Standards interpretation

Personal data governance: defining responsibilities and exclusions

Standards Interpretation

Controls for personal data governance are examined from initial evidence through exceptions, decision authority and continuing assurance.

In examining personal data governance: defining responsibilities and exclusions, for personal data governance, the General Data Protection Regulation was adopted in April 2016 and is to apply from 25 May 2018. It establishes principles including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. Education providers preparing for implementation should identify personal-data purposes, legal bases, individual rights, supplier arrangements, retention and security, particularly where data influence learner decisions.

In the context of personal data governance, Implementation should be organised around a decision that can be tested.

Application to personal data governance

For decisions concerning personal data governance, the General Data Protection Regulation adopted in April 2016 provides a policy reference for personal data governance.

For the matter, the public interest is not confined to institutional compliance. In the context of personal data governance, education information should be collected for a defined purpose, protected in proportion to its sensitivity and retained only for an authorised period.

  • Control third-party processing, with responsibility, scope and timing recorded.
  • Limit and review access.
  • Minimise collection.
  • Verify accuracy where information affects learners.
  • Test incident and recovery arrangements.

Controls for personal data governance

For the applicable requirement, scope should identify the people, decisions, services, locations and periods to which the arrangement applies. Exclusions require an objective reason and should not be inferred from organisational custom or the absence of an earlier complaint.

Risk assessment should give particular attention to uncontrolled supplier access or transfer, collection without a defined educational or legal purpose, and secondary use without adequate authority. A provider should also consider inaccurate data affecting decisions and retention beyond an identified need. For personal data governance, the control response should reflect whether an affected learner can identify the error and obtain an effective remedy in time.

The evidential record for the matter should permit a reviewer to trace the matter from decision to outcome. This may require incident response and notification records, supplier and transfer arrangements, data-quality and correction controls, and retention and secure disposal evidence, supported by role-based access and access reviews and lawful authority and consent records where relevant. Across the defined scope, further cases should be examined when the initial sample does not represent the affected scope or confirm sustained correction.

  • Who can authorise an exclusion?
  • Which learners and services are included?
  • How are changes in scope detected?
  • Does the same outcome apply across delivery modes?
  • Where does responsibility transfer?

Review of personal data governance

A competent review of the control should begin with the intended public or educational outcome, map every activity capable of affecting that outcome, and record where responsibility passes between functions or organisations. Test boundary cases before confirming the scope.

The final record on the conclusion should identify the applicable expectation, the relevant scope, the evidence examined, the sampling basis, material exceptions and the reason for the conclusion. The approving record should explain how an alternative approach satisfies the governing requirement.

Proportionality in relation to the matter does not mean reduced protection for learners exposed to greater risk. In the context of personal data governance, security, privacy and data quality are related but distinct.

When examining personal data governance, a traceable record enables responsibility to be established and errors to be corrected fairly. For the matter, the responsible body should be able to identify the evidence considered, the judgement made, the person or body authorised to make it and the action that followed.

A complete conclusion on the applicable requirement requires evidence extending beyond an individual measure or safeguard.