Issue - meetings

Data Protection (Information Security) action plan – annual governance report

Meeting: 12/07/2016 - Corporate Business Scrutiny Committee (Item 140)

140 Data Protection Annual Review pdf icon PDF 156 KB

Additional documents:

Minutes:

The Head of Legal and Democratic Services submitted a report that updated the Committee on the Shared Internal Audit Service (SIAS) report on data protection.  The Digital and Information Manager invited Members to comment on the current Data Protection status and to agree that future scrutiny and monitoring of the Council’s Data Protection risks would be best conducted through Covalent (the Council’s performance management system) and the quarterly performance reports.

 

Members were advised of the 3 data protection breaches that were detailed in the report, none of which had attracted any action from the Information Commissioner’s Office.  The Committee was advised that the Shared Internal Audit Service (SIAS) report had not made any recommendations for improvement.

 

The Digital and Information Manager responded to concerns from Councillor M Casey regarding the data protection breaches by advising that the Office of the Information Commissioner (ICO) was satisfied that the data protection protocols of the Authority were sufficiently robust.  Members were advised that whilst any breach was regrettable, they could occur due to human error.

 

The Chairman and the Officer responded to a number of other minor queries from the Committee regarding the inclusion of data protection reviews in the monthly corporate performance report.  Members received the report and approved the recommendations now detailed.

 

RESOLVED – that (A) the actions and developments in regard to data protection compliance be noted; and

 

(B)   the ongoing scrutiny and oversight of data protection compliance via the quarterly performance report and use of the Covalent system be agreed.