ICO lessons learned in 2023

What can you learn from the ICO's reprimands in 2023?

The ICO has issued this year’s lessons learned from reprimands they handed out during 2023. To ensure that you avoid the pitfalls other organisations have fallen victim to, the ICO advise these key points for 2023:

Avoid inappropriate disclosure of personal information by having policies in place and training your staff.

it’s very good practice to have Data Protection / Information Security, Acceptable Use, Remote Working and Data Classification and Handling policies in place. And, if you allow staff to use their own devices for work, then a Bring Your Own Device (BYOD) / Mobile Device Policy is also a very good idea. Policy content must always be based on the risk controls identified in your DPIAs / risk assessments and communicated via regularly refreshed staff training.

Respond to information requests on time.

To ensure an effective approach to Subject Access Requests (SARs) make sure you have a person who is nominated to deal with SARs and that they have had adequate training, so they know how to respond to a requester, how to disclose personal data and have time allocated to respond within the 30 - day time frame. Underpin this process with a documented SAR response procedure.

Implement a data protection by design and default approach.

This simply means that all personal data should be secret by default. So, if you develop applications, websites, databases, software or purchase them for use, they must be risk assessed to make sure they provide robust access controls which are security tested and any vulnerabilities have been identified and patched. Staff who use the software day - to - day must be trained to understand privacy risks and how to avoid them. Enforce data protection rules and training with security policies.

The ICO issue the lessons learned advice with the expectation that organisations will learn and improve based on this information, so if you feel you need further support or additional training days, please let Rebecca know and we can discuss your needs.

Get the latest news from Strident

6 Steps for Sorted IT

ISO & Data Protection