In March 2018 the Independent Privacy Auditor (IPA) and SECAS undertook a review of the Privacy Controls Framework. At the SEC Panel meeting on the 11th May 2018, the SEC Panel was satisfied with version 1.2 of the Privacy Controls Framework (PCF). The current version is still in draft and consultation will be issued to SEC Parties, Ofgem and Citizens Advice to seek feedback once further updates have been prepared.
The updates provided in the PCF cover a range of matters, including:
- Where there had previously been Assessment process elements ‘To be Confirmed’, these have been updated to reflect the agreed processes of the IPA;
- Greater detail regarding what the IPA may require as evidence for each Section I obligation,
- Acknowledgment of the General Data Protection Regulation that will be coming into force from 25th May 2018; and
- Inclusion of processes for the post Assessment period. This is to bring the PCF closer in line with the processes that have been well established in the Security Controls Framework (SCF).
The PCF can be found here – Privacy Controls Framework (PCF) v2.9
Any questions can be directed to the SECAS helpdesk.