Full Metal Jacket…

For many after the historic events in the UK, it may indeed feel necessary to don a metaphorical “full metal jacket” to survive what is an ongoing onslaught of the political landscape. Uncertainty grows and the decision to “Brexit” continues to have ramifications far beyond those that were considered by many, it seems.

Info Sec

Given these uncharted waters, we must look to our principles to steady ourselves. This is never more true than in the security community. Cyber threats continue to escalate, the capacity for intelligent risk analysis (end to end) remains never more relevant. The economic climate may be unstable but the economics of crime remain certain. So it behoves all professionals with responsibilities for both information and technology to arm themselves with a greater understanding of what is required to actually embed secure thinking across their organisations.

That being said, less of the cyber, more of the information view is required. This is not easy, given the legacy, at so many levels, that many are working with. Cyber is the domain in which the greatest threats to our corporate information is being realised. However, risks are coming from all domains – people, process, technology, physical – and now we can add politicians to this list! Professionals know this. Without having full knowledge of your information assets – without knowing what is important to your organisation and what could happen if that information fell into the wrong hands – you are actually running with a level of blindness that in and of itself creates risk(s) and ensures that you are not providing truthful reporting. But – and it’s a big BUT, “Security” is everyone’s responsibility – and everyone needs a LOT more understanding!

There is a US cyber security strategy, an EU one, country specific ones…. So what? It’s not stopping the rot. Corporate businesses are still supporting bad design practices as a result of not allowing the time required to design both safely and securely. Everyone is outsourced to a point of stretch that is unsustainable. In spite of Brexit, we remain full steam ahead on the preparations for the General Data Protection Regulation (GDPR), and with these come a requirement to be able to adopt a “full disclosure” approach to incidents and breaches.

We will also be preparing for adoption of the Network and Information Security (NIS) Directive, which is very much more a directive that operates at a government level but includes a requirement to establish “security and notification requirements for operators of essential services, as well as digital service providers” – with an explanation of who is covered by “essential services”.

Nonetheless, as per the “path to GDPR” picture, what is really required is good project management. In order to achieve the desired outcomes, which will include behaviour change (to deliver “privacy by design”), there is a lot of information required and a lot of understanding across the whole organisation. Security is everyone’s responsibility – and everyone needs a LOT more understanding! Procurement need to understand the implications of the deals being undertaken; so do Legal – and Legal need to not be looking to the Security community to educate them on matters of Information based legislation. Shame on them! Keep up with the law yourselves!

HR need to be much more engaged in helping to discipline badly behaving employees and support the need for showing good security behaviour as being an active element of annual appraisal processes.

IT need to be factoring in safety and security within all change management and future development – not coming to Security right at the end. None of this is rocket science; it’s not new news. Security is a collective. And much like all the rhetoric these past few months, stop believing the hype! The Security industry itself needs to look deep into its soul and reflect on the ethics of selling pipe dreams of layer upon layer of defence over the top of known insecure systems.

There are at least 85 different security tools from 45 different vendors. In an increasing “internet of things” environment, this approach is going to crumble and will embarrass us all. It’s a fallacy to think that we can cure cancer by putting a plaster on it – likewise the continued application of technology to a technology problem cannot be seen to make sense in the abstract!

In conclusion: ensure you know your information asset landscape; ensure you know the impact of the realisation of any threats to those information assets; and stop focussing on just all things “cyber”.

Act Now’s course on Information Risk & Security course runs in London and Manchester in October. See http://www.actnow.org.uk/courses/2015

About the Author

Andrea C Simmons, FBCS CITP, CISM, CISSP, M.Inst.ISP, MA, ISSA Senior Member has more than 17 years’ direct information security, assurance and governance experience. Andrea’s most recent role as Chief Information Security Officer for HP Enterprise Security was one of worldwide influence addressing Security Policy and Risk Governance seeking to support and evidence the delivery of organisational assurance across a wide portfolio of clients and services.

DP and #GDPR after #Brexit

brexit-1477615_1920

For the last six months, Data Protection experts, novices and agnostics have talked of little else but the General Data Protection Regulation, the new version of Data Protection law that will hold sway consistently across the 28 members of the European Union from the 25th May 2018.

Well, about that. 28 now becomes 27, as the United Kingdom has decided on a slim margin to vote ourselves out of the European Union, and sail off into the Atlantic. So what does this mean for the GDPR? Do we wave goodbye to the mandatory Data Protection Officer, the Right to Be Forgotten and the joys of impact assessments?

The short answer is no. The Information Commissioner has already announced that the only way forward for the UK’s creaking Data Protection legislation and its relationship with Europe is UK legislation as close to the GDPR as we can get. Every serious commentator in the Data Protection world (and all the others) are saying the same thing. The consensus is impressive but unsurprising – the redoubtable Max Schrems has proved how much creative mischief can be wrought if a country does not have a sound data protection relationship with the EU. Some of the comments coming out of the EU today make it clear how difficult it will be to achieve that relationship, so the one thing we cannot be certain of is when things will become certain.

Sooner or later, the GDPR or a close relation of it will replace the DPA in the UK. However, it is impossible to say when. Every business that offers services to EU citizens will be caught in limbo from the moment the Regulation goes live in the EU, struggling to balance the DPA in the UK and the GDPR abroad, or just succumbing to the GDPR on the basis that operating the higher GDPR standards will not cause them problems here.

In the meantime, what should organisations do? Our advice – keep your eyes peeled for the timetable for GDPR’s inception here, but look to your DP compliance now.

Consent

Whether you’re UK based or operating across the EU, the version of consent popular in the UK (implied, opt-out, buried in terms and conditions) isn’t consent. The ICO has taken enforcement action under both the DPA and the Privacy Regulations to this effect. Look everywhere that you rely on consent – you need freely given, specific and informed consent.

Fair processing

Linked to this is the issue of privacy policies and fair processing. It’s clear that the ICO does not think that long, legalistic fair processing notices are acceptable, so concentrate on communicating clearly with your customers, clients and service users.

Impact assessments

The difference between the ICO’s code on Privacy Impact Assessments and the Regulation’s requirements on impact assessments are very thin. Although the Regulation’s bold demands for Data Protection by Design (bold but not especially well explained) will only bite when we implement it, the ICO has been advocating for pro-active impact assessments in advance of new projects for a long time. We strongly advise you to look the ICO code now – it’s current good practice (and sometimes the ICO will enforce if you don’t). Moreover, it’s a dry run for the impact assessments and design principles that the GDPR will ultimately require.

Data Processors

Find every contractor and agent that your organisation does business with. Make sure there is a binding legal agreement between you and them. Like other steps we are mentioning here, this is self-preservation for the present as much for the future. If cloud computing is “your data on someone else’s computer”, then processors are “your data in the hands of someone who isn’t covered by the Data Protection Act”. Find them. Get contracts in place. Make sure they’re being followed.

Deletion

The GDPR Right to be Be Forgotten is a different beast to anything that the European courts have created under the current regime, and it is underpinned by a need to delete data from systems that process personal data. It’s well worth looking at how you might delete data and finding out where deletion / overwriting of data is difficult. When the GDPR lands, deletion will be a massive headache, but if you can’t delete now, you can’t comply with the existing Data Protection principle on retention.

Security

Every organisation needs a viable, appropriate, effective and validated security framework. Data Protection compliance under the DPA and the GDPR isn’t about incidents, it’s about effective and verified methods to prevent them, whether technical or organisational. Security isn’t everything that Data Protection is about, but there is no question that the highest penalties will still apply to poor security frameworks. The extra detail in the GDPR about security – especially what good security requires – is essential guidance and well worth implementing.

And that’s definitely not now!

BUT WHAT ABOUT….

Act Now is not predicting when the GDPR will come to the UK. Anyone who predicts confidently when it will arrive is fooling you, or themselves. The GDPR also contains a mandatory Data Protection Officer, mandatory breach notification and a whole lot else besides. It might be that the UK Government acts quickly to bring in legislation to introduce the whole package. However, while we might be confident that the GDPR is on its way, we’re not certain about when. Our advice is to work on the foundations now, and get ready to put the new GDPR structures on top when the timetable is a little clearer.

And that’s definitely not now!

Act Now continues to receive bookings for its GDPR workshops for which new dates and venues have been added. Our Data Protection Practitioner Certificate is ideal for those who want a formal qualification in this area. The syllabus is endorsed by the Centre for Information Rights based at the University of Winchester.

Nationwide breaches of DPA

clip_image002

To leave or to remain. What a difficult question and the citizens of the UK are wrestling daily with this issue under an intense barrage of claim and counter claim.

But sneaking under the radar are hundreds of breaches of Data Protection law some involving thousands or millions of data subjects. Not noticed them? If you work for a large organisation like BT or JCB your boss will have communicated to you that you should vote the way he thinks. He’s not the only one. Large companies are using the email address they hold for payroll purposes to communicate a political message to their staff. Principle 1 says

“Personal data shall be processed fairly and lawfully (and according to a condition from Schedule 2 and/or 3)”

They could look for a justification in Schedule 2 but they’d be better looking in Schedule 3 as political data is sensitive. So consent turns into the slightly more difficult informed consent but which employee ever consents that his data will be used to tell him which way to vote and which employer ever thought he’d need to help his employees with voting. Old faithful Schedule 2 (6) allows

“The processing is necessary for the purposes of legitimate interests pursued by the data controller or by the third party or parties to whom the data are disclosed, except where the processing is unwarranted in any particular case by reason of prejudice to the rights and freedoms or legitimate interests of the data subject.”

Which data subject would accept that political lobbying is warranted with his payroll data and who would ever say that voting recommendations were a legitimate interest of your boss. So all schedules are out of the window. So they can’t do it lawfully and/or fairly. Principle 1 breached.

Principle 2 says

“Personal data shall be obtained only for one or more specified and lawful purposes, and shall not be further processed in any manner incompatible with that purpose or those purposes.”

Specified means in fair processing and notification sent to Commissioner. So if an organisation hasn’t said to its employees that it will use their personal data for pushing a political end they can’t do it. Principle 2 breached.

It may be that these companies are stretching the definition of personnel & payroll to include ‘what might happen to your pay if we left the EU’ but it’s quite a long stretch. It may end up with someone in authority making a judgement one day. But time is short and it’s unlikely anyone will be interested after the polling stations close.

And these employers trying to influence people’s opinions or beliefs drops into the ICO definition of direct marketing.

clip_image004

Quite a few of these fit neatly with the leave/remain issue. If employers are doing it by electronic means then PECR applies. You could argue that a corporate email address isn’t personal data but there are plenty who will argue that it is. (But PECR’s only concerned with subscribers isn’t it?)

Further afield European businessmen are trying to help us make up our mind as well.

An email sent to a few million people recently (all the people who’ve ever flown with Ryanair) was brazenly labelled Brexit Special. Even with a public service announcement thrown in it clearly used email addresses collected for administration of air travel to influence voting intentions.

clip_image006

So there’s a possibility that millions of data subjects are having their rights infringed and Breaches of the DPA are legion. Captains of industry could argue that it’s their personal view to leave/remain not the corporate body that holds the payroll data but that just opens up another can of worms doesn’t it. We may get as far as a criminal offence of procuring or unauthorised obtaining if the boss uses the company data for a personal purpose.

At least it’s only a few breaches of the Data Protection Act. It could be worse – they could be lying to us.

It’ll all be forgotten on Friday morning. (Until the next referendum)

Act Now can help you prepare for the Regulation. Our one day GDPR workshops are ideal for those wanting to get a headstart in their preparations.

To Brexit or not to Brexit…

canstockphoto35750834

 

 

 

 

 

 

 

 

 

That is the question on everyone’s lips right now. With the EU referendum looming, the next big question is, How will the GDPR affect us should we decide to leave the EU? The majority opinion is that we will be definitely affected in some way or other by the regulation and most likely will have to adopt all of it, maybe in a slower timeframe… But there’s no escaping it!

There’s three likely outcomes should we leave the EU…

  1. We remain in the European free trade association or Economic area (EEA) of the EU similar to Norway in which case we would then be subjected to GDPR, in order to trade with the EU
  1. We leave all trade agreements and become similar to the USA – a ‘safe third country’, in which case we would have to have a suitable level of DP Regulation which for all intents and purposes will be the GDPR
  1. We completely go solo like Geri Halliwell, Robbie Williams, Zayn Malik…okay i’ll stop. Even in this scenario, we would have to make our own singles, do our own world tours… sorry, i mean have our own equivalent GDPR, or update our existing one and where better to find one? (I can sense a Blue Peter moment coming on…)

So in short… and forgive me for my Hunger Games level of enthusiasm of being selected in the games, but GDPR is coming one way or the another…The Real Question is… Are You Ready?

Let the Games Begin!

 

Act Now can Help you prepare for the regulation. We have full day courses on the regulation as well as courses available online. Please visit our website here to find out more.

 

 

New Local Government Transparency Code Consultation

canstockphoto14367173

The Local Government Transparency Code is due to be updated once again to require local authorities to proactively publish even more information. The Department for Communities and Local Government is consulting on proposals to require councils to publish:

  • more information about land and property assets they hold on the Government’s electronic Property Information Management System
  • existing procurement publication in particular forms
  • the costs of “in-house” service contracts above £500k
  • greater detail about parking charges as well as statistics about the enforcement of parking restrictions
  • information about dealings with small and medium-sized enterprises
  • all information under the Code through a single website landing page

The Code is made under Section 3 of the Local Government, Planning and Land Act 1980 which gives the Secretary of State the power to issue a code of practice about the publication of information by local authorities in England (as well as, amongst others, National Park Authorities, Fire and Waste Authorities and Integrated Transport Authorities) relating to the discharge of their functions.

In February 2015 the code was re issued to require local authorities to publish information about their social housing stock.  Smaller councils, including parish councils have to comply with the Transparency Code for Smaller Authorities, which was published in December 2014.

The consultation began on 12th May 2016. All responses should be received by no later than 8th July 2016.

Give your career a boost by gaining an internationally recognised qualification in FOI. No time/budget to attend courses? Keep up to date with all the latest FOI decisions by viewing our live one-hour web seminars

New IRMS Certificate in Information Governance


Page 1

 

Today, the Information and Records Management Society (IRMS) and Act Now Training launched the IRMS Foundation Certificate in Information Governance. This represents the first fully online certificated course covering data protection, freedom of information and records management.

In difficult economic times, traditional face-to-face learning is often the first activity to fall victim of budget cuts. However the area of Information Governance is currently the subject of rapid change. After four years of negotiation, the new EU General Data Protection Regulation (GDPR) has now been formally adopted by the European Parliament and will come into force on 25th May 2018.  The FOI Commission’s report, published in March, will lead to additional obligations for public authorities under the Freedom of Information Act. And the list goes on…

Employees and managers, both in the public and private sector, need timely and cost effective IG training.  The IRMS Foundation Certificate in Information Governance is the solution. This is an online certificated course designed for information management professionals who need to know about the basics of information rights and information management in their job role. It is an ideal starter qualification for those who wish to then progress to more advanced qualifications such as the as our Practitioner Certificate In Data Protection and the BCS FOI and DP Certificates.

Launched at the 2016 IRMS conference in Brighton, the IRMS Foundation Certificate in Information Governance is a fully online yet interactive course. There are four learning modules (Records Management, Security and Information Assurance, Data Protection and Freedom of Information). Using the latest web based technology, delegates will be able to learn from the comfort of their own desk by attending four live online webinars. In addition they will be able to tailor their learning through doing four recorded modules from a choice of six. Finally they will do a short online assessment to achieve the certificate endorsed by the excellent reputation of the IRMS.

Ibrahim Hasan, Director of Act Now Training, has developed the course with IRMS colleagues. He said:

“I am really pleased to have been involved with the development of this ground breaking new online qualification. I have used my experience in delivering Information Governance training for many years to help create a product which will hopefully meet a previously unmet demand amongst Information Management professionals.”

Meic Pierce Owen, the Chair of the IRMS said:

“I am genuinely proud to have overseen the development of this important qualification that offers all information professionals the opportunity to gain a solid grounding in contemporary Information Governance (IG). This qualification has relevance across all sectors and is equally valid for those looking to master the basics of contemporary IG as it is for those looking to progress to practitioner level study.

As a generalist practitioner who qualified from University just ahead of Data Protection, Freedom of Information and Information Security being covered in any detail on the courses, I am also delighted to put my money where my mouth is and be the first to sign up to study for this qualification- which I believe to be relevant to my CPD as well as being excellent value for money. I shall let you know how I get on…”

If you would like to know more about this exciting new course please visit us at the IRMS stand at the Brighton conference. See also our dedicated IRMS Certificate webpages or get in touch.

Be an Information Superhero and gain a Superhero Qualification!

 

 

25th May 2018: D-day For Data Protection (GDPR)

canstockphoto30465718

Following its formal adoption by the European Parliament in April, the General Data Protection Regulation (GDPR) was published on 4th May 2016 in the Official Journal. This means that it will be directly applicable throughout the EU (without the need for implementing legislation) from 25th May 2018.

Data Controllers now have two years to prepare for the biggest change to the EU data protection regime in 20 years.  With some breaches of the Regulation carrying fines of up to 4% of global annual turnover or 20 million Euros, everyone has to take Data Protection seriously.

 All Data Protection practitioners and lawyers need to read the Regulation and consider its impact on their organisation and clients. Act Now has a series of blog posts as well as a dedicated GDPR section on its website with articles on the different aspects of the Regulation.

Training and awareness at all levels needs to start now. We are running a series of GDPR webinars and workshops. Five out of eight of the next GDPR workshops are fully booked. We have also started running workshops on specific aspects of the Regulation e.g. Information Risk and Security.

Our team of experts is available to come to your organisation to deliver customised data protection/GDPR workshops as well as to carry out health checks and audits.

If you are looking for an up to date DP qualification with a focus on GDPR, have a look at our Data Protection Practitioner Certificate.

The next two years need to be spent wisely. Act Now can help you prepare for the Regulation in the most cost effective manner whilst also ensuring you and your organisation are fully prepared.

Last week my Dad died…

 FullSizeRender

 I have spent four years at university, have gained two degrees and many years of experience of practicing and teaching law; yet the principles upon which I base my life were taught to me by a former taxi driver and mill worker from a poor farming village in India. He died last Tuesday.

My dad, Ismail Muhammad Hasan, was born in Gujarat in India in 1949. Like many a young man of his generation, he came to the UK in the 60’s having been encouraged by the UK government to come and fill positions in the transport and textile industries. Dad arrived in 1969, at the age of twenty, and went straight to work in the factories of West Yorkshire. His aim was not just to make a new life for himself but also to support his elderly parents who were struggling to make ends meet by farming and running a small village shop.

Dad failed Norman Tebbit’s Cricket Test and would not have been able to spell “British Values” let alone name one of them. Yet his personal values and character reflected everything we are proud of in this country; hard work, kindness, honesty, decency and a sense of humour.

Dad chose a life of hard work and sacrifice and encouraged us to do the same. I remember asking him why I did not receive free school meals. His answer was:

“It’s better to eat what you buy with hard earned money.”

Through out his working life Dad often held two jobs. By day he worked in a factory and by night and weekends as a taxi driver. As one of the most experienced taxi drivers in Dewsbury, he was known and loved by many drivers as witnessed by their attendance at his funeral. Even after his retirement he continued to keep in touch with colleagues and offer his advice and support (whether they requested it or not!).

It was not easy being a taxi driver in the 70’s and 80’s. So often Dad would come home with a black eye, a bruised arm or a sad face, having been deprived of his night’s earnings by those who saw taxi drivers as easy targets. Racist abuse and attacks on taxi drivers were very common in those days.

Despite these difficult conditions, Dad went about his business with a smile and concern for all. He would always greet his English customers and factory colleagues by raising his hand and addressing them as “my friend.” He was always willing to lend his emotional and practical support to anyone in need regardless of race and religion. So often he would waive the taxi fare for customers who were old or infirm.

Dad came from a family of farmers and had little formal education. Yet he was really determined to ensure that his five children educated themselves to the highest level. In my youth he would discourage me from taking a part time job, even during the holidays, saying:

“Concentrate on your studies now; you have your whole life to work.”

He borrowed money from friends and family to ensure that I completed my professional exams (the Legal Practice Course) and qualified as a solicitor.

Despite suffering straitened financial circumstances for much of his early family life, Dad was an exemplary father. He was a “modern dad” before the term had been coined. He understood the importance of quality family time. For us this meant regular trips to the Blackpool Illuminations, Scarborough, Knowsley Safari Park and even the odd impromptu picnic at Dewsbury Park complete with chapattis and cold chicken curry. Much to the envy of my friends, we were regular visitors to the curry houses of Bradford. Christmas was always a high point in the year as we looked forward to his factory Christmas party when, courtesy of generous factory bosses, the old toy dumper track would be replaced with a shiny new one.

Dad understood well that Islam is all about love, kindness and generosity to all; Muslims and non-Muslims alike. He believed in the importance of integration but at the same time holding on to his Islamic practices and beliefs. We were the first family to move away from our mainly Muslim neighborhood to one which was predominantly white and middle class. We have happily lived there for the past 30 years. Until his latest bout of ill health, the few remaining elderly English neighbours would often get a visit from Dad enquiring about their health and well being. When some of them entered residential homes or hospital he would regularly visit them. Dad lived the saying of the Prophet Muhammad (PBUH):

“The best amongst you is the one who is most beneficial to others.”

Dad is survived by three sons and two daughters (as well as thirteen grandchildren) all of whom are successful in their own right. All owe everything to a man who came to this country over 45 years ago with nothing. Over 500 people attended Dad’s funeral with many more visiting the family home to pay their respects. Messages of support and sympathy have been received from all over the world.

As a family, we are grateful to friends, relatives, neighbours and well-wishers for their prayers and support during a difficult few days. We would also like to thank the brilliant staff at Pindersfields Hospital Stroke Unit for the wonderful care and support Dad received during his final days.

Despite my great loss, I am happy that I shared 44 years with such a wonderful human being and that his departure from this temporary abode was exactly the way he wanted; surrounded by his family, the Muslim attestation of faith (Kalimah) on his lips and a big smile on his face!

New Information Commissioner Approved

On Wednesday 27 April 2016, The Culture Media and Sport Committee approved the appointment of Elizabeth Denham as the new UK Information Commissioner following a pre-appointment hearing.

Ms Denham has held the role of Information and Privacy Commissioner in British Columbia since 2010. Prior to that she served as Assistant Privacy Commissioner of Canada for three years (Full CV here).

Jesse Norman MP, Chair of the Committee, said:

“The Committee noted with interest Ms Denham’s views on a range of topics, including the possible retention of emails as official records, the extension of FOI and directors’ liability for data breaches, in particular.

We also noted Ms Denham’s track record on data protection wit Government in British Columbia, and her proactive approach to protection of privacy with major international technology companies.”

Subject to final approval from Her Majesty The Queen, Ms Denham will take over from incumbent Christopher Graham in summer 2016. Mr Graham said:

“I am delighted that Elizabeth Denham is set to take over as the next Information Commissioner. Elizabeth is an experienced information rights practitioner, essential when the ICO is busier than ever and facing the challenges of the digital age.”

Denham will have to hit the ground running when she starts. She will have just two years to ensure that UK Data Controllers are adequately prepared for the new EU General Data Protection Regulation (GDPR), which represents the biggest change to the EU data protection regime in 20 years.

She will also have to help public authorities implement any changes the Government may make to the Freedom of Information regime as a result of the FOI Commission’s recent report.

The school that ticked the box

checklist-443126

Now and again as a trainer you know that someone is ticking a box. This happened to an Act Now trainer recently.

A meeting is held in a school somewhere in the heart of England and someone chirps up “Let’s get some Data Protection Training in school. Er.. Madge can you sort something out?  Super.” Madge has no knowledge of information law. She might be the secretary; she might be the playground supervisor but she’s been told to get on with it.

Weeks later Madge does some research on the internet; finds a company that does this and books some online training; a date is agreed and everything seems fine. Madge has opted for online training lasting an hour for a dozen or so admin staff even though for the same price she could have a real expert come to her site and give the school a 3 hour master class in DP (and throw in FOI & EIR for free).

But as the trainer asked to deliver this online training something doesn’t seem right.  You email the contact person to introduce yourself and ask for some steer on what they want and you’re met with a wall of silence. Time passes – no contact. Eventually a phone call elicits the information that they just want a general session on DP.

“How about FOI?” suggests the trainer helpfully.

“No we don’t need that.”

The trainer pulls together a general presentation and places a copy of the delegate materials in the online area alongside the link to access the training on the day where such things are held and informs the school.

Time passes.

The day before the training the school rings Act Now Office and asks how do they access the training. We refer them to the email sent a month previously. A flurry of questions are asked and answered and things finally look ready for the following day.

We start the training, Several people with young sounding names are present. They listen without saying anything. They don’t comment on the fact that their notification was a month late for renewal. They don’t find the lack of a privacy policy remarkable (despite the fact that they have a very handy Snow and Ice Policy in their list of 20 school policies). Their prospectus says nothing about any information law or rights of individuals to access information held by the school. The mini case studies towards the end are all met with the response “We’ll ask the head”. The FOI request sent to the school 6 weeks ago was denied. “No we’ve never seen it” (even though they are shown the actual email on screen).  There are no questions at all.

After 75 minutes they say thank you and leave. The automated feedback email isn’t returned. It’s as if the training session has become lost in a Sleepy Hollow style black hole.

6 weeks later the trainer has a look for their notification on the ICO site. It’s not there. The school is not listed on the Search The Register database. Presumably they let their notification lapse. The school’s website still doesn’t have a privacy policy, a data protection policy or any mention of freedom of information. Searches on the school website return nothing at all to show they have any idea about information law.

The trainer has an attack of conscience. Maybe Madge organized the training, paid the bill and ticked the box. Maybe an SMT meeting receives a note saying DP training has been done. Maybe no-one in a senior position knows how bad things are.  Should the trainer call the school and talk to senior management (if in fact he can get through to them) and say that they’re wide open to a notice being issued (and published on the web) or a prying parent with a grievance exposing their lack of compliance.

But schools like this are rare aren’t they? Schools have heard of DP and FOI and do have policies and procedures and notifications in place don’t they? Don’t they? DON’T THEY?

Are you responsible for schools and their compliance with information law? Do you know if they are aware of information law or how they are complying with it? Act Now offers online training for schools in DP & FOI and have delivered many on site half day workshops covering the subjects at schools all over the UK. Contact us to find out more. Don’t let your schools just tick a box (badly).

The new EU General Data Protection Regulation (GDPR) has now been approved and will come into force in two years time. Everyone, including schools, need to prepare now.