30.12.2014 Views

The Learning and Skills Councils Annual Report and Accounts for ...

The Learning and Skills Councils Annual Report and Accounts for ...

The Learning and Skills Councils Annual Report and Accounts for ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Management Commentary<br />

<strong>Report</strong>ing of personal data‐related incidents<br />

<strong>The</strong> tables that follow have been prepared in response to Cabinet Office guidance (originally issued to the LSC via the<br />

Department <strong>for</strong> Universitities, Innovation <strong>and</strong> <strong>Skills</strong> (DIUS) on 2 May 2008) on reporting personal data-related incidents in<br />

the management commentary section of departmental resource accounts.<br />

Table 1: Summary of protected personal data-related incidents <strong>for</strong>mally reported to the In<strong>for</strong>mation<br />

Commissioner’s Office in 2009–10<br />

Date of incident<br />

(month)<br />

May 2009<br />

Further in<strong>for</strong>mation<br />

on in<strong>for</strong>mation risk<br />

Nature of incident<br />

Loss arising from<br />

theft of personal data<br />

from vehicle<br />

Nature of data<br />

involved<br />

Learner’s personal<br />

data<br />

Number of people<br />

potentially affected<br />

Notification steps<br />

5 Notification to BIS,<br />

the In<strong>for</strong>mation<br />

Commissioner, police<br />

<strong>and</strong> the 5 individuals<br />

<strong>The</strong> LSC continued to monitor <strong>and</strong> assess its in<strong>for</strong>mation risks, in the light of the incident noted<br />

above, in order to identify <strong>and</strong> address any weaknesses <strong>and</strong> ensure continuous improvement of<br />

its systems.<br />

Incidents deemed by the Data Controller not to fall within the criteria <strong>for</strong> reporting to the In<strong>for</strong>mation Commissioner’s<br />

Office but recorded centrally within the department are set out in Table 2. Small, localised incidents are not recorded<br />

centrally <strong>and</strong> are not cited in these figures.<br />

Table 2: Summary of other protected personal data-related incidents in 2009–10<br />

Category Nature of incident Total<br />

I<br />

Loss of inadequately protected electronic equipment, devices or paper<br />

documents from secured government premises<br />

Nil<br />

II<br />

III<br />

Loss of inadequately protected electronic equipment, devices or paper<br />

documents from outside secured government premises<br />

Insecure disposal of inadequately protected electronic equipment, devices or<br />

paper documents<br />

IV Unauthorised disclosure Nil<br />

V Other Nil<br />

Nil<br />

Nil<br />

16 LSC <strong>Annual</strong> <strong>Report</strong> <strong>and</strong> <strong>Accounts</strong> 2009–10

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!