SlideShare a Scribd company logo
Surviving a Data Protection Audit
David Hickey
Thornton Group – Insurance Loss Adjusters
28 January 2015
• Largest firm of Insurance Loss
Adjusters in Ireland
• 170 staff in 8 locations
• Multiple group specialist companies
– Property, Jewellery, Liability, Marine,
Business Interruption
• Settle insurance claims on behalf of
major insurers
Compliance Agenda
• Regulated by Central Bank
• Consumer Protection Code
• Complaints & Internal Audit
• Information Security
• Data Protection
Data Protection
• DP was traditionally part of H.R. function
• Increasing DP questions arising in Information Security audits
• Engaged ISAS to carry out IS & DP readiness audit – Aug 2014
• Outcome: 43 issues of concern varying in severity
• Decision to train and appoint DPO – Sept 2014
Sept 22nd - Notification of Audit
• Audit date: Fri 10th Oct 2014
– Four week’s notice
– 3 investigators full day
– Interviews with key staff
– Paper & systems audit
– Possible “Walkabout”
• Documentation: Fri 3rd Oct
– Three weeks to get ready
ODPC Powers
”The Commissioner may carry out or cause to be carried out such
investigations as he or she considers appropriate in order to ensure
compliance with the provisions of this Act and to identify any
contravention thereof “
Immediate Concerns ?
• Compliance with Data Protection – unknown
• Issues from ISAS review – not yet addressed
• Staff awareness – uncertain
• Information flows – not documented
• Procedures – not documented
• Poor ODPCAudit could damage reputation or worse
We need a Plan !
Timeline
Week 4
PRE-2014
SOME POLICIES
IN PLACE
NOT ALL
PROCEDURES
DOCUMENTED
STAFF
AWARENESS
PATCHY
SEPT 2014
BOARD
APPOINTS
D. P. O.
POLICIES
REVIEW EXISTING
WRITE NEW
BASED ON THE
8 RULES
FOLLOW THE
INFORMATION
EMAILS TO STAFF
CALLWITH
ODPC
NOTICE OF
AUDIT
Internal
Discovery
Collection of DP-related
documents
Contract review
Current state review
EMAILTO ODPC
PROCEDURES
DOCUMENT EXISTING
CREATE NEW
REFLECT THE POLICIES
STAFF AWARENESS
TRAINING
PACK
TO ODPC
PEOPLE
INTERNAL CHECKS
AND AUDITS
STAFF TRAINING PLAN
DP TRAINING FOR KEY
STAFF
BRIEF AUDIT
PARTICIPANS
AUDIT
BY ODPC
Week 3Week 2Week 1BEFORE
Starting Point
Code of Practice on Data Protection
for the Insurance Sector
(Approved by the Data Protection Commissioner under Section
13 (2) of the Data Protection Acts, 1988 and 2003)
Week 1: what are we likely to be asked ?
• Kinds of personal data ?
• Any sensitive data ?
• Approximate volumes ?
• Our policies and procedures ?
• What staff training is provided ?
• Have we experienced difficulties in
relation to Data Protection ?
• Contracts with 3rd party data processors
?
• WHAT DIDWE DO?
– INTERNAL REVIEW
– Public documentation
– ODPC website
– Consulted ADPO
– Consulted ICS SKILLS
– Consulted AMNCH
– Re-engaged ISAS
– Engaged MASON HAYES & CURRAN
• INTRODUCTORY EMAILTO ODPC
Week 2: what do we need to prepare ?
• REVIEW
– Registration with DPC
• POLICIES
– Data Protection
– Information Security
– ePrivacy
– HR and Hiring
– Data retention and destruction
– Subject access requests
– Training
• WHAT DIDWE DO?
– Updated DP Policy
– Collated existing policies
– Wrote missing policies
– Updated staff / awareness
– Scheduled formal training
– Updated the Board
• PHONE CALLWITH ODPC
Week 3: Evidence ?
• PROCEDURES
– Document all processes
– Information handling
– Movement of paper
– Electronic file movement and security
• LOGS
– Breaches (real or potential)
– Subject access request
– User permission reviews
– Training
• DOCUMENTATION PACKTO ODPC
Week 4: Ready – Set – Go !
• POLICIES & CONTRACTS
– Review for completeness
• PROCEDURES
– Spot checks
• STAFF
– Reinforce awareness
– Brief potential interviewees
• DOCUMENTATION
– Collate and Index everything
• AUDIT BY ODPC
Audit Day
• 10:00am – 4:30pm
• 3 x ODPC investigators
• Dedicated Meeting Room
• 6 x company interviewees
• 40+ documents for review
1. ODPC introduction
2. Company CEO introduction
3. Ops Director Business overview
4. Policy and Procedure review
5. Logs and other records
6. Sample cases
7. Walkabout
8. Preliminary feedback
Investigation
• 3 Investigators
– Professional & Courteous
• Interested in Information/Data flow
– Overview of our business was important
• Parallel review of 40+ documents
– Little chance of missing anything
• Attention to detail
– Lots of questions and note taking
• Review of Specific (not Sample) cases
– Paper first, then electronic data relating to same cases
Walkabout
Walkabout
Audit Result
SUMMARY
“ Excellent co-operation was received throughout the
inspection.The InspectionTeam considered that there
was excellent organisational awareness of data
protection principles generally “
RECOMMENDATION
“ It is recommended that any [Data Subject] access
request received …… is passed to the relevant client in
the first instance and …. redacts any third party
personal data when providing documentation.”
December 2014
Lessons Learned
• A Data Protection Audit gets the Board’s attention !
• Be positive – use the opportunity to streamline bad practices
• It’s time consuming ! Get internal and external help
• Co-operate - provide documentation in advance to ODPC
• Be able to evidence that policies and procedures are in use
• Raise staff awareness
• Prepare an overview of the business and information flow
• Most important lesson: ENGAGE with ODPC !
ThankYou
david.hickey@thorntongroup.ie

More Related Content

Viewers also liked

Big Data Summit-Hudson Panel
Big Data Summit-Hudson PanelBig Data Summit-Hudson Panel
Big Data Summit-Hudson PanelMadison Ingold
 
Big Data Summit Granular Slides
Big Data Summit Granular SlidesBig Data Summit Granular Slides
Big Data Summit Granular SlidesMadison Ingold
 
Devi's Closet Offers Indian Couture in NYC: For Rent | Jim Luce
Devi's Closet Offers Indian Couture in NYC: For Rent | Jim LuceDevi's Closet Offers Indian Couture in NYC: For Rent | Jim Luce
Devi's Closet Offers Indian Couture in NYC: For Rent | Jim Lucenewmoodzee
 
QueensLandingWeddingPackage
QueensLandingWeddingPackageQueensLandingWeddingPackage
QueensLandingWeddingPackageLibby Dallis
 
Nanoelectronics
NanoelectronicsNanoelectronics
NanoelectronicsAakankshaR
 

Viewers also liked (6)

Big Data Summit-Hudson Panel
Big Data Summit-Hudson PanelBig Data Summit-Hudson Panel
Big Data Summit-Hudson Panel
 
Big Data Summit Granular Slides
Big Data Summit Granular SlidesBig Data Summit Granular Slides
Big Data Summit Granular Slides
 
Devi's Closet Offers Indian Couture in NYC: For Rent | Jim Luce
Devi's Closet Offers Indian Couture in NYC: For Rent | Jim LuceDevi's Closet Offers Indian Couture in NYC: For Rent | Jim Luce
Devi's Closet Offers Indian Couture in NYC: For Rent | Jim Luce
 
QueensLandingWeddingPackage
QueensLandingWeddingPackageQueensLandingWeddingPackage
QueensLandingWeddingPackage
 
Nanoelectronics
NanoelectronicsNanoelectronics
Nanoelectronics
 
Tem
TemTem
Tem
 

Similar to Surviving an ODPC Audit - Ireland

Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy IntroductionNiclasGranqvist
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICECFG
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protectionRachel Aldighieri
 
Multi-faceted Cyber Security v1
Multi-faceted Cyber Security v1Multi-faceted Cyber Security v1
Multi-faceted Cyber Security v1Asad Zaman
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceCobweb
 
An introduction to data protection - Edinburgh
An introduction to data protection - EdinburghAn introduction to data protection - Edinburgh
An introduction to data protection - EdinburghRachel Aldighieri
 
Legal and data protection update
Legal and data protection updateLegal and data protection update
Legal and data protection updateRachel Aldighieri
 
Introduction to computer forensic
Introduction to computer forensicIntroduction to computer forensic
Introduction to computer forensicOnline
 
501 ch 11 operational security
501 ch 11 operational security501 ch 11 operational security
501 ch 11 operational securitygocybersec
 
Ready or Not, Here They Come Preparing For Phase 2 HIPAA Compliance Audits
Ready or Not, Here They Come Preparing For Phase 2 HIPAA Compliance Audits Ready or Not, Here They Come Preparing For Phase 2 HIPAA Compliance Audits
Ready or Not, Here They Come Preparing For Phase 2 HIPAA Compliance Audits Resilient Systems
 
An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015Rachel Aldighieri
 
Making ‘Big Data’ Your Ally – Using data analytics to improve compliance, due...
Making ‘Big Data’ Your Ally – Using data analytics to improve compliance, due...Making ‘Big Data’ Your Ally – Using data analytics to improve compliance, due...
Making ‘Big Data’ Your Ally – Using data analytics to improve compliance, due...emermell
 
GDPR and EA Commissioning a web site part 2 - Legal Environment
GDPR and EA Commissioning a web site part 2 - Legal EnvironmentGDPR and EA Commissioning a web site part 2 - Legal Environment
GDPR and EA Commissioning a web site part 2 - Legal EnvironmentAllen Woods
 
Data Privacy Compliance: Why & How
Data Privacy Compliance: Why & How  Data Privacy Compliance: Why & How
Data Privacy Compliance: Why & How Andrea Huck-Esposito
 

Similar to Surviving an ODPC Audit - Ireland (20)

Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
 
SNW Fall 2009
SNW Fall 2009SNW Fall 2009
SNW Fall 2009
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protection
 
Prepare Your Firm for GDPR
Prepare Your Firm for GDPRPrepare Your Firm for GDPR
Prepare Your Firm for GDPR
 
Multi-faceted Cyber Security v1
Multi-faceted Cyber Security v1Multi-faceted Cyber Security v1
Multi-faceted Cyber Security v1
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
An introduction to data protection - Edinburgh
An introduction to data protection - EdinburghAn introduction to data protection - Edinburgh
An introduction to data protection - Edinburgh
 
Prosecutions seminar, Exeter
Prosecutions seminar, ExeterProsecutions seminar, Exeter
Prosecutions seminar, Exeter
 
Legal and data protection update
Legal and data protection updateLegal and data protection update
Legal and data protection update
 
Introduction to computer forensic
Introduction to computer forensicIntroduction to computer forensic
Introduction to computer forensic
 
Investigative powers in practice – EUROPEAN UNION – November 2018 OECD GFC
Investigative powers in practice – EUROPEAN UNION – November 2018 OECD GFCInvestigative powers in practice – EUROPEAN UNION – November 2018 OECD GFC
Investigative powers in practice – EUROPEAN UNION – November 2018 OECD GFC
 
501 ch 11 operational security
501 ch 11 operational security501 ch 11 operational security
501 ch 11 operational security
 
Ready or Not, Here They Come Preparing For Phase 2 HIPAA Compliance Audits
Ready or Not, Here They Come Preparing For Phase 2 HIPAA Compliance Audits Ready or Not, Here They Come Preparing For Phase 2 HIPAA Compliance Audits
Ready or Not, Here They Come Preparing For Phase 2 HIPAA Compliance Audits
 
An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015
 
Making ‘Big Data’ Your Ally – Using data analytics to improve compliance, due...
Making ‘Big Data’ Your Ally – Using data analytics to improve compliance, due...Making ‘Big Data’ Your Ally – Using data analytics to improve compliance, due...
Making ‘Big Data’ Your Ally – Using data analytics to improve compliance, due...
 
Data protection
Data protectionData protection
Data protection
 
GDPR and EA Commissioning a web site part 2 - Legal Environment
GDPR and EA Commissioning a web site part 2 - Legal EnvironmentGDPR and EA Commissioning a web site part 2 - Legal Environment
GDPR and EA Commissioning a web site part 2 - Legal Environment
 
Data Privacy Compliance: Why & How
Data Privacy Compliance: Why & How  Data Privacy Compliance: Why & How
Data Privacy Compliance: Why & How
 

Recently uploaded

Unveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdfUnveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdfSam H
 
chapter 10 - excise tax of transfer and business taxation
chapter 10 - excise tax of transfer and business taxationchapter 10 - excise tax of transfer and business taxation
chapter 10 - excise tax of transfer and business taxationAUDIJEAngelo
 
5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographer5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographerofm712785
 
Premium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern BusinessesPremium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern BusinessesSynapseIndia
 
anas about venice for grade 6f about venice
anas about venice for grade 6f about veniceanas about venice for grade 6f about venice
anas about venice for grade 6f about veniceanasabutalha2013
 
Memorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.pptMemorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.pptseri bangash
 
Digital Transformation in PLM - WHAT and HOW - for distribution.pdf
Digital Transformation in PLM - WHAT and HOW - for distribution.pdfDigital Transformation in PLM - WHAT and HOW - for distribution.pdf
Digital Transformation in PLM - WHAT and HOW - for distribution.pdfJos Voskuil
 
University of Connecticut Fees, Courses, Acceptance Rate, Admission deadline,...
University of Connecticut Fees, Courses, Acceptance Rate, Admission deadline,...University of Connecticut Fees, Courses, Acceptance Rate, Admission deadline,...
University of Connecticut Fees, Courses, Acceptance Rate, Admission deadline,...dvividconsultant15
 
Pitch Deck Teardown: RAW Dating App's $3M Angel deck
Pitch Deck Teardown: RAW Dating App's $3M Angel deckPitch Deck Teardown: RAW Dating App's $3M Angel deck
Pitch Deck Teardown: RAW Dating App's $3M Angel deckHajeJanKamps
 
Presentation: PLM loves Innovation PI 2013 Berlin
Presentation: PLM loves Innovation PI 2013 BerlinPresentation: PLM loves Innovation PI 2013 Berlin
Presentation: PLM loves Innovation PI 2013 BerlinJos Voskuil
 
Meaningful Technology for Humans: How Strategy Helps to Deliver Real Value fo...
Meaningful Technology for Humans: How Strategy Helps to Deliver Real Value fo...Meaningful Technology for Humans: How Strategy Helps to Deliver Real Value fo...
Meaningful Technology for Humans: How Strategy Helps to Deliver Real Value fo...Björn Rohles
 
IPTV Subscription UK: Your Guide to Choosing the Best Service
IPTV Subscription UK: Your Guide to Choosing the Best ServiceIPTV Subscription UK: Your Guide to Choosing the Best Service
IPTV Subscription UK: Your Guide to Choosing the Best ServiceDragon Dream Bar
 
sales plan presentation by mckinsey alum
sales plan presentation by mckinsey alumsales plan presentation by mckinsey alum
sales plan presentation by mckinsey alumzyqmx62fgm
 
Putting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxPutting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxCynthia Clay
 
Using Generative AI for Content Marketing
Using Generative AI for Content MarketingUsing Generative AI for Content Marketing
Using Generative AI for Content MarketingChuck Aikens
 
Team-Spandex-Northern University-CS1035.
Team-Spandex-Northern University-CS1035.Team-Spandex-Northern University-CS1035.
Team-Spandex-Northern University-CS1035.smalmahmud11
 
Securing Your Peace of Mind: Private Security Guard Services’
Securing Your Peace of Mind: Private Security Guard Services’Securing Your Peace of Mind: Private Security Guard Services’
Securing Your Peace of Mind: Private Security Guard Services’Dragon Dream Bar
 
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...BBPMedia1
 
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptx
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptxTaurus Zodiac Sign_ Personality Traits and Sign Dates.pptx
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptxmy Pandit
 
Enterprise Excellence is Inclusive Excellence.pdf
Enterprise Excellence is Inclusive Excellence.pdfEnterprise Excellence is Inclusive Excellence.pdf
Enterprise Excellence is Inclusive Excellence.pdfKaiNexus
 

Recently uploaded (20)

Unveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdfUnveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdf
 
chapter 10 - excise tax of transfer and business taxation
chapter 10 - excise tax of transfer and business taxationchapter 10 - excise tax of transfer and business taxation
chapter 10 - excise tax of transfer and business taxation
 
5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographer5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographer
 
Premium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern BusinessesPremium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern Businesses
 
anas about venice for grade 6f about venice
anas about venice for grade 6f about veniceanas about venice for grade 6f about venice
anas about venice for grade 6f about venice
 
Memorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.pptMemorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.ppt
 
Digital Transformation in PLM - WHAT and HOW - for distribution.pdf
Digital Transformation in PLM - WHAT and HOW - for distribution.pdfDigital Transformation in PLM - WHAT and HOW - for distribution.pdf
Digital Transformation in PLM - WHAT and HOW - for distribution.pdf
 
University of Connecticut Fees, Courses, Acceptance Rate, Admission deadline,...
University of Connecticut Fees, Courses, Acceptance Rate, Admission deadline,...University of Connecticut Fees, Courses, Acceptance Rate, Admission deadline,...
University of Connecticut Fees, Courses, Acceptance Rate, Admission deadline,...
 
Pitch Deck Teardown: RAW Dating App's $3M Angel deck
Pitch Deck Teardown: RAW Dating App's $3M Angel deckPitch Deck Teardown: RAW Dating App's $3M Angel deck
Pitch Deck Teardown: RAW Dating App's $3M Angel deck
 
Presentation: PLM loves Innovation PI 2013 Berlin
Presentation: PLM loves Innovation PI 2013 BerlinPresentation: PLM loves Innovation PI 2013 Berlin
Presentation: PLM loves Innovation PI 2013 Berlin
 
Meaningful Technology for Humans: How Strategy Helps to Deliver Real Value fo...
Meaningful Technology for Humans: How Strategy Helps to Deliver Real Value fo...Meaningful Technology for Humans: How Strategy Helps to Deliver Real Value fo...
Meaningful Technology for Humans: How Strategy Helps to Deliver Real Value fo...
 
IPTV Subscription UK: Your Guide to Choosing the Best Service
IPTV Subscription UK: Your Guide to Choosing the Best ServiceIPTV Subscription UK: Your Guide to Choosing the Best Service
IPTV Subscription UK: Your Guide to Choosing the Best Service
 
sales plan presentation by mckinsey alum
sales plan presentation by mckinsey alumsales plan presentation by mckinsey alum
sales plan presentation by mckinsey alum
 
Putting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxPutting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptx
 
Using Generative AI for Content Marketing
Using Generative AI for Content MarketingUsing Generative AI for Content Marketing
Using Generative AI for Content Marketing
 
Team-Spandex-Northern University-CS1035.
Team-Spandex-Northern University-CS1035.Team-Spandex-Northern University-CS1035.
Team-Spandex-Northern University-CS1035.
 
Securing Your Peace of Mind: Private Security Guard Services’
Securing Your Peace of Mind: Private Security Guard Services’Securing Your Peace of Mind: Private Security Guard Services’
Securing Your Peace of Mind: Private Security Guard Services’
 
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
 
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptx
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptxTaurus Zodiac Sign_ Personality Traits and Sign Dates.pptx
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptx
 
Enterprise Excellence is Inclusive Excellence.pdf
Enterprise Excellence is Inclusive Excellence.pdfEnterprise Excellence is Inclusive Excellence.pdf
Enterprise Excellence is Inclusive Excellence.pdf
 

Surviving an ODPC Audit - Ireland

  • 1. Surviving a Data Protection Audit David Hickey Thornton Group – Insurance Loss Adjusters 28 January 2015
  • 2. • Largest firm of Insurance Loss Adjusters in Ireland • 170 staff in 8 locations • Multiple group specialist companies – Property, Jewellery, Liability, Marine, Business Interruption • Settle insurance claims on behalf of major insurers
  • 3.
  • 4. Compliance Agenda • Regulated by Central Bank • Consumer Protection Code • Complaints & Internal Audit • Information Security • Data Protection
  • 5. Data Protection • DP was traditionally part of H.R. function • Increasing DP questions arising in Information Security audits • Engaged ISAS to carry out IS & DP readiness audit – Aug 2014 • Outcome: 43 issues of concern varying in severity • Decision to train and appoint DPO – Sept 2014
  • 6.
  • 7. Sept 22nd - Notification of Audit • Audit date: Fri 10th Oct 2014 – Four week’s notice – 3 investigators full day – Interviews with key staff – Paper & systems audit – Possible “Walkabout” • Documentation: Fri 3rd Oct – Three weeks to get ready
  • 8. ODPC Powers ”The Commissioner may carry out or cause to be carried out such investigations as he or she considers appropriate in order to ensure compliance with the provisions of this Act and to identify any contravention thereof “
  • 9. Immediate Concerns ? • Compliance with Data Protection – unknown • Issues from ISAS review – not yet addressed • Staff awareness – uncertain • Information flows – not documented • Procedures – not documented • Poor ODPCAudit could damage reputation or worse
  • 10.
  • 11. We need a Plan !
  • 12. Timeline Week 4 PRE-2014 SOME POLICIES IN PLACE NOT ALL PROCEDURES DOCUMENTED STAFF AWARENESS PATCHY SEPT 2014 BOARD APPOINTS D. P. O. POLICIES REVIEW EXISTING WRITE NEW BASED ON THE 8 RULES FOLLOW THE INFORMATION EMAILS TO STAFF CALLWITH ODPC NOTICE OF AUDIT Internal Discovery Collection of DP-related documents Contract review Current state review EMAILTO ODPC PROCEDURES DOCUMENT EXISTING CREATE NEW REFLECT THE POLICIES STAFF AWARENESS TRAINING PACK TO ODPC PEOPLE INTERNAL CHECKS AND AUDITS STAFF TRAINING PLAN DP TRAINING FOR KEY STAFF BRIEF AUDIT PARTICIPANS AUDIT BY ODPC Week 3Week 2Week 1BEFORE
  • 13. Starting Point Code of Practice on Data Protection for the Insurance Sector (Approved by the Data Protection Commissioner under Section 13 (2) of the Data Protection Acts, 1988 and 2003)
  • 14. Week 1: what are we likely to be asked ? • Kinds of personal data ? • Any sensitive data ? • Approximate volumes ? • Our policies and procedures ? • What staff training is provided ? • Have we experienced difficulties in relation to Data Protection ? • Contracts with 3rd party data processors ? • WHAT DIDWE DO? – INTERNAL REVIEW – Public documentation – ODPC website – Consulted ADPO – Consulted ICS SKILLS – Consulted AMNCH – Re-engaged ISAS – Engaged MASON HAYES & CURRAN • INTRODUCTORY EMAILTO ODPC
  • 15. Week 2: what do we need to prepare ? • REVIEW – Registration with DPC • POLICIES – Data Protection – Information Security – ePrivacy – HR and Hiring – Data retention and destruction – Subject access requests – Training • WHAT DIDWE DO? – Updated DP Policy – Collated existing policies – Wrote missing policies – Updated staff / awareness – Scheduled formal training – Updated the Board • PHONE CALLWITH ODPC
  • 16.
  • 17. Week 3: Evidence ? • PROCEDURES – Document all processes – Information handling – Movement of paper – Electronic file movement and security • LOGS – Breaches (real or potential) – Subject access request – User permission reviews – Training • DOCUMENTATION PACKTO ODPC
  • 18.
  • 19. Week 4: Ready – Set – Go ! • POLICIES & CONTRACTS – Review for completeness • PROCEDURES – Spot checks • STAFF – Reinforce awareness – Brief potential interviewees • DOCUMENTATION – Collate and Index everything • AUDIT BY ODPC
  • 20.
  • 21.
  • 22. Audit Day • 10:00am – 4:30pm • 3 x ODPC investigators • Dedicated Meeting Room • 6 x company interviewees • 40+ documents for review 1. ODPC introduction 2. Company CEO introduction 3. Ops Director Business overview 4. Policy and Procedure review 5. Logs and other records 6. Sample cases 7. Walkabout 8. Preliminary feedback
  • 23. Investigation • 3 Investigators – Professional & Courteous • Interested in Information/Data flow – Overview of our business was important • Parallel review of 40+ documents – Little chance of missing anything • Attention to detail – Lots of questions and note taking • Review of Specific (not Sample) cases – Paper first, then electronic data relating to same cases
  • 26. Audit Result SUMMARY “ Excellent co-operation was received throughout the inspection.The InspectionTeam considered that there was excellent organisational awareness of data protection principles generally “ RECOMMENDATION “ It is recommended that any [Data Subject] access request received …… is passed to the relevant client in the first instance and …. redacts any third party personal data when providing documentation.” December 2014
  • 27. Lessons Learned • A Data Protection Audit gets the Board’s attention ! • Be positive – use the opportunity to streamline bad practices • It’s time consuming ! Get internal and external help • Co-operate - provide documentation in advance to ODPC • Be able to evidence that policies and procedures are in use • Raise staff awareness • Prepare an overview of the business and information flow • Most important lesson: ENGAGE with ODPC !