Governance, Organisation, Law, Regulation and Standards QAN 603/0855/2

Size: px
Start display at page:

Download "Governance, Organisation, Law, Regulation and Standards QAN 603/0855/2"

Transcription

1 S Level 4 ertificate in Governance, Organisation, Law, Regulation and Standards QN 603/0855/2 Specimen Paper Record your surname/ last/ family name and initials on the nswer Sheet. Specimen paper only. 20 multiple-choice questions 1 mark awarded to each question. Mark only one answer for each question. There are no trick questions. number of possible answers are given for each question, indicated by either... or. Your answers should be clearly indicated on the nswer Sheet. The pass mark is 13/20. This is a specimen examination paper only. The full paper will contain 40 questions with a pass mark for the full paper of 26/40. opying of this paper is expressly forbidden without the direct approval of S, The hartered Institute for IT. opyright S 2016 Page 1 of 8 S Level 4 ertificate in Specimen Paper

2 1 Who are the responsible officers within the HMG Information Governance Framework? a) hief Executive. b) ccounting Officer. c) ccreditor. d) Senior Information Risk Owner. a, c and d only. a, b and c only. b, c and d only. a, b and d only. 2 The Microsoft orporation versus United States of merica (2013) case, colloquially known as the Microsoft Ireland case, was concerned with which matter of international law? The applicability of data disclosure warrants served on the US parent of an EU company for access to personal data stored in the EU. The application of anti-trust provisions in US law to a US company's activities in the European Union. The responsibility of a US company to inform EU citizens of the disclosure of their personal information when demanded by a US warrant. Microsoft's circumvention of privacy features built in to common browsers to allow the continued use of directed advertising. 3 Which of the following certifications are specifically concerned with ata entre security? a) SO 2. b) NSI/TI c) S EN d) ISO/IE (it's a standard for ata Storage devices in general) a and d only. b and d only. a only. c only. opyright S 2016 Page 2 of 8 S Level 4 ertificate in Specimen Paper

3 4 Who is accountable for information security within an ISO27001 certified organisation? The Information Security Manager. Everybody. The oard. The ata Protection Officer. 5 PI-SS forbids the storage of what sort of data? ard Holder ata (H). Personally Identifiable Information (PII). Primary ccount Number (PN). Sensitive uthentication ata (S). 6 Which of the following activities is core to a Security Operations entre? Resetting a user's password. Reviewing a rejected attempt to access a sensitive document. Provisioning a new user's access. llowing a user exceptional access to another user's online calendar. 7 resident of a nursing home is being treated for a serious, but not lifethreatening condition in hospital. Prior to discharge, the consultant wishes to share information about the resident s condition with the nursing home. Which is the MOST appropriate answer? The consultant can share relevant information on the resident s condition and ongoing treatment with medical staff who are employed by the nursing home. The consultant must first get the explicit and informed consent of the patient, then relevant information may be shared with the nursing home. The consultant can only give information regarding ongoing treatment that the patient cannot share themselves. The consultant can share relevant information if it is covered by a ata Sharing greement between the hospital and the nursing home. opyright S 2016 Page 3 of 8 S Level 4 ertificate in Specimen Paper

4 8 n employee has been accused of running their own business in work time and using work IT. The organisation, which is NOT a law enforcement body, wishes to investigate in accordance with their disciplinary policy. Which law or regulatory guidance is MOST pertinent? Police and riminal Evidence ct Information ommissioner's Employment Practices ode. Telecommunications (Lawful usiness Practice) (Interception of ommunications) Regulations Regulation of Investigatory Powers ct Which of the following types of devices would USULLY be certified under the ESG ssisted Product Scheme (PS)? Firewalls. ryptographic Link Encryptors. Intrusion etection Systems. Intrusion Protection Systems. 10 Which new offence under the omputer Misuse ct was created by the Serious rime ct 2015? Unauthorised acts causing, or creating risk of, serious damage. Unlawful obtaining etc. of personal data. Making, supplying or obtaining articles for use in offence under sections 1 or 3. Unauthorised access with intent to commit or facilitate commission of further offences. opyright S 2016 Page 4 of 8 S Level 4 ertificate in Specimen Paper

5 11 What is the name of the replacement scheme for the EU / US Safe Harbour greement? Safe Harbour 2. Privacy Guard. Safe Guard. Privacy Shield. 12 Which is the EST order for implementing an ISO27001 compliant ISMS? a) Risk assessment. b) Executive sponsorship. c) ontrols selection. d) Scoping. a, b, c, d. a, c, d, b. b, d, a, c. d, b, c, a. 13 What is the name of the international agreement, which is similar to the US ITR regulations? London. Vienna. hicago. Wassenaar. opyright S 2016 Page 5 of 8 S Level 4 ertificate in Specimen Paper

6 14 Which of the following are significant aspects introduced by the General ata Protection Regulation? a) hanges to the meaning of consent. b) The accountability principle. c) The right to be forgotten. d) Mandatory breach reporting.. a, b and c only.. a, b and d only.. a, c and d only.. b, c and d only. 15 The ata Protection ct 1998 s29 exemption, for notifying data subjects about data disclosures, applies to which of the following?. National Security.. Health, Education and Social Work.. rime and Taxation.. Transfers to parent organisations. 16 The project officer, in charge of an organisation s ISO27001 compliance programme, has been asked to advise a small customer finance office that is currently struggling to achieve PI-SS certification. What might the project officer suggest as the EST way forward? The finance office should carry on with PI-SS as that will be sufficient for ISO27001 compliance. The finance office should stop PI-SS certification as ISO27001 compliance will be sufficient. The finance office should be removed from the ISO27001 scope until they have achieved PI-SS as the standards are significantly different. The finance office should continue with both ISO27001 and PI-SS compliance efforts as the standards are very similar. opyright S 2016 Page 6 of 8 S Level 4 ertificate in Specimen Paper

7 17 Which ISO/IE standard specifically covers cloud services? ISO/IE ISO/IE ISO/IE ISO/IE The Information ommissioner OUL issue a monetary penalty under s55 of the ata Protection ct 1998 for which of the following breaches of the ct? Failure to notify the ommissioner that the organisation is processing personal data. Unlawfully obtaining personal data. significant data loss uncovered as a result of a s41 assessment notice. negligent breach of Principle 1 that might cause substantial distress. 19 Who does an expert witness act on behalf of? a) The prosecuting legal team. b) The defence legal team. c) The court. d) The rown Prosecution Service. a and b. c only. a and d. d only. 20 Which of the following is NOT an example of the principle of least privilege? personal assistant having delegate access to their boss's calendar. web-server instance running within a chroot environment. system administrator being required to log in as a normal user and then use sudo or Run s. n SNMP daemon running with local system administration privileges. opyright S 2016 Page 7 of 8 S Level 4 ertificate in Specimen Paper

8 -End of Paper- opyright S 2016 Page 8 of 8 S Level 4 ertificate in Specimen Paper

STEP BY STEP SCHOOL. Data Protection Policy and Privacy Notice

STEP BY STEP SCHOOL. Data Protection Policy and Privacy Notice Data Protection Policy and Privacy Notice 1 Contents 1. Aims... 3 2. Legislation and guidance... 3 3. Definitions... 3 4. The data controller... 4 5. Data protection principles... 4 6. Roles and responsibilities...

More information

Precedence Privacy Policy

Precedence Privacy Policy Precedence Privacy Policy This Policy describes how Precedence Health Care Pty Ltd (Precedence), and any company which it owns or controls, manages personal information for which it is responsible, specifically

More information

Office of the Australian Information Commissioner

Office of the Australian Information Commissioner Policy and Procedure Name Privacy Policy and Procedure Version 1.0 Approved By Chief Executive Officer Date Approved 19/10/2016 Review Date 30/06/2017 Opportune Professional Development in accordance with

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Document Number 2010/35/V1 Document Title Data Protection Policy Author Nic McCullagh Author s Job Title Information Governance Manager Department IM&T Ratifying Committee Capacity

More information

DATA PROTECTION POLICY (in force since 21 May 2018)

DATA PROTECTION POLICY (in force since 21 May 2018) DATA PROTECTION POLICY (in force since 21 May 2018) This Data Protection Policy is issued by IDM Südtirol - Alto Adige, with registered office in Piazza della Parrocchia n. 11 39100, Bolzano (hereinafter

More information

Standard Operating Procedures (SOP) Research and Development Office

Standard Operating Procedures (SOP) Research and Development Office Standard Operating Procedures (SOP) Research and Development Office Title of SOP: Principles of Data Collection and Storage SOP Number: 8 Supercedes: 1.0 Effective date: August 2013 Review date: August

More information

Personal Identifiable Information Policy

Personal Identifiable Information Policy Personal Identifiable Information Policy Page 1 of 24 Document Management Title of document Type of document Description IG2 Personal Identifiable Information Policy Policy This Policy supports the Information

More information

SM-PGN 01- Security Management Practice Guidance Note Closed Circuit Television (CCTV)-V03

SM-PGN 01- Security Management Practice Guidance Note Closed Circuit Television (CCTV)-V03 Security Management Practice Guidance Note Closed Circuit Television (CCTV)-V03 Date Issued Issue 7 Sep 17 Issue 8 Dec 17 Issue 9 Mar 18 Planned Review September- 2018 SM-PGN 01- Part of NTW(O)21 Security

More information

WISHIN Statement on Privacy, Security, and HIPAA Compliance - for WISHIN Pulse

WISHIN Statement on Privacy, Security, and HIPAA Compliance - for WISHIN Pulse Contents Patient Choice... 2 Security Protections... 2 Participation Agreement... 2 Controls... 3 Break the Glass... 3 Auditing... 3 Privacy Protections... 4 HIPAA Compliance... 4 State Law Compliance...

More information

Home Energy Saving (HES) scheme - Homeowner Application Form Version 10.0

Home Energy Saving (HES) scheme - Homeowner Application Form Version 10.0 Home Energy Saving (HES) scheme - Homeowner Application Form Version 10.0 Instructions for Completing the Application Form All fields in the form are MANDATORY. Incomplete applications will be returned.

More information

Student Privacy Notice

Student Privacy Notice Student Privacy Notice Queen s University Belfast collects, holds and processes personal information or data relating to its students. We need to do this in order for the University to carry out its functions

More information

The EU GDPR: Implications for U.S. Universities and Academic Medical Centers

The EU GDPR: Implications for U.S. Universities and Academic Medical Centers The EU GDPR: Implications for U.S. Universities and Academic Medical Centers Mark Barnes February 21, 2018 Agenda Introduction Jurisdictional Scope of the GDPR Compared with the Directive Offering Goods

More information

Home Energy Saving (HES) scheme - Homeowner Application Form Version 1.0

Home Energy Saving (HES) scheme - Homeowner Application Form Version 1.0 Home Energy Saving (HES) scheme - Homeowner Application Form Version 1.0 Instruction for Completing the Application Form All fields in the form are MANDATORY. Incomplete applications will be returned.

More information

PRIVACY AND NATURAL MEDICINE PRACTITIONERS

PRIVACY AND NATURAL MEDICINE PRACTITIONERS PRIVACY AND NATURAL MEDICINE PRACTITIONERS Table of Contents Introduction... 3 Privacy Key Concepts... 4 Summary of a Practitioner s Privacy Obligations... 5 Collecting Information... 5 Storage and Maintenance...

More information

INVEST NI INNOVATION VOUCHER SAMPLE ON-LINE APPLICATION FORM SAMPLE APPLICATION. Applications must be submitted through our online application form.

INVEST NI INNOVATION VOUCHER SAMPLE ON-LINE APPLICATION FORM SAMPLE APPLICATION. Applications must be submitted through our online application form. INVEST NI INNOVATION VOUCHER SAMPLE ON-LINE APPLICATION FORM SAMPLE APPLICATION This is a sample application to assist applicants in preparing their application prior to submitting an online application

More information

GDPR DATA PROCESSING ADDENDUM. (Revision March 2018)

GDPR DATA PROCESSING ADDENDUM. (Revision March 2018) GDPR DATA PROCESSING ADDENDUM (Revision March 2018) From 25 May 2018 the GDPR obliges a Controller to have a written agreement containing prescribed provisions with any Processor that it uses. This General

More information

Application for Recognition or Expansion of Recognition

Application for Recognition or Expansion of Recognition Application for Recognition or Expansion of Recognition Notes for applicants All Applicants Should Read This Section This form is for applicants who are: o applying to become a recognised awarding organisation

More information

Compliance with Personal Health Information Protection Act

Compliance with Personal Health Information Protection Act Compliance with Personal Health Information Protection Act Ontario s Personal Health Information & Protection Act (PHIPA) governs the collection, use and disclosure of personal health information by midwives

More information

ACC Privacy Policy. Policy Statement. Objective. Scope. Policy system. Policy standards. Collection

ACC Privacy Policy. Policy Statement. Objective. Scope. Policy system. Policy standards. Collection ACC Privacy Policy Policy Statement ACC s Privacy Policy sets out the standards that will enable personal and health information in our care to be managed as carefully and respectfully as if it were our

More information

Information for registrants. How to renew your registration

Information for registrants. How to renew your registration Information for registrants How to renew your registration Contents Introduction 1 Renewing your registration with the HCPC 2 Paying your registration renewal fee 12 What happens if 13 Contact us 15 Keeping

More information

Farm Data Code of Practice Version 1.1. For organisations involved in collecting, storing, and sharing primary production data in New Zealand

Farm Data Code of Practice Version 1.1. For organisations involved in collecting, storing, and sharing primary production data in New Zealand Farm Data Code of Practice Version 1.1 For organisations involved in collecting, storing, and sharing primary production data in New Zealand MARCH 2016 1 Farm Data Code of Practice The Farm Data Code of

More information

Privacy Policy - Australian Privacy Principles (APPs)

Privacy Policy - Australian Privacy Principles (APPs) Policy New England North West Health Ltd (Trading as HealthWISE New England North West) will be referred to as HealthWISE for the purposes of this document. HealthWISE recognises that Information Privacy

More information

Safeguarding Policy Children and Adults at Risk

Safeguarding Policy Children and Adults at Risk Policy Children and Adults at Risk ELT manager Responsible officer Vice Principal Academic Affairs Head of Student Support Date first approved by BoM 19 December 2011 First Review Date December 2014 Date

More information

Prescription Monitoring Program State Profiles - Michigan

Prescription Monitoring Program State Profiles - Michigan Prescription Monitoring Program State Profiles - Michigan Research current through December 2014. This project was supported by Grant No. G1399ONDCP03A, awarded by the Office of National Drug Control Policy.

More information

Job Description. Service Delivery Manager. Nurse Manager. Ward Sister. Staff Nurses

Job Description. Service Delivery Manager. Nurse Manager. Ward Sister. Staff Nurses Job Description Title: Ward Housekeeper Level: Band 1 Accountable to: Responsible to: Nurse Manager Senior Housekeeper Job Purpose The post-holder will assist Nursing staff in the delivery of non-clinical

More information

White Paper on the use of social media messaging services by medical professionals practising under UK law. December 2017

White Paper on the use of social media messaging services by medical professionals practising under UK law. December 2017 White Paper on the use of social media messaging services by medical professionals practising under UK law December 2017 CONTENTS 1. WHITE PAPER ON THE USE OF SOCIAL MEDIA MESSAGING SERVICES BY MEDICAL

More information

AUSTRALIAN RESUSCITATION COUNCIL PRIVACY STATEMENT

AUSTRALIAN RESUSCITATION COUNCIL PRIVACY STATEMENT AUSTRALIAN RESUSCITATION COUNCIL PRIVACY STATEMENT Personal Information The Australian Government website provides detailed information on the Rights and responsibilities with respect to Privacy Law on

More information

What information does Genome.One collect about you and why?

What information does Genome.One collect about you and why? PRIVACY POLICY About this Privacy Policy 1. Genome.One Pty Ltd ACN 608 029 732 (Genome.One) appreciates that privacy is important to you. Genome.One is committed to handling personal information (including

More information

PRIVACY MANAGEMENT PLAN

PRIVACY MANAGEMENT PLAN PRIVACY MANAGEMENT PLAN June 2017 CONTENTS Section 1: OVERVIEW... 2 1.1 Introduction... 2 1.2 What does this cover?... 3 1.3 What are the University s responsibilities?... 7 1.4 Further information...

More information

DOCUMENT CONTROL Title: Use of Mobile Phones and Tablets (by services users & visitors in clinical areas) Policy. Version: Reference Number: CL062

DOCUMENT CONTROL Title: Use of Mobile Phones and Tablets (by services users & visitors in clinical areas) Policy. Version: Reference Number: CL062 DOCUMENT CONTROL Title: Version: Reference Number: Use of Mobile Phones and Tablets (by services users & visitors in clinical areas) Policy 5 CL062 Scope: This Policy applies all employees of the Trust,

More information

GDPR readiness at efinancialcareers. Our Responsibilities and the General Data Protection Regulation

GDPR readiness at efinancialcareers. Our Responsibilities and the General Data Protection Regulation GDPR readiness at efinancialcareers Our Responsibilities and the General Data Protection Regulation 25 May 18 A word on privacy GDPR Enforcement Date efinancialcareers places data privacy at the heart

More information

New Zealand Farm Data Code of Practice. For organisations involved in collecting, storing, and sharing primary production data in New Zealand

New Zealand Farm Data Code of Practice. For organisations involved in collecting, storing, and sharing primary production data in New Zealand New Zealand Farm Data Code of Practice For organisations involved in collecting, storing, and sharing primary production data in New Zealand JUNE 2014 1 Farm Data Code of Practice The Farm Data Code of

More information

PRIVACY IMPACT ASSESSMENT (PIA) For the. Operational Data Store -Enterprise (ODSE) Department of the Navy - USMC

PRIVACY IMPACT ASSESSMENT (PIA) For the. Operational Data Store -Enterprise (ODSE) Department of the Navy - USMC PRIVACY IMPACT ASSESSMENT (PIA) For the Operational ata Store -Enterprise (OSE) epartment of the Navy - USMC SECTION 1: IS A PIA REQUIRE? a. Will this epartment of efense (o) information system or electronic

More information

Diabetes Eye Screener / Photographer Job Description

Diabetes Eye Screener / Photographer Job Description Diabetes Eye Screener / Photographer Job Description Post Title: Band: Directorate: Base: Managerially accountable to: Professional Accountable to: Diabetes Eye Screener / Photographer 4 (Subject to AFC)

More information

PRIVACY MANAGEMENT FRAMEWORK

PRIVACY MANAGEMENT FRAMEWORK PRIVACY MANAGEMENT FRAMEWORK Section Contact Office of the AVC Operations, International and University Registrar Risk Management Last Review July 2014 Next Review July 2017 Approval SLT14/7/176 Effective

More information

POLICY STATEMENT PRIVACY POLICY

POLICY STATEMENT PRIVACY POLICY POLICY STATEMENT PRIVACY POLICY Version: 3.0 Issue Date: 01/07/2009 Last Review: 10/02/2016 Issued By: General Manager APPROVAL This policy has been approved by the Boards of METRO Church Australia and

More information

Job Description, Ward Clerk

Job Description, Ward Clerk Job Description, Ward Clerk Job Title: Ward Clerk Grade: Band 2 Responsible to: Accountable To: Ward Manger Ward Manger Job Purpose: The post holder will be expected to provide clerical, administrative

More information

Date last amended: (refer Version Control Table) Director, Governance and Legal Division

Date last amended: (refer Version Control Table) Director, Governance and Legal Division PRIVACY POLICY Date first approved: 11 October 2002 Date of effect: 11 October 2002 Date last amended: (refer Version Control Table) Date of Next Review: December 2019 First Approved by: University Council

More information

Data Processing Agreement

Data Processing Agreement Data Processing Agreement between Customer and SmartRecruiters Europe Ltd 59-60 Thames Street, Windsor, Berkshire. SL4 1TX United Kingdom - hereinafter SmartRecruiters - both Customer and SmartRecruiters

More information

Protecting and managing personal data Changes on the horizon for hospitals and other health and care organisations

Protecting and managing personal data Changes on the horizon for hospitals and other health and care organisations the voice of the NHS in Europe Briefing May 2016 Issue 23 Protecting and managing personal data Changes on the horizon for hospitals and other health and care organisations Who should read this briefing?

More information

Access to Records Procedure under Data Protection Act 1998 Access to Health Records Act 1990

Access to Records Procedure under Data Protection Act 1998 Access to Health Records Act 1990 Access to Records Procedure under Data Protection Act 1998 Access to Health Records Act 1990 Procedure approved by: Executive Group Date: 14 November 2014 Next Review Date: September 2016 Version: 1.0

More information

APPLICATION FOR INITIAL APPOINTMENT TO THE RQIA LIST OF PART II MEDICAL PRACTITIONERS UNDER THE MENTAL HEALTH (NORTHERN IRELAND) ORDER 1986

APPLICATION FOR INITIAL APPOINTMENT TO THE RQIA LIST OF PART II MEDICAL PRACTITIONERS UNDER THE MENTAL HEALTH (NORTHERN IRELAND) ORDER 1986 APPLICATION FOR INITIAL APPOINTMENT TO THE RQIA LIST OF PART II MEDICAL PRACTITIONERS UNDER THE MENTAL HEALTH (NORTHERN IRELAND) ORDER 1986 Please complete electronically or legibly in block capitals using

More information

NHS Constitution summary of rights and responsibilities

NHS Constitution summary of rights and responsibilities NHS Constitution summary of rights and responsibilities The Health Act 2009 which received Royal Assent in November 2009, places a legal responsibility upon all providers and commissioners of NHS care

More information

IVAN FRANKO HOME Пансіон Ім. Івана Франка

IVAN FRANKO HOME Пансіон Ім. Івана Франка THE IVAN FRANKO HOME S COMMITMENT TO PRIVACY PRIVACY STATEMENT The Ivan Franko Home respects this privacy of our residents, employees, Directors, volunteers and donors. We are committed to ensuring that

More information

DRAFT Guidelines for Client Records

DRAFT Guidelines for Client Records DRAFT Guidelines for Client Records Introduction These DRAFT Guidelines provide good practice guidance for keeping client records for counselling and psychotherapy client work. The Guidelines are in draft

More information

Compass Privacy Compliance

Compass Privacy Compliance Compass Privacy Compliance Compass is committed to compliance with commonwealth and state privacy legislation in addition to relevant departmental policies and guidelines. The school has chosen to adopt

More information

SURPRISE POLICE DEPARTMENT PORTABLE VIDEO MANAGEMENT SYSTEM

SURPRISE POLICE DEPARTMENT PORTABLE VIDEO MANAGEMENT SYSTEM 1 of 8 I. PURPOSE The purpose of this policy is to establish procedures for the Portable Video Management System (PVMS), which includes a portable digital recording device (PDRD) designed to record the

More information

The National Patient Experience Survey Programme. Statement of information practices

The National Patient Experience Survey Programme. Statement of information practices The National Patient Experience Survey Programme Reference No: NPES-SoIP-02.17 Revision No: 00 Author: Approved by: National Patient Experience Survey team Rachel Flynn, Director of Health Information

More information

Defense Security Service National Industrial Security Program. Guidelines for Trustees, Proxy Holders and Outside Directors

Defense Security Service National Industrial Security Program. Guidelines for Trustees, Proxy Holders and Outside Directors Defense Security Service National Industrial Security Program Guidelines for Trustees, Proxy Holders and Outside Directors July 2009 Guidelines for Trustees, Proxy Holders, and Outside Directors (TO BE

More information

Sidney Sussex College CCTV POLICY. Page 1 of 11

Sidney Sussex College CCTV POLICY. Page 1 of 11 Sidney Sussex College CCTV POLICY Page 1 of 11 Contents 1. The CCTV system 2. Responsible Officers 3. Data Protection 4. The system 5. Purpose of the system 6. Covert recording 7. Access to Images 8. CCTV

More information

Research Governance Framework 2 nd Edition, Medicine for Human Use (Clinical Trial) Regulations 2004

Research Governance Framework 2 nd Edition, Medicine for Human Use (Clinical Trial) Regulations 2004 Title: Outcome Statement: Research Auditing and Monitoring Procedures Researchers in the Trust and research partners will be informed about the requirements and procedures involved in research audit and

More information

Visiting Celebrities, VIPs and other Official Visitors

Visiting Celebrities, VIPs and other Official Visitors Visiting Celebrities, VIPs and other Official Visitors Who Should Read This Policy Target Audience Healthcare Professionals Executive Team Version 1.0 May 2016 Ref. Contents Page 1.0 Introduction 4 2.0

More information

PRIVACY IMPACT ASSESSMENT (PIA) For the

PRIVACY IMPACT ASSESSMENT (PIA) For the PRIVACY IMPACT ASSESSMENT (PIA) For the DCAA Integrated Information Network (IIN) Defense Contract Audit Agency SECTION 1: IS A PIA REQUIRED? a. Will this Department of Defense (DoD) information system

More information

Lawful basis for processing personal and special category data guidance

Lawful basis for processing personal and special category data guidance Document author Assured by Data Protection Officer Information Governance Steering Group This document is version controlled. The master copy is on Ourspace. Once printed, this document could become out

More information

JOB DESCRIPTION. Specialist Practitioner of Transfusion for Shrewsbury, Telford and surrounding community hospitals. Grade:- Band 7 Line Manager:-

JOB DESCRIPTION. Specialist Practitioner of Transfusion for Shrewsbury, Telford and surrounding community hospitals. Grade:- Band 7 Line Manager:- JOB DESCRIPTION Job Title:- Specialist Practitioner of for Shrewsbury, Telford and surrounding community hospitals. Grade:- Band 7 Line Manager:- Associate Director of Patient Safety Professionally Accountability

More information

This policy has implications for all managers, staff, board members, students, apprentices and trainees, contractors and volunteers.

This policy has implications for all managers, staff, board members, students, apprentices and trainees, contractors and volunteers. Privacy Policy Purpose This document describes BGT s policy regarding the collection, use, storage, disclosure of and access to personal information, including health information, in relation to the personal

More information

THERAPY CENTRE JOB DESCRIPTION

THERAPY CENTRE JOB DESCRIPTION THERAPY CENTRE JOB DESCRIPTION Post Title: Admin Assistant Grade: Band 2 Accountable to: Deputy Physiotherapy Manager, Outpatients Responsible to: Therapy Office Manager Department: Therapy Centre, Princess

More information

A PHIPA Update from the IPC

A PHIPA Update from the IPC A PHIPA Update from the IPC April 10, 2017 Brian Beamish Commissioner Information and Privacy Commissioner of Ontario PHIPA Processes Internal review of PHIPA processes led to some changes o Most significant:

More information

Sample Privacy Impact Assessment Report Project: Outsourcing clinical audit to an external company in St. Anywhere s hospital

Sample Privacy Impact Assessment Report Project: Outsourcing clinical audit to an external company in St. Anywhere s hospital Sample Privacy Impact Assessment Report Project: Outsourcing clinical audit to an external company in St. Anywhere s hospital October 2010 2 Please Note: The purpose of this document is to demonstrate

More information

SENATE, No STATE OF NEW JERSEY. 216th LEGISLATURE INTRODUCED APRIL 28, 2014

SENATE, No STATE OF NEW JERSEY. 216th LEGISLATURE INTRODUCED APRIL 28, 2014 SENATE, No. STATE OF NEW JERSEY th LEGISLATURE INTRODUCED APRIL, 0 Sponsored by: Senator LORETTA WEINBERG District (Bergen) Senator JOSEPH F. VITALE District (Middlesex) Senator JAMES W. HOLZAPFEL District

More information

General Policy. Code of Conduct

General Policy. Code of Conduct 1. Policy Statement 2. Purpose 3. Scope 4. Associated Policies and Procedures 5. Associated Documents General Policy Code of Conduct This Code of Conduct affirms that SAE Institute Pty Ltd ( the Institute,

More information

REPORT OF THE BOARD OF TRUSTEES. Protection of Clinician-Patient Privilege (Resolution 237-A-17)

REPORT OF THE BOARD OF TRUSTEES. Protection of Clinician-Patient Privilege (Resolution 237-A-17) REPORT OF THE BOARD OF TRUSTEES B of T Report 16-A-18 Subject: Presented by: Referred to: Protection of Clinician-Patient Privilege (Resolution 237-A-17) Gerald E. Harmon, MD, Chair Reference Committee

More information

Rail Training Accreditation Scheme (RTAS) Rules

Rail Training Accreditation Scheme (RTAS) Rules (RTAS) Rules Purpose and Scope...1 1. The RTAS Rules...2 2. Roles and Responsibilities... 4 3. Management System Requirements...7 4. Breaches of the RTAS Rules...12 5. Investigating breaches of the RTAS

More information

Writtle College Health and Safety Policy

Writtle College Health and Safety Policy Writtle College Health and Safety Policy 2015-2016 Document Ownership: Role Title: Chair of the Board Department Approved by Senior Management Team 11 August 2015 Approved by Personnel & Remuneration Committee

More information

REPORTING ABUSE ACTUAL OR SUSPECTED: FREQUENTLY ASKED QUESTIONS

REPORTING ABUSE ACTUAL OR SUSPECTED: FREQUENTLY ASKED QUESTIONS PRACTICE FACT SHEET REPORTING ABUSE ACTUAL OR SUSPECTED: FREQUENTLY ASKED QUESTIONS INTRODUCTION This is a quick reference to frequently asked questions (FAQs) about the reporting of abuse of children

More information

Terms and Conditions. Erasmus+ 30 years story submission

Terms and Conditions. Erasmus+ 30 years story submission Terms and Conditions Erasmus+ 30 years story submission 1 EUROPEAN COMMISSION Directorate-General for Education, Youth, Sport and Culture Directorate B - Youth, Education and Erasmus+ Unit B.1 Higher Education

More information

I. PURPOSE DEFINITIONS. Page 1 of 5

I. PURPOSE DEFINITIONS. Page 1 of 5 Policy Title: Computer, E-mail and Mobile Computing Device Use Accreditation Reference: Effective Date: October 15, 2014 Review Date: Supercedes: Policy Number: 4.31 Pages: 1.5.9 Attachments: October 15,

More information

Employ Florida Marketplace Terms and Conditions Governing your access and use of the Employ Florida Marketplace (EFM)

Employ Florida Marketplace Terms and Conditions Governing your access and use of the Employ Florida Marketplace (EFM) Attachment 1 Employ Florida Marketplace Terms and Conditions Governing your access and use of the Employ Florida Marketplace (EFM) Introduction: Please read the following information carefully. It contains

More information

Physician Assistant Jurisprudence Examination

Physician Assistant Jurisprudence Examination Physician ssistant Jurisprudence xamination The examination you take will be composed of 50 questions, randomly selected from the questions listed below. You will have 90 minutes to take the exam. For

More information

High Dependency Unit, Highgate Hospital

High Dependency Unit, Highgate Hospital JOB DESCRIPTION TITLE: RESPONSIBLE FOR: RESPONSIBLE TO: ACCOUNTABLE TO: SUMMARY OF POSITION: Critical Care Sister / Charge Nurse High Dependency Unit, Highgate Hospital Nursing Services Manager Hospital

More information

Social Media IUSM-GME-PO-0031

Social Media IUSM-GME-PO-0031 Social Media IUSM-GME-PO-0031 FULL POLICY CONTENTS Scope Reason for Policy Policy Statement Procedures Definitions ADDITIONAL DETAILS Implementation Oversight Additional Contacts Forms Related Information

More information

DATED [2015] (1) NORTH YORKSHIRE COUNTY COUNCIL (2) [INSERT NAME OF GRANT RECIPIENT] FUNDING AGREEMENT - GRANT [INSERT PROJECT TITLE]

DATED [2015] (1) NORTH YORKSHIRE COUNTY COUNCIL (2) [INSERT NAME OF GRANT RECIPIENT] FUNDING AGREEMENT - GRANT [INSERT PROJECT TITLE] DATED [2015] (1) NORTH YORKSHIRE COUNTY COUNCIL (2) [INSERT NAME OF GRANT RECIPIENT] FUNDING AGREEMENT - GRANT [INSERT PROJECT TITLE] 14502708.2 CONTENTS 1. DEFINITIONS... 4 2. INTERPRETATION...16 3. GRANT...17

More information

Policy No. AD I1 ** Information from collection to retention shall be managed according to relevant legislation.

Policy No. AD I1 ** Information from collection to retention shall be managed according to relevant legislation. Community Living and Respite Services Inc. (CLRS) Policy No. AD I1 ** Issue No. 6 Issue Date: May 2005, August 2009February 2011Renamed Previously Information Privacy Policy. Revised Date February 2011,

More information

Guidance for care providers in Scotland using CCTV (closed circuit television) in their services

Guidance for care providers in Scotland using CCTV (closed circuit television) in their services Guidance for care providers in Scotland using CCTV (closed circuit television) in their services www.careinspectorate.com 1 This guidance draws on similar guidance produced by the Care Quality Commission

More information

Getting Ready for Ontario s Privacy Legislation GUIDE. Privacy Requirements and Policies for Health Practitioners

Getting Ready for Ontario s Privacy Legislation GUIDE. Privacy Requirements and Policies for Health Practitioners Getting Ready for Ontario s Privacy Legislation GUIDE Privacy Requirements and Policies for Health Practitioners PUBLISHED BY THE COLLEGE OF DENTAL HYGIENISTS OF ONTARIO SEPTEMBER 2004 2 This booklet is

More information

Clinical Lead. Contract of Employment

Clinical Lead. Contract of Employment JOB DESCRIPTION AND PERSON SPECIFICATION FOR Clinical Lead AGENDA FOR CHANGE BAND Band 7 HOURS AND DURATION As specified in the job advertisement and the Contract of Employment AGENDA FOR CHANGE REF NO

More information

Contract of Employment

Contract of Employment JOB DESCRIPTION AND PERSON SPECIFICATION FOR Deputy Sister / Deputy Charge Nurse AGENDA FOR CHANGE BAND Band 6 HOURS AND DURATION As specified in the job advertisement and the Contract of Employment AGENDA

More information

Home Energy Saving scheme. Application Guide Version 1.1

Home Energy Saving scheme. Application Guide Version 1.1 Home Energy Saving scheme Application Guide Version 1.1 IMPORTANT NOTICE It is the responsibility of each applicant to the Home Energy Saving scheme to ensure that they have read, and fully understand,

More information

National VET Data Policy

National VET Data Policy National VET Data Policy November 2017 1 Version Control Version Purpose/Change Author Date Number 1 Endorsed by the Council of Australian Governments (COAG) Industry and Skills Council (CISC) Kelly Fisher

More information

A general review of HIPAA standards and privacy practices 2016

A general review of HIPAA standards and privacy practices 2016 A general review of HIPAA standards and privacy practices 2016 45 CFR, 164 Health Insurance Portability and Accountability Act Treatment, Payment and Healthcare Operations 42 CFR, Part 2, Confidentiality

More information

COMIC RELIEF AWARDS THE GRANT TO YOU, SUBJECT TO YOUR COMPLYING WITH THE FOLLOWING CONDITIONS:

COMIC RELIEF AWARDS THE GRANT TO YOU, SUBJECT TO YOUR COMPLYING WITH THE FOLLOWING CONDITIONS: Example conditions of grant Below are the standard conditions that we ask grant holders to sign up to when accepting a grant from Comic Relief. These conditions are provided here only as an example; we

More information

SECURITY and MANAGEMENT CONTROL OUTSOURCING STANDARD for NON-CHANNELERS

SECURITY and MANAGEMENT CONTROL OUTSOURCING STANDARD for NON-CHANNELERS SECURITY and MANAGEMENT CONTROL OUTSOURCING STANDARD for NON-CHANNELERS The goal of this document is to provide adequate security and integrity for criminal history record information (CHRI) while under

More information

Employing nurses in local authorities. RCN guidance

Employing nurses in local authorities. RCN guidance Employing nurses in local authorities RCN guidance Employing nurses in local authorities Acknowledgements The RCN wishes to thank the following for their involvement and support in the development of this

More information

Mandatory Reporting A process

Mandatory Reporting A process Mandatory Reporting A process guide for employers, facility operators and nurses Table of Contents Introduction.... 3 What is the purpose of mandatory reporting?... 3 What does the College do when it receives

More information

Submission to the Consultation on Development of a Framework on Secondary Use of My Health Record Data

Submission to the Consultation on Development of a Framework on Secondary Use of My Health Record Data Submission to the Consultation on Development of a Framework on Secondary Use of My Health Record Data Introduction Thank you for the invitation to make a submission to the consultation on secondary use

More information

PRIVACY POLICY USES AND DISCLOSURES FOR TREATMENT, PAYMENT, AND HEALTH CARE OPERATIONS

PRIVACY POLICY USES AND DISCLOSURES FOR TREATMENT, PAYMENT, AND HEALTH CARE OPERATIONS PRIVACY POLICY As of April 14, 2003, the Federal regulation on patient information privacy, known as the Health Insurance Portability and Accountability Act (HIPAA), requires that we provide (in writing)

More information

RULES - Copernicus Masters 2017

RULES - Copernicus Masters 2017 RULES - Copernicus Masters 2017 ORGANISER OF THE COPERNICUS MASTERS The Copernicus Masters is organised under an ESA contract by Anwendungszentrum GmbH Oberpfaffenhofen ( the Organiser ) and is supported

More information

ROLE DESCRIPTION. Physiotherapy Musculoskeletal Practitioner Telephone Triage Physiotherapist

ROLE DESCRIPTION. Physiotherapy Musculoskeletal Practitioner Telephone Triage Physiotherapist ROLE DESCRIPTION Job Title: Location: Hours of Work: Responsible To: Responsible For: Physiotherapy Musculoskeletal Practitioner Telephone Triage Physiotherapist Longbow Close, Shrewsbury and a GP Practice

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Version Number 5 Version Date March 2017 Policy Owner Chief Information Officer Author Information Governance Manager First approval or date July 2013 last reviewed Staff/Groups

More information

PRIVACY POLICY. 1. Privacy Statement

PRIVACY POLICY. 1. Privacy Statement PRIVACY POLICY 1. Privacy Statement 2. Privacy Principles NIDA s Privacy Policy discloses how NIDA collects, protects, uses and shares information gained about individuals. This statement outlines how

More information

Technology Standards of Practice

Technology Standards of Practice 2016 Technology Standards of Practice Used with permission from the Association of Social Work Boards (2016) Table of Contents Technology Standards of Practice 2 Definitions 2 Section 1 Practitioner Competence

More information

Deputise and take charge of the given area regularly in the absence of the clinical team leader who has 24 hour accountability and responsibility.

Deputise and take charge of the given area regularly in the absence of the clinical team leader who has 24 hour accountability and responsibility. JOB DESCRIPTION AND Public Health Nurse School Nurse PERSON SPECIFICATION FOR: AGENDA FOR CHANGE BAND: Band 6 HOURS AND DURATION; As specified in the job advertisement and the Contract of Employment AGENDA

More information

Guidance for organisations applying for both registration and licensing as a new service provider

Guidance for organisations applying for both registration and licensing as a new service provider Guidance for organisations applying for both registration and licensing as a new service provider CQC and Monitor have combined the separate application forms to apply for a CQC registration and an NHS

More information

Implementing the Revised Common Rule Exemptions with Limited IRB Review

Implementing the Revised Common Rule Exemptions with Limited IRB Review Implementing the Revised Common Rule Exemptions with Limited IRB Review Introduction: Four of the exempt categories in the revised Common Rule include a provision for limited IRB review. This resource

More information

DISCLOSURE & BARRING SERVICE POLICY AND PROCEDURES

DISCLOSURE & BARRING SERVICE POLICY AND PROCEDURES DISCLOSURE & BARRING SERVICE POLICY AND PROCEDURES Updates Who Updated Comments September annually Lewis, Bridget TABLE OF CONTENTS GENERAL PRINCIPLES... 3 TYPES OF DISCLOSURE AND BARRING SERVICE... 4

More information

Employee Assistance Professionals Association of South Africa: an Association for Professionals in the field of Employee Assistance Programmes

Employee Assistance Professionals Association of South Africa: an Association for Professionals in the field of Employee Assistance Programmes Employee Assistance Professionals Association of South Africa: an Association for Professionals in the field of Employee Assistance Programmes EAPA-SA, PO Box 11166, Hatfield, 0028. Code of Ethics 2010

More information

Family Violence Risk Assessment and Risk Management Framework: key components

Family Violence Risk Assessment and Risk Management Framework: key components Family Violence Information Sharing, Child Information Sharing, and the Redevelopment of the Family Violence Risk Assessment and Risk Management Framework 19 APRIL 2018 Family Violence Risk Assessment

More information

Trial Management: Trial Master Files and Investigator Site Files

Trial Management: Trial Master Files and Investigator Site Files Title: Outcome Statement: Written By: Trial Management: Trial Master Files and Investigator Site Files Staff working on research studies in NSFT will be informed about the requirements of setting up and

More information

Business Risk Planning

Business Risk Planning Business Risk Planning SENTINEL EVENTS EHNAC Background The Electronic Healthcare Network Accreditation Commission (EHNAC) is a federally recognized, standards development organization and tax-exempt,

More information

Nursing Homes Ireland in association with Irish Small and Medium Enterprises Association (ISME)

Nursing Homes Ireland in association with Irish Small and Medium Enterprises Association (ISME) Guide to Garda Vetting Nursing Homes Ireland in association with Irish Small and Medium Enterprises Association (ISME) What is Garda Vetting? Garda Vetting is the term given to the process where the Gardaí

More information