Work First Scotland: privacy impact assessment
Privacy impact assessment for our Work First Scotland programme, which will provide employability support for disabled people under the terms of the Scotland Act 2016.
7. Risks identified and appropriate solutions or mitigation actions proposed
Is the risk eliminated, reduced or accepted?
Risk | Ref | Solution or mitigation | Result |
---|---|---|---|
Mismanagement by DWP staff – eg claimants who are not eligible for WFS are referred in error and therefore data shared inappropriately |
DPF 01 |
|
As a result, this risk is reduced, but not eliminated. It can be accepted on the grounds that monitoring referrals will be a central role of the Operational Delivery Group. |
Personal data is mis-managed by SG service providers |
DPF 02 |
|
Accept – risk is low |
Personal data is mis-managed by SG staff |
DPF 03 |
|
Accept – risk is low |
Systems: there is the potential for systems to be hacked, giving access to personal data. |
DPF 04 |
|
Accept – risk is low |
General Data Protection Regulation – Fair Processing Notices do not meet new standard. |
DPF 05 |
|
Accept – risk is low |
The SRO referral process introduces additional risk that personal data will become accessible. |
DPF 06 |
|
Accept – risk is moderate |
Contact
There is a problem
Thanks for your feedback