Report of the Comptroller and City Solicitor.
General Data Protection Regulation (GDPR)/ Data Protection Act (DPA) 2018 which provided Members with an update on the progress of phase 2 of the GDPR/DPA Implementation Project and the planned outcomes for the final phase of the work to embed GDPR/DPA implementation into the Corporation.
The Deputy Chairman (Member) expressed concern over phishing attacks, as the Members, Officers and employees of the City Corporation may be vulnerable to such attacks.
Members expressed concern with data protection policies and schools under the City of London Corporation, as schools may have different data protection and retention policies. The Comptroller & City Solicitor advised that the data protection officer can only advise, not direct, on how policies are followed; furthermore, there is no data protection officer for John Cass and the Academies.
RESOLVED – That Members:
1) note the report; and,
2) agree that GDPR/DPA monitoring reports in particular in relation to data breaches take place three times per year.