Information security and data protection update
Home » Information security and data protection update
Anne Austin
Director
Article 42 GDPR provides for the ICO to approve private (and voluntary) certification schemes aimed at processors of personal data.
On 13 February the ICO approved ‘the Legal Services Operational Privacy Certification Scheme’ (the acronym is ‘LOCS 23’). Aimed at legal services providers, and also at those who supply to such providers, eg software companies, the ICO states that ‘the scheme will provide them with certainty that they are adhering to data protection standards and reduce time and resource assessing third party data processors. It will also reassure their clients that they are committed to looking after their personal details and have strong information security in place.’
Promoted by 2Twenty4 Consulting Limited, the scheme is aimed at ensuring proper treatment of and protection for personal data. Sharing some features with the Government’s CyberEssentials accreditation and with ISO 27001: 13, the LOCS 23 scheme should be regarded as complimentary to these.
So, what does the Legal Services Operational Privacy Certification Scheme actually require?
It sets out 51 ‘controls’ – i.e. must-do activities – with extensive guidance on what is required to achieve them. Most law firms will have at least some of these already, for example:
- mandatory registration and co-operation with the ICO
- a data protection policy
- a data retention policy
- a business continuity plan, and
- robust back-up and restore processes
There are other controls that a law firm should be doing, e.g. establishing and documenting a lawful basis for processing personal data before actually doing the processing and also being able to justify why the particular lawful basis selected (e.g., contract) is appropriate.
Other requirements are more onerous, for example the creation of a ‘Privacy Council’ that takes overall responsibility for data protection issues within the law firm, and conducting external vulnerability or penetration testing. If you have CyberEssentials you might well be conducting pen tests already. There are additional requirements where a law firm uses third party suppliers, eg data hosting services, SaaS (Software as a Service) providers, translation services, and off-site storage of paper records.
Is the Legal Services Operational Privacy Certification Scheme (LOCS 23) mandatory?
Solicitors might well breathe a collective sigh of frustration at the prospect of more requirements and/or accreditations. However, you do not need to do it; the LOCS 23 scheme is voluntary. We are neutral on the matter. Law firms typically hold and process vast amounts of personal data – all of which is highly valuable, especially in the wrong hands. Whether you wish to obtain LOCS 23 accreditation or not, we believe that there are strong advantages in ensuring that you know what data you have, what lawful bases you use to process data, how it is processed, who can access it, and generally in having a firm grip on data processing activity. Even if you don’t want the accreditation, you might therefore wish to use the criteria in the LOCS 23 scheme to self-determine your level of overall compliance.
Law Society issue more fines for permitting ‘Friday afternoon fraud’
December’s ‘Compliance Lifeline’ featured a law firm that was reprimanded by the ICO for permitting a phishing attack. This month, the Law Society uses the case of another (and unnamed) Solicitor who was fined for permitting a ‘Friday afternoon fraud’ – I am unable to identify the case from recent SDT published records and so I can’t verify the details. Clearly there are strong links and overlaps between data protection and cyber security. These types of cases amply illustrate why it is important to be on top of both.
New UK data rights regime?
And… if you haven’t had enough of data protection, it will hit the news again soon when the Government’s Data Protection and Digital Information (No 2) Bill – perhaps the most controversial Bill that you might have never heard of – completes its passage through Parliament. Having cleared all stages in the House of Commons, it is currently at Committee Stage in the House of Lords. In weakening relevant GDPR protections it has attracted fierce criticism, but this is surprisingly poorly covered by mainstream media. You can read here what the Open Rights Group – a UK-based digital campaigning organisation – have to say about it. You can read other trenchant criticism of the Bill by following the hyperlink above.
It’s likely that on receiving the Royal Assent that the LOCS 23 scheme discussed above will require amendment. A promoter of the scheme claims that ‘The [LOCS 23] standard will rapidly become everyday business compliance in the legal sector.’ Given the impending change in the law, I predict that even if they adopt it, which is perhaps speculative, law firms and supply chains will prefer to wait until the new rules are in place and have had time to settle down. The promoter also claims that the certification will become a requirement in public procurement where law firms tender for public contracts. This is not my experience – for example, the supplier contract for panel law firms on the EMLawshare framework (operated by Nottinghamshire County Council on behalf of its members) does not currently prescribe for any quality mark or accreditation, and instead has detailed provisions about data processing and security requirements. Whether that approach will change remains to be seen.
Further, it’s possible that on the Bill becoming law the EU Commission might wish to review its ‘adequacy’ award to UK data protection laws. I will write more extensively about the Bill at the appropriate time, which time might be affected by a UK General Election expected at some stage this year.
Ed Austin
Solicitor & Director