Practical DSPT:Information Asset Register & Record of Processing Activities

Join us for a practical webinar designed to help care providers strengthen their Data Security and Protection Toolkit (DSPT) policies & processes. This session will explore how to effectively implement and maintain the Information Asset Register (IAR) and the Record of Processing Activities (ROPA).
It is a requirement of the Data Protection Act (2018) and the General Data Protection Regulation (GDPR) that all personal and sensitive data has a legal basis for being held and being shared.
This means as a care provider, you are legally obliged to keep a record of all the personal data you hold for staff, residents and families/carers, and what data they share with others.
To meet this requirement, it is easiest to have two lists:

· Record of Processing Activities (ROPA) – contains where data is received from, where it is sent to and the legal basis for doing this.
· Information Asset Register (IAR) – contains what type of information is held, where it is stored and how it is protected.
A Record of Processing Activities (ROPA) is a list of confidential data, where it is received from or where it is sent to and the legal basis for doing this. All data in the IAR marked as being received from or shared with external organisations needs to be included in your ROPA.
An Information Asset Register (IAR) is a list of all the places where information is stored, whether the information in that place is special category information, and how that information is kept safe.

View all Events