Personal Data and Programme Management

One of the main reasons programmes that involve personal data become delayed or go over budget is because there hasn’t been proper planning for handling personal data as part of the programme design. Often, organisations will plan their timelines around technical or organisational changes. But, they will not necessarily consider how to handle the personal data their programme must also cover.

 

Periodic Table of the GDPR

 

This causes problems because statutory requirements like data protection impact assessments are often done whilst the programme is ongoing. This can be a blocker to technical or organisational change, as these must be approved and recorded before progress can be made. At an extreme if something like A DPIA is not approved, the whole programme could be in trouble.

 

The GDPR itself recognises this challenge. It encourages organisations to put personal data in the front at the front and centre of their thinking by introducing the concept of privacy by default and privacy by design

 

Privacy by Default and By Design

 

  • The GDPR expect organisations to put in place appropriate organisational and technical measures to manage and protect personal data at the design stage
  • Data protection must also be a factor in building and implementing new systems and processes
  • It helps reduce future costs and the risks of a data breach

 

This means personal data should be at the core of the design stage alongside planning for budgets timelines and other factors that are critical to programme success

Examples of Programmes

 

Examples of these kinds of programmes include:

  • transferring personal data to a new IT system or processing platform
  • when employees being TUPEd over to a new organisation in large numbers
  • a large scale data sharing partnership is being entered into with another organisation

 

It also means the programmes you to think carefully about the kind of discovery they need to undertake in order to find out what personal data may be involved in the programme that they’re delivering. For example it is not enough to say does this data set contain personal data. You should be much more granular at the planning stage and explore whether that personal data actually contains personal identifiers whether the GDPR actually applies. For example, the data set could only include the data of people who are deceased and whether there are any sensitivities around personal data such as data relating to health or criminal convictions

 

Even if datasets turn out to not to contain GDPR regulated or personal data assurance needs to be done confirming that this is correct before the programme can move on to the final stages of delivery. Another thing that needs to be understood is data flows or what point is personal data come into the organisation how long is it retained who has access to it what are the appropriate security measures

 

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

 

Some Key Questions

 

Finally you need to understand what framework the personal data is being captured and processed through. For example

  • Who is the data controller and who is the data processor?
  • Is there a contract or data sharing agreement in place?
  • What’s the lawful basis for the data processing is it consent or is it for a statutory function

 

When delivering your programme you may also wish to consider factors that may not seem immediately relevant to the delivery of the programme itself. These include updating privacy information and your record of processing activity

 

Without considering these factors at the programme design stage you risk reaching the GDPR or causing unnecessary reputational risk to your organisation. You may also risk the programme going overtime or over budget or creating a need for scope change whilst the programme is ongoing.

Key risks

 

  • Not fully understanding the personal data your programme encompasses until programme delivery is advanced, causing delays and extra costs
  • Being unable to provide proper assurance that the programme is maintaining appropriate technical and organisational security measures during the programme and post-delivery
  • A lack of trust or confidence among stakeholders (including data subjects) that the programme is capable of delivering

 

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

Getting this right means bringing in appropriate subject matter expertise at the very start of programme planning. They will help you develop an appropriate checklist or milestones for delivery and success for any transfer of personal data or any programme that involves the processing of personal data. Remember, regulators like the Information Commissioner will take into account the level of data protection by design you have implemented if there is ever a complaint or a data breach.

 

 

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.