Jump to content

Recommended Posts

Posted

[*]The DPO - who is the best person to take this role in school

This is my top one.

 

and how will this person be funded?

 

The funding question is a non-starter. Pay rises, pension and NI increases haven't been funded for at least 5 years. There isn't any chance whatsoever of getting money to pay for GDPR. That said, raising awareness that yet another thing is about to damage already over-stretched school budgets does no harm.

  • Thanks 1
Posted
As this is an EU directive, what will happen when we leave the EU? Are we going to spend time, energy and money implementing this, only for a government (of whatever flavour) to 'review' it in the not too distant future?
  • Thanks 1
Posted
As this is an EU directive, what will happen when we leave the EU? Are we going to spend time, energy and money implementing this, only for a government (of whatever flavour) to 'review' it in the not too distant future?

 

It'll apply. The UK gov is currently writing it into UK law.

  • Thanks 1
Posted

It has been stated absolutely that GDPR will be fully implemented and the law is currently passing through parliament at the moment. If we trade with Europe we have to.

In addition other Commonwealth countries are looking to change their DP laws to match GDPR.

Sorry @StevieM there's no way out.

  • Thanks 2
Posted
Thanks for that. I wasn't actually thinking about a way out, though, more about successive governments' penchants for meddling, e.g. the constant revisions to the National Curriculum.
  • Thanks 1
Posted
  1. Data Audit - some kind of guidance about what a compliant data audit in a school should look like and what compliant documentation should look like. Why are we all coming up with our own versions when they could provide a template for us to follow
  2. Public Interest - examples of what is and what isn't public interest would be fantastic. It seems to me that currently we have to make our own judgement based on vague wording whose interpretation is going to vary from school to school.
  3. DPO - as our SLT asked: where on Earth is this money coming from as it will probably lead to redundancies to fund this :( (I know this is a non starter but we *have* to let them know how bad it is out here).

 

These, especially the the top two.

 

I understand it's important, but I would like to know how to actually carry out the nuts and bolts of what's required, or at least, find a company who are willing to provide training.

  • Thanks 1
Posted
Training for anyone tasked with this complicated job?

The Data Protection Bill puts accreditation of certifications in the hands of the ICO, so it is a two hander... the DfE needs to know what training will be needed and ICO needs to agree.

Posted
Thanks for that. I wasn't actually thinking about a way out, though, more about successive governments' penchants for meddling, e.g. the constant revisions to the National Curriculum.

The Data Protection Bill that is progressing through Parliament at the moment is trying to Brexit proof things... and the sticking point is data transfer agreements between us and EU. Because the bill is effectively GDPR, the expectation is that the transfer will not be a problem.

Posted
I think what we're looking for is guidance on how to do this or better yet a framework to follow. 22000 schools in the country and, within a margin of tolerance, we're all doing the same thing with the same data, so why are we all trying to work this out ourselves? I was at a GDPR meeting recently where the speaker said what we all need to do is go back and get key people in a room with a blank sheet of paper. This seemed crazy to me; there's going to be a massive cross-over between your bit of paper and mine, so why don't DfE make a start on the piece of paper for us, identifying the points we need to tweak it for our own situations? This is why this discussion forum and the crowd-sourced compliance spreadsheet are excellent resources.
Posted

Part of the problem is that DfE is a large organisation so those doing stakeholder work with schools might not be asking the right questions of the right people.

 

Schools could start by going to the old Becta materials and asking themselves are they even at *that* point ... and if not what do they need to do to get there, then look at the ICO site and ask the same.

 

Yes, we know that this would have been a task for Becta in the old days, but I think even they would be on the back foot with this due the getting the DP Bill through, Still awaiting guidance from ICO, etc.

Posted
I think everyone would agree we would like the DfE to provide us guidance and clarity on GDPR. I have found someone who is genuinely listening to our concerns about GDPR.

 

I would like to co-ordinate a 'voice' into DfE about the areas where that guidance is most needed.

 

Here’s my top 3 issues…what are yours? The more replies we get the more compelling our cry for help.

 

  1. The DPO - who is the best person to take this role in school and how will this person be funded?
  2. Legal basis for processing - when can't a public funded school use 'Public interest' as a legal basis for processing?
  3. SARs - what data should and shouldn't be included in a SAR?

 

Keep them coming please. I'd like to get back to the DfE as soon as I can.

 

Hi - this is the reason I joined the forum and had offered to in other threads, and have already been gathering your questions and concerns so far since May, as well as those of academics, child rights groups, teachers and parents in one place - all been /being / to be asked of the DfE and the ICO. I've had several discussions with Grumbledook to support your company work too. Forum members can read their examples and questions asked from the forum included in this. It's work-in-progress and report to come out once UK Bill is final.(expected Jan 2018).

 

Anyone can add and contribute comments to include case study questions, not only read, But for schools very little of 1,2, 3 above should be new. Your current legal basis for processing, and Subject Access Request reqs. are very unlikley to change compared with today. Where we see is trickier as regards profiling for example, are the relatively new technologies in schools, such as apps and safeguarding, where the tools involve third party processors, and where the boundaries of necessity, proportionality and questions of retention lie. Even then GDPR is not likely to change this much, but it seems many in schools have not paid attention to data protection reqs. or clear legal basis and fair processing on their introduction so far. The DfE is not going to catch this up for schools, and the ICO has already published guidance over several years for the education sector.

 

For schools, our report will discuss applied edTech and school processes and policies and offer suggestions how you need to apply these in practice, but if you're using it now, you should know your current legal basis for the data collection and any onward distribution. If your school honestly doesn't have a qualified, trained data protection resource to ask or access (even if shared across schools / MAT / LA which is also fine under GDPR), then you should raise this as a critical risk, and ask whether your school would be OK with having no trained First Aider. Meeting requirements of data protection law is not an optional extra.

https://docs.google.com/document/d/10KD1adCAeWXG_5SioUNBSzu-yfsNdIdtlj5xlOqbIFQ/edit?usp=sharing

Note 29/7/2017: This is a collaborative working file which does not set out to address all GDPR issues or offer answers. It is intended to present collated questions from, and for, applied practice, gathered throughout 2017 -- from education practitioners, schools, child rights’ advocates, tech third parties, discussions and events -- for anyone who needs to obtain consistent answers as UK derogations become clear, or where a national approach may need thought out at policy level, and regulators may need to offer opinion and guidance. Many thanks to all contributing. For direct questions or contact please use Twitter direct message @Defenddigitalme or email jen [at] defenddigitalme.com

  • Thanks 4
Posted

Hey @edugeekers

 

I've told the DfE that schools are desperate for guidance on GDPR from them and ICO. They asked me to gather a list of the top issues schools are facing so they know where they can help.

 

Do I go back to the DfE and say

 

'well actually just a handful of schools feel they need help from the DfE'

 

This isn't a voice its a whisper!

 

Yes I am telling you off!

 

Please say something even you agree with another person's post.

Posted

The big one for me is that I can't see anyone in our school staffing structure who could possibly take on this role - and I think that's true for most primaries.

 

There isn't anyone sufficiently senior who doesn't have a significant role in data processing. There also isn't anyone who could meet the expertise requirements. And that's before you get near whether anyone would have enough time to do it.

 

I also don't think that the DfE have reached the right people with the message about how important it is to sort out - I do wonder whether that's because they don't have any practical advice. Network managers and technicians are being bombarded with emails about GPDR from tech companies, but I don't think much is going to senior managers - so why would they worry about this more than the other important things they're doing. We all know data protection is important and a legal requirement, but in the day to day running of a school it isn't going to compete with child protection or teaching and learning or managing the budget or managing staff...

  • Thanks 4
Posted
Network managers and technicians are being bombarded with emails about GPDR from tech companies, but I don't think much is going to senior managers - so why would they worry about this more than the other important things they're doing.

 

Agreed. A large amount of unsolicited email comes in selling something with a GDPR angle, but SLT weren't aware of GDPR (or of it's importance) until we raised it with them as something to tackle. It does feel like there's a paucity of useful guidance and that schools have been left at the mercy of GDPR profiteers.

  • Thanks 1
Posted
I think a lot of schools are aware of it but don't understand it, have been scared or put off by the profiteers, and are waiting for guidance from the DfE or LEA. Many at this point probably don't know the questions they want to ask the DfE because they haven't yet had any guidance on it, so aren't aware of what they don't understand. Does that make sense?! It is a bit circular, obviously.
  • Thanks 1
Posted
As a more constructive comment, I'd like to add that an issue which causes day to day headaches for us is third-party services. Teachers wanting to sign up to some service or other that has caught their eye, but we have to say "hang on.. ummm, bear with", as we're not yet clear on how we decide to approve the use of a third-party service or not. It may be that we've just not done enough homework on GDPR here, but that's a practical issue that will be facing all schools, and where childrens' personal data crosses over from a public body to a private organisation.
  • Thanks 1
Posted
As a more constructive comment, I'd like to add that an issue which causes day to day headaches for us is third-party services. Teachers wanting to sign up to some service or other that has caught their eye, but we have to say "hang on.. ummm, bear with", as we're not yet clear on how we decide to approve the use of a third-party service or not. It may be that we've just not done enough homework on GDPR here, but that's a practical issue that will be facing all schools, and where childrens' personal data crosses over from a public body to a private organisation.

 

Is the process for checking GDPR compliance not broadly the same as we've been doing already to check DPA compliance? Assuming we have all been checking DPA compliance of third parties, of course...

Posted

What I would like the DfE/ICO to produce is straightforward guidance as to what is actually changing.

 

When I get a 'We're making changes to our terms and conditions' letter from my bank, they include a booklet with a table comparing details of the old way of doing things with the new. Something like that would be a good starting point so that we can simply change the tyre rather than reinvent the wheel.

Posted
The big one for me is that I can't see anyone in our school staffing structure who could possibly take on this role - and I think that's true for most primaries.

 

There isn't anyone sufficiently senior who doesn't have a significant role in data processing. There also isn't anyone who could meet the expertise requirements. And that's before you get near whether anyone would have enough time to do it.

 

I also don't think that the DfE have reached the right people with the message about how important it is to sort out - I do wonder whether that's because they don't have any practical advice. Network managers and technicians are being bombarded with emails about GPDR from tech companies, but I don't think much is going to senior managers - so why would they worry about this more than the other important things they're doing. We all know data protection is important and a legal requirement, but in the day to day running of a school it isn't going to compete with child protection or teaching and learning or managing the budget or managing staff...

 

Yes this is what I'm finding - Us as network managers are being bombarded with info on it but the senior managers aren't getting anything from their sources, so it's up to us to impress upon them how important it is that we deal with it. There's very little guidance from upabove at LEA/Government level just how this is going to affect schools & at the mo most of us seem to be shooting in the dark trying to work out how this affects us all.

 

Heads sending me on GDPR training so I'm more aware of it and has asked for a brief presentation on it, but the other schools I've spoke to weren't even aware of it until I mentioned it or were only aware of it at the most basic level.

Posted

it's been a topic now discussed for the first time by Governors too. Interesting difference that at an LA Primary School, there is nothing coming through the authority simply a copy of the letters advising schools have a requirement to address. The challenge is that this crosses both IT, Admin and finance aspects so finding a body with capacity to take ownership is really difficult. Wearing my other hat as an Academy Trustee elsewhere, this has been discussed and agreed to be a central trust wide project with local stakeholders. Again external skills to help steer the process are really needed. I definitely think the work and services Tony @GrumbleDook is offering will be a huge help. I expect over the next few months guidancee from the NGA and others will grow and may help shape the discussion alongside all the operational efforts.

 

This was quite an interesting and useful presentation the NGA shared to governors from last month which may be of interest ? https://www.brownejacobson.com/education/training-and-resources/training-videos/2017/09/how-to-implement-gdpr-in-your-school-hear-from-dai-durbridge-and-helena-wootton

 

and "The Key" shared this as a resource which is handy too - https://dpreformdotorgdotuk.files.wordpress.com/2016/03/preparing-for-the-gdpr-12-steps.pdf it might be a bit out of date though. There is a good section regularly updated for school leaders on the Key that i am using to take a steer from too ( you will need a school account to access) . https://schoolgovernors.thekeysupport.com/school-improvement-and-strategy/government-policies-legislation/general-data-protection-regulation/?marker=full-search-q-GDPR-result-1

 

There is a separate discussion as a vendor, for NetSupport in the education sector that we are having, that actually sits on three levels. We have the normal requirement that every other business will need to have to ensure our own standards and data security, meet GDPR guidelines, we then have the need to ensure each product meets these (actually most have no relationship as they don't store or access any school data), but our main one does, NetSupport DNA, and in meeting guidelines, data maps and capabilities need to be shared with schools so they can be sure the solutions they use meet their obligations as the primary data holder and then finally as a Vendor, we also have tools ( resource discovery under SW inventory) within NetSupport DNA that can help the process a small amount, by discovering resources which may contain data about students across the network (like a spreadsheet or old access database) so they can either be removed, recorded or the information perhaps moved to a more suitable location.

 

Within our product, we have our own central database management functions to ensure all data is wiped based on agreed timescales and the database remains within the local school enterprise. Fortunately none of our solutions need to or have any access to School information management systems so we are typically very much one or two steps removed.

 

Will share any main updates i see from governors perspective here (unless a better forum to share in), but diplomatically many are a bit dumbed down from the detail needed by network managers and bursars at an operational level.

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...