PART 5Enforcement and penalties

Power of inspection16

1

F1The designated competent authority for an OES may—

a

conduct F2all or any part of an inspection;

b

appoint a person to conduct F3all or any part of an inspection on its behalf; F4...

c

direct the OES to appoint a person who is approved by that authority to conduct F5all or any part of an inspection on its behalf,

F6....

2

The Information Commissioner may—

a

conduct F7all or any part of an inspection;

b

appoint a person to conduct F8all or any part of an inspection on its behalf; F9...

c

direct that a RDSP appoint a person who is approved by the Information Commissioner to conduct F10all or any part of an inspection on its behalf,

F11....

3

For the purposes of carrying out the inspection under paragraph (1) or (2), the OES or RDSP (as the case may be) must—

a

pay the reasonable costs of the inspection F12if so required by the relevant competent authority or the Information Commissioner;

b

co-operate with the F13inspector;

c

provide the inspector with F14... access to their premises F15in accordance with paragraph (5)(a);

F16d

allow the inspector to examine, print, copy or remove any document or information, and examine or remove any material or equipment, in accordance with paragraph (5)(d);

e

allow the inspector access to any person from whom the inspector seeks relevant information for the purposes of the inspection;

F17f

not intentionally obstruct an inspector performing their functions under these Regulations; and

g

comply with any request made by, or requirement of, an inspector performing their functions under these Regulations.

4

The F18relevant competent authority or Information Commissioner may appoint a person to F19conduct all or any part of an inspection under paragraph (1)(b) or (2)(b) on its behalf on such terms and in such a manner as it considers appropriate.

F205

An inspector may—

a

at any reasonable time enter the premises of an OES or RDSP (except any premises used wholly or mainly as a private dwelling) if the inspector has reasonable grounds to believe that entry to those premises may be necessary or helpful for the purpose of the inspection;

b

require an OES or RDSP to leave undisturbed and not to dispose of, render inaccessible or alter in any way any material, document, information, in whatever form and wherever it is held (including where it is held remotely), or equipment which is, or which the inspector considers to be, relevant for such period as is, or as the inspector considers to be, necessary for the purposes of the inspection;

c

require an OES or RDSP to produce and provide the inspector with access, for the purposes of the inspection, to any such material, document, information or equipment which is, or which the inspector considers to be, relevant to the inspection, either immediately or within such period as the inspector may specify;

d

examine, print, copy or remove any document or information, and examine or remove any material or equipment (including for the purposes of printing or copying any document or information) which is, or which the inspector considers to be, relevant for such period as is, or as the inspector considers to be, necessary for the purposes of the inspection;

e

take a statement or statements from any person;

f

conduct, or direct the OES or RDSP to conduct, tests;

g

take any other action that the inspector considers appropriate and reasonably required for the purposes of the inspection.

6

The inspector must—

a

produce proof of the inspector’s identity if requested by any person present at the premises; and

b

take appropriate and proportionate measures to ensure that any material, document, information or equipment removed in accordance with paragraph (5)(d) is kept secure from unauthorised access, interference and physical damage.

7

Before exercising any power under paragraph (5)(b) to (d) or (g), the inspector—

a

must take such measures as appear to the inspector appropriate and proportionate to ensure that the ability of the OES or RDSP, as the case may be, to comply with any duty set out in these Regulations will not be affected; and

b

may consult such persons as appear to the inspector appropriate for the purpose of ascertaining the risks, if any, there may be in doing anything which the inspector proposes to do under that power.

8

Where under paragraph (5)(d) an inspector removes any document, material or equipment, the inspector must provide, to the extent practicable, a notice giving—

a

sufficient particulars of that document, material or equipment for it to be identifiable; and

b

details of any procedures in relation to the handling or return of the document, material or equipment.

9

In this regulation—

a

a reference to a “test” is a reference to any process which is—

i

employed to verify assertions about the security of a network or information system; and

ii

based on interacting with that system, including components of that system,

and includes the exercising of any relevant security or resilience management process;

b

“inspection” means any activity carried out (including any steps mentioned in paragraph (5)) for the purpose of—

i

verifying compliance with the requirements of these Regulations; or

ii

assessing or gathering evidence of potential or alleged failures to comply with the requirements of these Regulations,

including any necessary follow-up activity for either purpose;

c

“inspector” means any person conducting all or any part of an inspection in accordance with paragraph (1) or (2).