Episode 2 - Why does retention keep being forgotten?
13m 15s
The host, Scott Salons, introduces the IG Lighthouse podcast, aiming to cover the full spectrum of information governance, not just data protection or privacy, but also FOI, mental health, softer skills, and change management. He outlines a diverse lineup of guests and topics for the season, including interviews on FOI, imposter syndrome, data ethics, and stakeholder management. The central theme of this introductory episode is why retention, records management, and appropriate deletion are consistently forgotten or ignored by organizations. He cites recent fines, court issues, and government inquiries as examples. He explores potential reasons: cost, apathy (since deletion isn't as engaging as data analytics), fear and misunderstanding of GDPR leading to panic deletion, and inadequate standards like ISO 27001 that mention retention but lack depth. The host invites listeners to share their thoughts on why this pattern persists. He also previews future episodes, including a discussion on fairness, personal development, and a critical look at the Data Use and Access Act, which he considers a missed opportunity to reorganize data laws post-Brexit. He encourages subscriptions, comments, and topic suggestions, framing the podcast as a resource for data professionals.
[MUSIC]
Hello everyone, and welcome to the initial podcast session of the IG Lighthouse with me,
Scott Salons. There are two reasons why we wanted to run this podcast, some of which I mentioned in
the little intro thing I live on. Another one was A, I'm a bit behind the times, everyone else is
doing one, and they're good, there are some really good runs out there, and if you haven't seen them,
go and subscribe to them, there are some pretty good ones out there, so I'm definitely behind
the trend when it comes to these scenes, but also, there aren't many of them actually looking at
the full breadth of information governance. There are a couple now, which you should definitely
go and see, Tim's, that would be a particularly good one, but there are also others that just don't
really go anywhere near that sort of thing, so this is what we wanted to do. We want to look at the
full range of IG, not just debt protection, not just privacy, but also a little bit of FOI,
so one of the sessions we've got coming up, we're talking to Lynn Weif about her experiences with
FOI and her insights. We're also going to be talking about mental health, and I've got a session
with Catherine coming up as well, talking about imposter syndrome. We're going to talk about some
of the softer skills, so we're going to look at, we've got a really, really good interview with
a gentleman called Bruce Hullam, who is an expert in our field, but also in change management,
a managing change, and we do have a session in this series, picking up debt protection, especially
around data ethics with Sarah Newman. So we're looking at a wide range of different things,
and some of it will be, with me, just on my own, some of it will be with others, it depends,
probably on what mood we're in and seeing what's what and what's not, we'll see what's what,
and what's not. And some of this I blame on some of you guys, because someone said I have a voice
that people could listen to for hours. Whoever that person was, you can thank them, or blame them,
not really sure. Anyhow, in this session, I wanted to explore something that's been in the press
relatively recently, about why retention, records management, retaining and appropriately
deleting keeps being forgotten. It keeps, there is a sense of irony there, the whole concept of
forgetting people and the right to be forgotten and deletion and records management,
is constantly being forgotten about. We've seen it with the recent case with that charity,
they've got fined by the ICO, we've seen it with issues of data and records being destroyed by
that court, the recent court issue, we've seen it with, well, it's been a pretty much
in government, every government inquiry, going, deletion, retention, appropriate collection of
records, just keep being forgotten about in some form or another. And it's got to be thinking,
why, why do organisations, governments, whatever, keep forgetting or overlooking or deliberately
ignoring, I will leave others to decide what. Why does that keep happening? Time and time and time
again, these lessons keep getting being taught and time and time again, they keep being forgotten.
Is it a cost thing? Because that's the thing the most people go to, straight away,
yeah, you could make that argument, because there are some things that do,
an RM program does cost money, so yeah, cost isn't a factor that can automatically be discounted.
Is it a apathy thing? And by that, what I mean is, let's be honest, retention,
appropriate deletion, apart from being very therapeutic, I mean, a girl fashion clearer
and deletion section is definitely therapeutic. Apart from that, isn't really exciting,
doesn't grab people in the same way that other things do. What you can do with data, how you can
present it, manipulate it, find out stuff about it, all that stuff gets attention, it lights people
up, but to get them to light up on deletion, appropriate storage, retention, it's a bit more
difficult to do. So one of the things I hope to do during the course of this podcast is to explore
that a little bit more. How can we, and how have people, because they do want to talk to an interview
every day of people, and how they've done it, how they've achieved buying, what works,
we've all heard the phrase, you know, you bribe someone with food, that's a good way of getting them
to attend things, yeah, that's true, but how does that actually work? How do you begin, how do you
go start about doing it? And that's what I kind of want to go through over the next few coming weeks
and as we build and grow. So cost, yeah, apathy, yeah. Is it also a little bit of, do you remember,
there was an incident where, was MPs got load of training on GDPR and then went out and started
deleting a lot of their constituency correspondence because they're clearly completely misunderstood
what the requirement was. The truth of that, whenever we know in intricate detail, if someone knows,
do let me know, but surely the rumor alone, and this comes up, I've done training with political
representatives and others before, this does come up, people then panic, I think they have to
delete everything. There is this kind of just perception that retention is deletion, and this
not fear-mongering, that's not the right word, but fear, full stop, misunderstanding, full stop,
that retention, GDPR, all those fun exciting things are actually about problems,
and are actually about, no one must get rid of it, the GDPR says so, oh no, is that it, I wonder?
And I just know what you think, why do you think retention keeps being forgotten about,
appropriate deletion keeps being forgotten about? Have you seen examples where everything
else has been considered, but that hasn't? Another area to look at, well it's just popped into my head,
is also, I see this a lot with things like ISO 27001 compliance, they have a section on retention
or a records management policy, but it doesn't really go into any detail, it just says you need to have one.
That's Nummies, doesn't mean it's effective, doesn't mean it's any good, and certainly doesn't mean
that it means that your deletion practice are effective, yeah it's been securely deleted,
but it shouldn't have been deleted in the first place. So even in my view, I think even ISO
gets this or ISO 27001 doesn't quite get this right either, it shouldn't be a records management
framework, that's what ISO 15489 is for, but I do think that section on records management
or the records policy or records retention policy, I can't remember the exact wording on the top
of the head, it needs a little tweaking, I think a little bit, to make it clear that it should be
something that is actually effective, and it means if something is going to be destroyed,
yes it should be done securely, lovely, secure destruction should always be in place,
yes we all agree with that, but it should also be appropriate destruction, authorised destruction,
not just, oh we've done it securely, so it's fine, GDPR says so, hmm, no,
so those things, I'm not entirely sure what the root call or what the root call reason is,
but it's definitely something, so let me know what do you think, why do you think these things
keep being forgotten about again and again and again? In the next session, we're going to look at,
I want to chat with Lynn White,
about FOI and a little bit of Eurovision so you get a feel for when it was recorded and
my failure to get you to upload you to appropriately. I accept that, my failure.
Rules going to look out so if the rest of this season next session I'm going to explore is
the concept of fairness. So the question I'm going to pose to you and something to think about is
is it fair to ask if it's fair? I'll leave you with that one. We're also then got a session on
Impostors of Drones. I'm also then going to take you through how to develop your development.
So we'll look at personal development, things to consider, factors, questions to ask yourself.
So one of those things we often ignore it or we just follow what our organisations do,
but actually have you actually thought about your own personal development?
And how to go through it. So I'll go through some of that. We're also then going to look at
data ethics. We're going to look out and have a session on stake holder management,
which I know doesn't sound exciting. When anyone ever says stake holder manager and you just think,
but actually I want to turn it into the art of how to win friends and influence people
because let's be honest, we as IG folk are going to do in this every single day and you need to be
good at it in order to actually get anywhere. So we are going to have a look through some stuff.
What we're going to do, then we've got the session on change management with Bruce,
and then finally for this season, so episode number 10, we're going to look at and explore
the data use and access act because by then a few more things would have come out more,
no, a little bit more. And there are lots of great places out there that take you through it and
the different elements of it, and we want to be pulling out part in different episodes, yes.
But we'll also be exploring why I think it's a missed opportunity,
because I think they could have done a few more useful things. And actually this was an
opportunity to reset start again. Well, not start again completely, that's the wrong term, but
take the opportunities that Brexit has presented is what I'm going to pitch it as, but that's not
to deviate away from a standard, but to just reorganize it so it's a bit more useful.
I think he's probably the best way of putting it, but we'll cover that in episode 10.
So this is your IG loudhouse, this is everything that you need as a data professional
to work with data, information and records, and hopefully over the next few seasons,
you'll get a lot from it, you'll subscribe, recommend it to your colleagues and others,
and we'll also talk about lots of different things that come under the big umbrella that is
information governance. So like, subscribe, comment, and let us know if there's anything you want to
want us to cover off. Otherwise, I'll see you in the next time.
Podcast Summary
Key Points:
The podcast aims to cover the full breadth of information governance (IG), including data protection, privacy, FOI, mental health, and softer skills.
Upcoming sessions will feature guests like Lynn Weif (FOI), Catherine (imposter syndrome), Bruce Hullam (change management), and Sarah Newman (data ethics).
The host highlights a recurring issue
Possible reasons for this neglect include cost, apathy (since deletion isn't exciting), fear and misunderstanding of GDPR (leading to panic deletion), and ineffective standards like ISO 27001 that lack detailed retention guidance.
The season will also explore fairness, personal development, stakeholder management (framed as "winning friends and influencing people"), and the Data Use and Access Act, which the host views as a missed opportunity.
The host encourages audience engagement through subscribing, commenting, and suggesting topics.
Summary:
The host, Scott Salons, introduces the IG Lighthouse podcast, aiming to cover the full spectrum of information governance, not just data protection or privacy, but also FOI, mental health, softer skills, and change management. He outlines a diverse lineup of guests and topics for the season, including interviews on FOI, imposter syndrome, data ethics, and stakeholder management. The central theme of this introductory episode is why retention, records management, and appropriate deletion are consistently forgotten or ignored by organizations.
He cites recent fines, court issues, and government inquiries as examples. He explores potential reasons: cost, apathy (since deletion isn't as engaging as data analytics), fear and misunderstanding of GDPR leading to panic deletion, and inadequate standards like ISO 27001 that mention retention but lack depth. The host invites listeners to share their thoughts on why this pattern persists.
He also previews future episodes, including a discussion on fairness, personal development, and a critical look at the Data Use and Access Act, which he considers a missed opportunity to reorganize data laws post-Brexit. He encourages subscriptions, comments, and topic suggestions, framing the podcast as a resource for data professionals.
FAQs
The podcast aims to explore the full breadth of information governance, including data protection, privacy, FOI, and softer skills like mental health and change management.
The host suggests reasons like cost, apathy, and misunderstanding, noting that deletion and retention are less exciting than data use and are often overlooked or misinterpreted.
He mentions a charity fined by the ICO, a court issue involving destroyed data, and recurring problems in government inquiries about deletion and records.
He thinks ISO 27001's retention section is too vague, lacking detail on effectiveness, and should emphasize appropriate and authorized destruction, not just secure deletion.
Sessions will include FOI with Lynn White, fairness, imposter syndrome, personal development, data ethics, stakeholder management, change management, and the Data Use and Access Act.
He believes it's a missed opportunity to reorganize data regulations usefully, potentially leveraging Brexit, rather than just making minor changes.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.