Sign Up

What is 8 + 4?

Have an account? Sign In Now

Sign In

What is 8 + 4?

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

What is 8 + 4?

Have an account? Sign In Now

Please type your username.

Please type your E-Mail.

Please choose an appropriate title for the question so it can be answered easily.
Please choose the appropriate section so the question can be searched easily.

Type the description thoroughly and in details.

What is 8 + 4?

Sign InSign Up

Watercooler by DPOrganizer

Watercooler by DPOrganizer Logo Watercooler by DPOrganizer Logo

Watercooler by DPOrganizer Navigation

Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Categories
    • GDPR
    • Privacy Management
    • Professional Development
    • Software tips and tricks
    • Polls
  • Help
  • About Watercooler
Home/ Questions/Q 3472
Next
In Process
Anonymous
  • 0
Asked: February 18, 20212021-02-18T13:56:53+01:00 2021-02-18T13:56:53+01:00In: GDPR

What will supervisory authority ask for?

  • 0

Hi, could you please share experiences from having dealt with supervisory authorities?
I understand details will differ from case to case, but looking to get som input so we can better prepare in case something goes wrong or they do a random visit to us.
For example, what did they ask for and how long did you have to respond? Did they do physical visits or technical audits? Were they pragmatic or helpful, or only looking for error?
Thank you,
/ Concerned

  • 2 2 Answers
  • 0 Followers
  • 0
Answer
Share
  • Facebook

    2 Answers

    • Voted
    • Oldest
    • Recent
    1. Barry Moult

      Barry Moult

      • 0 Questions
      • 29 Answers
      • 0 Best Answers
      • 29 Points
      View Profile
      Barry Moult Bronze contributor
      2021-02-22T13:46:03+01:00Added an answer on February 22, 2021 at 1:46 pm

      Hi. From a health perspective.
      2 Things
      If there has been a data breach from my experience the supervisory authority( in our case the ICO) will ask for the following:
      Policies and procedures
      Training (if an individual has been involved have they had training in last 12 months?)
      Dependent on the breach will want to see
      DPIA
      RoPA
      Then will ask;
      What actions were taken?
      What Lessons learnt?
      Was Duty of Candour carried out?

      The ICO carried out a number of consensual audits in Health Organisations in 2020. From the reports (available on the ICO website) I have pulled all the recommendation from those audits into a spreadsheet (action plan). I’m happy to share.

      • 2
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
    2. Chris Roberts

      Chris Roberts

      • 0 Questions
      • 42 Answers
      • 0 Best Answers
      • 42 Points
      View Profile
      Chris Roberts Silver contributor
      2021-02-23T10:26:44+01:00Added an answer on February 23, 2021 at 10:26 am

      Barry has already provided a great summary. I would add from a UK (ICO) perspective the following.

      An ICO Case Officer effectively triages the case based on your response and depending on the issue may escalate the matter to the investigations department. Ensuring you acknowledge their initial communication, in a timely, professional and cooperative manner can go a long way – remember they are looking for evidence that the organisation is taking the matter seriously. If the case does escalate to the investigations team, they will be reviewing all of your past communications.

      Have your evidence easily to hand and well organised, evidence thus far from my personal experience, is that the ICO will take this as sign you are in control of the personal data you process. Good luck.

      • 1
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn

    Leave an answer
    Cancel reply

    You must login to add an answer.

    What is 8 + 4?

    Forgot Password?

    Sidebar

    Ask A Question

    Trending contributors

    Smurf333

    Smurf333

    • 11 Answers
    Bronze contributor
    Dave_Wylie

    Dave_Wylie

    • 28 Answers
    Bronze contributor
    CRodica

    CRodica

    • 6 Answers
    Rising star contributor
    Atis

    Atis

    • 4 Answers
    Ian G

    Ian G

    • 5 Answers
    Rising star contributor

    Recent questions

    • Ian G

      Revoke.com - new third party portal for customer right requests

      • 0 Answers
    • Anonymous

      Instagram!!

      • 0 Answers
    • Olga

      DPO in EU and UK

      • 1 Answer
    • Smurf333

      DBS scenario with HR retaining excessive information for longer than ...

      • 0 Answers
    • CRodica

      Parties role towards employees data for administrative purposes

      • 0 Answers

    Explore

    • Home
    • Categories
      • GDPR
      • Privacy Management
      • Professional Development
      • Software tips and tricks
      • Polls
    • Help
    • About Watercooler

    Footer

    Your privacy

    • Cookie notice
    • Privacy notice

    Terms and policy

    • Acceptable Use Policy
    • Terms of Use

    © 2021 DPOrganizer. All Rights Reserved. With Love by DPOrganizer.