Wednesday, 24 September 2014

The relative merits of BCS and IAPP qualifications

The British Computer Association didn’t delay marking the exam I took last week. So, now I have another data protection qualification under my belt. Hurrah!

I had a very interesting response to my last blog. Someone who very kindly commented on the certification scheme run by the International Association of Privacy Professionals explained:

“I can tell you as someone who has the CIPP foundation and Europe qualification that they are ones you get so you can say you have them. They are totally different to ISEB in that ISEB teaches you a lot about the law and practice. Those with less experience in data protection may find the training for the CIPP regional exams useful but I didn't feel they taught me very much. The exams are all multiple choice and also quite subjective in places and there were questions for which two answers were right! You have to guess sometimes what the question setter's view on data protection is.

There were a lot of questions on the Data Retention Directive in my Europe exam, which is totally irrelevant to my job and to all those not working in telecoms companies. They were odd questions too, such as one asking you to pick the purpose from a list of 4 for which governments cannot bring in national data retention laws. I can't remember the choices but it was not something I had ever come across and in any event not something I would ever need to know as a DPO, given what the government decides to do is completely out of our hands!

They are though regional, so cannot go into as much detail as ISEB (and presumably Foundation) can, so they serve different needs. BCS ones are also focused on UK law, so probably a better bet for UK practitioners who want to gain in-depth knowledge.

I would say having done ISEB makes me a better DPO and having CIPP might provide an advantage with some employers. Being an IAPP member allows me to be part of a global networking group and the online resources and events that come with it. The CIPP qualifications are recognised in many parts of the world and are increasingly asked for in job ads, although primarily in the US. I was disappointed to see the recent changes to IAPP whereby we now have to do CPE to keep it.”

That person then went to express a concern that former IAPP members are therefore likely to lose their CIPP qualifications:

“I don't see how IAPP could ever insist you remove reference to the qualification just because you no longer pay them any money!”

They concluded:

“I think BCS is the way to go for actual learning and knowledge, and CIPP to have on your CV.”


So, if anyone fancies any hints and tips on how to prepare for the latest BCS exam, please don’t hesitate to ask.

.

Friday, 19 September 2014

BCS holds first public exam for its new Foundation Certificate

There were huge queues snaking around Covent Garden this morning. Television crews were also covering the great event. People had evidently been queuing for days to be one of the first to have what will become a very treasured possession.

I, on the other hand, wasn’t queuing for a new iPhone.

I was in a shorter queue, just a hundred yards away. I was waiting patiently to sit the very first public exam for the British Computer Society’s new Foundation Certificate in Data Protection at the BCS’s offices in Covent Garden.

To be fair, it wasn’t really a queue. After all, there was no-one on front of me, and there was no-one behind me, actually. I was the first (and quite possibly the only) candidate for this first public exam session.

How was it for me?

Well, I sat the 40-question multiple choice paper, laughed at some of the questions, and found it quite hard to understand just what the examiners were trying to get at with one or two of the questions.  It was all over in less than an hour.

And my impression?

I think it’s a really good introduction into the (occasionally mysterious) world of data protection.  Most data protection officers will find it a useful grounding – and a recognised qualification like this ought to place many people in good stead. It provides candidates with the basic framework around which the really complicated bits of data protection hang.

Candidates don’t need to have a brain the size of the planet to pass this exam.  And, rather than just testing the law, it also tests a candidate’s knowledge of what is best practice, as advocated by the ICO.

Candidates also don’t need to undertake a formal training session before sitting the exam.  It would certainly help if they were to attend one of the accredited training courses, though (that is, once the trainers have got their formal training accreditation from the BCS to deliver an appropriate training course). 

Candidates also don’t need deep pockets to keep the qualification. The BCS does not require certificate holders to subscribe to or to continue to subscribe to the BCS in order to keep it.  That may be of considerable interest to employers. 

I’m so keen on the concept that I’ve a good mind to apply to the BCS myself to become an accredited trainer. I’ve got my exam notes. I’ve prepared coursework that ought to entertain and educate students for the time that the BCS considers necessary to study for the qualification. (Which is just 16 hours). I’ve even sat the exam. What more could a group of motivated students want?

Those who pass this exam may feel that they’ve had enough data protection training for a while, and not feel a need to step up to the next level, which is the qualification more fondly known as the ISEB Certificate in Data Protection.   The ISEB has a reputation as the hardest data protection exam around.

Do make sure you’ve got ISEB’s little brother under your belt. That really will stand you in good stead during the initial phases of your data protection career. When you've more experience of the data protection world, then feel free to take the "full fat" ISEB data protection exam.

By launching this Foundation Certificate, candidates now face a choice between the BSI’s certification scheme and that operated by the International Association of Privacy Professionals.

As I have not taken any of the IAPP’s exams, I’m not qualified to express a preference between them. 

I’m just pleased that the CIPP/E exam potentially faces some stiff competition from the BCS.

.

Friday, 1 August 2014

How effective are Civil Monetary Penalties?

The ICO has recently, and without much publicity, published on its website a report it had commissioned on the effect of Civil Monetary Penalties.  It uses CMPs as both a sanction and a deterrent against a data controller or person who deliberately or negligently disregards the law. The overarching aim, according to the ICO, is to promote compliance and improve public confidence.

Given that this (19 page) report supports CMPs, I’m surprised that it has not attracted more attention.  Perhaps, if it were accompanied by an ICO press release, the privacy panoptican more fondly known as the IAAP daily digest might have drawn more attention to it. But no.

The document was formally published the week after many of the UK’s data protection finest had gathered in Central London to mark the launch of the ICO’s Annual Report for 2013-14. But I don't think that anyone at the event mentioned its forthcoming release.

The document contains the output from a team of independent researchers who had interviewed representatives from 14 organisations who had received a CMP. The researchers had also canvassed the views (by means of an online survey) of 85 organisations that had not received a CMP. It’s not clear whether any of the researchers who were involved in this exercise had received any formal data protection training. It might have added to the credibility of the report if the text had contained a section describing what data protection experience and qualifications the researchers actually had.

In the absence of this, we are left to ponder the impact of a report that summarises the views of a small number of respondents.

The key findings included the following:

  • Organisations that had been issued with a CMP subsequently took their data protection obligations more seriously, as a result of greater senior management buy-in.
  • This greater focus on compliance extended to peer organisations, especially those who appreciated that they shared a range of the shortcomings that had attracted the ire of the ICO’s enforcement team. 
  • There remains a lack of understanding of just what poor practices trigger the CMP threshold, particularly around the meaning of the terms “serious” and “substantial damage and distress”.
  •  Some respondents felt there was a lack of transparency about how CMPs were calculated. These could be linked to some organisations expressing discontent about the clarity of the Notice of Intent.

What we don’t know – because the report did not set out to inquire, was how these findings compare with the views (and subsequent behaviours) of data controllers who were subject to other ICO enforcement tools.

Have organisations that have received Enforcement Notices, or who have made Voluntary Undertakings, also taken their data protection obligations more seriously, as a result of greater senior management buy-in? And has this greater focus on compliance extended to peer organisations, especially those who appreciated that they shared a range of the shortcomings that had attracted the ire of the ICO’s enforcement team?

Once we understand the answers to those questions, we might be in a better position to appreciate the relative value of CMPs as an appropriate enforcement tool.

In these circumstances, I think the ICO is to be congratulated for not drawing too much attention to the report.

Source:


I am grateful to Janine Regan of Speechleys for drawing this report to my attention.

.

Thursday, 31 July 2014

Another hero leaves the stage

Well well well.

John Bowman, winner of the Data Protection Hero of the Year award for 2013, has moved on.

Lauded for his outstanding service to the country as the Ministry of Justice’s lead negotiator, overseeing the negotiations on the European Commission’s data protection proposals, John has left the MoJ and the Civil Service. His departure will leave a huge gap which, at this delicate stage in the DAPIX data protection discussions, will be extraordinarily difficult to fill.

John was appointed Head of EU and International Data Protection Policy at the MoJ in November 2011. He had completed a review of Claims Management Regulation, and previously led MoJ’s engagement with Muslim communities on raising awareness of domestic and matrimonial law.  He also headed the UK delegation to the 2011 Special Commission on the practical application of the Hague Conventions on international child abduction. So his has a huge range of experience that I’m sure most organisations would do anything to take advantage of.

All eyes will be focused on his LinkedIn account for the official announcement of his next role.

I’m sure I join many UK data protection professionals in wishing John the very best for the future.



Source:

http://dataprotector.blogspot.co.uk/2013/12/john-bowman-data-protection-hero-of.html



.