Subject: Freedom of Information Request – Information Asset Ownership and Data Governance Roles Dear Sir/Madam, I am writing to you under the Freedom of Information Act 2000 to request the following information: Question/s to be Answered Under the FOIA I’d like to request the following information please for each organisation that operates under this FOI email (if the answers are different for each organisation/there are multiple organisations).
1. Name of organisation SIRO (Senior Information Risk Owner) or similar post (Chief Information Governance Officer etc), or responsible person for SIRO duties. There may be more than one SIRO.
2. Contact email of person or persons named in question 1.
3. Name of organisation DPO (Data Protection Officer) or responsible person for DPO duties.
4. Contact email of DPO.
5. Have you appointed, or do you plan on appointing or delegating the position of IAO to any employees?
6. Who is responsible for the leading IAO structure, I.E. the SIRO/’Lead’ IAO/Head of Governance/Head of Corporate Services etc?
7. Who is responsible for reviewing and implementing any training needs for the IAO’s?
8. In relation to questions 6 and 7, can we please be provided with the contact email address of the appropriate person?
9. Is IAO training delivered by an external third party or internally?
10.Are you or have you considered becoming ISO 27001 compliant or certified? If so when?
11.Following on from Q10, If so whom is/would be responsible for implementation or exploration of ISO 27001? (as in, the person/job title/email address)
12. Who is the person responsible for the physical security controls in your estate e.g. CCTV, Lighting, barriers, intrusion detection and fencing.
13. In relation to question 12 when was the effectiveness of these controls last reviewed?
14. In relation to question 12 can we please be provided with the name/job title and email address of this person?
15. Who would be the person responsible for the organisation of external training within your organisation. E.g. Head of learning and development / HR Manager.
16. Can you please provide the name/job title and email address for the person in question 15?
I would prefer to receive this information in electronic format (e.g. Word or Excel), if available. If you require any clarification to process this request, please let me know as soon as possible. I understand that under the Act, I am entitled to a response within 20 working days of your receipt of this request. Thank you for your time and assistance.