In line with data protection requirements and good practice, National College of Ireland (‘NCI’) wish to put in place, and be able to demonstrate, appropriate and effective management of personal data throughout the Organisation.
NCI wishes to demonstrate commitment and compliance with the current Data Protection Acts and the General Data Protection Regulation (GDPR). Fundamental to the GDPR are the principles of accountability and transparency. This means that Controllers and Processors are both responsible and, accountable for the protection of personal data, and must be able to demonstrate how they maintain compliance with data protection requirements.
The implementation of an approved Data Protection Policy goes towards demonstrating NCI’s commitment to the protection of personal data, and provides a basis for maintaining and improving compliance with data protection requirements and good practice.
1.1 PURPOSE OF THIS DOCUMENT
NCI collects, processes, and stores significant volumes of personal data and sensitive personal data (special category data) on an ongoing basis. NCI are committed to complying with data protection legislation and good practice.
The purpose of this document is to provide a statement of intentions and directions of NCI for managing compliance with data protection requirements which is formally approved by senior management. The aim of this policy is to ensure that any individual who handles personal data, whether they are a member of staff or a contractor, is fully aware of the requirements and act in accordance with data protection procedures.
The objectives of the data protection policy are to:
- Enable NCI to meet its own requirements for the management of personal data.
- Ensure NCI meets applicable statutory, regulatory, contractual and/or professional duties.
- Protect the interests of individuals and other key stakeholders.
- Support organisational objectives and obligations.
- Impose controls in line with NCI acceptable level of risk. This document also highlights key data protection procedures within NCI.
1.2 SCOPE AND CONSTRAINTS
This policy applies to all personal data processed by NCI, regardless of the media on which the personal data is stored (paper-based, electronic, CCTV or otherwise).
This policy applies to:
- any person who is employed by NCI or is engaged by NCI, whether on a paid or voluntary basis, including contractor and sub-contractors, and who process personal data in the course of their employment or engagement. Failure of any staff member or agent to comply with this policy may lead to disciplinary action being taken in accordance with NCI’s disciplinary procedures. Failure of a third party contractor/subcontractor to comply with this policy may lead to termination of the contract and/or legal action.
1.3 POLICY REVIEW, APPROVAL, AND CONTINUOUS IMPROVEMENT
In line with best practice, this policy has been approved by senior management, along with a commitment of continual improvement. This document will be reviewed at least annually by senior management and the NCI Data Protection Officer to ensure alignment to appropriate risk management requirements and its continued relevance to current and planned operations, legal developments, legislative obligations, and information commissioner guidance.
1.4 REFERENCES
- General Data Protection Regulation
- Data Protection Act 2018
- E-Privacy Directive
- S.I No. 336/2011 – European Communities (Electronic Communications, Networks, and Services) (Privacy and Electronic Communications) Regulations 2011
- Article 29 Working Party Guidelines on the concepts of “controller” and “processor”
- Guidelines, recommendations, and best practice issued by the European Data Protection Board
This document forms part of the NCI Personal Data Management System, and should be read in conjunction with the other documents within the management system:
- NCI Data Retention Policy (Document Reference: NCI-PDMS-03)
- NCI Privacy Notice(s) (Document Reference: NCI-PDMS-04)
- NCI Data Breach Incident Procedure (Document reference: NCI-PDMS-05)
1.5 DEFINITIONS
The following key GDPR terms and definitions are provided here for ease of use. For a complete list of definitions refer directly to the regulation.
1. ‘Anonymisation’ is the process of turning data into a form which does not identify individuals and where identification is not likely to take place. This allows for a much wider use of the information.
2. 'Personal Data' means any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Recital 26 also clarifies anonymous information “The principles of data protection should therefore not apply to anonymous information, namely information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable. This Regulation does not, therefore, concern the processing of such anonymous information, including for statistical or research purposes”.
3. ‘Special Categories of Personal Data’ refers to the processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation.
NCI will avoid all processing of special categories of personal data where possible. It is understood that certain business activities within NCI require the processing of special categories of data (e.g. processing of data concerning health and disability). The general processing of special categories is prohibited in NCI, and in the rare instance it is required, Head of Departments must ensure all processing is defined in the data inventory, along with an appropriate legal basis (reference 1, Art 6), and derogation (reference 1, Art 9) for processing of such special categories recorded within the data inventory.
4. 'Data controller' means the natural or legal person, public authority, agency or another body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
In certain instances, NCI alone determines the purpose and means of processing, and in other instances, NCI might jointly determine the purpose and means of processing with a third party. In both circumstances, NCI would be considered a controller of this information. Section 8 of this policy provides further information on the responsibilities of controllers, processors, and third parties.
5. ‘Data subject’ any living individual who is the subject of personal data held by an organisation. Data subjects within NCI may include members of the public, students (current, past, and prospective), employees (current, past, and prospective), suppliers (e.g. sole traders or staff acting on behalf of the supplier), and other individuals such as external third parties, CPD members, and any other individual NCI might communicate with.
6. 'Processing' means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
7. 'Processor' means a natural or legal person, public authority, agency or another body which processes personal data on behalf of the controller.
8. ‘Third Party’ means a natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons, who, under the direct authority of the controller or processor, are authorised to process personal data
9. ‘Profiling’ means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person. This can include analysing or predicting aspects concerning a person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements.
10. ‘Pseudonymisation’ means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data is not attributed to an identified or identifiable natural person.
Examples of pseudonymisation within NCI may include the use of student IDs instead of student names for access authorisation. Where anonymisation cannot be used, the next best of pseudonymisation should be used.
11. 'Recipient' means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.