ICO's internal Data Protection policy

The request was successful.

Dear Information Commissioner’s Office,

I was wondering whether you have revised your internal data protection policy ahead of GDPR for your staff and, if so, can you please provide me a copy.

Could you please provide me with your current Data Protection Policy regardless of whether it has been updated.

Yours faithfully,
B Harrison

AccessICOinformation, Information Commissioner's Office

Thank you for contacting the Information Commissioner’s Office. We confirm
that we have received your correspondence.

 

If you have made a request for information held by the ICO we will contact
you as soon as possible if we need any further information to enable us to
answer your request. If we don't need any further information we will
respond to you within our published, and statutory, service levels. For
more information please visit [1]http://ico.org.uk/about_us/how_we_comply

 

If you have raised a new information rights concern - we aim to send you
an initial response and case reference number within 30 days.

 

If you are concerned about the way an organisation is handling your
personal information, we will not usually look into it unless you have
raised it with the organisation first. For more information please see our
webpage ‘raising a concern with an organisation’ (go to our homepage and
follow the link ‘for the public’). You can also call the number below.

 

If you have requested advice - we aim to respond within 14 days.

 

If your correspondence relates to an existing case - we will add it to
your case and consider it on allocation to a case officer.

 

Copied correspondence - we do not respond to correspondence that has been
copied to us.

 

For more information about our services, please see our webpage ‘Service
standards and what to expect' (go to our homepage and follow the links for
‘Report a concern’ and ‘Service standards and what to expect'). You can
also call the number below.

 

If there is anything you would like to discuss with us, please call our
helpline on 0303 123 1113.

 

Yours sincerely

 

The Information Commissioner’s Office

 

Our newsletter

Details of how to sign up for our monthly e-newsletter can be found at
[2]http://www.ico.org.uk/tools_and_resource...

 

Twitter

Find us on Twitter at [3]http://www.twitter.com/ICOnews

 

References

Visible links
1. http://ico.org.uk/about_us/how_we_comply
2. http://www.ico.org.uk/tools_and_resource...
3. http://www.twitter.com/ICOnews

Information Commissioner's Office

29 January 2018

 

Case Reference Number IRQ0722672

 

Dear B Harrison
 
Request for Information
 
Thank you for your message which we received on 25 January, in which you
have made a request for information held by the Information Commissioner's
Office (ICO). 
 
Your request has been passed to the ICO’s Information Access Team, and is
being dealt with in accordance with the Freedom of Information Act 2000
under the reference number shown above. 
 
As you are probably aware the FOIA provides individuals with the right of
access recorded information held by public authorities. It is important to
note that a release under FOIA is applicant blind and therefore
effectively a release to the wider world.
 
We will respond to your FOIA request promptly, and no later than 22
February which is 20 working days from the day after we received your
request.
 
Should you wish to reply to this email please be careful not to amend the
information in the ‘subject’ field. This will ensure that your reply is
added directly to your case.
 
Yours sincerely
 
 
 
 

Danny Langley
Lead Information Access Officer
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow,
Cheshire SK9 5AF
T. 01625 545784  F. 01625 524510  [1]ico.org.uk  [2]twitter.com/iconews
Please consider the environment before printing this email

 
 

References

Visible links
1. http://ico.org.uk/
2. https://twitter.com/iconews

Information Commissioner's Office

21 February 2018

 

Case Reference Number IRQ0722672

 

Dear B Harrison

Request for Information
 
Further to our acknowledgement of 29 January we can now respond to your
request for information of 25 January.
 
We have dealt with your request in accordance with your ‘right to know’
under section 1(1) of the Freedom of Information Act 2000 (FOIA).
 
Request
 
In your email you asked:
 
“I was wondering whether you have revised your internal data protection
policy ahead of GDPR for your staff and, if so, can you please provide me
a copy. Could you please provide me with your current Data Protection
Policy regardless of whether it has been updated.”
 
Our response
 
I can confirm we have an internal compliance project to ensure ICO
compliance with GDPR although no ‘revised internal data protection policy’
is held at the time we received your request.  
 
I should clarify that our present ‘internal data protection policy’ is
codified not in one document but across a number of specific policies and
procedures which cover the various requirements that the Data Protection
Act places upon the ICO, both as the regulator of the Act but also as a
data controller for the personal information we process to undertake our
role.
 
Our current internal data protection policy is therefore covered in the
following documents:
 
The privacy notice on our website:
[1]https://ico.org.uk/global/privacy-notice/
 
Our strategy in relation to information governance:
[2]https://ico.org.uk/media/about-the-ico/p...
 
Our data retention schedule:
[3]https://ico.org.uk/media/about-the-ico/p...
 
Our procedure in relation to the disclosure of ICO staff information:
[4]https://ico.org.uk/media/about-the-ico/p...
 
And our procedure on handling subject access requests:
[5]https://ico.org.uk/media/about-the-ico/p...
 
Because we have published these documents on our website, they are
technically withheld under section 21 of the FOIA, which exempts
information which is ‘available to the requestor by other means’.
 
Review Procedure
 
I hope this provides you with some helpful information. However, if you
are dissatisfied with this response and wish to request a review of our
decision or make a complaint about how your request has been handled you
should write to the Information Access Team at the address below or e-mail
[6][ICO request email].
 
Your request for internal review should be submitted to us within 40
working days of receipt by you of this response. Any such request received
after this time will only be considered at the discretion of the
Commissioner.
 
If having exhausted the review process you are not content that your
request or review has been dealt with correctly, you have a further right
of appeal to this office in our capacity as the statutory complaint
handler under the legislation. To make such an application, please write
to our Customer Contact Team at the address given or visit our website if
you wish to make a complaint under the Freedom of Information Act.
 
A copy of our review procedure can be accessed from our website.
[7]here.
 
Yours sincerely
 
 

Danny Langley
Senior Information Access Officer
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow,
Cheshire SK9 5AF
T. 01625 545784  F. 01625 524510  [8]ico.org.uk  [9]twitter.com/iconews
Please consider the environment before printing this email

 
 
 

References

Visible links
1. https://ico.org.uk/global/privacy-notice/
2. https://ico.org.uk/media/about-the-ico/p...
3. https://ico.org.uk/media/about-the-ico/p...
4. https://ico.org.uk/media/about-the-ico/p...
5. https://ico.org.uk/media/about-the-ico/p...
6. mailto:[ICO request email]
7. https://ico.org.uk/media/about-the-ico/p...
8. http://ico.org.uk/
9. https://twitter.com/iconews