Quality improvement method

Using internal evidence to strengthen personal data governance

Quality Improvement Methods

A controlled method for personal data governance is set out through cause analysis, assigned responsibility, outcome measures and closure evidence.

In examining using internal evidence to strengthen personal data governance, for the corrective action, the purpose of an improvement method is not to produce an action plan; it is to change a material condition and verify that the change is sustained.

In examining using internal evidence to strengthen personal data governance, for the matter, the instrument should be used to identify the intended direction, the actors addressed and the implementation measures that remain necessary.

In examining using internal evidence to strengthen personal data governance, for personal data governance, the General Data Protection Regulation was adopted in April 2016 and is to apply from 25 May 2018. It establishes principles including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. Education providers preparing for implementation should identify personal-data purposes, legal bases, individual rights, supplier arrangements, retention and security, particularly where data influence learner decisions.

Application to personal data governance

In the context of personal data governance, the intended substantive result should remain the starting point for review.

In examining using internal evidence to strengthen personal data governance, review of the corrective action should follow a stated and reproducible method.

The principal risks in relation to the intended improvement are inaccurate data affecting decisions, retention beyond an identified need, secondary use without adequate authority, and uncontrolled supplier access or transfer. Across the defined scope, the relationship between the risks is material: one failed safeguard may remove the evidence needed to activate another.

Controls for personal data governance

For internal evidence to strengthen personal data governance, the most relevant material is likely to include supplier and transfer arrangements, data-quality and correction controls, lawful authority and consent records where relevant, and a register of information assets and purposes.

The assurance record for corrective action should retain the date of the evidence, the source responsible for it, the scope examined and the version of any instrument or definition applied. For personal data governance, traceable source and version information allow genuine improvement to be distinguished from administrative revision.

  • Minimise collection before it is relied on for a decision with material effect.
  • Provide accessible correction and complaint routes before it is relied on for a decision with material effect.
  • Test incident and recovery arrangements.
  • Control third-party processing.
  • Verify accuracy where information affects learners.

Review of personal data governance

Implementation of internal evidence to strengthen personal data governance should be organised around a decision that can be tested. Review of using internal evidence to strengthen personal data governance should give particular attention to adverse cases, unequal effects and errors that learners may be unable to identify or remedy after the event.

Authorities and providers reviewing corrective action should proceed in a defined sequence. For personal data governance, the reviewer should map the complete process, identify the intended result and responsible authority at each stage, and test normal cases together with exceptions. When examining personal data governance, results should distinguish a single case from evidence of a wider control weakness.

For decisions concerning personal data governance, the improvement record for personal data governance should contain the verified problem, affected scope, immediate containment, causal analysis, selected intervention, accountable owner, resources, milestones and effectiveness measure. Oversight bodies should receive a clear account of residual risk and action that remains incomplete.

Implications for personal data governance

Interpretation of internal evidence to strengthen personal data governance should avoid two errors: treating a formal commitment as proof of effect, and treating one adverse case as proof that every part of the system has failed.

No individual measure is sufficient to establish effective operation of corrective action across the affected scope.