Interpretation of implementation of personal data governance identifies scope, evidence, decision authority, material exceptions and continuing review.
Its significance for personal data governance lies in the quality of implementation rather than in formal acknowledgement alone. For the matter, interpretation should begin with the intended outcome, then identify the controls and evidence needed to show that the outcome is achieved across the declared scope.
Application to implementation of personal data governance
For personal data governance, the General Data Protection Regulation adopted in April 2016 provides a policy reference for personal data governance.
When examining personal data governance, the General Data Protection Regulation was adopted in April 2016 and is to apply from 25 May 2018. It establishes principles including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. Education providers preparing for implementation should identify personal-data purposes, legal bases, individual rights, supplier arrangements, retention and security, particularly where data influence learner decisions.
The principal risks in relation to the applicable requirement are retention beyond an identified need, collection without a defined educational or legal purpose, excessive access to learner information, and inaccurate data affecting decisions. Across the defined scope, a weakness in one part of the control environment may obscure a related failure elsewhere. For personal data governance, review should follow the sequence of decisions and records rather than assess documents in isolation.
In the context of personal data governance, records should remain protected against unauthorised alteration while legitimate amendments remain visible.
Evidence concerning personal data governance should be selected against a clearly defined question. For the control, the most relevant material is likely to include lawful authority and consent records where relevant, retention and secure disposal evidence, incident response and notification records, and data-quality and correction controls.
Controls for implementation of personal data governance
Proportionality in relation to personal data governance does not mean reduced protection for learners exposed to greater risk.
For personal data governance, traceability is necessary for accountable decision-making and fair correction. For the conclusion, the responsible body should be able to identify the evidence considered, the judgement made, the person or body authorised to make it and the action that followed. The record for personal data governance should prevent a later amendment from being treated as if it applied when an earlier decision was made.
- Provide accessible correction and complaint routes.
- Control third-party processing.
- Test incident and recovery arrangements before it is relied on for a decision with material effect.
- Assign accountable data owners.
- Minimise collection.
Review of implementation of personal data governance
The method for the control is to specify mandatory fields, source ownership, access rights, retention and correction procedures. For personal data governance, test a sample from creation through use, amendment, reporting and disposal, including records created during disruption or by a delivery partner. Across the defined scope, the review record should preserve exceptions capable of showing a weakness in design, implementation or coverage.
The final record on the matter should identify the applicable expectation, the relevant scope, the evidence examined, the sampling basis, material exceptions and the reason for the conclusion. When examining personal data governance, departure from an illustrative method may be justified where equivalent outcome and evidence are established.
- Are partner records subject to equivalent controls?
- Can an amendment be distinguished from the original?
- Is the record attributable?
- Can records be retrieved throughout the required period?
- Are access rights proportionate?
Implications for implementation of personal data governance
When examining personal data governance, where responsibilities for delivery are shared with partners, suppliers or several public bodies, responsibility should be mapped across the complete service. Agreements governing personal data governance should allocate information exchange, incident escalation, learner communication, record custody and corrective authority. Learner safeguards associated with personal data governance should remain continuous where provision is delivered by several bodies.
In the context of personal data governance, the relevant outcome should be capable of direct and consistent explanation.
The objective for personal data governance should be explicit, the evidence proportionate and learner impact visible. Where evidence concerning personal data governance cannot support assurance, the limitation should be reported and corrective work should remain open.