This Privacy Notice is intended to tell you how CIISA will collect and handle your personal information when you contact, work or communicate with us.
If you have any questions or if you think there is something else we should be saying about how we handle your personal information, please contact dpo@ciisa.org.uk.
Privacy Notice Summary
Last updated: September 2026
The Creative Industries Independent Standards Authority (CIISA) is committed to transparent, confidential and respectful handling of personal information.
This notice explains what personal information we collect, why we use it, who we may share it with, how long we keep it and the rights you have.
This privacy notice applies to every information exchange with CIISA including when you visit our website, report an incident, register with us, use our registrants hub, contact us, receive communications from us, engage with CIISA or exercise your data protection rights.
Who is responsible for my information?
CIISA is the Data Controller of the personal information covered by this notice. This means that we are both accountable and responsible for making sure that personal data is handled security, appropriately and in compliance with UK Data Protection Law. For more information, see the relevant sections below.
What information might you have about me?
This depends on how you interact with us. It can include your name and contact details, correspondence with us, information about your engagement with CIISA and technical information about your use of our website. For more information, see the relevant sections below.
Why do you use my information?
We use personal information to run CIISA, communicate and engage with people, operate and secure our website, provide updates, meet legal obligations and protect our legal rights. For more information, see the relevant sections below.
How can I exercise my rights?
Contact our Data Protection Officer, Angharad Jackson at dpo@ciisa.org.uk. For more information, see the relevant sections below.
Who regulates CIISA’s use of personal data?
CIISA is registered with the Information Commissioner’s Office as a data controller. Our registration number is ZB543188.
Who is CIISA?
CIISA is an independent standards authority in the UK whose purpose is to uphold and improve standards of behaviour across the creative industries and to help prevent and tackle bullying and harassment, including discriminatory bullying and harassment.
For data protection purposes, CIISA is the controller of the personal information described in this notice. This means we are responsible for deciding why and how that information is used.
Your Rights
What are my Information Rights?
You have the right to ask us if, how and why we are storing your personal data. You also have the right to ask for copies of your personal data, the right to ask us to stop using your personal data or and the right to ask us to delete it.
CIISA will handle each information rights request according to UK data protection law. We will always seek to grant information rights requests but there may be circumstances in which this is not possible, in which case we will write to you setting out the reasons why.
How can I get access to my personal data?
You have the right to ask CIISA for copies of your personal information by emailing dpo@ciisa.org.uk. CIISA will evaluate your request and respond to you in writing. There may be circumstances in which CIISA cannot provide you with everything you have asked for. In this case we will again write to you and let you know why.
The Information Commissioner’s Office (ICO) has published useful guidance on how to ask for your personal information here https://ico.org.uk/for-the-public/getting-copies-of-your-information-subject-access-request/.
When might I not get access to my personal data?
CIISA may withhold information, in certain circumstances, withhold access to your data. For example, the law allows CIISA to refuse some or all of your request if if is designed to disrupt CIISA’s work, a repeat request for information you have already been provided with or if it includes information about other people, or if confidence is necessary to protect workers’ health, safety and welfare. A full list of exemptions is available on the ICO’s website www.ico.org.uk.
Under UK GDPR there is a right to ask for my information to be deleted. Does that mean if I ask you to, you will delete all my personal data?
CIISA will handle requests for deletion (also known as erasure) according to UK data protection law. We will always seek to grant information rights requests but there may be circumstances in which this is not possible, in which case we will write to you setting out the reasons why.
- CIISA handles your personal data under a lawful basis known as legitimate interests. This means that we do not need your consent to hold or use your personal data. CIISA is processing your personal data under the lawful basis of legitimate interests. We are able to do this lawfully as we can demonstrate the following:
CIISA’s purpose is to uphold and improve the standards of behaviour across the creative industries.
CIISA needs to be able to listen to, record and analyse the experiences and stories of those who work in and with the creative industries to prevent and tackle all forms of bullying and harassment, including behaviour of a discriminatory nature. This will involve the processing, albeit minimised, of personal data. - CIISA is working towards shared professional standards of behaviour. This is about supporting safe and inclusive working environments and treating people with dignity. CIISA’s use of personal data to achieve this is proportionate and responsible as set out in our Legitimate Interest Assessment [legitimate interest assessment]. On balance, CIISA’s legitimate interests override individual personal data rights.
For more information about your rights, the Information Commissioner’s Office (ICO) provide useful guidance here https://ico.org.uk/for-the-public/your-right-to-get-your-data-deleted/
If I think that some or all of my personal data you hold is wrong, how can I put it right?
You have the right to get your personal data corrected, also known as the right to rectification. You will need to tell us what you think we have got wrong, what you think we need to do to put it right, and if you have it, provide us with evidence supporting your position.
CIISA will likely record information which can be regarded as an opinion, and therefore not categorised as personal data. For example, if someone makes a note of a colleague’s behaviour in a meeting, that note could be a correct record of their opinion at that time, whilst still being an subjective record of events. For this reason, CIISA will need to treat all requests for rectification on a case-by-case basis.
The process will be as follows:
- You tell CIISA that you believe the personal information we hold about you is incorrect.
- CIISA ‘freezes’ your data whilst we investigate. This process will usually take less than one month. If it takes longer., we will write to you to let you know.
- CIISA will issue a formal letter outlining our decision and why. This could include updating the information or marking as disputed.
- If you disagree with our findings, you will be able to submit a data protection complaint to CIISA in the first instance.
- If you are still not satisfied, you will then be able to complain to the ICO.
For more information about your rights, the Information Commissioner’s Office (ICO) provide useful guidance here https://ico.org.uk/for-the-public/your-right-to-get-your-data-corrected/
Who do I contact about data protection at CIISA?
Contact our Data Protection Officer, Angharad Jackson at dpo@ciisa.org.uk.
For more information about your rights, the Information Commissioner’s Office (ICO) provide useful guidance here https://ico.org.uk/for-the-public/ .
Personal Data
Who do I ask about data protection and CIISA?
In the first instance, the best person to contact is the data protection officer (DPO) via dpo@ciisa.org.uk. However, protecting your data runs through everything we do at CIISA so everyone who works at CIISA should be able to answer your data protection questions or signpost to right person or information.
Where do we get information about you from?
Most of the personal information we use comes directly from you.
For example, you may give us information when you email or telephone us, write to us, attend a meeting or event, engage with CIISA, sign up for updates or make a data protection request.
We may also receive information from organisations or people with whom we engage as part of our work.
Information about your use of our website may be collected automatically through your device and through cookies and similar technologies.
We do not obtain information about website visitors from unrelated third-party data brokers.
How will you keep my personal data safe?
CIISA will keep your personal data safe by working to recognised security standards which will be independently audited before we begin handling personal information. As CIISA begins to carry out its operational services, we will continue to test our security arrangements. For more information, please contact dpo@ciisa.org.uk.
CIISA will keep your personal data safe by working to recognised security standards which will be independently audited before we begin handling personal information. As CIISA begins to carry out its operational services, we will continue to test our security arrangements. For more information, please contact dpo@ciisa.org.uk.
Which security standards does CIISA comply with?
CIISA works to the best practice set out by the National Cyber Security Centre (NCSC) in their Cyber Assurance Framework. CIISA will accredit to Cyber Essentials before we begin handling personal information. Cyber Essentials is a government-backed certification scheme that will help us keep our data and your data safe from cyber-attacks. Our security arrangements will be reviewed by independent assessors, accredited through IASME, the NCSC’s Cyber Essentials delivery partner. You can find out more about Cyber Essentials here.
Why do you need personal data to do your work?
CIISA carries out an important role in setting and monitoring professional Standards for working environments across the creative industries. To do that, CIISA carries provides a vital reporting service – allowing people from across the creative industries to report experiences and behaviours that may not align with the expectations given in CIISA’s Standards. As personal data is information that relates to an identifiable person, this reporting is likely to capture personal data about you and other people involved.
Why do you need my personal data when I report a concern?
Personal data is information about or relating to someone who can be identified. If we do not know who has raised a concern, we will only be able to address that concern in the most general way. Whilst you can choose to withhold your identity when using our confidential reporting service, that may mean that we are able to do less with the information you give us.
We also need to know who you are if you want to follow-up with us after raising a concern. We need to make sure that we are talking with the person who raised the concern, and not with someone impersonating them. To do that we will need to be able to contact you securely and privately. To enable this, you will need to provide a means of communication such as a private email address. We will publish more information on how our confidential communications will work to keep you and your data safe before we start collecting personal information.
We will treat your information confidentially which means that if even if we collect and use your personal information within CIISA, we will not identify you outside CIISA unless you ask us to. For example, even if a report or standards notice is based on the personal information of one or more individuals, we will not name or otherwise allow those people to be identified in the report. We will do this through a structured approach to anonymisation to remove the risk of re-identification.
This will enable us to help people to resolve concerns, understand thematic issues and trends and conduct independent, evidence-based investigations where necessary.
Will you capture other people’s personal information when I raise a concern?
CIISA is here to uphold and improve standards of behaviour across the creative industries. We may not be able to address concerns without understanding who was involved, their roles and their actions. If they can be identified, then that becomes their personal data, even if they aren’t identified by name.
That doesn’t give them an automatic right to gain access to information about a concern raised by someone else. Whilst they will have the right to ask CIISA for access to their personal information, CIISA will consider each request on a case-by-case basis. CIISA will never release the identity or personal information of the person who raised the concern in response to a subject access request. CIISA will work within data protection law to safeguard the safety, wellbeing, privacy and data protection rights or the person who raised a concern in confidence.
What types of personal data do you collect?
CIISA will minimise the personal data we collect – we will only capture and keep the information we need to fulfil our purpose. This includes:
- contact information about the people we work with or who raise concerns with us,
- equality and diversity information to help us ensure our service is inclusive and to identify inequalities in the Creative Industries.
- information about concerns that are raised which may include descriptive personal data such as recording the individual impact of poor behaviour.
Do you collect sensitive information about me, for example about my health?
CIISA will collect information which could be viewed as especially sensitive. This information is described in UK data protection law (GDPR) as ‘special category’. CIISA is required to put extra safeguards around our use, storage or management of special category data.
Special Category data is defined as information about your political opinions, religious or philosophical beliefs, genetic or biometric data, gender, health and wellbeing, racial or ethnic origin, sexual orientation and trade union membership.
Information we collect
The information we collect depends on how you interact with us.
When you contact us
We may collect information including:
- your name;
- email address;
- postal address;
- telephone number;
- the organisation you represent or are telling us about, where relevant;
- details of your correspondence or engagement with us;
- records of meetings, telephone calls or other
communications; and - other information that you choose to provide to us.
When you report an incident to is
You can report completely anonymously. However, should you wish for a response we will need contact details.
- your name;
- email address;
- postal address;
- telephone number;
- the organisation(s) you telling us about, where relevant, your work or relationship with that organisation, dates and locations and other information relevant to the report.
- equality and diversity information about you that helps us understand who is (and is not) reporting to CIISA so we can take steps to ensure our service is fair and open to all as well as identifying trends and patterns affecting different social groups and communities.
- details of your correspondence or engagement with us;
- records of meetings, telephone calls or other communications; and
- other information that you choose to provide to us.
When you sign up for updates and communications about CIISA’s activities
We will collect:
- your name;
- email address; and
- your communication preferences.
When an organisation registers with CIISA
We will collect:
- Contact details for the organisation. This may include details of individuals working for or with that organisation such as names, telephone numbers and email addresses to enable billing and account management.
- Emails and names of individuals who access CIISA’s registrants’ hub to access information specifically for registered organisations.
For more information, visit our registration information on our website.
When you use our website
We may automatically collect information including:
- your IP address;
- internet service provider;
- browser type;
- device type;
- device identifiers;
- pages you visit;
- the date and time of your visit;
- how long you spend on particular pages; and
- website performance and diagnostic information.
Some of this information may be collected using cookies and similar technologies.
Why we ask for personal data
Do I have to give you my personal data? What happens if I don’t?
You don’t need to tell us who you are or provide information which may identify you which means that we won’t hold any personal data. Data must be about an identifiable person to be personal data. We will record what you are happy telling us but the more you withhold, the less we may be able to do with it. If you have any specific concerns, then please contact dpo@ciisa.org.uk.
Confidentiality
If I tell you about something, will it remain confidential?
CIISA takes confidentiality very seriously. CIISA will only share data with others in very limited circumstances when:
- we believe that someone is at significant risk of harm in which case we will contact the police.
- we are legally obligated to do so.
CIISA will not share your personal data or identity with people who may be involved in your complaint, your concern or your industry without your permission to do so.
Raising concerns in confidence
If I tell you about a concern, who else will get to see it?
If you raise a concern with us, we will share with the CIISA colleagues who need access as part of their job. CIISA will ensure that only the people who have a legitimate reason to see the data can. We will proactively monitor access so that we pick up on any unauthorised attempts to view personal data are both thwarted and investigated.
CIISA will not share your personal data or identity with people who may be involved in your complaint, your concern or your industry. We will not share your personal information nor disclose your identity without your permission to do so unless:
- we believe that someone is at significant risk of harm in which case we will contact the police.
- we will also disclose information when legally obligated to do so.
Keeping my identity safe
I want to tell you about something happening at my workplace but don’t want the people I work with to find out that it’s me. How will you keep my confidence?
If you raise a concern with us, only CIISA’s staff (who need access as part of their job) will see your personal information. That means controls even within CIISA such as locking down our information systems so that only the people working on your concern can see it. We will proactively monitor activity so that we pick up on any unauthorised attempts to view personal data are both thwarted and investigated.
CIISA will not share your personal data or identity with people who may be involved in your complaint, your concern or your industry. We will not share your personal information nor disclose your identity without your permission to do so unless:
- we believe that someone is at significant risk of harm in which case we will contact the police.
- we will also disclose information when legally obligated to do so.
If someone asks for their personal information under UK data protection law, will they be able to find out information about people who have raised concerns about them?
The short answer is no, not through the right of access. The UK’s data protection laws allow people to ask for copies of their information as well as providing safeguards for the personal data of third parties which may be included in that information.
Example:
Person A and Person B contact CIISA with their concerns about inappropriate behaviour by Person C at rehearsals for a well-known TV production. Person C writes to CIISA asking for their personal information. CIISA withholds any identifying information about Person A, Person B and anyone else who has reported concerns. The information CIISA provides to Person C is Person C’s information only. CIISA does provide any information that could identify Person A and Person B, even indirectly, such as their age, gender, their religion, the date and time, their ethnicity, their role and so on. This sort of information which can be used to piece together an identity is still personal data and hence would not be disclosed to a third party.
Will anyone else see my information?
If I tell you about a concern, who else will get to see it?
If you raise a concern with us, we will share with the CIISA colleagues who need access as part of their job. CIISA will ensure that only the people who have a legitimate reason to see the data can. This means that we will be able to lock down cases so only the assigned caseworker can view and work on them. We will proactively monitor access so that we pick up on any unauthorised attempts to view personal data are both thwarted and investigated.
Your personal data will never be shared with members of the public or with individuals inside the Creative Industries without your consent or knowledge.
In exceptional circumstances, CIISA may need to disclose personal information to third parties but this is limited to:
- when there is an immediate risk of harm to an individual and CIISA discloses to the police
- when CIISA is compelled by law to disclose information, for example, to the Information Commissioner if they are investigating a data protection complaint.
Who do we share information with?
CIISA handles two main types of information. The first is information about incidents of poor or inappropriate which have been reported to us. This is often deeply personal, emotive and shared with us in expectation of confidence. This report information would only ever be shared with either the reporter’s consent, when obliged to do so by law or if there is a clear and iminent risk of harm requiring us to inform the police.
The second type of information is that which we use to conduct our business and will include personal data. For example, employee records or invoices from contractors working for us. We may share this type of business information where necessary with organisations that provide services to CIISA, such as professional, technical, communications, accounting or other support services. This will not include personal data obtained via incident reports.
These organisations may only use personal information for the purposes for which it has been provided and must handle it appropriately.
We may also share information:
- with professional advisers;
- with regulators or government bodies;
- with law-enforcement organisations;
- with courts or tribunals;
- where necessary to establish, exercise or defend legal
rights; - where necessary to protect someone’s vital interests;
- where you have asked or consented to us doing so.
We will only share information where there is an appropriate reason and lawful basis for doing so.
Data protection complaints
CIISA must take steps to help you if you want to make a complaint about how we have handled your personal information. We will acknowledge your complaint within 30 days and respond to it without undue delay. You can contact us at dpo@ciisa.org.uk.
Or write to:
CIISA22 Wycombe End
Beaconsfield
Buckinghamshire
HP9 1NB
United Kingdom
Can I also complain to the ICO? How?
The ICO will normally expect you to have complained to CIISA first. If you remain dissatisfied with CIISA’s response to your complaint, you have the right to complain to the ICO. For more information see https://ico.org.uk/for-the-public/how-to-make-a-data-protection-complaint/
Information Commissioner’s OfficeWycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Where is my personal data held?
All CIISA information will be processed and stored in the United Kingdom. CIISA intends to only store, use and manage data within the UK. We will not transfer personal data outside the UK without your permission.
What lawful basis are you using to process my personal data?
CIISA is processing your personal data under the lawful basis of legitimate interests. We are able to do this lawfully as we can demonstrate the following:
- CIISA’s purpose is to uphold and improve the standards of behaviour across the creative industries.
- CIISA needs to be able to listen to, record and analyse the experiences and stories of those who work in and with the creative industries to prevent and tackle all forms of bullying and harassment, including behaviour of a discriminatory nature. This will involve the processing, albeit minimised, of personal data.
- CIISA is working towards shared professional standards of behaviour. This is about supporting safe and inclusive working environments and treating people with dignity. CIISA’s use of personal data to achieve this is proportionate and responsible as set out in our Legitimate Interest Assessment [legitimate interest assessment]. On balance, CIISA’s legitimate interests override individual personal data rights.
Data Protection when more than one organisation is involved
What would a CIISA Investigation involving multiple organisations look like?
If CIISA becomes aware of a potential pattern of behaviour, it may issue separate and confidential Standards Notices to each relevant organisation, requesting their cooperation. Each Notice will be issued independently and will not identify any other organisation involved. It will ask only for the relevant data needed to assess the issues.
At the same time, CIISA will issue a Standards Notice to the individual concerned, notifying them of the proposed investigation and inviting their comments.
CIISA will then carry out an investigation in line with its usual procedures to establish what happened. We would review and analyse the information provided by each organisation to determine whether there is evidence of a repeated pattern of behaviour that breaches CIISA’s Standards.
Once the investigation is complete, CIISA will share an Investigation Findings Report with the individual for comment. Each organisation will only receive the parts of the report relevant to its own involvement; no organisation will see information provided by others, to preserve confidentiality.
CIISA will then proceed to its Adjudication and reporting stages. If the Adjudication Panel determines that a pattern of behaviour has occurred that breaches CIISA’s Standards, both the individual and each relevant organisation will be notified of that finding.
If CIISA decides to publish a summary of the investigation, it will ensure that no third-party identifying details are disclosed. CIISA may only publish details identifying the individual where there is a significant public interest in doing so.
All processing is carried out under strict confidentiality, with proportionate safeguards and in line with CIISA’s Privacy and Data Protection Policies, ensuring fairness, security, and respect for individuals’ rights at every stage.
GDPR and CIISA
Does UK GDPR prohibit CIISA?
No. UK GDPR sets out how personal information can be used. CIISA complies with UK GDPR as a data controller. There is no conflict between CIISA’s mission to uphold standards and the UK GDPR.
How will CIISA’s work operate under the UK GDPR and Data Protection Act 2018?
As a data controller, CIISA takes data protection and privacy of all parties extremely seriously.
Our Services Guide sets out our general approach to how we will process data securely and fairly (and in accordance with the UK GDPR and data protection laws) and we will be producing all relevant Data Protection and Privacy policies (including Data Protection Impact Assessments for all high-risk processing) in due course as we finalise our service design.
Our lawful bases for processing
CIISA’s primary lawful basis for processing personal data is that it is necessary for the purposes of CIISA’s legitimate interests under Article 6(1)(f) of the UK GDPR. These legitimate interests reflect CIISA’s independent role in promoting high standards and accountability within the creative industries. They include:
- monitoring and upholding CIISA’s Standards;
- safeguarding individuals, particularly those in vulnerable positions;
- addressing patterns of harmful conduct across the creative industries;
- providing accountability where statutory remedies are not used; and
- supporting and complementing existing regulators where appropriate
In some cases, CIISA may also rely on other lawful bases such as consent (Article 6(1)(a)) or compliance with a legal obligation (Article 6(1)(c)) depending on the nature of the data and purpose of processing.
Where CIISA processes sensitive personal data (for example, relating to health, safeguarding, or allegations of misconduct), it will do so under Article 9(2)(g) of the UK GDPR and the substantial public interest conditions set out in Schedule 1, Part 2 of the Data Protection Act 2018, particularly paragraphs 10 (preventing or detecting unlawful acts) and 18 (safeguarding of individuals at risk).
If CIISA processes information relating to criminal behaviour, this will be done only where authorised under Schedule 1 of the Data Protection Act 2018 and supported by appropriate policy and procedural safeguards.
CIISA plans to carry out investigations about potential patterns of behaviour by an individual that may have occurred across different organisation. How will CIISA be able to do that whilst complying with UK GDPR?
CIISA acts as the central authority for monitoring and embedding its Standards across the creative industries. This means it is uniquely placed to investigate potential patterns of harmful or inappropriate behaviour that may occur across multiple organisations or sectors.
To do this lawfully, CIISA operates as an independent data controller under the UK GDPR. This allows CIISA to receive and handle personal data from different organisations in the creative industries where it is necessary and proportionate to support its role in safeguarding individuals and upholding professional standards. Each organisation remains responsible for its own data but may share relevant information with CIISA for the lawful purposes of assisting CIISA in pursuing its legitimate interests.
CIISA then reviews all the information securely and confidentially to see whether there is evidence of a repeated pattern of behaviour. If sensitive or criminal-offence data is involved, CIISA will rely on the substantial public interest provisions in the UK GDPR and Data Protection Act 2018 and apply strict safeguards to protect individuals’ privacy and rights at every stage.
By operating as a trusted, central authority, CIISA can lawfully combine and assess information from multiple sources to identify wider patterns of behaviour that no single organisation can detect alone.
Transparency
Does CIISA publish information about what you do?
Yes. CIISA publishes information regularly on our website. We will publish clear Privacy Notices explaining what data we collect, why we use it, how long we keep it, and with whom it may be shared.
Will anyone be able to identify me from the material published on your website?
No. CIISA will take steps to remove identifying information before we publish anything unless you have given us your permission to disclose your identity.
What transparency legislation are you subject to?
CIISA is not subject to any transparency legislation including the Freedom of Information Act. However, CIISA intends to be proactively transparent.
Can I submit a Freedom of Information request to CIISA?
No. CIISA is not subject to the freedom of information act (FOIA).
I’m a researcher and I think CIISA may have information that would help me. How can I get hold of it?
Please check our website. If you can’t find what you are looking for, please contact dpo@ciisa.org.uk.
Are you registered with the Information Commissioner’s Office (ICO)?
Yes, CIISA’s registration number is ZB543188 and you can see our registry information here: https://ico.org.uk/ESDWebPages/Entry/ZB543188.
Marketing
Will my data ever be used for marketing purposes?
Yes, CIISA will conduct awareness campaigns and marketing activities. However you will always have the option to opt in or out, as we will never contact you without your explicit consent.
Publishing
Will you publish standards notices?
CIISA will not publish details, as this is a confidential process. However, should CIISA see a pattern of concern (e.g. an organisation repeatedly chooses to ignore a Notice or not respond fully), we may publish that an organisation has not responded to a Standards Notice. That would not provide details that would identify any individuals. CIISA will not name individuals unless they have asked us to do so.
Will you publish your work?
Yes, CIISA intends to publish information about our work and our investigations. This is to promote learning and behavioural improvements across the sector. We will protect the identifies of those involved by anonymising the information we publish.
Bad Faith Reports
What will you do about bad faith reports?
Whilst we anticipate that most people will raise concerns in good faith, CIISA is aware that some people may make reports to cause harm and distress to others. CIISA will take steps to ensure our reporting data is accurate and is not influenced by misleading/ false reporting. We will carefully analyse the details of reports alongside cross-referencing with our database or other relevant information. We will ask individuals to provide us with information that supports their concerns.
We will assess and grade each report (including the source and evidence/information given) for reliability and content. This grading will enable CIISA to determine how to proceed and whether it is possible to process the information.
If CIISA considers that a report given to us is false or misleading, we will delete the report immediately and take no further action on it. Should we later identify (or become aware) that a report was false or misleading, we will discontinue any action we have begun.
Artificial Intelligence
Will you use AI?
AI can be a powerful tool that can turbocharge making sense of data, unlocking learning and providing personalised service. But there are also concerns about hallucinations, about bias, security and privacy and how this still relatively new technology will work in practice. CIISA intends to make ethical, secure use of AI by designing and following clear guardrails which we will also publish on our website.
How will you protect my data when using AI?
CIISA will take steps to ensure that your personal data continues to be protected even when using AI. This means that:
- We will conduct data protection impact assessments to understand and mitigate risks before using AI.
- We will not nor will we allow others to use CIISA data to train AI models.
- We will adhere to best practices for AI governance.
Is AI going to decide if my concern is taken forward?
No, humans will always make decisions at CIISA. We call this ‘human in the loop’. This means that we may use AI to summarise large documents or find trends in data but any decision affecting people will always be taken by people.
Deep Fakes
How will you deal with deepfakes?
We understand the anxiety caused by increasingly convincing deepfake technology. CIISA will use digital forensic tools to identify and assess possible deep-fakes as part of our process of considering all the evidence in a case. We will assess and grade each report (including the source and evidence/information given) for reliability and content. This grading will enable CIISA to determine how to proceed and whether it is possible to process the information.
Retention and deletion
How long will you keep my personal data?
We will usually keep your personal data for a period of twelve months after you have raised a concern with us. For further information please see our retention policy [retention policy].
If I ask you to delete my data, will you delete everything?
You have the right to ask us to delete your data but there may be circumstances where we are unable to do so either fully or in part. If we do agree to your request to erase your data we will retain a ‘stub’ record with just enough information to be able to prove we carried out your request. We will then retain this stub record for a further 12 months.
Legitimate Interests
Legitimate interests is one of the lawful bases organisations can use under data protection law.
Where we rely on it, we consider:
- the purpose for which we want to use the information;
- whether using the information is necessary for that purpose; and
- the impact that using it could have on your rights and interests.
We will not rely on legitimate interests where our interests are overridden by your rights and freedoms.
Data Protection Impact Assessments
CIISA will complete DPIAs setting out what we intend to do, how we will work, risks arising and how we intend to deal with them before starting our operations processing personal data. We intend to publish our DPIAs, withholding only technical or security information when that poses a potential security risk.
Freedom of Information
Can I submit a Freedom of Information request to CIISA?
No. CIISA is not subject to the freedom of information act (FOIA).
Do you use cookies?
Yes. Our website uses cookies and similar technologies.
Some cookies are strictly necessary for the website to operate and do not require your consent.
Where we use non-essential cookies, we will give you the opportunity to choose whether to accept them through our cookie preference controls. Cookies and similar technologies may collect information about your device and how you interact with our website. You can change your cookie preferences using the cookie controls available on our website.