Providing GDPR support and advice to Basketball England
Our information governance experts were asked to support Basketball England to be compliant with GDPR. Enabling them to comply with this legislation means they can focus on achieving their organisation’s goals while making sure personal data is handled correctly.
Firstly, we coordinated a records survey to identify all personal information held by Basketball England. This helped to develop an information flow outlining where information comes into the organisation, who it’s shared with and how it’s managed.
With our support and advice, Basketball England could draft their first Information Asset Register. This highlights assets containing personal information and also acts as a Record of Processing Activities.
Once work was completed on the Information Asset Register, it allowed us to also:
- Identify requirements to draft and publish privacy notices
- Review consent forms for personal data relying on consent for processing, to ensure compliance with the Data Protection Act 2018
- Draft a records retention schedule for all personal information
- Identify and review processing contracts to ensure inclusion of GDPR Article 28 clauses
- Draft and publish appropriate information governance policies
- Identify controller to controller information sharing and draft appropriate information sharing agreements
We also provided extensive training for staff (including management) to ensure all stakeholders had sufficient knowledge and understanding of data protection legislation.
Our work has provided Basketball England with the confidence to manage their information assets in a compliant way. We continue to advise on any GDPR related matter, which provides them with the assurance that they conform with data protection legislation.
“Basketball England began a partnership with Veritau in 2019. As a small national governing body, we needed to seek outside expertise to assist with our information governance.
Very quickly, Veritau’s team were able to review our policy and privacy notices, and supported us in forming an action plan to improve our systems and processes.
Veritau provided training for all staff which was very well received. They have provided ongoing advice for our Data Protection Officer and advised on changes in legislation to inform adjustments to privacy notices.
Where we have had to respond quickly to an incident, Veritau’s team has been on hand to help us to assess the situation and respond in a timely way and in compliance with UK GDPR.
We were provided with the contact details of a number of key staff who we found to be extremely knowledgeable, accessible and approachable. With their development support and assistance, we are definitely in a stronger position as an organisation and we would have no hesitation in recommending Veritau.”
– Safeguarding and Compliance Manager, Basketball England
Speak to an expert
Information Governance Manager
Andy has over 20 years’ experience working in information governance within local government. He specialises in the development and implementation of bespoke information strategy, policy and processes. Andy has a professional interest in making information open and transparent, and enhancing ethical considerations around data.