{"schema_version":"ICEQC_NEWS_ARTICLE_V1","id":"iceqc-news-c69c47c86622b8f4","slug":"2021-05-21-a-corrective-action-cycle-for-digital-data-protection","language":"en","publication_status":"READY_FOR_IMPORT","publication_date":"2021-05-21","last_modified_date":"2021-05-21","title":"A corrective-action cycle for digital data protection","summary":"Provides an evidence-led method for improving a corrective-action cycle for digital data protection, from definition of the problem to review of effectiveness and residual risk.","category":{"code":"QUALITY_IMPROVEMENT_METHODS","label":"Quality Improvement Methods"},"article_type":"Quality improvement method","publisher":"International Council for Education Quality Certification (ICEQC)","jurisdictional_scope":"International","historical_reference_basis":"Institutional reliance on online systems","reference_authority":"Relevant public authorities and official international sources","sections":[{"heading":null,"paragraphs":["The institutional reliance on online systems provides the immediate reference point for consideration of digital data protection in 2021. The analysis of the improvement objective proceeds on the basis that improvement should begin with a defined problem, a credible account of its causes and a measure capable of showing whether the response has worked. Assessment should focus on the public outcome rather than presume one administrative arrangement."]},{"heading":"Improvement objective and baseline","paragraphs":["The historical reference basis is the institutional reliance on online systems. Its relevance to digital data protection should be assessed against the affected jurisdiction, learner population and form of provision.","Responsibility for the issue under review should be visible at the point where consequential decisions are made. A decision concerning the improvement objective should recognise that follow-up should determine whether the change is embedded in ordinary operations and whether it has created new risks or unequal effects. In relation to a corrective-action cycle for digital data protection, incomplete evidence, unmanaged conflict, absent learner groups or material learner impact require a higher level of review.","In practical terms, the practice should be reviewed against a stated method rather than general assurance. Oversight of the practice should reflect the principle that the subject should be examined as a connected system of policy, people, resources, decisions and evidence. Transfer of decisions or records can expose weaknesses not visible in separate reviews of individual controls. The method, assumptions and limitations should be stated in terms suitable for responsible decision-making.","Relevant evidence for the intervention will normally include supplier and transfer arrangements, a register of information assets and purposes, role-based access and access reviews, data-quality and correction controls, and lawful authority and consent records where relevant. In relation to a corrective-action cycle for digital data protection, the conclusion should rely on evidence whose date, source and coverage are sufficient for the decision. An unresolved contradiction is a limitation on the conclusion and should be reported as such."]},{"heading":"Controls and accountable action","paragraphs":["The quality significance of digital data protection follows from a basic distinction between availability and effective provision. A decision concerning the corrective programme should recognise that education information should be collected for a defined purpose, protected in proportion to its sensitivity and retained only for an authorised period.","Failure in relation to the issue under review may arise even where the stated policy is reasonable. Material concerns include excessive access to learner information, retention beyond an identified need, collection without a defined educational or legal purpose, and inaccurate data affecting decisions. An exception should be assessed by effect, duration, recurrence and reach, including possible exposure beyond the initial sample."],"bullets":["Assign accountable data owners.","Provide accessible correction and complaint routes.","Limit and review access.","Minimise collection.","Test incident and recovery arrangements."]},{"heading":"Evidence of effect","paragraphs":["A proportionate method is available for digital data protection. For the issue under review, the reviewer should map the complete process, identify the intended result and responsible authority at each stage, and test normal cases together with exceptions. The conclusion should identify whether further sampling or system-level action is required. Adverse cases and unresolved contradictions should be retained because they may reveal limitations concealed by an average result.","A decision to close improvement work on the issue under review should be made by a person with authority and sufficient independence from implementation.","Interpretation of the intervention should avoid two errors: treating a formal commitment as proof of effect, and treating one adverse case as proof that every part of the system has failed. For the issue under review, security, privacy and data quality are related but distinct. A secure record may still be inaccurate or used without adequate authority, and a lawful use may still be poorly governed. The analysis of the issue under review proceeds on the basis that improvement data should not be selected only because it is readily available.","The assurance record for the practice should retain the date of the evidence, the source responsible for it, the scope examined and the version of any instrument or definition applied. A superseded conclusion should be retained where it formed the basis of a material decision."]},{"heading":"Sustaining improvement","paragraphs":["Where digital data protection involves partners, suppliers or several public bodies, responsibility should be mapped across the complete service. The division of responsibilities should cover records, communication, escalation and the power to require correction. Division of delivery responsibilities must not create gaps in learner protection.","Assessment of the issue under review should reconcile more than one source of evidence and control. A reasoned conclusion should reconcile the governing requirement, evidence of operation, learner outcomes and residual risk, and remain open to better evidence."]}],"word_count":759,"content_hash":"sha256-fa74a0d4b51b3bd0682d24bc15258f08fb0c55cb2fc160174f79e08b8ca24efc","seo_keywords":["a corrective-action cycle for digital data protection","education quality improvement","education quality","ICEQC"],"schema_type":"TechArticle"}
