ED Decision 2021/002/R
FEEDBACK PROCESS — DATA PROTECTION – GRADING SYSTEM
(a) The data access and security policy may, as a minimum, define:
(1) a policy for access to information only to specifically authorised persons identified by their position in order to perform their duties. The required authorised person(s) does (do) not need to be the EBT manager; it could be the EBT programme manager or a third party mutually acceptable to unions or staff and management. The third party may also be in charge of ensuring the correct application of the data access and security policy (e.g. the third party is the one activating the system to allow access to the authorised persons);
(2) the identified data retention policy and accountability;
(3) the measures to ensure that the security of the data includes the information security standard (e.g. information security management systems standard e.g. ISO 2700x-ISO 27001, NIST SP 800-53, etc.);
(4) the method to obtain de-identified crew feedback on those occasions that require specific follow-up; and
(b) When there is a need for data protection, it is preferable to de-identify the data rather than anonymise it.
Loading collections...