Work First Scotland: privacy impact assessment
Privacy impact assessment for our Work First Scotland programme, which will provide employability support for disabled people under the terms of the Scotland Act 2016.
8. Incorporating Privacy Risks into planning
Explain how the risks and solutions or mitigation actions will be incorporated into the project/business plan, and how they will be monitored. There must be a named official responsible for addressing and monitoring each risk.
Risk | Ref | How risk will be incorporated into planning | Owner |
---|---|---|---|
Mismanagement by DWP staff – eg claimants who are not eligible for WFS are referred in error and therefore data shared inappropriately |
DPF 01 |
|
JCP Integration Team Leader |
Personal data is mis-managed by SG service providers |
DPF 02 |
|
Service Delivery Team Leader |
Personal data is mis-managed by SG staff |
DPF 03 |
|
Service Delivery Team Leader |
Systems: there is the potential for systems to be hacked, giving access to personal data. |
DPF 04 |
|
JCP Integration Team Leader |
General Data Protection Regulation – Fair Processing Notices do not meet new standard. |
DPF 05 |
|
Service Delivery Team Leader |
The SRO referral process introduces additional risk that personal data will become accessible. |
DPF 06 |
|
Service Delivery Team Leader |
Contact
There is a problem
Thanks for your feedback