BS 10012:2017 – What are the Benefits and How Do I Achieve Certification

|
|
PUBLISHED on
21 Jul
2022

BS 10012 is a British management system standard which has been developed to enable organisations to implement a personal information management system (PIMS). It provides a framework for maintaining and improving compliance with data protection legislation and good practice.

The framework will help you to manage risks to the privacy of personal data and implement appropriate policies, procedures and controls.

In March 2017, BSI updated this Standard in response to the introduction of the European Union General Data Protection Regulation (GDPR).

Article 42 of the GDPR encourages the “establishment of data protection certification mechanisms…. for the purpose of demonstrating compliance with this Regulation of processing operations by controllers and processors.”  This is exactly what BS 10012 is intended to offer.

BS 10012 follows the ‘Plan-Do-Check-Act’ continuous improvement model and is aligned to ISO Annex SL, adopted by all key management system standards, which enables organisations to integrate their PIMS with other standards, notably ISO/IEC 27001:2013.

It is also a standard which organisations can certify against.

Benefits of Implementing BS 10012:2017

By implementing and certifying your PIMS against BS 10012:2017, you will be able to:

  • Demonstrate your commitment to protecting client and stakeholder personal data
  • Identify risks to personal information and implement controls to mitigate them
  • Use the management system as part of a privacy compliance framework to demonstrate compliance with the GDPR and the Data Protection Act 2018
  • Benchmark and continually improve your management of personal data against recognised best practice
  • Protect your reputation and minimise adverse publicity
  • Gain competitive advantage when seeking and retaining business.

How do I Achieve Certification to BS 10012:2017

As stated above, BS 10012:2017 has been drafted using the rules specified for management system standards in the ISO Directives Annex SL and follows the common structure and core text as standards such as ISO/IEC 27001:2013 and ISO 9001:2015.

As one of UK’s leading implementers of ISO 27001 and with its wealth of data protection experience and expertise, URM is uniquely placed to assist you develop and implement a PIMS and achieve certification with BS 10012:2017.

These services range from conducting a gap analysis (where one of URM’s consultants will assess your existing PIMS and compare it against the BS 10012 requirement) to full lifecycle services.

URM also offers a readiness assessment service for those organisations seeking certification. With the full lifecycle implementation services, URM can assist you meeting requirements such as:

Understanding and documenting the context of the organisation (inc. determining the scope of the PIMS

Demonstrating leadership and commitment with respect to the PIMS (incl. establishing a PIMS policy)

Planning actions to address risks and opportunities (incl. defining a data inventory and data flow analysis process, a data protection impact assessment (DPIA) process and a risk treatment process)

Determining and providing the resources needed for the establishment, implementation, maintenance and continual improvement of the PIMS

Implementing the PIMS (incl. conducting risk assessments and ensuring the organisation meets the principles and requirements of the GDPR* e.g. to ensure that personal information is processed fairly and lawfully and in a transparent manner )

Evaluating the performance of the PIMS (incl. conducting internal audits and management reviews

Continually improving the PIMS (incl. implementing corrective and preventive actions).

Does your organisation fully comply with the General Data Protection Regulation (GDPR)?

If uncertain, URM is able to conduct a high-level GDPR gap analysis which will assist you understand your current levels of compliance and identify gaps and vulnerabilities.
Thumbnail of the Blog Illustration
Data Protection
Published on
18/7/2024
ICO Enforcement Action January – June 2024

URM’s blog reviews ICO enforcement activities for the 1st half of 2024, highlighting trends & shifts in how it enforces against data protection breaches.

Read more
Thumbnail of the Blog Illustration
Data Protection
Published on
22/7/2022
Tips on Demonstrating UK GDPR Compliance

We provide some questions which should help you in determining your level of compliance with the GDPR

Read more
Thumbnail of the Blog Illustration
Data Protection
Published on
5/7/2024
Oral references now count as processing for GDPR purposes (in the EU at least)

URM’s blog explores a recent ECJ ruling which dictates that oral job references are covered by the GDPR

Read more
We used URM as we had a large amount of information to redact for a Court of Protection case and neither had the time nor the knowledge to be able to complete this appropriately. URM were suggested to us and we made contact. They responded very quickly and were able to explain their role, estimated timescales & costings. During the initial consultation, they were very professional and approachable, and certainly had the skills we required. URM’s consultant provided us with details of the work they had completed before & we felt confident to pursue the work with them. We were on a tight deadline for court and URM were confident that they could provide the services we required in a timely manner. The logistics of sending a large amount of confidential documents were easy to navigate and straightforward. We were unable to very accurately gauge how much work was required, however URM’s Team supported us with this and maintained regular contact regarding their progress and addressed any concerns they had. When we needed to contact them, they were prompt with their responses. The work did take longer that envisaged, however that was due to the amount of work that we, as clients, were unable to accurately identify would be required. We did, however, meet the deadline for court. I would certainly use the services of URM again & if possible would work with same team. The services are not cheap, however redacting sensitive information is a skilled task and, therefore, having a professional complete this work is priceless.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.