{"schema_version":"ICEQC_NEWS_ARTICLE_V1","id":"iceqc-news-a04ea60326eb113b","slug":"2016-04-27-documenting-implementation-of-personal-data-governance","language":"en","publication_status":"READY_FOR_IMPORT","publication_date":"2016-04-27","last_modified_date":"2016-04-27","title":"Documenting implementation of personal data governance","summary":"Sets out the scope, decision criteria and evidential basis relevant to documenting implementation of personal data governance, including the treatment of material limitations.","category":{"code":"STANDARDS_INTERPRETATION","label":"Standards Interpretation"},"article_type":"Standards interpretation","publisher":"International Council for Education Quality Certification (ICEQC)","jurisdictional_scope":"International","historical_reference_basis":"General Data Protection Regulation adopted in April 2016","reference_authority":"European Union institutions and relevant national authorities","sections":[{"heading":null,"paragraphs":["The immediate international context is the General Data Protection Regulation adopted in April 2016. Its significance for personal data governance lies in the quality of implementation rather than in formal acknowledgement alone. For the issue under review, interpretation should begin with the intended outcome, then identify the controls and evidence needed to show that the outcome is achieved across the declared scope."]},{"heading":"Applicable scope","paragraphs":["The instrument identified by the General Data Protection Regulation adopted in April 2016 provides a formal policy reference for personal data governance. In relation to documenting implementation of personal data governance, this distinction protects learners from overstated claims and enables providers to plan against a defined obligation.","The General Data Protection Regulation was adopted in April 2016 and is to apply from 25 May 2018. It establishes principles including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. Education providers preparing for implementation should identify personal-data purposes, legal bases, individual rights, supplier arrangements, retention and security, particularly where data influence learner decisions.","Responsibility for the relevant requirement should be visible at the point where consequential decisions are made. The analysis of the relevant requirement proceeds on the basis that a provider should be able to trace the expectation from approved policy through implementation, monitoring, identified exceptions and corrective action. Escalation should follow whenever the available record cannot support a safe conclusion for the affected learners.","The principal risks in relation to the relevant requirement are retention beyond an identified need, collection without a defined educational or legal purpose, excessive access to learner information, and inaccurate data affecting decisions. A weakness in one part of the control environment may obscure a related failure elsewhere. In relation to documenting implementation of personal data governance, review should follow the sequence of decisions and records rather than assess documents in isolation.","The technical issue within the issue under review concerns the basis on which a conclusion is reached. Oversight of the control should reflect the principle that a reliable record should identify what occurred, when it occurred, who was responsible, the authority for the action and any later correction. Records should remain protected against unauthorised alteration while legitimate amendments remain visible. The judgement should state its supporting evidence and any condition limiting application to the declared scope.","Evidence should be selected against a clearly defined question. For the control, the most relevant material is likely to include lawful authority and consent records where relevant, retention and secure disposal evidence, incident response and notification records, and data-quality and correction controls. Confidence is strengthened by corroboration, not by the volume of records drawn from the same underlying source."]},{"heading":"Implementation and evidence","paragraphs":["Proportionality in relation to personal data governance does not mean reduced protection for learners exposed to greater risk. A decision concerning the issue under review should recognise that security, privacy and data quality are related but distinct. A secure record may still be inaccurate or used without adequate authority, and a lawful use may still be poorly governed. In reviewing the control, a prescribed method should not be treated as the only acceptable method where another approach establishes the same outcome with equivalent evidence.","Traceability is necessary for accountable decision-making and fair correction. For the assurance question, the responsible body should be able to identify the evidence considered, the judgement made, the person or body authorised to make it and the action that followed. The record should prevent a later amendment from being treated as if it applied when an earlier decision was made."],"bullets":["Provide accessible correction and complaint routes.","Control third-party processing.","Test incident and recovery arrangements before it is relied on for a decision with material effect.","Assign accountable data owners.","Minimise collection."]},{"heading":"Assessment of conformity","paragraphs":["A proportionate method is available for personal data governance. The method for the control is to specify mandatory fields, source ownership, access rights, retention and correction procedures. Test a sample from creation through use, amendment, reporting and disposal, including records created during disruption or by a delivery partner. The review record should preserve exceptions capable of showing a weakness in design, implementation or coverage.","The final record on the issue under review should identify the applicable expectation, the relevant scope, the evidence examined, the sampling basis, material exceptions and the reason for the conclusion. Departure from an illustrative method may be justified where equivalent outcome and evidence are established. No complete conclusion should be recorded while a material evidential limitation remains."],"bullets":["Are partner records subject to equivalent controls?","Can an amendment be distinguished from the original?","Is the record attributable?","Can records be retrieved throughout the required period?","Are access rights proportionate?"]},{"heading":"Review and corrective action","paragraphs":["Where personal data governance involves partners, suppliers or several public bodies, responsibility should be mapped across the complete service. Agreements should allocate information exchange, incident escalation, learner communication, record custody and corrective authority. Learner safeguards should remain continuous where provision is delivered by several bodies.","The relevant outcome should be capable of direct and consistent explanation. A decision concerning the issue under review should recognise that education information should be collected for a defined purpose, protected in proportion to its sensitivity and retained only for an authorised period. Formal adoption, expenditure and activity do not in themselves establish the intended result. Implementation evidence should be sufficient to identify unequal consequences and assign corrective responsibility.","The appropriate response to the issue under review is therefore one of controlled implementation and review. The objective should be explicit, the evidence proportionate and learner impact visible. Where evidence cannot support assurance, the limitation should be reported and corrective work should remain open."]}],"word_count":925,"content_hash":"sha256-2a61d6bc065d7e6e6bee4ded8b5ef3f596b540a59384e60b5e2136b603d46ae4","seo_keywords":["documenting implementation of personal data governance","education quality standards","education quality","ICEQC"],"schema_type":"TechArticle"}
