12 December 2023
The ICO has issued this year’s lessons learned from reprimands they handed out during 2023. To ensure that you avoid the pitfalls other organisations have fallen victim to, the ICO advise these key points for 2023:
it’s very good practice to have Data Protection / Information Security, Acceptable Use, Remote Working and Data Classification and Handling policies in place. And, if you allow staff to use their own devices for work, then a Bring Your Own Device (BYOD) / Mobile Device Policy is also a very good idea. Policy content must always be based on the risk controls identified in your DPIAs / risk assessments and communicated via regularly refreshed staff training.
To ensure an effective approach to Subject Access Requests (SARs) make sure you have a person who is nominated to deal with SARs and that they have had adequate training, so they know how to respond to a requester, how to disclose personal data and have time allocated to respond within the 30 - day time frame. Underpin this process with a documented SAR response procedure.
This simply means that all personal data should be secret by default. So, if you develop applications, websites, databases, software or purchase them for use, they must be risk assessed to make sure they provide robust access controls which are security tested and any vulnerabilities have been identified and patched. Staff who use the software day - to - day must be trained to understand privacy risks and how to avoid them. Enforce data protection rules and training with security policies.
The ICO issue the lessons learned advice with the expectation that organisations will learn and improve based on this information, so if you feel you need further support or additional training days, please let Rebecca know and we can discuss your needs.