Sagima Posted November 10, 2016 Posted November 10, 2016 I've been asked to find out how this will affect us and whether we need to do anything. Do any of you know of any handy guides to how it relates to us in education? thanks
Net-Ctrl Posted November 10, 2016 Posted November 10, 2016 Hello, this is something we're talking to a number of organisations about outside EDU. Our partner Gemalto have produced some useful content: https://safenet.gemalto.com/data-protection/data-compliance/european-union-eu-compliance/ There is access to datasheets, on-demand recordings etc. Hopefully will help. 1
Seb1780 Posted November 10, 2016 Posted November 10, 2016 I've been asked to find out how this will affect us and whether we need to do anything. Do any of you know of any handy guides to how it relates to us in education? From my perspective, it's DPA+; because we fall under the scope of the DPA we'll fall under the scope of GDPR, and they'll be more onerous requirements upon us, especially when dealing with third parties who handle our data. However, given our forthcoming departure from the EU this may never apply to us in schools provided we don't provide a service to EU member states.
Sagima Posted November 11, 2016 Author Posted November 11, 2016 Well none of it looks like it will cost the school anything extra except (my) time so I imagine that it will probably be approved at the meting this morning. It seems to boil down to encrypt everything, record details about the encryption and what your users are up to on your systems. I do a fair bit of that already.
Steve21 Posted November 11, 2016 Posted November 11, 2016 Does that actually mean "everything" needs to be encrypted now? Servers, including via file, application, database, and full disk virtual machine encryption. Storage, including through network-attached storage and storage area network encryption. Media, through disk encryption. Networks, for example through high-speed network encryption. Steve
Sagima Posted November 11, 2016 Author Posted November 11, 2016 I don't think you need to encrypt desktops but honestly as it seems I'm encrypting everything else I may just go ahead and do those too.
Stone_Charli Posted November 11, 2016 Posted November 11, 2016 (edited) @Sagima We did a webinar very recently on GDPR. We'll be uploading the recording to our website shortly. I'll post back here when I have the link. In the meantime, here's an article we did on it and how it will affect schools: https://www.stonegroup.co.uk/how-will-gdpr-affect-schools/ The article's more of an overview, the webinar goes into much more detail as it was delivered by our Compliance Manager. Hope this helps! Edited November 11, 2016 by Stone_Charli added a word 2
Sagima Posted November 11, 2016 Author Posted November 11, 2016 @Sagima We did a webinar very recently on GDPR. We'll be uploading the recording to our website shortly. I'll post back here when I have the link. In the meantime, here's an article we did on it and how it will affect schools: https://www.stonegroup.co.uk/how-will-gdpr-affect-schools/ The article's more of an overview, the webinar goes into much more detail as it was delivered by our Compliance Manager. Hope this helps! That would be great - thanks
Stone_Charli Posted November 15, 2016 Posted November 15, 2016 Sorry for the slight delay - here's the webinar: https://www.youtube.com/watch?v=x_EYh9Gm32U Charli
LiamR Posted February 20, 2017 Posted February 20, 2017 Sorry for joining the thread late in the day... To answer the earlier questions, Yes it has been confirmed that we the UK will proceed regardless of any exit of the EU. Plus, at the point GDPR becomes law in May 2018, we will still be in the EU. In regards to encryption. The report does articulate that encryption may mitigate the risk of data loss, for example the breach notification rules do not apply to encrypted data. However I think it is important to consider the specific use case/risk you are planning to mitigate. For example, full disk encryption on your servers will mitigate the risk of the servers or their disks being stolen. However it does nothing to prevent the data being leaked unintentionally by somebody with access to the server, who then uploads a file to dropbox. So for me, encryption is a good step, but should be used in conjunction with other approached. As the ICO have discretion over the penalties they impose, I think that the most important first step, is to be able to provide a plan of action, including staff at all levels. As per Charli's comments, there is some good info on the Gemalto site (vendor websites can be a great source of info, though they will tend to look for the areas that coincidently they can address). However, I would also start by taking a look at the ICO's own 12 step guide here: https://ico.org.uk/media/1624219/preparing-for-the-gdpr-12-steps.pdf Thanks Liam.
maturelady Posted March 17, 2017 Posted March 17, 2017 Sorry I'm repeating the same thing as I did in the post: GDPR Data Protection and Memory Sticks. but GDPR is important. It is going to have a major impact in schools as we hold and share so much data. Whether we stay or leave the EU is immaterial - ICO has clearly said that the initiative will go ahead. A lot of questions regarding the new GDPR initiative is in the Webinar ICO produced and is worth listening to if you have an hour to spare! If not there's a PowerPoint that summarises it all and will be useful to use to get the message across that DP is about to change big time. https://ico.org.uk/about-the-ico/new...ector-webinar/ You may find this useful. 2
jslate1980 Posted March 18, 2017 Posted March 18, 2017 Sorry I'm repeating the same thing as I did in the post: GDPR Data Protection and Memory Sticks. but GDPR is important. It is going to have a major impact in schools as we hold and share so much data. Whether we stay or leave the EU is immaterial - ICO has clearly said that the initiative will go ahead. A lot of questions regarding the new GDPR initiative is in the Webinar ICO produced and is worth listening to if you have an hour to spare! If not there's a PowerPoint that summarises it all and will be useful to use to get the message across that DP is about to change big time. https://ico.org.uk/about-the-ico/new...ector-webinar/ You may find this useful. The link is showing as page not found
maturelady Posted March 18, 2017 Posted March 18, 2017 You can't get the staff! Try this https://ico.org.uk/about-the-ico/news-and-events/events-and-webinars/data-protection-for-the-education-sector-webinar/ 2
DavePa Posted March 22, 2017 Posted March 22, 2017 This one may be useful: https://ico.org.uk/media/1624219/preparing-for-the-gdpr-12-steps.pdf
elsiegee40 Posted March 30, 2017 Posted March 30, 2017 Does anyone know whether each school in a MAT must have a trained officer, like safeguarding, or whether there can be one person in the full trust with overall responsibility for GDPR within the trust?
GrumbleDook Posted March 30, 2017 Posted March 30, 2017 It is not uncommon to have one person setting the general strategic approach and then working with each school to make sure it fits the policies and requirements on any particular needs or circumstances if that school.
elsiegee40 Posted March 30, 2017 Posted March 30, 2017 It is not uncommon to have one person setting the general strategic approach and then working with each school to make sure it fits the policies and requirements on any particular needs or circumstances if that school. So you're saying a centralised MAT DPO function ensuring compliance across all academies in a MAT would be OK @GrumbleDook? I was wondering id this one was going to be like the DSL.
Leeoakley Posted March 30, 2017 Posted March 30, 2017 I have a meeting on Monday with a "GDPR Consultant" if you want me to try and get answers to specific questions for any of you, drop them as a reply here and I will see what I can do. Lee
maturelady Posted March 30, 2017 Posted March 30, 2017 I just asked ICO - reading their reply I think the answer is Yes schools can share a DPO Here's their reply: We have recently published further guidance regarding DPO's under GDPR, and if you haven't already done so, you may wish to look at the guidance we have published on our GDPR microsite https://ico.org.uk/for-organisations/data-protection-reform/overview-of-the-gdpr/accountability-and-governance/#dpos It is possible for a single DPO to act for a group of companies or public authorities, taking into account their structure and size. More recently, the Article 29 Working Party issued further guidance regarding DPO's and published a useful list of FAQ's you may wish to look at http://ec.europa.eu/newsroom/document.cfm?doc_id=43823 and http://ec.europa.eu/information_society/newsroom/image/document/2016-51/wp243_annex_en_40856.pdf respectively Hope it helps 2
GrumbleDook Posted March 30, 2017 Posted March 30, 2017 Yes, I had a similar conversation last week. It all depends what your group determines as an 'organisation'. If it deals with the majority of all other items separately, then it could be expected that this would be the case for the DPO ... but however it is dealt with it needs to be clearly managed and with accountability. If all else fails, the Heads of the individual schools are where the buck stops unless it is clear that the responsibility sits further up. 2
maturelady Posted March 30, 2017 Posted March 30, 2017 I agree with GrumbleDook - where the DPO has their office is a bit irrelevant. The school is the data controller and thus is absolutely responsible to ensure compliance. The DPO's job is to advise and make it happen. If anything goes wrong it will be the school that is fined, not the DPO or the Head.
maturelady Posted March 30, 2017 Posted March 30, 2017 (edited) Leeoakley I'm interested in your meeting with a 'GDPR consultant'. Are they education specialist? I'd be keen to know if they have knowledge of what data schools have and how its shared, eg SIMS data goes to a payment provider who then shares it with a cashless provider (or the other way around depending on the system you use) I'm always concerned that external 'experts' dont know how you work in schools and you'll be left doing the donkey work. Please post the outcome of your meeting. Edited June 20, 2017 by elsiegee40 Put the GDPR letters in the right order 1
GrumbleDook Posted March 30, 2017 Posted March 30, 2017 Examples of how schools do, or should do, information audits would be a good thing. Becta never managed to get this out but did some good leg work ... I'd love to see how somehow works out. I'm also going to raise some of this with a Governors' advice company to see what they can come up with too.
Leeoakley Posted April 3, 2017 Posted April 3, 2017 (edited) Morning, The reason for the meeting is that we are looking at developing some training around GDPR. 'GRDP consultant' Wont be an educational specialist, however that's what we will bring to the table. Unfortunately I fear that due nature of GDPR from my reading to date, you may be left doing some donkey work either way If the consultant cant answer the questions I have, then it will be back to the drawing board. I have a section of questions around the "education sector" because of our client base. Although I don't work at a school I have been working with schools for 10 years. I have worked with schools directly onsite and remotely as well as local authorities, support companies, MAT's etc. I have also had the please of visiting 100s of schools over my career. Happy to post up the outcome of the meeting. Tony- Would you be up for running through the outcome if I email it over to you? Edited April 3, 2017 by Leeoakley
GrumbleDook Posted April 3, 2017 Posted April 3, 2017 Tony- Would you be up for running through the outcome if I email it over to you? Happy to have a look. I have a bunch of webinars from folk like AIIM in my calendar ... looking for info from any and every source at the moment! 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now