Jump to content

Recommended Posts

Posted

I've been asked to find out how this will affect us and whether we need to do anything. Do any of you know of any handy guides to how it relates to us in education?

 

thanks

Posted
I've been asked to find out how this will affect us and whether we need to do anything. Do any of you know of any handy guides to how it relates to us in education?

 

From my perspective, it's DPA+; because we fall under the scope of the DPA we'll fall under the scope of GDPR, and they'll be more onerous requirements upon us, especially when dealing with third parties who handle our data.

 

However, given our forthcoming departure from the EU this may never apply to us in schools provided we don't provide a service to EU member states.

Posted

Well none of it looks like it will cost the school anything extra except (my) time so I imagine that it will probably be approved at the meting this morning.

It seems to boil down to encrypt everything, record details about the encryption and what your users are up to on your systems. I do a fair bit of that already.

Posted

Does that actually mean "everything" needs to be encrypted now?

 

Servers, including via file, application, database, and full disk virtual machine encryption.

Storage, including through network-attached storage and storage area network encryption.

Media, through disk encryption.

Networks, for example through high-speed network encryption.

 

Steve

Posted
I don't think you need to encrypt desktops but honestly as it seems I'm encrypting everything else I may just go ahead and do those too.
Posted (edited)

@Sagima We did a webinar very recently on GDPR. We'll be uploading the recording to our website shortly. I'll post back here when I have the link. In the meantime, here's an article we did on it and how it will affect schools: https://www.stonegroup.co.uk/how-will-gdpr-affect-schools/

 

The article's more of an overview, the webinar goes into much more detail as it was delivered by our Compliance Manager.

 

Hope this helps!

Edited by Stone_Charli
added a word
  • Thanks 2
Posted
@Sagima We did a webinar very recently on GDPR. We'll be uploading the recording to our website shortly. I'll post back here when I have the link. In the meantime, here's an article we did on it and how it will affect schools: https://www.stonegroup.co.uk/how-will-gdpr-affect-schools/

 

The article's more of an overview, the webinar goes into much more detail as it was delivered by our Compliance Manager.

 

Hope this helps!

 

That would be great - thanks

  • 3 months later...
Posted

Sorry for joining the thread late in the day...

 

To answer the earlier questions, Yes it has been confirmed that we the UK will proceed regardless of any exit of the EU. Plus, at the point GDPR becomes law in May 2018, we will still be in the EU.

 

 

In regards to encryption. The report does articulate that encryption may mitigate the risk of data loss, for example the breach notification rules do not apply to encrypted data. However I think it is important to consider the specific use case/risk you are planning to mitigate. For example, full disk encryption on your servers will mitigate the risk of the servers or their disks being stolen. However it does nothing to prevent the data being leaked unintentionally by somebody with access to the server, who then uploads a file to dropbox. So for me, encryption is a good step, but should be used in conjunction with other approached. As the ICO have discretion over the penalties they impose, I think that the most important first step, is to be able to provide a plan of action, including staff at all levels.

 

As per Charli's comments, there is some good info on the Gemalto site (vendor websites can be a great source of info, though they will tend to look for the areas that coincidently they can address). However, I would also start by taking a look at the ICO's own 12 step guide here: https://ico.org.uk/media/1624219/preparing-for-the-gdpr-12-steps.pdf

 

Thanks

Liam.

  • 4 weeks later...
Posted

Sorry I'm repeating the same thing as I did in the post: GDPR Data Protection and Memory Sticks. but GDPR is important.

It is going to have a major impact in schools as we hold and share so much data. Whether we stay or leave the EU is immaterial - ICO has clearly said that the initiative will go ahead.

A lot of questions regarding the new GDPR initiative is in the Webinar ICO produced and is worth listening to if you have an hour to spare! If not there's a PowerPoint that summarises it all and will be useful to use to get the message across that DP is about to change big time.

https://ico.org.uk/about-the-ico/new...ector-webinar/

You may find this useful.

  • Thanks 2
Posted
Sorry I'm repeating the same thing as I did in the post: GDPR Data Protection and Memory Sticks. but GDPR is important.

It is going to have a major impact in schools as we hold and share so much data. Whether we stay or leave the EU is immaterial - ICO has clearly said that the initiative will go ahead.

A lot of questions regarding the new GDPR initiative is in the Webinar ICO produced and is worth listening to if you have an hour to spare! If not there's a PowerPoint that summarises it all and will be useful to use to get the message across that DP is about to change big time.

https://ico.org.uk/about-the-ico/new...ector-webinar/

You may find this useful.

 

The link is showing as page not found

Posted
Does anyone know whether each school in a MAT must have a trained officer, like safeguarding, or whether there can be one person in the full trust with overall responsibility for GDPR within the trust?
Posted
It is not uncommon to have one person setting the general strategic approach and then working with each school to make sure it fits the policies and requirements on any particular needs or circumstances if that school.
Posted
It is not uncommon to have one person setting the general strategic approach and then working with each school to make sure it fits the policies and requirements on any particular needs or circumstances if that school.

So you're saying a centralised MAT DPO function ensuring compliance across all academies in a MAT would be OK @GrumbleDook? I was wondering id this one was going to be like the DSL.

Posted

I have a meeting on Monday with a "GDPR Consultant" if you want me to try and get answers to specific questions for any of you, drop them as a reply here and I will see what I can do.

 

Lee

Posted

I just asked ICO - reading their reply I think the answer is Yes schools can share a DPO

Here's their reply:

We have recently published further guidance regarding DPO's under GDPR, and if you haven't already done so, you may wish to look at the guidance we have published on our GDPR microsite https://ico.org.uk/for-organisations/data-protection-reform/overview-of-the-gdpr/accountability-and-governance/#dpos

 

It is possible for a single DPO to act for a group of companies or public authorities, taking into account their structure and size. More recently, the Article 29 Working Party issued further guidance regarding DPO's and published a useful list of FAQ's you may wish to look at http://ec.europa.eu/newsroom/document.cfm?doc_id=43823 and http://ec.europa.eu/information_society/newsroom/image/document/2016-51/wp243_annex_en_40856.pdf respectively

 

Hope it helps

  • Thanks 2
Posted

Yes, I had a similar conversation last week.

 

It all depends what your group determines as an 'organisation'.

 

If it deals with the majority of all other items separately, then it could be expected that this would be the case for the DPO ... but however it is dealt with it needs to be clearly managed and with accountability.

 

If all else fails, the Heads of the individual schools are where the buck stops unless it is clear that the responsibility sits further up.

  • Thanks 2
Posted

I agree with GrumbleDook - where the DPO has their office is a bit irrelevant.

The school is the data controller and thus is absolutely responsible to ensure compliance. The DPO's job is to advise and make it happen. If anything goes wrong it will be the school that is fined, not the DPO or the Head.

Posted (edited)

Leeoakley

 

I'm interested in your meeting with a 'GDPR consultant'. Are they education specialist? I'd be keen to know if they have knowledge of what data schools have and how its shared, eg SIMS data goes to a payment provider who then shares it with a cashless provider (or the other way around depending on the system you use)

 

I'm always concerned that external 'experts' dont know how you work in schools and you'll be left doing the donkey work.

 

Please post the outcome of your meeting.

Edited by elsiegee40
Put the GDPR letters in the right order
  • Thanks 1
Posted

Examples of how schools do, or should do, information audits would be a good thing. Becta never managed to get this out but did some good leg work ... I'd love to see how somehow works out.

 

I'm also going to raise some of this with a Governors' advice company to see what they can come up with too.

Posted (edited)

Morning, The reason for the meeting is that we are looking at developing some training around GDPR.

 

'GRDP consultant' Wont be an educational specialist, however that's what we will bring to the table. Unfortunately I fear that due nature of GDPR from my reading to date, you may be left doing some donkey work either way :(

 

If the consultant cant answer the questions I have, then it will be back to the drawing board. I have a section of questions around the "education sector" because of our client base. Although I don't work at a school I have been working with schools for 10 years. I have worked with schools directly onsite and remotely as well as local authorities, support companies, MAT's etc. I have also had the please of visiting 100s of schools over my career.

 

Happy to post up the outcome of the meeting.

 

Tony- Would you be up for running through the outcome if I email it over to you?

Edited by Leeoakley
Posted
Tony- Would you be up for running through the outcome if I email it over to you?

 

Happy to have a look.

 

I have a bunch of webinars from folk like AIIM in my calendar ... looking for info from any and every source at the moment!

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...