{"schema_version":"ICEQC_NEWS_ARTICLE_V1","id":"iceqc-news-7b7656f07f915f30","slug":"2016-11-15-using-internal-evidence-to-strengthen-personal-data-governance","language":"en","publication_status":"READY_FOR_IMPORT","publication_date":"2016-11-15","last_modified_date":"2016-11-15","title":"Using internal evidence to strengthen personal data governance","summary":"Describes how improvement in using internal evidence to strengthen personal data governance can be planned, measured and maintained through clear responsibility and follow-up.","category":{"code":"QUALITY_IMPROVEMENT_METHODS","label":"Quality Improvement Methods"},"article_type":"Quality improvement method","publisher":"International Council for Education Quality Certification (ICEQC)","jurisdictional_scope":"International","historical_reference_basis":"General Data Protection Regulation adopted in April 2016","reference_authority":"European Union institutions and relevant national authorities","sections":[{"heading":null,"paragraphs":["The General Data Protection Regulation adopted in April 2016 provides the immediate context for internal evidence to strengthen personal data governance. For the intervention, the purpose of an improvement method is not to produce an action plan; it is to change a material condition and verify that the change is sustained.","The formal status of the General Data Protection Regulation adopted in April 2016 should be preserved in any public account. For the issue under review, the instrument should be used to identify the intended direction, the actors addressed and the implementation measures that remain necessary.","The General Data Protection Regulation was adopted in April 2016 and is to apply from 25 May 2018. It establishes principles including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. Education providers preparing for implementation should identify personal-data purposes, legal bases, individual rights, supplier arrangements, retention and security, particularly where data influence learner decisions."]},{"heading":"Improvement objective and baseline","paragraphs":["In relation to using internal evidence to strengthen personal data governance, the intended substantive result should remain the starting point for review. Oversight of internal evidence to strengthen personal data governance should reflect the principle that education information should be collected for a defined purpose, protected in proportion to its sensitivity and retained only for an authorised period. Inputs and formal commitments should be distinguished from demonstrated operation and outcome. Assurance should address actual effect and provide a means of correcting disadvantage that the arrangement did not intend.","In practical terms, the intervention should be reviewed against a stated method rather than general assurance. The analysis of the practice proceeds on the basis that the subject should be examined as a connected system of policy, people, resources, decisions and evidence. A control framework may fail at its interfaces even where each component appears satisfactory in isolation. Decision-makers should receive an intelligible account of how the result was reached and where it should not be applied.","The principal risks in relation to the improvement objective are inaccurate data affecting decisions, retention beyond an identified need, secondary use without adequate authority, and uncontrolled supplier access or transfer. In relation to using internal evidence to strengthen personal data governance, the relationship between the risks is material: one failed safeguard may remove the evidence needed to activate another."]},{"heading":"Controls and accountable action","paragraphs":["Evidence collection should be designed around the decision question rather than administrative convenience. For internal evidence to strengthen personal data governance, the most relevant material is likely to include supplier and transfer arrangements, data-quality and correction controls, lawful authority and consent records where relevant, and a register of information assets and purposes. Each source has limitations; confidence depends on corroboration between independent records and transparent treatment of uncertainty.","The assurance record for the corrective programme should retain the date of the evidence, the source responsible for it, the scope examined and the version of any instrument or definition applied. Traceable source and version information allow genuine improvement to be distinguished from administrative revision. The evidential history should preserve conclusions that were operative when a material decision was made."],"bullets":["Minimise collection before it is relied on for a decision with material effect.","Provide accessible correction and complaint routes before it is relied on for a decision with material effect.","Test incident and recovery arrangements.","Control third-party processing.","Verify accuracy where information affects learners."]},{"heading":"Evidence of effect","paragraphs":["Implementation of internal evidence to strengthen personal data governance should be organised around a decision that can be tested. Review of using internal evidence to strengthen personal data governance should give particular attention to adverse cases, unequal effects and errors that learners may be unable to identify or remedy after the event. Oversight requires a traceable line from the approved objective through responsible action to evidence of outcome.","For operational review of the corrective programme, authorities and providers should proceed in a defined sequence. For the practice, the reviewer should map the complete process, identify the intended result and responsible authority at each stage, and test normal cases together with exceptions. Results should distinguish a single case from evidence of a wider control weakness.","The improvement record for the practice should contain the verified problem, affected scope, immediate containment, causal analysis, selected intervention, accountable owner, resources, milestones and effectiveness measure. A completed task does not close the matter unless improvement in the relevant condition is established. Oversight bodies should receive a clear account of residual risk and action that remains incomplete.","Accountability for the corrective programme should follow decision-making authority."]},{"heading":"Sustaining improvement","paragraphs":["Interpretation of internal evidence to strengthen personal data governance should avoid two errors: treating a formal commitment as proof of effect, and treating one adverse case as proof that every part of the system has failed. In reviewing the improvement objective, security, privacy and data quality are related but distinct. A secure record may still be inaccurate or used without adequate authority, and a lawful use may still be poorly governed. In reviewing the corrective programme, correcting an individual record does not establish that the process which produced the error has been corrected.","No individual measure is sufficient to establish effective operation of the corrective programme across the affected scope. The final judgement should connect the applicable expectation to implementation and outcomes while identifying unresolved risk."]}],"word_count":869,"content_hash":"sha256-97ad24e72427a309e79d29a5bc3f89db91ba1dd5243720222eaa15ddc4aec7cd","seo_keywords":["using internal evidence to strengthen personal data governance","education quality improvement","education quality","ICEQC"],"schema_type":"TechArticle"}
