Digital Data Protection Impact Assessment (DPIA) ALPHA

Project details:

Organisation Greater Manchester Combined Authority
Department Digital - Information Governance
Collaboration Level Share Ideas
Budget £50K > £100k
Key Contact Stephen Girling
Phase start 03 December 2018
Phase Estimated end 22 May 2019

Tags

Description

Data Protection Impact Assessment (DPIA) are a requirement of data protection legislation but are seen as an intensive and onerous process. We know a range of templates are currently used resulting in a complicated and fragmented approach particularly across partnerships. Challenges include that process are reliant on a small number of specialist staff causing capacity issues. Process are not user friendly enough to enable general staff to complete them and there is a lack of confidence / understanding to answer key questions appropriately. There are issues around document control including tracked changes and responses to Data Protection Officer recommendations. A more coherent approach to access and storage is also need, DPIAs are living documents – A central repository will allow ease of access across delivery teams and the sharing of best practice. There is also the opportunity to reduce duplication by ensuring information collated through DPIA processes is used to support complementary processes e.g. risk registers and risk identification.

Our solution is the creation of a universal and compliant Digital DPIA Tool to empower and support staff. It will also support the generation of a privacy risk register, an aspect that has been highlighted as a challenging area of work.

At a basic level success would the creation of an easy to use product with minimal IT support, hosting costs and training requirements that would be used with GM and has the potential to be used at scale. Creating a more ergonomic and user friendly DPIA process that all staff feel comfortable with and providing crucial technical support. Saving partners time and capacity but ultimately removing barriers to the creation of compliant DPIA. Supporting a culture shift that meets the legal requirement of ‘data protection by design and by default’. Success would be measured by user engagement, key partner feedback and ultimately through the quality of DPIAs produced with GM.


People

Watchers

Contributors

Status Updates

07 June 2019

  • Stephen Girling

    We have really valued collaborating with the Information Commissioner's Office (ICO) on this project. Their contribution as subject matter experts as helped us shape the content of the tool and they will be an integral partner as we move into the next phase of the project. This is a link to the ICO's newsletter where our project is reported on: http://newsletter.ico.org.uk/q/1AFNnrfY5G/wv 

22 May 2019

22 May 2019

  • Stephen Girling

    Hello all!

    We have reached the end of the Digital DPIA Alpha project!

    It has been a pleasure running this project and we are very excited for what the future might hold. This tool really does have the potential for national scalability and we really want to push on to the next level in the future.

    For a glimpse of the vision of this project, check out our video:

    You can find the code output from the tool we developed on GitHub here: https://github.com/DigitalDPIA/DigitalDPIA 

    We now await feedback on the project and will be submitting a request for support for the next phase in due course.

    For any information on the project please feel free to get in touch: stephen.girling@greatermanchester-ca.gov.uk

    Hopefully this is not goodbye, just a see you soon!

    Steve
     

03 May 2019

  • Stephen Girling

    Hola!

    If you were unable to join us for the show and tell sessions in April, you can now watch the recording below or on YouTube here: https://t.co/9MaG8tZc9l 

    Happy viewing!

    Steve


26 April 2019

  • Stephen Girling

    Project Update Friday 26th April

    Hi all! 

    We are fast approaching the end date of our project, the 21st May! This is what has been happening over the last two weeks:

    Show and Tell Session

    Over the past two weeks we held two show and tell online webinars for the Digital DPIA project. These webinars gave people an overview of the project, why we are doing what we are doing, the benefits and the people who have been involved. We then gave a presentation of the functionality within the tool which was great in demonstrating what we have achieved. WE didn't showcase the actual test environment as development was on-going and I know from past experience in other projects, demos of tests environments invariably show up something unexpected! So we gave a presentation instead but we think the messages got across. We will look to create some videos of the actual system before the close of the project. 

    Overall, the feedback of the project has been very positive and it was a pleasure to present the project to our stakeholders.

    I think it is very likely that there will be more of these sessions throughout May so if you have been unable to attend the show and tell sessions in April, please do reach out to me and I will add you to the list of people for the next one.

    Development

    We have now reached the significant milestone of coming to the end of the development phase. We are extremely proud of all that we have achieved in the past 12 weeks and we have reached a stage where we have a prototype model which really does demonstrate the value this tool will bring to organisations. No new development will be started until the next Beta phase but there will be some continuing work on fixing bugs and tidying up the sandpit environment. 

    Final Three Weeks

    We now enter the final phase of the project where we write the end of project report. This will include a business case, user research report, benefits realisation document and recommendations for the next phase. In the next three weeks we will be looking at creating some video walkthroughs of the actual system too so look out for these on our YouTube channel. 

    As always, we will be tweeting via @gmcadigital or have a search for the #FixThePlumbing and #DigitalDPIA.

    Steve



26 April 2019

  • Stephen Girling

    Project Update Friday 26th April

    Hi all! 

    We are fast approaching the end date of our project, the 21st May! This is what has been happening over the last two weeks:

    Show and Tell Session

    Over the past two weeks we held two show and tell online webinars for the Digital DPIA project. These webinars gave people an overview of the project, why we are doing what we are doing, the benefits and the people who have been involved. We then gave a presentation of the functionality within the tool which was great in demonstrating what we have achieved. WE didn't showcase the actual test environment as development was on-going and I know from past experience in other projects, demos of tests environments invariably show up something unexpected! So we gave a presentation instead but we think the messages got across. We will look to create some videos of the actual system before the close of the project. 

    Overall, the feedback of the project has been very positive and it was a pleasure to present the project to our stakeholders.

    I think it is very likely that there will be more of these sessions throughout May so if you have been unable to attend the show and tell sessions in April, please do reach out to me and I will add you to the list of people for the next one.

    Development

    We have now reached the significant milestone of coming to the end of the development phase. We are extremely proud of all that we have achieved in the past 12 weeks and we have reached a stage where we have a prototype model which really does demonstrate the value this tool will bring to organisations. No new development will be started until the next Beta phase but there will be some continuing work on fixing bugs and tidying up the sandpit environment. 

    Final Three Weeks

    We now enter the final phase of the project where we write the end of project report. This will include a business case, user research report, benefits realisation document and recommendations for the next phase. In the next three weeks we will be looking at creating some video walkthroughs of the actual system too so look out for these on our YouTube channel. 

    As always, we will be tweeting via @gmcadigital or have a search for the #FixThePlumbing and #DigitalDPIA.

    Steve



05 April 2019

  • Stephen Girling

    Project Update Friday 5th April

    This week Peter and I attended the LocalGovDigitalCamp North West event in Manchester. We were invited along to give a presentation on the Digital DPIA project. 

    It was great to give people an overview of the project and what we are looking to achieve. The reaction from the attendees was warm with many paying their compliments to the presentation throughout the day. 

    I chatted to one person whose experience of DPIA's reflected very much the people we have spoken to: they are long, hard work, hard to understand and go endlessly back and forth before they are approved. He stressed how good it would be for there to be guidance within a DPIA which explains what the more complex questions mean and prompt what the user should be thinking of when they complete the form. It is reassuring that we have already considered this and worked it into our development but it is always good to hear from different people the issues we are addressing.

    Another person I spoke to asked me if I had knowledge of a specific DPIA being completed for a particular type of processing. It wasn’t something I was familiar with however this lead to us chatting about how it might be good if it was possible to access existing DPIA's that had been completed for a particular system or type of processing to give people a head start on completing their own. I mentioned this kind of functionality currently exists in the Information Sharing Gateway for Sharing Agreements and it is an intriguing idea for the later phases of this project to look to build a similar functionality or perhaps a stock library of DPIA's. No doubt there are a lot of things to consider with the actual practicalities of this but as a suggestion for consideration, I found it very interesting. 

    Along with ourselves there was a mixture of speakers on the day talking in different ways about digital innovation and ways of working. A common theme running through a lot of the presentations was keeping people, whether that be staff, residents or customers at the heart of what we are doing. It was perhaps surmised best by Vimla Appadoo from FutureGov who said "Digital is the journey, not the outcome." 

    There was a consistent message from a number of speakers regarding taking an Agile approach to digital. The idea of working iteratively, having a big vision but starting small to achieve it, not being afraid to fail, and being able to work in small dynamic teams echoed the MHCLG approach to their Local Digital Funded projects. It seems increasingly, more and more people are moving away from traditional 'Big Bang' Waterfall approaches to an Agile approach that better facilitates changes to scope, and also the ability to stop a project if it is not working without huge financial implications. Moving to a truly Agile approach requires a top down system change and so for now we find ourselves in a hybrid world of agile delivery but often with the requirement for the more traditional styles of project governance. I am sure though, that we are all on a journey and overtime Agile will become the normalised way of working. 

    I enjoyed staying for the remainder of the day to attend the workshops in the afternoon. I particularly enjoyed a lively discussion regarding Councils having a Digital Strategy as this was very relevant to some other work me and my team are doing regarding a Greater Manchester Information Strategy. The Digital DPIA will become one of the key tools that underpin this strategy so hearing people discuss what they want from a Digital strategy gave good learning to inform the Information strategy. 

    Another interesting workshop in the afternoon was a demonstration of how Kirklees Council have developed an Alexa skill so that residents can ask Alexa about their bin collections and report missed collections. This, along with advancements to AI, chatbots etc. demonstrate some exciting times ahead in this arena.

    Oh, and I also won some pretty decent Bluetooth headphones in a raffle which was a lovely bonus!

    There will hopefully more opportunities such as this one to go to events and present on the work we are doing. I chatted to Shelley from the iNetwork and we think the Digital DPIA project could certainly be a topic at their next events. 

    Development on the Digital DPIA tool continued this week with the focus being on the legal section. 

    Show and Tell sessions are planned for Tuesday 16th and Tuesday 23rd April so look out for invitations to these soon!

    If you haven't checked out the latest Digital DPIA video, do so! The link is in the post below!

    Arrivederci! 

    Steve

    Here are some photos from the event including a particularly powerful quote from Madeleine Albright