Jump to content

Recommended Posts

Posted
How can the law have created such a ridiculous roll that no one on the SLT had actually do unless they have some weird SLT setup? Also how many company have someone that can hold the leadership to account but don't have active control over this stuff.

 

To quote Mr Bumble in Oliver Twist by Charles Dickens

59736CD8-BE08-471F-B3B9-5B1F4FE3A9D1-16392-00001147BAE82347.jpg

Posted

In fairness, larger organisations will often have people who have dedicated roles around compliance and auditing, so I guess it would be envisaged it lands on those people. Or to force the organisation to employ someone, as a way of ensuring data protection is a a serious, not secondary, concern.

 

An exemption for smaller organisations might have been helpful though!

 

Either that or someone was in bed with consultancy firms....

Posted
An exemption for smaller organisations might have been helpful though!

 

I think there is such an exemption, but most schools are too big. Not unreasonable really - we have a workforce of over 100 people and a "turnover" of around £5m. We're not a small organisation.

Posted
Fair point, but neither are schools big enough to have a compliance department. We're stuck in the middle a bit!

 

Schools are excellent at compliance ... finance, safe guarding, recruitment, QA, governance ... it is just that they are also poor at compliance ... when it is something that schools think is not so important.

Posted (edited)

So to check I have this right, it seem like if 3 schools are working as a loose consortium (mostly for offering a broader range of A levels to sixth form students) school A could provide the DPO to school B, school B to school C, and school C to school A, with any dual school issues resolved by whichever is the uninvolved school? That way there isn't even a suggestion of any "you scratch my back..." conflicts of interest as each school is monitored by a school they themselves are not monitoring. Would that sound fairly OK to those who have a good handle on the topic?

 

Also, while the DPO is responsible for ensuring compliance, I assume the actual task of implementing all compliance measures can still be given to the Data Manager (who I strongly suspect can't ever be DPO for obvious reasons) with the DPO simply supervising to ensure it's done properly and signing off on that aspect?

 

Edit - that's before we even start thinking about the poor primaries in all of this, who haven't generally got specialist data managers. I suspect there could be a kinda internal market developing in some places between the secondaries and their feeder primaries with the secondary DPO also working with the primaries to ensure they have their ducks in a row...

Edited by crispybits
Posted (edited)

There is still confusion and uncertainty about the need for a DPO. https://www.hcrlaw.com/preparing-general-data-protection-regulation-gdpr-10-steps-schools/ says that quote

"Under GDPR, certain data controllers and data processors MUST appoint a DPO. These include:

  • Public authorities (with some minor exceptions) – this means that all maintained schools and academies will have to mandatorily designate a DPO;
  • Any organisation whose core activities require “regular and systematic monitoring” of data subjects on a “large scale”; or “large scale” processing of personal data or criminal records.

At this stage, the terms “large scale” are undefined so we are expecting guidance to be published on this. For now, it is potentially possible that those organisations that carry out background checks of individuals or children’s data or process large amounts of personal data by virtue of CCTV etc., may be required to appoint a DPO.

At this stage, it is not clear if an independent school will have to appoint a DPO or not. That said, our strong view is that all independent schools should appoint one in any event because of the significant tasks required to comply with both existing data protection law and the forthcoming GDPR. Your DPO should receive enhanced DPO training."

But on http://gdpr.school it clearly states "It will be mandatory for schools to appoint a data protection officer"

 

GDPR.school also states "When the GDPR (General Data Protection Regulation) comes into effect on 25 May 2018, every state funded and private school, as well as nurseries and child care organisations, must name their data protection officer (DPO). This person may be a member of staff or someone from an outside organisation – there are no formal qualifications required for the role however the DPO must meet certain criteria.

GDPR mandates the appointment of a DPO for all public bodies including all state-run schools. Private schools and nurseries must also appoint a DPO because their core activities involve ‘regular and systematic monitoring of data subjects on a large scale".

I didn't think an existing member of staff could work autonomously in the role of a DPO, surely a new recruit would be better placed to act independently.

These mixed messages are not helping the situation, so who do we believe. Do we assume that we must have a DPO and start the recruiting process now or wait for it to be fully ratified and agreed before we make the next move.

Edited by MrWrighty
Posted

I'm assuming you're at an independent school @MrWrighty so ask yourself this: bearing in mind independent schools won't be exempt from the GDPR, how would you achieve and maintain compliance without appointing someone to oversee it all? Which is what the second section you highlight says too. So, it looks like you need one whether legally mandated to get one or not.

 

I also think the second bullet point ("any organisation whose core activities require ... large scale processing of personal data") would cover an independent school, too.

  • Thanks 1
Posted
I didn't think an existing member of staff could work autonomously in the role of a DPO, surely a new recruit would be better placed to act independently.

 

I think that's what this whole thread has been about. It's very difficult to find someone with the seniority, independence and rank to fulfill the role. And yet schools will struggle to find the money to add another head to their staff numbers or pay an external contractor :(

Posted (edited)
I'm assuming you're at an independent school @MrWrighty so ask yourself this: bearing in mind independent schools won't be exempt from the GDPR, how would you achieve and maintain compliance without appointing someone to oversee it all? Which is what the second section you highlight says too. So, it looks like you need one whether legally mandated to get one or not.

 

I also think the second bullet point ("any organisation whose core activities require ... large scale processing of personal data") would cover an independent school, too.

 

Enjay I wasn't expecting exemption from GDPR, but more clarity on need to have a DPO. The cost to a school will be high for such a responsible role, perhaps £30K to £40K a year, I honestly don't know what this role would demand in remuneration. How many schools and come to think of it, businesses afford such an individual.

Edited by MrWrighty
Posted
Enjay I wasn't expecting exemption from GDPR, but more clarity on need to have a DPO. The cost to a school will be high for such a responsible role, perhaps £30K to £40K a year, I honestly don't know what this role would demand in remuneration. How many schools and come to think of it, businesses afford such an individual.

 

Okay. So the official line seems to be "yes you will need to have one, over to you to work out how you'll manage this!".

 

Very few people currently in the school are capable of doing it (seniority, knowledge, etc.), we would struggle to afford to appoint someone just to be DPO, and outside agencies possibly wouldn't understand what we do and certainly wouldn't spot if we're doing it wrong. A lot of LEAs don't seem to be helping, larger MATs could potentially appoint someone across the whole group, everyone else? No clue!

Posted
Enjay I wasn't expecting exemption from GDPR, but more clarity on need to have a DPO. The cost to a school will be high for such a responsible role, perhaps £30K to £40K a year, I honestly don't know what this role would demand in remuneration. How many schools and come to think of it, businesses afford such an individual.

 

While there is going to be a lot of work involved, especially initially, I think long term you'd have to be a MAT or a very large school to need a full time person for the role. I think a lot of places would be looking at maybe a day or two a week, depending on whether they employ the DPO in a purely advisory / responsibility role, or whether they have them deal with all the paperwork as well.

 

I'm increasingly thinking that we'll be paying an outside contractor to be the DPO, with them doing the consultancy and compliance side of things, and passing the grunt work back to school admin.

 

You are right though, there's likely to be a budget hit for this regardless, at a time when we can ill afford it.

Posted
The position of independent schools interesting ... and this is where we start looking at the draft DP bill. Sections 67-69 deals with DPO. Section 67 actually says that all controllers must appoint a DPO. This goes further than the public bodies as stated in GDPR, and it is subject to change, but at this point we would say that it is something independent schools should at least prepare for, rather than leave it too late should that section stand as it is.
Posted
Is it just me that feels that this law is designed so that we fail at it? I feel completely overwhelmed by it how can we ever deliver all that is required? There not even training course to go on?
Posted
Is it just me that feels that this law is designed so that we fail at it? I feel completely overwhelmed by it how can we ever deliver all that is required? There not even training course to go on?

I agree. Despite the fact that the guidance suggests that if you're compliant with the current DPA it shouldn't be a big change, that's definitely not how it feels.

 

However, if I step aside from the role of data controller and view in the context of how I'd like my personal data to be treated, I don't think there's anything that unreasonable being asked. I think in general the organisations/people processing my personal data have got away with ignoring my rights and using data for things I didn't intend and not taking sufficient care of its security. Introducing regulations to better control it seems necessary.

  • Thanks 1
Posted
Is it just me that feels that this law is designed so that we fail at it? I feel completely overwhelmed by it how can we ever deliver all that is required? There not even training course to go on?

I'm getting emails about courses, training etc on an almost daily basis.

 

You could say the current law is designed so that we fail - at least if you look at it from the POV of compliance. Schools are rubbish at DP (part of the reason why GDPR is such a hill to climb), many of us live in a "everyone does it so it must be OK" cloud of false security.

Posted

There are a raft of folk doing various levels of training. We don’t do it ourselves but have partners and contacts who do.

 

GroupCall have been sessions but I’ll see if one of our other contacts has anything on local to you.

 

Would it be helpful for members if we put up a page on our site about training?

  • Thanks 1
Posted
There are a raft of folk doing various levels of training. We don’t do it ourselves but have partners and contacts who do.

 

GroupCall have been sessions but I’ll see if one of our other contacts has anything on local to you.

 

Would it be helpful for members if we put up a page on our site about training?

 

Yes also it would be good to note the training available for the Technical or Senior Leader also by area.

  • Thanks 1
Posted
There are a raft of folk doing various levels of training. We don’t do it ourselves but have partners and contacts who do.

 

GroupCall have been sessions but I’ll see if one of our other contacts has anything on local to you.

 

Would it be helpful for members if we put up a page on our site about training?

 

Yes, please do!

  • Thanks 1
  • 3 weeks later...
Posted
Based on the obvious evidence that the DPO role cannot be the Network Manager where would that leave the IT Technician or Senior IT Technician if you have one? could they be asked to do it?
Posted
Too low down the foodchain to make those decisions really, and i'd be very confused if your techs had legal knowledge to that extent! :p

 

Steve

 

True I'm just thinking whether the conflict of interest argument would still stand. Basically our IT Tech and Business Manager went to a brief recently (don't know why I wasn't invited as Network Manager!!). They were told that the SBM should be the DSO which is debatable but it was hinted that there is nothing stopping the IT Tech with the right training.

Posted
True I'm just thinking whether the conflict of interest argument would still stand. Basically our IT Tech and Business Manager went to a brief recently (don't know why I wasn't invited as Network Manager!!). They were told that the SBM should be the DSO which is debatable but it was hinted that there is nothing stopping the IT Tech with the right training.

 

Even more so I'd say, as they'd have even less "independent" stance to over-rule both NM, BM, and Head etc :p Which end of the day is what DPO needs to do if there's any issues etc

 

Steve

  • Thanks 1
Posted
True I'm just thinking whether the conflict of interest argument would still stand. Basically our IT Tech and Business Manager went to a brief recently (don't know why I wasn't invited as Network Manager!!). They were told that the SBM should be the DSO which is debatable but it was hinted that there is nothing stopping the IT Tech with the right training.

I'm remaining cautious with all the training providers, particularly where the quote how to help you achieve compliance. The law is not passed yet, so whilst I'm sure there are many offering useful advice, there are going to be a number jumping on the band-wagon for a quick buck.

 

- - - Updated - - -

 

True I'm just thinking whether the conflict of interest argument would still stand. Basically our IT Tech and Business Manager went to a brief recently (don't know why I wasn't invited as Network Manager!!). They were told that the SBM should be the DSO which is debatable but it was hinted that there is nothing stopping the IT Tech with the right training.

I'm remaining cautious with all the training providers, particularly where the quote how to help you achieve compliance. The law is not passed yet, so whilst I'm sure there are many offering useful advice, there are going to be a number jumping on the band-wagon for a quick buck.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...