Best Practice Update

Photo of a person's arm and putting a letter in the post box.  Data Protection Education logo on the bottom right of the image

We've recently had more than one breach reported where physical files have got lost in the post.

In such cases, the sender remains the data controller and is responsible for ensuring that the optimum data security measures are in place during transfer. Where possible, consider whether a physical drop-off (and get a receipt) is a more secure option.

computer keyboard with due diligence on a blue key

Adapted from: The Irish Data Protection Commissioner

The UK GDPR does not prescribe the exact process for carrying out a DPIA beyond the minimum features outlined above, allowing for flexibility and scalability in line with your organisation’s needs. Although there is no one prescribed approach to take, the following steps can guide you through the process:

Navy cie with an envelope, one with a phone symbol on with @ above a hand. Data protection education logo at the top

The Data Protection Officer (DPO) can provide support in many areas but are you aware of what we do help with?

There are some more well-known areas of data protection that we would be called upon to advise such as subject access requests and breaches but DPO’s don’t only provide advice and support when things go wrong,

Search