Stories from April, 2024

Understanding The Public Records Act

The Public Records Act 1958 (PRA 1958) is a significant piece of legislation in the United Kingdom. It governs the management and preservation of public records. The Act is important because establishes the framework for the selection, preservation, and accessibility of public records. This ensures transparency, accountability, and historical continuity.

Read more
Corporate Governance Mistakes

Corporate governance mistakes arise from flawed frameworks that set out how a company operates. Corporate governance plays a crucial role in organisational success and sustainability, and offers a range of benefits for various stakeholders. Contents Common Mistakes in Corporate Governance Core Reasons for Corporate Governance Mistakes Consequences of Corporate Governance

Read more
The machine readable data challenge

The obligation to provide information in a reusable, and machine readable data format not only arises under the Freedom of Information Act. It is also important for GDPR – when people exercise their right to data portability, for example. What exactly this means is a bit nebulous and in fact

Read more
Understanding and Managing Bribery

Bribery and preventing it are a core part of identifying and managing conflicts of interests. Unlike many other types of interests, or activities that can conflict with professional standards, bribery is recognised as a form of corruption The Bribery Act 2010 is a key piece of legislation in the UK

Read more
The Right to Restrict Processing: GDPR rights explained

The Right to Restrict Processing is one of people's rights to control their data under GDPR. It is perhaps one of the most complex. This is for two reasons: like many rights it only applies in certain circumstances in many ways this right exists to help people facilitate their other

Read more
The Hierarchy of Risk Controls

[su_box title="About the Author" box_color="#020a4a"]Michael Is a professionally qualified risk management expert and has many years' experience supporting, developing and improving effective risk management systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead

Read more
The Caldicott Principles

The Caldicott principles, and the Caldicott Guardians who look after them, are a key part of information governance and data protection for services like health and social care. In this article we will explore the Caldicott principles and what they mean, before looking at who a Caldicott guardian is and

Read more
Freedom of Information: Ensuring Compliance

Under the Freedom of Information Act requests for information must be responded to in 20 working days in most circumstances (see below). Timely disclosure of information under the Freedom of Information Act 2000 (FOI Act) is crucial for upholding transparency and accountability in public institutions. Failure to release requested information

Read more
Ensuring and Enforcing Policy Compliance

  Policies and policy compliance are a core part of any organisation’s activities. They set out an organisation’s attitudes and expectations, setting a framework or rules and behaviours people are expected to follow. In our experience many organisations get policies wrong. They don’t write them down, or if they do

Read more
Non Disclosure Agreements and Conflicts of Interests

Non disclosure agreements (NDAs) play a significant role in managing conflicts of interests, particularly in organisational settings. Here's how NDAs are linked to the management of conflicts of interests. [su_box title="About the Author" box_color="#020a4a"]Michael has over 15 years experience supporting, developing and improving effective conflict of interests systems. He has

Read more
Data Portability: rights under GDPR explained

Like all rights the right to data portability is not absolute. It only applies in some circumstances. The restrictions, and potential complexity that arises from them, on this right illustrate the importance of knowing the lawful basis for your data processing. Also, you should be drafting clear privacy statements, and

Read more
Information Asset Owner – Their Work and Role

An information asset owner plays a pivotal role in information governance by overseeing the management, protection, and utilisation of specific information assets within an organisation. They are responsible for ensuring that these assets are properly managed throughout their lifecycle. Contents What are Information Assets? Who Are Information Asset Owners? Responsibilities

Read more