Jump to content

Recommended Posts

Posted
Logging into Purple Mash (online service for Primary pupils) I now get this to accept...

[ATTACH=CONFIG]45873[/ATTACH]

 

Perhaps jumping the gun a bit for 2? It's a positive they are preparing in advance but the details of the bill are still being thrashed out.

Posted

Having had a chat with a few folk about the ‘compliance’ comment ... many are putting in statements about what they will do in their policies but devil is in the detail within their processes ... and also there are folk who will be near to GDPR compliance, but not DPA 2018.

 

It is getting to be a grey area and we suggest that suppliers say ‘to Support GDPR compliance’ and we’ll feedback to Purple Mash on your comments (though they do lurk on here).

Posted
Went to a LA meeting last night and was told that The Lords had recommended that schools be exempt from the DPO requirement. Anyone got any more info on that?
Posted (edited)

Oh I wasn't celebrating, on the contrary I think that dropping the requirement wouldn't be a smart move. From everything I've seen and heard, to actually be compliant with GDPR takes an expert and is way beyond what most school staff will be able to do without the correct training. Just chatting to some of the, qualified, LA DPOs about their jobs, shows me that this is not a simple role. I fear that schools could see this (understandably) as a cheap way of doing it and fall foul of the lack of expertise.

Unfortunately not quite true. An amendment prodding that was tabled in the Lords, but it was turned down.

 

See here for details:

 

https://www.edugeek.net/showthread.php?t=189777

Yeah, aware of that, but this is not what the LA was talking about. We were informed by a LA DPO who is following the progress of the bill through Parliament, that an actual recommendation has been made, but I can't find any evidence of this.

Edited by ZeroHour
Posted (edited)

(Apologies, I've amended my reply as I realised I was linking to the same thread quoted above)

 

The Lords amendment was the only one going through at the moment, and as said before it was dropped. There was no indication that it was for the greater good and common sense anyway, just the self interest of a few peers.

Edited by Stutwo
Posted
The proposed amendment wasn't for the greater good and common sense, just for the self-interest of a few Lords who had roles at high-flying Universities. The amendment was dropped when the proposers were satisfied that the DPO role wasn't going to get in the way of university fundraising. There was a discussion with a link to the Hansard records in another thread in this forum.

 

Found it: http://www.edugeek.net/forums/data-protection-information-handling/189777-new-data-protection-bill-exemption-schools.html

Thanks, but that's the same as above, this is not what was being discussed.

 

So, as far as our LA understands, a recommendation has been made that schools should be exempt from the requirement to employ a DPO. This is separate to the discussion about the amendment that was raised and dropped.

Posted

Sorry I just noticed that and amended my response as you posted yours.

 

I'm not aware of anywhere that could be recommended other than the Lords at the moment though? I've got a meeting with our LA on the GDPR this afternoon so I'll ask the question there.

  • Thanks 1
Posted
Sorry I just noticed that and amended my response as you posted yours.

 

I'm not aware of anywhere that could be recommended other than the Lords at the moment though? I've got a meeting with our LA on the GDPR this afternoon so I'll ask the question there.

Awesome, thanks! The LA seem pretty adamant but I can't find any evidence of it.

Posted

I tend to do my reviews of Hansard before going to bed (it helps) but haven’t seen anything new yet ...

 

It may be that a group is lobbying DCMS on this, but we’ve heard nothing from DfE on that ...

 

We have spoken with a few more GDPR notables and have some possible options but need to get them checked out before suggesting them.

 

However, one thing is becoming clear ... and it is something we’ve raised already.

 

A lot of the tasks don’t need a DPO in place right now ... you can start without one for data discovery, data minimisation, etc.

  • Thanks 1
  • 3 weeks later...
Posted (edited)

Hello,

 

Just returned from a GDPR training course provided by my LEA. This was ran by a legal team who consult for them. Sharing some of my findings:

 

Data Controller – The person with legal responsibility for personal data (This is the Governors for maintained schools)

Data Processor – Any person who is not an employee of the data controller who processes data (SIMS, GroupCall, Wisepay, etc)

Data Subject – The individual (Student, Staff)

Data Protection Officer – The individual at the centre of the school’s risk based approach to Data Protection

 

DPO must be appropriately involved in all matters concerning the protection of personal data. Need not be a qualified data protection professional must have sufficient knowledge and expertise. Was told there was nothing official at the moment that said it can't be a BM, NM, DH, etc (although I am confused as it does say otherwise in article 29 - also says 'expert' knowledge?) Shouldn't be an 'extra hat'.

Awaiting further guidance from DFE.

Brexit has thrown a spanner in the works and now a UK bill is going through Parliament.

 

A huge amount of work to be done to be done (admittedly, a lot of this should be happening already)

You need a written contract every time you employ a processor to process personal data.

 

Must only appoint processors (third parties like SIMS, Wisepay, etc) who can provide sufficient guarantees that GDPR requirements will be met and rights of data subjects protected.

***Applies to old and new contracts***

 

Severe breach that needs reporting is defined as something that is likely to result in high risk to a person’s rights and freedom.

 

How many people on here are (or are thinking) of taking on the DPO role? Would you be seeking an honorarium ro some form, of pay increment for undertaking this work?

Edited by ronnoco
Posted

How many people on here are (or are thinking) of taking on the DPO role? Would you be seeking an honorarium ro some form, of pay increment for undertaking this work?

 

I'm not considering it, but I'd want a pay rise linked to the extra work and responsibility, taking into account how much time it'll consume initially (Payment 01*) and the year-on-year once it's running smoothly (Payment 02).

 

*at say an hourly rate.

  • Thanks 1
Posted

I suspect many on here could only take on the DPO role at the expense of their current position as there is a direct conflict of interest preventing them doing both.

 

Not something I would consider without a lot of training and a big pay rise.

  • Thanks 1
Posted
I still confused why a NM can’t do both rolls. A deputy or other slt can do that and child protection.

Do what, be deputy and do child protection? I don’t see the conflict here?

Posted
Hello,

 

Just returned from a GDPR training course provided by my LEA. This was ran by a legal team who consult for them.

 

I was there too and found some of their comments appeared to be ill researched, I plan on attending several other events to see where the concensus lies.

 

How many people on here are (or are thinking) of taking on the DPO role? Would you be seeking an honorarium ro some form, of pay increment for undertaking this work?

 

I was most concerned to hear that Norfolk County Council had appointed the Head of IT as their DPO. I'm just an 'umble Data Manager and I won't be putting my hand up, nor would my SLT lead who attended with me!

Posted (edited)
I posted the exact wording in another thread but basically a DPO can’t have any input into the nature or purpose of the processing and also must have the required expertise to do the job. I doubt that any school has someone with the kind of knowledge and expertise to be a DPO just hanging around on the staff doing a different job? Edited by sparkeh
  • Thanks 2
Posted
I still confused why a NM can’t do both rolls. A deputy or other slt can do that and child protection.

 

Because, in my opinion, the DPO needs to be both independent and have authority at the highest level. You will struggle to find anyone working in a school who is independent from the handling of data, and very few of them will have the authority to over-rule the Head.

  • Thanks 1
Posted

Brexit has thrown a spanner in the works and now a UK bill is going through Parliament.

 

 

Only in that it's difficult to get progress on much in parliament currently due to the volume of work caused by Brexit. There was always going to have to be UK legislation to implement the EU regulation. The Government clarified pretty quickly after the referendum that it would unaffected by the result.

  • Thanks 1
Posted

https://www.gdpr.school/wp-content/uploads/2017/08/Who-will-be-your-DPO.pdf might help.

 

I’ve had some follow on chats with ICO around this and it is pretty clear that the school has to evaluate if there are possible conflicts of interests.

 

If the school says that there are not then they have to justify it.

 

From every example we have discussed on here, no NM can do the role for their own school. The guidance comes from ICO, not DfE.

  • Thanks 2
Posted (edited)
I still confused why a NM can’t do both rolls. A deputy or other slt can do that and child protection.
@nicholab What Seb said...

Because, in my opinion, the DPO needs to be both independent and have authority at the highest level. You will struggle to find anyone working in a school who is independent from the handling of data, and very few of them will have the authority to over-rule the Head.

A Network Manager directly controls how data is processed. They cannot therefore rule on whether the way the data is being processed is legitimate as they would be ruling on how they do their own job.

 

The role of the DPO is that of an independent auditor. They must have:

- the knowledge to know what is right and wrong in the eyes of the law

- the independence to review without prejudice what data is processed and how data is processed

- the seniority to overrule the most senior members of a school/MAT/organisation if data is not being processed in line with the law

Edited by elsiegee40
Posted (edited)

I have very little knowledge on this subject at the moment but personally, I think the NM seems like a good person to undertake the role as a lot of DP work relates to digital. The NM understands how third parties like SIMS, Groupcall, etc obtain and use data whereas you DH probably has no idea of the actual workings. Also, NM will be involved in Internet/E-Mail monitoring, filtering, encryption of laptops, memory sticks, CCTV, social media, etc - they are at the forefront of what a lot of this is about and will know what steps to take. Surely every member of staff would have a conflict of interest. i.e. You make a big muck up a send student data to the wrong parent, that's a breach. You could choose not to report it and smooth it over yourself and hope you don't get found out. It becomes a question of honesty and integrity.

 

I'm confused about what we should be following as from May. Is it a case of we follow the EU GDPR document until the UK bill is passed? The Solicitors on our course said that it was Article 29 that explained that it shouldn't be the NM, BM, Head, etc - like that wasn't relevant for us. How does Article 29 fit in with all of this?

 

There are schools in my area that only employ 5 staff. With these, an existing member of staff would probably have to fulfil the role as I doubt the school would have the budget to outsource. I think as long as you are following all the guidance and making good efforts and most importantly, can prove what you have done - i.e. I follow the Data Protection Progress Plan I have been given and produce all the necessary folders, guidance, evidence and put those things into action (including staff training) - over time and with a lot of study of the act, you will naturally become very skilled and experienced at DP.

 

It's a tricky one. A member of staff can go on a Child Protection Course then become the designated senior professional for CP. You certainly aren't going to know much after a one day course. This could well be viewed the same.

 

Doing a basic qualification in DP would of-course help and in this day and age, the skills, experience and any qualifications you can here gain here could be very advantageous.

 

It really does depend if it is a deal breaker for an existing Head, NM, BM, etc to do the job and if you are prepared to do it.

Edited by ronnoco
Posted

You don't need them. You could simply contact the parent who's details you discovered, tell them sorry, etc and not report it. Or even do nothing but apologise to the parent you sent the wrong information too. You're unlikely to get caught from e-mail logs.

 

That breech should be reported, so if you are a data subject (which everyone is in a school) you could have a conflict of interest being the DPO I would have thought.

 

I do get that a NM is very close to the data and has the highest of access but in my eyes, that's probably a good thing for carrying out this role...you're more likely to understand what to look for and be in a position to spot it.

Posted

I look after the school asset register but this has to be done with the Bursar and the Head. If I had full control of it I could easily write off a few machines etc and no one would be any the wiser. It's the same with being a DPO it would be too easy to cover your own backside or equally drop someone else in it.

 

ps please visit my ebay store for old laptops and servers etc hush hush

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...