Advisory
Key Findings from a Full Compliance Audit 2023/4 (2024-08-12)
Issued 2024-08-12View on JOIC's website Source document
Summary
This is an advisory report from the Jersey Office of the Information Commissioner (JOIC) summarising the key findings of a full compliance audit of one (unnamed) public sector data controller, conducted during 2023/4. The audit focused on staff data protection training and awareness, and on the security of personal data, and the report sets out good practice observed, deficiencies found, and JOIC's recommended best practice for all organisations to follow.
Areas of good practice found
- Technical security: Devices had multi-factor authentication and complex password requirements; personal devices were banned for work use and this was followed in practice.
- Access controls: Software systems had audit functions and role-specific access controls limiting access to those who needed it.
- Breach reporting culture: Staff were generally able to identify breaches and felt comfortable and supported reporting them without fear of repercussions.
Deficiencies identified
- Training: Data protection training was generic and not tailored to employees' roles or the sensitivity of data they accessed.
- Policies and procedures: Staff were unfamiliar with organisational policies on data security, retention, and safe destruction of personal data.
- Data sharing: Employees were unsure of the lawful basis for sharing personal data, unaware of data sharing agreements, and often defaulted to relying on consent.
- Confidentiality: Open plan office layouts lacked confidential spaces for discussing sensitive matters.
- Messaging and virtual meetings: Risk of personal data exposure via visible screen notifications during physical or virtual meetings, and via messaging platforms used to discuss individuals.
JOIC sets out best practice recommendations for all data controllers (not just the audited body) covering tailored, role-specific training delivered before system access is granted and refreshed at least yearly, effective and communicated policies with adherence checks, clear identification of lawful bases and data sharing agreements before sharing personal data, evaluation of office layout and privacy screens, and guidelines on closing irrelevant apps, managing notifications, and governing use of messaging platforms (including awareness that messages are discoverable under subject access requests). The audited organisation itself was required to implement remedial changes within a timeframe stipulated by JOIC, though that timeframe is not specified in this public report.
Key obligations
- Provide data protection training that is specific and tailored to an employee's role rather than generic, tick box training
- Provide training to new employees before they are given access to systems and personal information, and refresh training at least yearly thereafter
- Ensure staff are aware of, and actually adhere to in practice, organisational policies on data security, retention and safe destruction of personal data
- Identify and document the lawful basis being relied upon before sharing personal data, and know when sharing is or is not permissible
- Put in place data sharing agreements between parties before personal data is shared, and make relevant staff aware of them
- Evaluate office layout and use of privacy screens to protect confidentiality of personal data discussions
- Create guidelines requiring closure of irrelevant applications or management of notifications during physical or virtual meetings where screens may be visible to others
- Create and circulate a policy on use of messaging platforms to discuss clients or individuals, including which platforms may or may not be used, and ensure staff know such communications are discoverable under subject access requests
- Include all relevant messaging platforms within the search scope when responding to a subject access request
- The audited controller must implement remedial changes as directed by JOIC within its stipulated timeframe
Applies to
public sector data controllers, data controllers generally
Deadlines
- at least yearly: Recommended minimum frequency for refresher data protection training after initial training on system access