Continuing Professional Development (CPD) system in Tier 4 of the Agricultural Reform Programme: Data protection impact assessment

Data protection impact assessment to accompany consultation on Continuing Professional Development (CPD) in Tier 4 of the Agricultural Reform Programme. Tier 4 focuses on people and professional development. This includes skills, knowledge transfer, training, advisory services, and business support.


5. Data controllers and data processors/sub processors

5.1 Data controllers

Organisation Scottish Government
Activities Sponsor of the CPD system in Tier 4 of the Agricultural Reform Programme. It would set out the policy in relation to the CPD system, including the groups or sectors in Scottish agriculture who are within the scope of the CPD system, the data that was to be collected and processed, policy for exemptions from the CPD system as a result of specific circumstances.
Is the organisation a public authority or body as set out in Part 2, Chapter 2, Section 7 of the Data Protection Act 2018? Yes.
Lawful basis for processing under UK General Data Protection Regulation (UK GDPR) Article 6 for the collection and sharing of personal data – general processing The lawful basis for processing in this instance is public task (the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller). (GDPR Article 6(1)(e)).
Lawful basis for processing under UK General Data Protection Regulation (UK GDPR) Article 9 – special category data or Article 10 – criminal convictions data Article 9(2)(g) – processing is necessary for reasons of substantial public interest, on the basis of law which shall be proportionate to the aim to support agriculture and to make provision for CPD for those involved in agriculture and related industries. Processing would respect the essence to the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and interests of the data subject.
Condition in Schedule 1 or 2 of the Data Protection Act 2018 Processing satisfies the conditions of Schedule 1 of the Data Protection Act 2018 in that processing is necessary for the purposes of performing or exercising obligations or rights which are imposed or conferred by law on the controller or the data subject in connection with employment and when the processing is carried out, the controller has an appropriate policy document in place. Processing satisfies the conditions of Schedule 2 of the Data Protection Act 2018 as the processing is necessary for the purposes of identifying or keeping under review the existence or absence of equality of opportunity or treatment of groups of people specified in relation to that category with a view to enabling such equality to be promoted or maintained. This is personal data concerning health to ascertain whether an exemption from participating in the CPD system for a specific period of time is required from the CPD system.
Law enforcement – if any law enforcement processing will take place – lawful basis for processing under Part 3 of the Data Protection Act 2018 The CPD system would not require any data subjects to provide data on existing criminal convictions. However, the data to be processed would be used by the Scottish Government to determine whether data subjects were compliant with the requirements of the CPD system where there were mandatory requirements to be met.
Legal gateway for any sharing of personal data between organisations Sections 30-31 of Agriculture and Rural Communities (Scotland) Act 2024. The Scottish Government would expect to procure the CPD system. Conditions relating to data sharing would be required to be met. There would also be a data sharing agreement put in place.

5.2 Data processors and sub processors

Organisation Activity Contract in place compliant with UK GDPR Art 28?
Name of organisation is not currently known. The Scottish Government is expected to undertake procurement for the CPD system. Data processor for the CPD system. It would develop, host, maintain the CPD system and provide management reports to the Scottish Government as required in the contract. This would include:
  • what IT systems or other methods it would use to collect personal data;
  • how it would store the personal data;
  • the details of the security measures that would be used to protect the personal data;
  • how it would transfer the personal data from one organisation to another;
  • how it would retrieve personal data about certain individuals;
  • how it would ensure it adheres to a retention schedule; and
  • how it would delete or dispose of the data.
The processor may be required to data share with other organisations (names not currently known) to upload data relating to the completion of CPD activities for users. A policy on this has not currently been set out or agreed.
The relationship between the Scottish Government and a contractor regarding personal data would be covered by the Scottish Government standard model contract set up during the procurement process. The contract would be compliant with the Article.

5.3 Data flows

The Flowchart of Data flows is at Annex B.

Contact

Email: Tier4ARP@gov.scot

Back to top