Jump to content

Recommended Posts

Posted
As a more constructive comment, I'd like to add that an issue which causes day to day headaches for us is third-party services. Teachers wanting to sign up to some service or other that has caught their eye, but we have to say "hang on.. ummm, bear with", as we're not yet clear on how we decide to approve the use of a third-party service or not. It may be that we've just not done enough homework on GDPR here, but that's a practical issue that will be facing all schools, and where childrens' personal data crosses over from a public body to a private organisation.

 

To some extent, this is what we are trying to do via this thread and related spreadsheet.

 

http:// https://www.edugeek.net/showthread.php?t=188142https://www.edugeek.net/showthread.php?t=188142

 

The sooner we can get more on the list the sooner I can start getting responses on and you can see who is being proactive.

Posted
Thanks for that. I wasn't actually thinking about a way out, though, more about successive governments' penchants for meddling, e.g. the constant revisions to the National Curriculum.

 

This was certainly a concern raised when several of local schools met together to discuss how we should proceed.

Posted

So what do I want from the DfE/ICO?

 

1. Data Audit - some education-specific guidance and example template for a data audit and what related documentation should look like.

2. Public Interest - examples of what is and what isn't public interest, and what educational data would be outside of this (with relevant guidance)

3. Clear guidance to MATs/Heads about how GDPR compliance should/could be structured, including responsibilities, DPO role etc

 

I would certainly agree with these along with who should be the DPO and what data being held constitutes being public interest.

 

From some of the comments earlier I would like to see guidance to head teachers so they understand that they are expected to do something, that it affects every employee of a school and that it is not just an IT thing as it is much bigger than that. My personal feeling is that we in IT should be being told what to do rather than doing the telling. We should not be wagging the dog!

Posted
Out of interest ... has anyone used the old Becta materials on Data Protection? Either historically, or possibly still using them?

 

There used to be a cached version of the Becta website... Is that still available?

Posted

I manage 3 schools - all of which GDPR has never been mentioned nor spoken about.

 

Personally I think the role of DPO should be held with the director/ headteacher. However I personally see this becoming a role that either IT or the SBM will end up with.

 

Personally I'd like to know what state/ LA schools have to do in comparison to academies - are LA's responsible for ensuring schools are compliant or is it solely upto each school independently?

 

It will be very interesting to see over the coming year how many people end up with the DPO role without any notification or recognition. What does it mean personally for the DPO, will they/ can they be held personally liable for any fault on behalf of an organisation or a school? If so, perhaps the DPO should be named on the annual Data Protection registration so that they are fully aware of the role they are taking on.

Posted
I manage 3 schools - all of which GDPR has never been mentioned nor spoken about.

 

Personally I think the role of DPO should be held with the director/ headteacher. However I personally see this becoming a role that either IT or the SBM will end up with.

 

Personally I'd like to know what state/ LA schools have to do in comparison to academies - are LA's responsible for ensuring schools are compliant or is it solely upto each school independently?

 

It will be very interesting to see over the coming year how many people end up with the DPO role without any notification or recognition. What does it mean personally for the DPO, will they/ can they be held personally liable for any fault on behalf of an organisation or a school? If so, perhaps the DPO should be named on the annual Data Protection registration so that they are fully aware of the role they are taking on.

I don't think you will legally be able to employ the services of your IT department or SBM as the DPO there is far too much conflict of interest for them to fulfil this role effectively. It will also be a very demanding role. I see it as a new role via consultancy or recruitment, either way it will be expensive. Any individual either recruited or consultant will need time to fully understand the infrastructure, data sets etc and be senior enough to have the ear of the SLT and Governors etc. Its not going to be easy by any means.

Posted
I manage 3 schools - all of which GDPR has never been mentioned nor spoken about.

 

Personally I think the role of DPO should be held with the director/ headteacher. However I personally see this becoming a role that either IT or the SBM will end up with.

 

Cannot happen, a conflict of interests. Please see the resources thread which has links to articles on who can/cannot be DPO.

 

Personally I'd like to know what state/ LA schools have to do in comparison to academies - are LA's responsible for ensuring schools are compliant or is it solely upto each school independently?

 

The responsibility is with the Legal Entity. In the case of maintained schools, that will be the school themselves. With Academies, you need to chat to your trust and see who is set as the legal entity and registered with the ICO.

 

It will be very interesting to see over the coming year how many people end up with the DPO role without any notification or recognition. What does it mean personally for the DPO, will they/ can they be held personally liable for any fault on behalf of an organisation or a school? If so, perhaps the DPO should be named on the annual Data Protection registration so that they are fully aware of the role they are taking on.

 

The DPO has to be named, as they are "the first point of contact for supervisory authorities and for individuals whose data is processed (employees, customers etc)" (from ICO's https://ico.org.uk/for-organisations/data-protection-reform/overview-of-the-gdpr/accountability-and-governance/ page). The DPO is not liable under GDPR, it is the Data Controller (but they may be contractually responsible) and Data Processors who are.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...