Print

Print


Taking iphones first. My understanding is that the finger print information is only held locally to identify the individual, but I may be wrong on that and happy to be corrected. 

As for Whatsapp, the key here is to have some acceptable use procedure/policy in place to ensure that staff are aware of their oblgations in respect of personal data.

The next thing to consider is what risk do each of these pose. If iPhones is as I said, and WhatsApp policies forbid the transfer of sensitive data, then I would say that the risks are not high and therefor a full DPIA is not needed.

Just my off the cuff, Friday afternoon thoughts... I feel certain that some of what I have said will be challenged, but hopefully it will encourage debate.

Simon.

Simon Howarth MSc. MBCS CITP CIPP/E
Director & Consultant, Data Protection Officer

The Information Edge
(Webtech Systems Limited)

Tel. +44 (0) 7836 365588
www.informationedge.co.uk

-----Original Message-----
From: This list is for those interested in Data Protection issues <[log in to unmask]> On Behalf Of Danny Budzak
Sent: 22 August 2019 16:41
To: [log in to unmask]
Subject: [data-protection] Privacy Impact Assessment and work mobile phones

Hi, 

I realise it is nearly the bank holiday and this may disappear into the ether....but on the off chance that anyone is still concentrating...

Has anyone done a Data Privacy Impact Assessment on work supplied smartphones - particulary the iPhone? 

Three issues have immediately presented themselves to me: 

1. Use of fingerprint to set up access to iPhone - this seems to be voluntary for security, but where does the data go? 

2. Uncontrolled use of WhatsApp

3. WhatsApp in general in terms of compliance...

If this too much on a Thursday afternoon, I will understand so...

...have a good (Bank Holiday) weekend

thanks + rgds

Danny

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
     All archives of messages are stored permanently and are
      available to the world wide web community at large at
      http://www.jiscmail.ac.uk/lists/data-protection.html
     If you wish to leave this list please send the command
       leave data-protection to [log in to unmask] All user commands can be found at https://www.jiscmail.ac.uk/help/subscribers/subscribercommands.html
 Any queries about sending or receiving messages please send to the list owner
              [log in to unmask]
  Full help Desk - please email [log in to unmask] describing your needs
        To receive these emails in HTML format send the command:
         SET data-protection HTML to [log in to unmask]
   (all commands go to [log in to unmask] not the list please)
    ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
     All archives of messages are stored permanently and are
      available to the world wide web community at large at
      http://www.jiscmail.ac.uk/lists/data-protection.html
     If you wish to leave this list please send the command
       leave data-protection to [log in to unmask]
All user commands can be found at https://www.jiscmail.ac.uk/help/subscribers/subscribercommands.html
 Any queries about sending or receiving messages please send to the list owner
              [log in to unmask]
  Full help Desk - please email [log in to unmask] describing your needs
        To receive these emails in HTML format send the command:
         SET data-protection HTML to [log in to unmask]
   (all commands go to [log in to unmask] not the list please)
    ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^