CIO Applications Europe
About UsConferencePartner With Us
Close
  • Applications
      • Business Intelligence & Analytics
      • Call Center Solutions
      • CRM & Customer Experience
      • Data Center
      • Digital Transformation
      • E-Invoicing
      • Intelligent ERP & Automation
      • Risk Management & Compliance
      • Unified Communications (UCaaS)
  • Industries
      • Automotive & Mobility
      • Construction & Infrastructure
      • Financial Services
      • Healthcare
      • Retail & E-commerce
      • Telecom & Media
      • Travel and Hospitality Tech
  • Technologies
      • Cloud
      • Cybersecurity & Resilience
      • Data Engineering & Analytics
      • Generative and Agentic AI
      • IoT & Edge Computing
      • Robotics
  • Platforms
      • AWS
      • IBM
      • Microsoft
      • Salesforce
      • SAP
      • ServiceNow
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • CXO Awards
    • Europe
      • US
  • Topics

  • Menu
      • Business Intelligence & Analytics
      • Cloud
      • Digital Transformation
      • Generative and Agentic AI
      • Microsoft
      • Risk Management & Compliance
      • Travel and Hospitality Tech
      • Unified Communications (UCaaS)
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Generative and Agentic AI
  • Digital Transformation
  • Business Intelligence & Analytics
  • Cloud
Topics
  • Topics

  • Business Intelligence & Analytics
  • Cloud
  • Digital Transformation
  • Generative and Agentic AI
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Unified Communications (UCaaS)
  • Home
  • GDPR

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

Office for National Statistics

Andy Wall, CSO

Getting to know you?

Organisation Crown Jewels

Data is becoming the lifeblood of modern society. The rapid development of business technology is a revolution that facilitates the processing and analysis of more data, in richer and more complex forms. The outcomes for commercial organisations and Government Departments from this work inform medium and longer-term decisions about policy and services.

At the heart of this revolution is the collation of huge amounts of data – commercial, personal, business, intellectual – the crown jewels of the organisation. There are massive benefits from this to organisations and societies but also dangers. For a host of reasons including processing capability, efficiency, management, access and of course protection, there is a tendency centralise data holdings either in internally managed infrastructure and systems or external hosting (I’m not going to get into the cloud, data can be anywhere discussion).

These big data collections give the legal and security teams some very difficult headaches. Big data equals big, juicy target. Lots of data equals identification and management issues. Many different data sets equal different content, different legal and regulatory implications. So how can organisations deal with these issues in a way that drives a consistent level of data protection?

The Data Value Issue

ONS is a huge consumer of data. We obtain open source, commercial, market sensitive, and personal information. We use these sources to produce official statistics for shaping Government and local services across decades. We also want to explore new data sources and produce the more detailed, granular statistics and analysis, including exploratory work for statistics such as migration, trade, education, and enhanced financial accounts. The range of data is enormous. It also poses challenges. Is open source, anonymised licensed data that same as geolocation mobile phone data? Is private taxpayer data the same as property data available freely on the Internet? Is there a difference in how these are processed separately or together?

As a Government department, our data sets have a designated owner - the information Asset Owner – who is a real person and is responsible for specific data sets. It is these people who determine the appropriate use of the data in business terms that considers its content and sensitivity. Historically this use has been on a ‘silo’ basis where the data is generally used in isolation from other data sets or linked with other data using highly controlled methods.

ONS is undergoing significant change within its statistical environment to meet the challenges of new data sources, technologies, statistical production, and the Digital Economy Act. At its core, this will result in a single, organisation-wide platform that contains multiple datasets that can be linked and matched for statistical purposes. Traditional approaches used to assess data set content and determine its business use were not valid in this new world. ONS needed a more tangible that enabled improved understanding of the actual content of a data set and how it can be linked and matched with other data sets. Importantly, this new approach also catered for the perspectives of security and regulatory issues, including supplier agreements on the access and use of data they supply. Typical questions arising from this were:

• Where is the data?
• Who can access is?
• Can it be shared?
• How should it be managed?
• What compliance is needed?

These are all issues that affect any business dealing with data. ONS has found a way to deal with it using a simple but very powerful technique.

A Model for Data Sensitivity?

If a magic wand were to be waved then when an organisation obtained data it would know a lot about it, particularly what its content was, how sensitive it was, how it could be used and what controls were needed to protect it. It so happens that these are burning issues with modern data protection legislation and the General Data Protection Regulation.

Over a period of several months ONS built a model.

For this model to work it had to deal with a huge variety of data sets, it had to apply organisation-wide and it certainly needed to be a consistent. It must also recognise that the data has a ‘value’ based on its content that should provide an indication of its protection requirements. Finally, it had to be a repeatable method that could stand the test of time and data evolves. As a shopping list, it was a pretty big one.

What emerged was the Data Sensitivity Model. This utilises two key concepts to describe data: descriptive criteria that show the makeup of the data through seven lenses and characteristics that describe to range within the lens.

Sensitivity Ratings

In the ONS world, the IAO is responsible for a sensitivity assessment of their data set with support from Security and data specialists. This is underpinned by a tool that enables the selection of characteristics for each descriptor to generate a score that is translated into a simple Red, Amber or Green rating. Subsequent management and use of the data set is then based on its rating.

Low sensitivity (green). This applies to open source and non-disclosive data that can be shared across ONS for statistical research purposes. The supplier agreement typically associated with this allows full access by ONS employees with an approved business need;

Medium sensitivity (Amber). This applies to data that is commercially sensitive, market sensitive or contains attributes that could be used to identify sensitive information relating to individuals or groups of individuals. The supplier agreement typically associated with this allows for some access by ONS employees with an approved business need;

High sensitivity (red). This applies to data that is contains significant aggregate information relating to individuals, groups or enterprises. The supplier agreement typically associated with provides conditions for access by ONS employees with an approved business need.

Running data through the model for three typical data sets within the Office generates the following outputs.

What have we got from this?

Consistency, consistency, consistency…. Every data set has a rating, and everybody has a guide on how is should be managed. Not only has this helped understand data set content, as each specific data set is assessed which has provided an overall data sensitivity matrix. This shows those datasets that can combined for greater analysis or those which should have restrictions for sensitivity, security or data partner reasons.

The implementation of the model has:

• Enabled a measured judgement of the sensitivity of the content of a dataset;
• Improved data set information understanding and management within the IAO, security and business communities;
• Enabled consistent assessment of potential individual and aggregated data combining a range of sensitivities;

• Provided a basis for protecting data in relation to its content in a consistent manner;
• Enabled the development of a data set ‘matrix’ highlighting data that can be aggregated and data that cannot.

For ONS it has been a real win-win. Better understanding, better control, better compliance.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
The Leadership Perspectives forum brings together voices shaping construction technology and innovation. Participation is by invitation only. It features leaders who are not merely observing technological change, but actively contributing to it through digital transformation and execution-driven insights.
EDITOR'S CHOICE
  • Willis Towers Watson

    Legal & General

    Building Technology Foundations That Last

    Mark Hall, Group Chief Technology Officer

  • Willis Towers Watson

    Adp Uk

    "Shift left" Defect Discovery using Agile and DevOps

    Keith Watson, Director Of Devops

  • Willis Towers Watson

    Motor Oil

    Trust, Security Strategy and the AI-Driven Threat Landscape

    Syngelakis J. Christos, Group Data Protection Officer

  • Willis Towers Watson

    Swiss Re [SWX: SREN]

    A Future of Enhanced Human Work

    Sergio Chelli, IT Procurement Manager at Swiss Re [SWX: SREN]

Weekly Brief

loading

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

×
#

CIO Applications Europe Weekly Brief

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from CIO Applications Europe

Subscribe

loading

THANK YOU FOR SUBSCRIBING

CIO Applications Europe
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@cioapplicationseurope.com
  • sales@cioapplicationseurope.com
  • marketing@cioapplicationseurope.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 CIO Applications Europe. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://gdpr.cioapplicationseurope.com/leadership-perspective/getting-to-know-you-nid-1034.html