Skip to content

Information Governance

DPO? DSPT? DPIA? ISMS? ISO 27001? ISO 9001?

Why do you need to know what these mean?

Why do you need them?

If you hold personal information about your customers then, by law, you must protect it!

Information governance is a framework that you use to secure confidential data in your solution. You must evidence that you are handling data safely, securely and legally. The technical aspects and operational policies are complex and often easy to get wrong. 

Even more confusing is that there isn’t a one-fits-all solution. Every digital product and service uses and handles data differently and, therefore, requires appropriate protection.

Information Governance as a Service (IGaaS)

So, how do you know what you need?

Our Process

Understand

We help you understand what you need. You can choose what you want – one element or the whole service.

We will value the work you may have done and will build on it to achieve the outcomes you want.

We will work with you to create a plan that is bespoke to you.

Understand

Deliver

We put the plan into action to create the capability you need.

Work with you and represent you to extrernal bodies to ensure that you are aligned to the required standards. 

Support you with project management if required.

Deliver

Sustain

We can integrate compliance into your software delivery life cycle.

Maintain digital compliance for new or updated products.

We take care of all the admin so you can work on your business. 

Sustain

There is no one fits all solution, rather we tailor a solution to your needs. You choose what works best for you. We provide a bespoke, straightforward, understandable and manageable service to achieve your compliance.

You may not have to hand an expert in data protection or a registered clinician who is trained in clinical safety. Our IGaaS provides both when, where and for as long as you need them.

Other Services

Our Information Governance as a Service option will quickly set up an ISMS & QMS that includes the technical, physical and legal procedures and policies required for information risk management. This framework is ready to be integrated into your business.

Read more

Do you process NHS patient or customer data? If so, you’ll need evidence that you have systems and processes in place to protect the data, and remove it if requested. We can provide a Data Protection Officer, who will help you to identify and minimise risks and complete compulsory assessments, that are required on an ongoing basis.

Our IGaaS will help you comply with your data protection requirements.

Read more

The ability to sell your digital product into the NHS can mean success for your business. Yet selling into the NHS is a complex process.

Framework Genie is your guide along this journey. We help you identify a suitable framework, obtain the necessary compliances to achieving a fully validated and assessed product, and support you step by step to a successful listing.

Read more

You may not have to hand an expert in Clinical Safety. Our CSaaS provides a CSO when, where and for as long as you need them.

Read more

If your product stores, collects or uses NHS data, then you need to complete a DTAC.

Like any journey, if you’ve not travelled it before, its always much easier and quicker with a guide. We will partner you along this process, we know how to get you there in the most efficient route, we speak the language of the NHS so that you don’t have to!

Read more

What do all these acronyms mean?

ISO 27001 is an international standard to help you manage your information security. It requires you to set up an Information Security Management System (ISMS). Framework Genie has created an ISMS that includes the technical, physical and legal procedures and policies required for information risk management. This framework is ready to be integrated into your business.

  • Identify the gaps and then create your ISMS.
  • Assess and audit all your information security risks.
  • Mitigate these risks by implementing suitable controls and governance.
  • Achieve certification with an external auditor.

ISO 9001 helps organisations implement clear, repeatable processes to maintain a quality service for their customers every time.

Achieving ISO 9001 accreditation will help you establish a Quality Management System (QMS) that will help you increase productivity, win new business and save money.

  • Identify the gaps and then create your QMS.
  • Assess and audit all your business processes.
  • Mitigate these risks by implementing suitable controls and governance.
  • Achieve certification with an external auditor.

DTAC stands for Digital Technology Assessment Criteria. If your product collects, stores and uses NHS data (including personally identifiable data) the DTAC assessment will check for compliance.

If you want to sell into the NHS, you need a DTAC.

DTAC is the NHS baseline for health technologies and sets out very comprehensive criteria for digital health tools used by the NHS. There are many elements that make up DTAC, these are clinical safety, data protection, technical security, interoperability, usability and accessibility standards.

To ensure your compliance, you will need to assign a:

  • Data Protection Officer (DPO), who is independent and an expert in data protection, to ensure your compliance.
  • Clinical Safety Officer (CSO), who is a registered clinician, to validate that your product minimises the risks of harming users.

It’s a Digital Security Protection Toolkit.  This is used by the NHS to inform in the public domain of your performance against the National Data Guardian’s 10 data security standards.  This is an online self-assessment for organisations which must be completed annually and may be audited by the NHS.  This is now in its 6th version, which introduced many new changes, for example all your staff must have an ‘appropriate understanding of information governance and cyber security’.

All organisations that have access to NHS patient data and systems must use this toolkit to provide assurance that they are practicing effective data security and that personal information is handled correctly.

It’s a Data Protection Impact Assessment. Its process is designed to help you systematically analyse, identify and minimise the data protection risks of a project or plan. It is a key part of your accountability obligations under the UK General Data Protection Regulations (GDPR) and when done properly helps you assess and demonstrate how you comply with all of your data protection obligations. It is a legal requirement.

It’s a Data Protection Officer. ​How you access, process and store data is an important part of DTAC. Many organisations will need to nominate a DPO who will assist you to monitor internal compliance, inform and advise on your data protection obligations.

Do you need a DPO? The ICO provide a 5 minute online questionnaire to help you decide.

Our IGaaS provides options for a DPO for when, where and as long as you need them.

Our IGaaS process involves three simple steps:

Understand
We assess the compliance work you may have already done, complete a gap analysis, then help you create a bespoke plan based on your individual needs – whether that’s one element or the whole service.

Deliver
Using our extensive library of templates and tools, we can quickly set up your Information Security Management Systems and train you to achieve compliance. We support you with project management and represent you to external assessors.

Sustain
Because we integrate compliance into your software delivery lifecycle, you can easily manage digital compliance for new or updated products. We take care of the admin so you can focus on your business.