BS 10012:2017 – Data Protection, Specification for Personal Information Management Systems

BS 10012:2017 Certification Service

BS 10012:2017

BS 10012, also known as the “Data Protection Personal Information Management System,” or “BS 10012:2017 Data Protection Personal Information Management System,” is a management system standard related to the processing and protection of personal data. This standard was published by the British Standards Institution (BSI), which is based in the United Kingdom.

BS 10012 helps you maintain and improve compliance with data protection legislation and provide assurance to your stakeholders by providing a framework for the Personal Information Management System standard. In particular, it aims to help organizations regulate their processes for the processing and protection of personal data and take appropriate measures. 

The standard provides a framework covering the following topics:

 

 

Furthermore, it supports compliance with data protection legislation, enhances customer loyalty, safeguards your reputation and ensures that your personal data management practices are recognised as best practice. 

The standard helps organisations to effectively manage personal data and ensure legal compliance, thereby contributing to the establishment of a reliable data protection management system. It is therefore an important reference source for organisations working in the fields of data protection and privacy. 

 

Definition and scope of personal data,
The determination and implementation of the legal conditions for the processing of personal data,
Establishing the appropriate policies, processes and procedures necessary for the processing of personal data,
Establishing procedures for the detection, reporting and handling of personal data breaches,
Training staff and raising their awareness,
Controlling access to personal data and implementing security measures.
Identifying and managing risks related to personal information,

BS 10012 certification is suitable for organisations of all sizes in any sector. 

The standard emphasises the importance of data protection, particularly in sectors where data protection is critical, such as banking, finance, healthcare, the public sector and the IT sector. The standard also applies to organisations that manage large volumes of personal data, as well as to other organisations such as data centres and IT outsourcing companies. 

Preparation and Planning

  • Application: The first step is to apply to an accredited certification body for BS 10012 Data Protection and Personal Information Management certification.
    • Data Protection and Personal Information Management System Planning: The organisation draws up a plan for the Data Protection and Personal Information Management System. This plan includes data protection and personal information management policies, objectives and management processes. 

System Setup Implementation

  • Implementation of the Data Protection and Personal Information Management System: The organisation implements the Data Protection and Personal Information Management System in accordance with the BS 10012 standard. This includes the monitoring, measurement and analysis of the Data Protection and Personal Information Management System.
    • Monitoring and evaluating the performance of the Data Protection and Personal Information Management System: The performance indicators necessary to achieve the objectives relating to the effectiveness of the Data Protection and Personal Information Management System are identified and monitored.

Internal Audit and Management Review

  • Internal Audit: The organisation carries out internal audits to assess the effectiveness of the Data Protection and Personal Information Management System and its compliance with the standard.
    • Management Review: Management reviews the performance of the Data Protection and Personal Information Management System and identifies areas for improvement. 

Certification Audit

    • Independent Audit: An independent audit is carried out by the certification body to assess the organisation’s Data Protection and Personal Information Management System and its compliance with the standards. 

Reporting and Feedback: Audit findings are reported and feedback is provided to facilitate the necessary improvements.