Document Feedback - Review and Comment
Step 1 of 4: Comment on Document
How to make a comment?
1. Use this to open a comment box for your chosen Section, Part, Heading or clause.
2. Type your feedback into the comments box and then click "save comment" button located in the lower-right of the comment box.
3. Do not open more than one comment box at the same time.
4. When you have finished making comments proceed to the next stage by clicking on the "Continue to Step 2" button at the very bottom of this page.
Important Information
During the comment process you are connected to a database. Like internet banking, the session that connects you to the database may time-out due to inactivity. If you do not have JavaScript running you will receive a message to advise you of the length of time before the time-out. If you have JavaScript enabled, the time-out is lengthy and should not cause difficulty, however you should note the following tips to avoid losing your comments or corrupting your entries:
-
DO NOT jump between web pages/applications while logging comments.
-
DO NOT log comments for more than one document at a time. Complete and submit all comments for one document before commenting on another.
-
DO NOT leave your submission half way through. If you need to take a break, submit your current set of comments. The system will email you a copy of your comments so you can identify where you were up to and add to them later.
-
DO NOT exit from the interface until you have completed all three stages of the submission process.
(1) Under the Data Protection Act 2018 and the General Data Protection Regulation (GDPR), Hibernia College is obliged to keep personal data safe and secure and to respond promptly and appropriately in the event of a personal data security breach. This procedure lays out the steps to be followed by the College in the event that a personal data security breach or suspected personal data security breach occurs. (2) Students have a responsibility to report any breach or suspected breach of personal data to the Data Protection Officer as soon as they become aware of such a breach at dpo@hiberniacollege.net. (3) The Data Protection Officer is responsible for this procedure. (4) All Staff, Faculty and Adjunct Faculty are responsible for engaging with and adhering to, this procedure as required. (5) All Staff, Faculty and Adjunct Faculty are responsible for reporting any breach or suspected breach of personal data to the Data Protection Officer without delay. (6) A personal data security breach is any incident which gives rise to an unauthorised disclosure, loss, destruction or alternation of personal data held by the College in any format. This includes any breaches which result from malicious conduct, lack of appropriate security controls, system or human failure or error. Personal data security breaches can happen for a number of reasons, including: (7) Any individual who suspects that a personal data security breach has occurred, whether they have caused, been subject to or identified a breach of personal data, are required to: (8) Immediately upon becoming aware of the breach, notify the Data Protection Officer at dpo@hiberniacollege.net, who will advise them on any required steps that need to be taken (9) Notify their line manager (where applicable) without delay (10) Complete the Personal Data Security Breach Report Form, available under the resources section of the Hibernia College Quality Framework, and forward to the Data Protection Officer as soon as possible (11) The Data Protection Officer conducts an initial assessment as a matter of priority, which will include a review of: (12) Where the outcome of an initial assessment confirms that a personal data breach has not occurred, the process concludes, and the Data Protection Officer notifies the reporter that no data breach has occurred. (13) Where the outcome of an initial assessment confirms that a personal data security breach has occurred, the Data Protection Officer will immediately proceed to coordinate the College response, as follows. (14) In the event of a confirmed personal data security breach, immediate and appropriate steps must be taken to mitigate the risks and limit the extent of the breach by the Data Protection Officer and, in consultation with any relevant College Staff, will: (15) As is set out above, where a personal data security breach is confirmed, the Data Protection Officer in conjunction with relevant College Staff, will conduct a risk assessment to assess the potential adverse consequences for the affected data subjects. The assessment will consider the likelihood of the risks taking place and the severity of such risks and will consider the following criteria: (16) Where the personal data security breach is likely to result in a high risk to the rights and freedoms of the data subject, the College will inform the affected data subjects, without undue delay. (17) Where it is necessary to notify the data subject, the Data Protection Officer will assist staff to communicate the details of the data breach to the data subject(s) to include the: (18) Where the College has determined that the personal data security breach is likely to result in a risk to the rights and freedoms of data subjects, the Data Protection Officer will notify the Data Protection Commission without undue delay, and no later than 72 hours, after becoming aware of the breach. If, for any reason, the breach cannot be notified to the Data Protection Commission within 72 hours, the notification will be accompanied by reasons for the delay. (19) The notification will include the nature of the personal data security breach, including the: (20) The Data Protection Officer retains all records of the incident (21) The Records and Data Manager, in consultation with all relevant stakeholders, will conduct a review of the incident to: (22) The review report is issued to all relevant departments. (23) A post-incident review will be conducted to ensure that the steps taken during the incident were appropriate and effective and to identify any areas which may need to be improved in future to avoid any recurrence.Personal Data Security Breach Management Procedure
Section 1 - Introduction
Purpose and Parent Policy
The Personal Data and Records Policy is the parent policy. Responsibilities
Student Responsibilities
Staff, Faculty and Adjunct Faculty Responsibilities
Section 2 - Procedure for Managing Personal Data Security Breaches
Part A - What is a data breach?
Part B - Identification and Initial Assessment of a Suspected Breach of Personal Data
Identification and Notification of Suspected Personal Data Security Breach
Initial Assessment
Outcome of Initial Assessment
Part C - Managing a Confirmed Personal Data Security Breach
Containment and Recovery
Risk Assessment
Notification of the Data Subject
Notification of the Data Protection Commissioner
Evaluation and Response