.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now