ryoung Posted July 4, 2017 Posted July 4, 2017 Dear colleagues. As part of our getting ready for GDPR, I am coordinating a data audit. Practical advice on how to undertake this is rather thin on the ground? The best example I can find is given by the ICO of the Isle of Man https://www.inforights.im/media/1271/gdpr_part-1_toolkit_mapping_may2016.pdf I attach a photo of their summary A4 inventory and also spreadsheet i have created which adapts the IoM approach: it takes the view of the data we are collecting by student, member of staff, and parent. Our team will then go through each data collection sheet we issue identify a data item and our compliance, row by row. Parents teachers and students each have their own worksheet. data audit findings.xlsx I think this approach can work. great to hear comments or other ideas. GDPR is proving to be a real time sink 3
enjay Posted July 5, 2017 Posted July 5, 2017 That's a nice template, but I think it will need a bit of tweaking when you come to actually fill it in because many of those data fields are collected for multiple purposes, multiple data processors and stored in a variety of ways/locations.
ryoung Posted July 7, 2017 Author Posted July 7, 2017 Good point. Plan: after a given data item say student contact details in a row we will insert rows underneath which identify where else that data item is used, location, security etc.
clangstaffnhts Posted March 16, 2018 Posted March 16, 2018 It looks clear and simple ryoung I agree with enjay though as it is an issue we are also having. Many of our data collections are then processed into up to 10 other systems for various reasons. It would be very hard to map all this so clearly. Are you going to the degree of listing each data field? For example within a student enrolment we collect many data fields.
enjay Posted March 19, 2018 Posted March 19, 2018 It looks clear and simple ryoung I agree with enjay though as it is an issue we are also having. Many of our data collections are then processed into up to 10 other systems for various reasons. It would be very hard to map all this so clearly. Are you going to the degree of listing each data field? For example within a student enrolment we collect many data fields. I think we're going with the main information audit saying "basic details, e.g. name, date of birth, school email address, class group" and putting that in the information audit, then having a separate document listing all the EdTech suppliers with a column for each field, so we can see specifically what is being shared with whom (reasonably quick to put together since most of the sharing is done via SIMS reports).
clangstaffnhts Posted March 20, 2018 Posted March 20, 2018 I think we're going with the main information audit saying "basic details, e.g. name, date of birth, school email address, class group" and putting that in the information audit, then having a separate document listing all the EdTech suppliers with a column for each field, so we can see specifically what is being shared with whom (reasonably quick to put together since most of the sharing is done via SIMS reports). Just to confirm is it a requirement to list which data fields are transferred to external systems or is it enough to say that personal or special category data is transferred to the system? Also do we have to list each element of data within our privacy policies or is it enough to say that personal and special category data is processed to the third party system in question?
enjay Posted March 20, 2018 Posted March 20, 2018 Check with your DPO, but I think it okay just to give categories and examples, certainly none of the template information audits I've seen list field by field. We have over 50 data processors, so if we listed a line item for each data field we shared with each processor, the information map would be enormous.
tinkerbotsict Posted March 20, 2018 Posted March 20, 2018 How have you got on with the xml file thinking of using something like this but wanted to see how people have progressed?
clangstaffnhts Posted March 21, 2018 Posted March 21, 2018 Check with your DPO, but I think it okay just to give categories and examples, certainly none of the template information audits I've seen list field by field. We have over 50 data processors, so if we listed a line item for each data field we shared with each processor, the information map would be enormous. DPO... what DPO? Unfortunately the school is yet to appoint a DPO hence me chasing my tail trying to make some progress with this in advance of 25th May! Thanks for the info though - this is useful. I did think it was a big ask to have to list every date field processed by each external platform. I think I will take the approach of listing a data set data is pulled from and then listing individual data fields only for Special Category data such as ethnicity. For example the GCSEPod online learning platform processes data from our 'Student personal data set' (which is their general personal info such as name, DOB etc) and the following data field from the 'Student Special category data set' 'Ethnicity'.
enjay Posted March 21, 2018 Posted March 21, 2018 For example the GCSEPod online learning platform processes data from our 'Student personal data set' (which is their general personal info such as name, DOB etc) and the following data field from the 'Student Special category data set' 'Ethnicity'. GCSEPod don't need to know ethnicity, so don't send it. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now