Jump to content

Recommended Posts

Posted (edited)
Dear All. Quick question if I may? As nobody in IT should be assigned a Data Protection Officer role, who in your school is responsible for GDPR compliance? Thanks in advance... Prad, Director of IT, University College School Edited by prad-ucs
  • Thanks 2
Posted (edited)

Basically this :p

 

But we've asked between our local LEA and few other sources and basically come to the conclusion:

 

IT Manager = No

Head = No

Deputy Head = No

Business Manager = No

CPO/DPA etc = No

 

We're currently looking at options using an external company on a part-time basis etc as feel it's gonna make everyones life easier

 

Steve

Edited by ZeroHour
Posted

I predict that GDPR will be that massive, it'll require someone new to be employed or co-employed with other establishments.

 

To log every transaction and how it's processed (physical or digital), it's a huge job that will constantly change.

Posted (edited)

Again, kinda this :S

 

Our LA ha proposed creating a DPO service that we can (for a fee) sign up to. We are also part of a teaching alliance which I believe may explore some options.

Lord knows where the money will come from though.

Edited by ZeroHour
Posted
I predict that GDPR will be that massive, it'll require someone new to be employed or co-employed with other establishments.

 

To log every transaction and how it's processed (physical or digital), it's a huge job that will constantly change.

You aren't really logging every transaction, systems do that for you where needed. The DPO makes sure that you know what data you have, and how it being processed, why, and how etc. They have oversight of the DPIAs..

 

It is a significant and serious role, but shouldn't be an industry of itself.

Posted (edited)

What I mean is that it shouldn’t become a massive chore within the school. It should be a little of everyone, just like Safeguarding is.

 

Yes, you will have companies that have solutions that can help keep it that way.

Edited by ZeroHour
  • Thanks 1
Posted
It should be a little of everyone, just like Safeguarding is.

 

That's our model. The named DPO will likely be one of our Deputy Heads, with team involvement from HT, SBM, HR and IT Mgrs.

  • Thanks 1
Posted
I believe outsourcing your DPA / GDPR officer is a possible solution if you can't dedicate a member of staff to it. It is something my employer offers as a service. :)
Posted
That's our model. The named DPO will likely be one of our Deputy Heads, with team involvement from HT, SBM, HR and IT Mgrs.

Won't that be a conflict of interests under the rules?

Posted
Don't think so. Which rule do you think we're breaking? According to https://www.gdpr.school/wp-content/uploads/2017/08/Who-will-be-your-DPO.pdf (from GDPRiS) he can under certain circumstances.

 

It does depend, but I'd assume for most schools they couldn't as it'll be conflicted still depending on what else they do within the school. It's under the notes on the table - CANNOT be a DPO if these duties lead to a conflict of interests of their own role – see regulations, obviously that does depend on their exact roles and requirements though, as an example if your deputy head is involved with implementing a new system in the school that uses data they can't be involved etc

 

Steve

Posted
Don't think so. Which rule do you think we're breaking? According to https://www.gdpr.school/wp-content/uploads/2017/08/Who-will-be-your-DPO.pdf (from GDPRiS) he can under certain circumstances.

 

It does depend, but I'd assume for most schools they couldn't as it'll be conflicted still depending on what else they do within the school. It's under the notes on the table - CANNOT be a DPO if these duties lead to a conflict of interests of their own role – see regulations, obviously that does depend on their exact roles and requirements though, as an example if your deputy head is involved with implementing a new system in the school that uses data they can't be involved etc

 

Steve

The regulations also state that the DPO must have “expert knowledge of data protection law and practices.” I find it hard to imagine a situation where a Deputy Head has the required knowledge and it sufficiently removed from data for it not to be a conflict but then yeah, every school is different.

Posted

‘Expert’ knowledge is an interesting term, aimed at companies with over 250 staff (so probably handling a sizeable number of customers).

 

Education establishments seem to have been forgotten about.

 

We are asking on this, but schools often rotate duties ... so senior staff may have expertise that is not presently being used.

 

Also, when bringing new SLT in, Data experience is keenly sought anyway, so there should be some options.

Posted
It does depend, but I'd assume for most schools they couldn't as it'll be conflicted still depending on what else they do within the school. It's under the notes on the table - CANNOT be a DPO if these duties lead to a conflict of interests of their own role – see regulations, obviously that does depend on their exact roles and requirements though, as an example if your deputy head is involved with implementing a new system in the school that uses data they can't be involved etc

 

Steve

 

He wouldn't be solely responsible for the implementation of that new system, though.

 

Also, isn't the DPO role more about ensuring others are achieving compliance? So he could ask me to review the IT security of the new system and as DPO he would check I've followed policy/process in doing so.

 

I do take your point though.

Posted

It's not about the sole role etc, if he has input into the system and how the school are using it it's not an independent view etc. If he's assigned it to you to check as Deputy/SMT etc (Or even as part of SMT agreed to use the system etc), then he's been involved in the checks so can't really verify it's followed right, if that makes sense?

 

It's all very whishy washy though :p But that's my understanding and what I've picked up from other meetings about this with our local councils etc

 

Steve

Posted
If he's assigned it to you to check as Deputy/SMT etc (Or even as part of SMT agreed to use the system etc), then he's been involved in the checks so can't really verify it's followed right, if that makes sense?

 

What if he assigns it to me as DPO, not DH, saying "these are the policies you must follow, now go and check it", and I then report back later with my findings and evidence I followed the policy.

 

If he can't do it, then the only other option is surely to outsource it - no-one within the school of appropriate seniority is totally hands-off from the data processing.

Posted (edited)
What if he assigns it to me as DPO, not DH, saying "these are the policies you must follow, now go and check it", and I then report back later with my findings and evidence I followed the policy.

 

Again from my understanding then the school side has failed as you've not been asked to check anything from that side :p As stupid as it sounds.

 

Think of it this way, SMT tell you to do XYZ. You do XYZ. DPO verifies you did XYZ correctly. Everyones happy! :p

 

If DPO tells you to do XYZ, and you do XYZ, DPO can't verify it's been done right as such. Not happy! (again from my understanding)

 

What are the safeguards to enable the DPO to perform her/his tasks in an independent manner (Article 38(3))?

Several safeguards exist in order to enable the DPO to act in an independent manner as stated in recital 97:

- No instructions by the controllers or the processors regarding the exercise of the DPO’s tasks

- No dismissal or penalty by the controller for the performance of the DPO’s tasks

- No conflict of interest with possible other tasks and duties

 

What are the ‘other tasks and duties’ of a DPO which may result in a conflict of interests (Article 38(6))?

The DPO cannot hold a position within the organisation that leads him or her to determine the purposes and the means of the processing of personal data. Due to the specific organisational structure in each organisation, this has to be considered case by case.

 

As a rule of thumb, conflicting positions may include senior management positions (such as chief executive, chief operating, chief financial, chief medical officer, head of marketing department, head of Human Resources or head of IT departments) but also other roles lower down in the organisational structure if such positions or roles lead to the determination of purposes and means of processing.

 

If your DH has no instructions from the school (Read Head/SMT/Gov) in regards to DPO policies or tasks, and has no involvement with any decisions in regards to the purpose and data processed I'd highly doubt he could fulfil both sides fairly unless they relax the rules, but that is an opinion and you may disagree. (Again based on what's currently be said/written out)

 

Steve

Edited by Steve21
Posted
Hmm, that second one you highlight could be a problem - our DH/DPO is the person who decides we use Sisra for example. What are you quoting from there? We might need a rethink on this...
Posted

It's from one of the millions of PDFs been nosying in, but it's one of the documents from the Article 29 Data Protection Working Party guys, basically the "experts of DataProtection" of the member states of the EU:

 

https://en.wikipedia.org/wiki/Article_29_Data_Protection_Working_Party

 

Found it originally on the European Commission Site https://ec.europa.eu/commission/index_en

 

Linked both parts below, the full thing and the FAQ part:

http://ec.europa.eu/newsroom/document.cfm?doc_id=44100

http://ec.europa.eu/information_society/newsroom/image/document/2016-51/wp243_annex_en_40856.pdf

 

But lots of different places basically say the same, the DPO can't be a decision maker in regards to how/where the data processing is done etc

 

Steve

Posted

^ That's our problem. Everyone here with the aptitude/knowledge to be DPO has too much influence over school data functions according to the legislation.

 

The ideal person would be an ex-SLT part-timer who has experience but doesn't have any day-to-day authority to influence data.

Posted

Aye, the other option we were debating if we don't get someone in externally is basically doing a swapsie with a local school.

 

So as an example Head/Deputy etc of X school is our DPO, and our Head/Deputy is their DPO. Only downside again is whether there'd be problems with the amount of time needed to run the role, still think best option would be getting an external company. Whether that's split between schools/LEA etc or whether it's standalone

 

Steve

Posted
^ That's our problem. Everyone here with the aptitude/knowledge to be DPO has too much influence over school data functions according to the legislation.

 

The ideal person would be an ex-SLT part-timer who has experience but doesn't have any day-to-day authority to influence data.

I keep thinking about this periodically and the point I get stuck at is: Why would anyone who's not involved in either the procurement or management of data systems have acquired the level of knowledge required to carry out this role?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...