We never used "Live" data for a test system, always dummy records (made
up) purely because the use i.e. processing would not satisfy most if not
all of the DP Principles.
Jane Holden
Corporate Services Officer
Legal Services
Barrow-in-Furness Borough Council
Town Hall, Duke Street
Barrow-in-Furness
Cumbria LA14 2LD
Tel: 01229 876452
Fax: 01229 876515
-----Original Message-----
From: This list is for those interested in Data Protection issues
[mailto:[log in to unmask]] On Behalf Of Mike Gater
Sent: 28 June 2012 14:22
To: [log in to unmask]
Subject: [data-protection] Use of Live (personal) data used within
training database
Dear all,
Our organisation is about to migrate multiple HR systems (Payroll,
People
data, leave / sickness absence and security screening data) into one
"single" system. ~15,000 employee details.
A copy database has been created for future tech support (testing
environment) and it has been proposed that a further copy is created and
subsequently used for system administrator training. The issue I have is
that both of these instances will have "Live" data (at the time of
migration) but will not be maintained. As you can imagine some of this
data
will be rather sensitive, but I take comfort that the trainee would only
have access to see the same data that they would see within the
Production
system. That said, if an individual was to move around within the
organisation, it is possible the administrator will still be able to see
data about that individual (albeit old data), when in production they
would
no longer have the access/privilege to do so.
As you can see, for every comfort or justification, I find a worry or
issue..... Am I over cooking this, or are there more serious
implications
than I have thought of (I have not listed all my concerns above)? Has
anyone had any experience of this scenario?
Any advice / comments would be greatly received.
Kind Regards
Mike
Records & Information Management
"The information contained in this email may be commercially sensitive
and/or legally privileged. It is intended solely for the person(s) to
whom it is addressed. If you are not a named recipient, you are on
notice of its status. Please notify the sender immediately by reply
e-mail and then delete this message from your system. You must not
disclose it to any other person, copy or distribute it or use it for any
purpose.
Views expressed in this email are not necessarily those of Sellafield
Ltd.
Sellafield Ltd, a company owned by Nuclear Management Partners Ltd, is
registered in England and Wales, Company number 1002607. The registered
office is situated at Booths Park, Chelford Road, Knutsford, Cheshire
WA16 8QZ."
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
All archives of messages are stored permanently and are
available to the world wide web community at large at
http://www.jiscmail.ac.uk/lists/data-protection.html
If you wish to leave this list please send the command
leave data-protection to [log in to unmask]
All user commands can be found at
http://www.jiscmail.ac.uk/help/commandref.htm
Any queries about sending or receiving messages please send to the list
owner
[log in to unmask]
Full help Desk - please email [log in to unmask] describing your
needs
To receive these emails in HTML format send the command:
SET data-protection HTML to [log in to unmask]
(all commands go to [log in to unmask] not the list please)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
Barrow Borough Council - Enhancing the economic and social future
of the Borough.
Think - UK businesses use 2 million tonnes of paper each year - do
you really need to print this e-mail?
This e-mail and any files transmitted with it are confidential and
intended solely for the use of the individual to whom it is
addressed. Any view or opinions presented are solely of the author
and do not necessarily represent those of Barrow Borough Council.
If you are not the intended recipient you may not use, disclose,
distribute, copy, print or rely on this e-mail. If you have received
this e-mail in error please contact the sender.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
All archives of messages are stored permanently and are
available to the world wide web community at large at
http://www.jiscmail.ac.uk/lists/data-protection.html
If you wish to leave this list please send the command
leave data-protection to [log in to unmask]
All user commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm
Any queries about sending or receiving messages please send to the list owner
[log in to unmask]
Full help Desk - please email [log in to unmask] describing your needs
To receive these emails in HTML format send the command:
SET data-protection HTML to [log in to unmask]
(all commands go to [log in to unmask] not the list please)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
|