Records Management
Records Management
Records Management is recognised by the Crofting Commission as fundamental to its role as a Regulator. Effective records management ensure that the Commission has the right information at the right time to support its decision-making processes.
The Commission is committed to maintaining and improving good records management practises that meet operational needs, accountability requirements and stakeholder expectations. Effective records management will ensure that information:
- Is created and managed efficiently
- Is stored appropriately and is easily retrievable
- Is destroyed or preserved in accordance with the Commission’s Retention Schedules
- Is easily accessible to the public where possible.
The Public Records (Scotland) Act 2011 highlights the importance of records management and our aim is to ensure that we meet the legal requirements placed on us by this Act. By ensuring good records management practices are in place throughout the organisation, we will meet our requirements under the Data Protection Act 2018, the Freedom of Information (Scotland) Act 2002 and the duties placed on us by the Crofters (Scotland) Act 1993 to act as an efficient and effective regulator.
Records Management Policy
Our policy applies to the management of all documents and records, in all technical or physical formats or media, created or received by the Crofting Commission in the conduct of its business activities. It applies to all staff, contractors, consultants and third parties who are given access to our documents and records and information processing facilities. Our policy aims to ensure that all individuals are aware of what they must do to manage records effectively and efficiently and in accordance with any relevant legislation.
What Are Records?
The term ‘records’ as defined by the relevant British Standard is as follows:
“Information created, received and maintained as evidence and information by an organisation or person, in pursuance of legal obligations or in the transaction of business”. (ISO 15489-1:2016)
Examples of items that can constitute records include, but are not limited to:
- Documents (electronic or paper)
- Case papers
- Computer files
- Paper files
- Emails
- Intranet and internet pages
- Reports
- Diaries (electronic or paper)
Records, if well-kept, are a reliable source of evidence and information. Following the good practice set out in the ‘Scottish Ministers Code of Practice on Records Management’ and explained in the Public Records (Scotland) Act 2011, should ensure that records are well-kept.
Why Do We Need to Manage Records?
Robust records management practices support the Crofting Commission in delivering and meeting our statutory duties as a regulatory body. By adopting this policy, we aim to ensure that all information is created and managed efficiently, stored appropriately, is easily retrievable, destroyed or preserved in accordance with the Commission’s retention schedules, meets current and future need and is easily accessible to the public where necessary. This in turn, will enable the Commission to:
- Carry out its business effectively
- Make informed decisions
- Comply with relevant legislation
- Ensure transparency and openness
- Maintain continuity and consistency
- Actively manage performance
- Maintain an appropriate audit trail to meet business, regulatory and legislative requirements.
Statutory And Regulatory Environment
As a regulator the Crofting Commission operates in an environment influenced by the Crofters (Scotland) Act 1993 and the Crofting Reform (Scotland) Act 2010; and as a public authority, with obligations under the Data Protection Act 2018, the Freedom of Information (Scotland) Act 2002 and the Environmental Information (Scotland) Regulations 2004.
The legal and regulatory framework for records management is outlined below and includes:
- The Public Records (Scotland) Act 2011
- The Data Protection Act 2018
- The UK General Data Protection Regulations (UK GDPR)
- The Freedom of Information (Scotland) Act 2002
- The Environmental Information (Scotland) Regulations 2004
Related guidance and codes of good practice:
- Section 61 – Scottish Ministers Code of Practice on Records Management
- BS ISO15489-1 – Records Management
Responsibilities
We have a responsibility to ensure that our records are managed well. All our staff are responsible for ensuring that the records they create or maintain comply with the requirements in this policy.
Different staff have different roles in relation to records management and these responsibilities are detailed below.
Accountable Officer
The Chief Executive Officer has overall accountability for records management and for ensuring that information risks are assessed and mitigated to an acceptable level.
Senior Information Risk Owner (SIRO)
The Director of Operations has overall familiarity with information risks and leads the Commission’s response. The SIRO is the focus for the management of information risk.
Information Asset Owners (IAOs)
The IAOs have responsibility for the understanding of what information assets are held, what is added, what is removed, how the asset is moved, who has access and why. An IAO may delegate responsibility for particular areas of the role but retains the accountability for proper management and handling of assets in compliance with statutory obligations.
Records Manager
The Records Manager, a role held by the Compliance Manager, is responsible for ensuring that all records management procedures and policies are kept up to date and relevant, for supporting and providing guidance to staff on records management issues and auditing compliance with the records management policy and associated standards.
Board of Commissioners
All members of the board recognise the importance of a solid approach to records management and are responsible for maintaining this policy, keeping an oversight of performance against it, and seeking assurance from an audit perspective that it, and accompanying procedures are being adhered to.
Executive Team
The members of the Executive Team recognise the importance of a solid approach to records management. They ensure that the commitments given in this policy are met, and that the records management function is appropriately resourced and accounted for within the wider governance of the organisation.
The Director of Corporate Services, a member of the Executive Team, is the senior responsible officer for records management and has overall responsibility for ensuring compliance with this records management policy.
Line Managers
All line managers within the Commission familiarise themselves with this policy and the supporting standards, policies and procedures and they ensure that their staff are also familiar. They ensure that their staff have appropriate training, identifying any training needs and making sure these are addressed. They ensure that any records management issues or concerns within their areas are raised with the Records Manager.
Operational Staff, Contractors, Consultants and Third Parties
All staff, contractors, consultants and third parties – everyone who receives, creates, maintains or has access to Commission documents and records are responsible for ensuring that they act in accordance with our records management policy, relevant guidance and procedures.
Relevant Policies, Guidance And Procedures
This policy is supported by a set of policies, guidance and procedures which define the management of the Crofting Commission’s records and what tools it uses.
A copy of the following policies, guidance and procedures are available on request:
- Records Management Plan
- Information Management Policy
- Acceptable Use Policy
- Business Classification Scheme
- Information Asset Register
- Data Breach Plan
