Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
GM2 ORO.FC.231(c) Evidence-based training
Available versions for ERULES-1963177438-18371
ED Decision 2021/002/R
found in: Air Operations (965/2012) Part-ARO Part-ORO Part-CAT Part-SPA Part-NCC Part-NCO Part-SPO (Feb 2025)
From
Air Operations Rev... (Mar 2026)
Air Operations (96... (Feb 2025)
Air Operations (96... (Sep 2023)
From section
To
Air Operations Rev... (Mar 2026)
Air Operations (96... (Feb 2025)
Air Operations (96... (Sep 2023)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
GM2 ORO.FC.231(c) Evidence-based training ED Decision 2021/002/R FEEDBACK PROCESS — DATA PROTECTION – GRADING SYSTEM (a) The data access and security policy may, as a minimum, define: (1) a policy for access to information only to specifically authorised persons identified by their position in order to perform their duties. The required authorised person(s) does (do) not need to be the EBT manager; it could be the EBT programme manager or a third party mutually acceptable to unions or staff and management. The third party may also be in charge of ensuring the correct application of the data access and security policy (e.g. the third party is the one activating the system to allow access to the authorised persons); (2) the identified data retention policy and accountability; (3) the measures to ensure that the security of the data includes the information security standard (e.g. information security management systems standard e.g. ISO 2700x-ISO 27001, NIST SP 800-53, etc.); (4) the method to obtain de-identified crew feedback on those occasions that require specific follow-up; and (b) When there is a need for data protection, it is preferable to de-identify the data rather than anonymise it.
GM2 ORO.FC.231(c) Evidence-based training ED Decision 2021/002/R FEEDBACK PROCESS — DATA PROTECTION – GRADING SYSTEM (a) The data access and security policy may, as a minimum, define: (1) a policy for access to information only to specifically authorised persons identified by their position in order to perform their duties. The required authorised person(s) does (do) not need to be the EBT manager; it could be the EBT programme manager or a third party mutually acceptable to unions or staff and management. The third party may also be in charge of ensuring the correct application of the data access and security policy (e.g. the third party is the one activating the system to allow access to the authorised persons); (2) the identified data retention policy and accountability; (3) the measures to ensure that the security of the data includes the information security standard (e.g. information security management systems standard e.g. ISO 2700x-ISO 27001, NIST SP 800-53, etc.); (4) the method to obtain de-identified crew feedback on those occasions that require specific follow-up; and (b) When there is a need for data protection, it is preferable to de-identify the data rather than anonymise it.
##### GM2 ORO.FC.231(c) Evidence-based training *ED Decision 2021/002/R* **FEEDBACK PROCESS — DATA PROTECTION – GRADING SYSTEM** (a) The data access and security policy may, as a minimum, define: (1) a policy for access to information only to specifically authorised persons identified by their position in order to perform their duties. The required authorised person(s) does (do) not need to be the EBT manager; it could be the EBT programme manager or a third party mutually acceptable to unions or staff and management. The third party may also be in charge of ensuring the correct application of the data access and security policy (e.g. the third party is the one activating the system to allow access to the authorised persons); (2) the identified data retention policy and accountability; (3) the measures to ensure that the security of the data includes the information security standard (e.g. information security management systems standard e.g. ISO 2700x-ISO 27001, NIST SP 800-53, etc.); (4) the method to obtain de-identified crew feedback on those occasions that require specific follow-up; and (b) When there is a need for data protection, it is preferable to de-identify the data rather than anonymise it.