Jump to content

Recommended Posts

Posted

Dear colleagues. As part of our getting ready for GDPR, I am coordinating a data audit. Practical advice on how to undertake this is rather thin on the ground? The best example I can find is given by the ICO of the Isle of Man https://www.inforights.im/media/1271/gdpr_part-1_toolkit_mapping_may2016.pdf

 

I attach a photo of their summary A4 inventory and also spreadsheet i have created which adapts the IoM approach: it takes the view of the data we are collecting by student, member of staff, and parent. Our team will then go through each data collection sheet we issue identify a data item and our compliance, row by row. Parents teachers and students each have their own worksheet.

 

data audit findings.xlsxPersonal data inventory.png

 

I think this approach can work. great to hear comments or other ideas. GDPR is proving to be a real time sink

  • Thanks 3
Posted
That's a nice template, but I think it will need a bit of tweaking when you come to actually fill it in because many of those data fields are collected for multiple purposes, multiple data processors and stored in a variety of ways/locations.
Posted
Good point. Plan: after a given data item say student contact details in a row we will insert rows underneath which identify where else that data item is used, location, security etc.
  • 8 months later...
Posted

It looks clear and simple ryoung I agree with enjay though as it is an issue we are also having. Many of our data collections are then processed into up to 10 other systems for various reasons. It would be very hard to map all this so clearly.

 

Are you going to the degree of listing each data field? For example within a student enrolment we collect many data fields.

Posted
It looks clear and simple ryoung I agree with enjay though as it is an issue we are also having. Many of our data collections are then processed into up to 10 other systems for various reasons. It would be very hard to map all this so clearly.

 

Are you going to the degree of listing each data field? For example within a student enrolment we collect many data fields.

 

I think we're going with the main information audit saying "basic details, e.g. name, date of birth, school email address, class group" and putting that in the information audit, then having a separate document listing all the EdTech suppliers with a column for each field, so we can see specifically what is being shared with whom (reasonably quick to put together since most of the sharing is done via SIMS reports).

Posted
I think we're going with the main information audit saying "basic details, e.g. name, date of birth, school email address, class group" and putting that in the information audit, then having a separate document listing all the EdTech suppliers with a column for each field, so we can see specifically what is being shared with whom (reasonably quick to put together since most of the sharing is done via SIMS reports).

 

Just to confirm is it a requirement to list which data fields are transferred to external systems or is it enough to say that personal or special category data is transferred to the system?

 

Also do we have to list each element of data within our privacy policies or is it enough to say that personal and special category data is processed to the third party system in question?

Posted
Check with your DPO, but I think it okay just to give categories and examples, certainly none of the template information audits I've seen list field by field. We have over 50 data processors, so if we listed a line item for each data field we shared with each processor, the information map would be enormous.
Posted
Check with your DPO, but I think it okay just to give categories and examples, certainly none of the template information audits I've seen list field by field. We have over 50 data processors, so if we listed a line item for each data field we shared with each processor, the information map would be enormous.

 

DPO... what DPO? Unfortunately the school is yet to appoint a DPO hence me chasing my tail trying to make some progress with this in advance of 25th May!

 

Thanks for the info though - this is useful. I did think it was a big ask to have to list every date field processed by each external platform. I think I will take the approach of listing a data set data is pulled from and then listing individual data fields only for Special Category data such as ethnicity.

 

For example the GCSEPod online learning platform processes data from our 'Student personal data set' (which is their general personal info such as name, DOB etc) and the following data field from the 'Student Special category data set' 'Ethnicity'.

Posted
For example the GCSEPod online learning platform processes data from our 'Student personal data set' (which is their general personal info such as name, DOB etc) and the following data field from the 'Student Special category data set' 'Ethnicity'.

 

GCSEPod don't need to know ethnicity, so don't send it.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...