Skip to main content
Normal View

Data Protection

Dáil Éireann Debate, Tuesday - 13 June 2023

Tuesday, 13 June 2023

Questions (852)

Peadar Tóibín

Question:

852. Deputy Peadar Tóibín asked the Minister for Social Protection the security protections in place for remote workers within civil and public service organisations to safeguard against personal information of members of the public in audio, text and electronic form being inadvertently exposed to unauthorised third parties within the remote setting; if she can provide a copy of the remote working best practice guidelines for civil and public service workers; and if she will make a statement on the matter. [28641/23]

View answer

Written answers

On 12th September 2022, my Department implemented a formal Blended Working policy under which staff members may apply for a blended working arrangement, with attendance both in the office and remotely, subject to role suitability and other conditions.

The Department's Blended Working Policy was developed in accordance with the Framework for Blended Working for Civil Service Organisations, which was launched by the Department of Public Expenditure and Reform (DPER) in March 2022.

The Department's Blended Working Policy sets remote working best practice guidelines and also general rules in relation to Blended Working that:

• In order for an Officer's application for a Blended Working Arrangement to be considered the Officer must first complete an Applicant Declaration that their workstation allows compliance with data security and applicable confidentiality standards, that they will continue to comply with all of their obligations as a civil servant, including all legislative obligations, and remain bound by all relevant organisational policies and procedures, and that they continue to be bound by the same standards and behaviours whether working in the office, or remotely.

• All staff must ensure that they comply with all relevant health and safety obligations and confirm that the workstation allows compliance with data security and applicable confidentiality standards.

• The work of the Department requires some staff to undertake highly sensitive and confidential work and as such access technologies / equipment / data accessible in office locations.

• Local printing is not facilitated at home locations.

• That staff are reminded of their responsibility to take necessary precautions to safeguard the equipment and ensure that the appropriate policies are followed in relation to security, personal data, and work use.

The Department's policy details Security, Confidentiality, Secrecy and Standards of Behaviour as follows:

• Work related documents must be stored securely.

• Business calls should be conducted in a confidential setting.

• Sensitive or confidential documents must be password-protected and devices must be shut down when not in use.

• Screens must be locked when the employee is away from the device at any time.

• Organisational IT equipment must be used in line with relevant organisational policies.

• Lost or stolen devices must be reported immediately to the employer in line with the relevant organisational procedure.

• Freedom of Information (FOI) – all records on computers/laptops etc., including instant messaging conversations are encompassed under the FOI Acts.

• Standards of Behaviour – staff working remotely are governed by the same standards of behaviour as when in the office environment – respect, dignity, conduct, professionalism etc.

• Disclosure of information - staff remain subject to obligations in respect of confidentiality and the requirement under the Official Secrets Act 1963 to avoid improper disclosure of information gained in the course of their official work.

In addition to the usual Data Protection training which is undertaken regularly, staff are also made aware by way of the Department's Blended Working Policy that their obligations under the General Data Protection Regulation (GDPR) and Data Protection Acts 1988 to 2018 are not confined to the employer’s work premises.

In 2022, the Department developed and deployed an e-learning module to support the Department's Blended Working Policy, which reinforces that staff will always need to comply with data security and confidentiality standards, regardless of where they work. The e-learning module also states that staff must continue to comply with all their legislative obligations as a Civil Service and remain bound by all relevant policies and procedures, regardless of the location from which their work is being carried out.

Top
Share