Two really quick points. The it literate are the ones I am thinking of who have seriously advanced skills, enough to modify the system without IT, (knew of an ex army intel information security officer working in a non-it post). He would have no qualms about using his skill set on the local government system. I am less worried by the lowest common denominator as they would not challenge the system.
On the second point, by definition the organisation *has* to be a data controller to dispose of personal information on its system. Surely, deleting personal information is within the definition of the DPA.
I may have an idiosyncratic view of the dpa, but I would suggest that unauthorised uploading of personal information is more problematic in terms of the dpa than it would appear at first glance.
If someone runs an unauthorised chess club membership from their work system, that is going to be a huge headache from a dpa perspective.
I will submit this to the ICO and see what comes back.
Thanks to everyone who contributed to the theme, it has helped me clarify my thinking.
Best
Lawrence
Lawrence W. Serewicz
Principal Information Management Officer
Room 4/140
Durham County Council
DH1 5UF
0191-372-8371
Help protect our environment by only printing this email if absolutely necessary. The information it contains and any files transmitted with it are confidential and are only intended for the person or organisation to whom it is addressed. It may be unlawful for you to use, share or copy the information, if you are not authorised to do so. If you receive this email by mistake, please inform the person who sent it at the above address and then delete the email from your system. Durham County Council takes reasonable precautions to ensure that its emails are virus free. However, we do not accept responsibility for any losses incurred as a result of viruses we might transmit and recommend that you should use your own virus checking procedures.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
All archives of messages are stored permanently and are
available to the world wide web community at large at
http://www.jiscmail.ac.uk/lists/data-protection.html
If you wish to leave this list please send the command
leave data-protection to [log in to unmask]
All user commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm
Any queries about sending or receiving messages please send to the list owner
[log in to unmask]
Full help Desk - please email [log in to unmask] describing your needs
To receive these emails in HTML format send the command:
SET data-protection HTML to [log in to unmask]
(all commands go to [log in to unmask] not the list please)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
|