DIP Participants shall adhere to the Authority’s ‘Data Best Practice Guidance’.
Without prejudice to DSD003 ‘Assurance and Reporting’ the DIP Manager may undertake audits of DIP Participant’s compliance with this DSD.
DIP Participants shall provide such information (including copies of data protection policies, privacy policies and data protection impact assessments), co-operation, and assistance in relation to any request made by the DIP Manager (or any third party appointed by it to undertake such assurance activities, or its or their representatives) as the DIP Manager may reasonably require to demonstrate adherence to the DIP Rules in respect of any system interacting with the DIP.
For the avoidance of doubt, the purpose of such audits shall be to provide assurance that DIP Users have relevant policies and procedures in place. The DIP Manager provides no warranty to any DIP User (or to DIP Users as a whole) that a DIP Users policies and procedures are appropriate or fit for purpose.
In the event of a Personal Data Breach, where such breach relates to use of the DIP, DIP Users should inform the DIP Manager as soon as practicable and keep the DIP Manager informed as each action is taken.
Where a Personal Data Breach may impact more than one DIP User, the DIP Manager shall take all reasonable endeavours to ensure relevant information is passed to the required organisations, and actions are aligned in respect of potentially impacted DIP Users. So far as practicable, the DIP Manager shall pass information as soon as it can so that other DIP users may report within the required time frames.
Where the DIP Manager (or DIP Service Provider) identifies a Personal Data Breach (whether their own breach or somebody else’s) they shall liaise with the relevant DIP Users to ensure requisite actions are taken (including compliance with any legal requirements).
Dependent on the nature of the Personal Data Breach the DIP Manager may:
notify some, or all, DIP Users of the situation. DIP Users should immediately follow any instructions issued by the DIP Manager to mitigate the risk of the security incident;
Suspend a DIP User’s access in accordance with DSD002 ‘DIP Connection and Operation’ with no prior notification;
notify the Information Commissioner’s Office of the data breach; and
notify the police or other appropriate agency or body of the data breach.
Open – Data is made available for all to use, modify and distribute with no restrictions;
Public – Data is made publicly available but with some restrictions on usage;
Shared – Data is made available to a limited group of participants possibly with some restrictions on usage; and
Closed – Data is only available within a single organisation.
The definitions are based on the Open Data Institute’s data spectrum and shall be reviewed by the DIP Manager at least annually to ensure the DIP Rules align with industry best practice.
Once initial classification has occurred, triaging shall follow. This is the process by which actions to de-classify a data set can be identified. Consideration shall be given to without limitation:
Would the data set be less sensitive but retain its value after anonymisation / redaction?
Can risk be reduced by requiring licence restrictions?
Can risk be reduced if shared with a limited group or licence restrictions?
Can limiting audience or imposing licence restrictions reduce commercial risk?
Once the data has been triaged, mitigating actions shall be applied. Mitigation can include, but not be limited to:
Redaction – Removal of sensitive data;
Anonymisation – Removal of personal data;
Aggregation – Combine data sets so the collective sum is less sensitive;
Limitation – Only share with specific individuals or group(s);
Noise – Combine original data with meaningless data to confuse;
Delay – Wait until data is less sensitive before sharing;
Differential Privacy – Obscuring the data in such a way as to mask original identities;
Shift/rotate – Altering the position or orientation of spatial or time series data;
Randomisation – Making random changes to data; and
Normalisation – Modifying data to reduce the difference between individual subjects.
Following Mitigation, the requested data set shall be re-classified and, if deemed appropriate be subjected to further triage and mitigation until all stakeholders are in agreement that the correct classification has been achieved for the data set to meet the purpose for which it was requested.
The DIP Manager shall be obliged to produce open data guidance to complement the contents of this DSD which may be used by other DIP Participants in relation to their own open data policy.
Version | Date | Description of Change | Approval Reference |
1.0 | 01/10/24 | 01 October 2024 Non- Standard Release | P353/08 |