enjay Posted November 29, 2017 Posted November 29, 2017 I have very little knowledge on this subject at the moment but personally, I think the NM seems like a good person to undertake the role as a lot of DP work relates to digital. The NM understands how third parties like SIMS, Groupcall, etc obtain and use data whereas you DH probably has no idea of the actual workings. Also, NM will be involved in Internet/E-Mail monitoring, filtering, encryption of laptops, memory sticks, CCTV, social media, etc - they are at the forefront of what a lot of this is about and will know what steps to take. Surely every member of staff would have a conflict of interest. i.e. You make a big muck up a send student data to the wrong parent, that's a breach. You could choose not to report it and smooth it over yourself and hope you don't get found out. It becomes a question of honesty and integrity. And that is exactly why the NM can't be DPO. It will of course be the NM who selects the encryption method, then the NM/technician who encrypts them; where the DPO comes in is ensuring the selected encrypted method was suitable and that all laptops have actually been encrypted. The NM knows where the bodies are, e.g. they know which brand of laptop stubbornly refused to encrypt so would know not to spot-check those ones when reviewing compliance. In much the same way the finance manager cannot do the annual financial audit. Remember, the DPO is not about making everything compliant, the DPO is about ensuring everything is compliant - oversight not action, if you will. Also remember the GDPR relates to paper just as much as it relates to digital. Digital is the bulk of it nowadays, of course, but putting the responsibility within IT could send the wrong message about how to handle paper (and indeed verbal). 1
ronnoco Posted November 29, 2017 Posted November 29, 2017 The DPO comes in ensuring the selected encrypted method was suitable and that all laptops have actually been encrypted. The NM knows where the bodies are, e.g. they know which brand of laptop stubbornly refused to encrypt so would know not to spot-check those ones when reviewing compliance. I don't think a DPO in general would even get involved in such things as encryption. They might ask 'are the laptops encrypted?' to the NM but I doubt most would do more than that. Us 'techies' think of such things - hence my point, the broad understanding of a lot of this.
elsiegee40 Posted November 29, 2017 Posted November 29, 2017 I have very little knowledge on this subject at the moment but personally, Then I suggest you read back through this thread and take note of the need for independence and seniority. You cannot be making decisions about whether your organisation is lawfully processing data if you are the one directly responsible for how the data is processed. There is a huge conflict of interest and the DPO is not allowed to have a conflict of interest by law. Few Network Managers have the seniority in the organisation to overrule the Head, Principal, MAT CEO, Finance Director and the like. The DPO needs to be able to do their job without fearing that it will result in them sacked. The DPO is also responsible for all paper data processing. Landing the job on the NM is like saying that eSafety is entirely the responsibility of the NM... eSafety isn’t; it is a safeguarding problem that is owned by the DSL.
ronnoco Posted November 29, 2017 Posted November 29, 2017 It's a grey area to me as this was an LEA course ran by a legal company comprising of 4 X Solicitors and they definitely said that further information is needed to clarify who can undertake this role. What I presumed from that is you wont officially know the answer until the UK bill has been passed.
enjay Posted November 29, 2017 Posted November 29, 2017 they definitely said that further information is needed to clarify who can undertake this role. That's possibly true, but I'm sure the NM will remain on the list of people who can't. 1
ronnoco Posted November 29, 2017 Posted November 29, 2017 OK, so next question - when will it be clarified? Are we waiting for the UK bill? What does it say on the EU GDPR? If we were going to follow this had we not decided to leave the EU, does it definitely say it can't be the NM? Thanks for the input, much appreciated.
DavR Posted November 29, 2017 Posted November 29, 2017 That's the rub @ronnoco, nowhere is it written in black and white in the EU law who can and cannot be DPO. Even when the UK law comes in, it's unlikely to give a list across all industries what roles can and cannot be the DPO. Like a lot of law, it's all down to interpretation. Hopefully DfE or ICO will clarify one day exactly who can or can't, but til then you have to look at the rule of do they have control over how or why data is processed. If you make decisions on how, or why, the data is processed, it can't be you. That accounts for Network Manger, Headteacher and a lot of SLT, all have conflict of interest. The DPO needs to audit these decisions, and you can't audit yourself. That's why this is such a long thread, no-one can find a role in their organisation senior enough to have the clout, but detached enough to be free of conflict. It's a right pain! 1
nicholab Posted November 29, 2017 Posted November 29, 2017 That's the rub @ronnoco, That's why this is such a long thread, no-one can find a role in their organisation senior enough to have the clout, but detached enough to be free of conflict. It's a right pain! How can any organisation have this role? Over rule the top management but not deal with the data?
sparkeh Posted November 29, 2017 Posted November 29, 2017 How can any organisation have this role? Over rule the top management but not deal with the data? Outsource.
GrumbleDook Posted November 29, 2017 Posted November 29, 2017 How can any organisation have this role? Over rule the top management but not deal with the data? There is a saying in the army... “I’m sorry Sir/Ma’am, you seem to be confusing *your* rank with *my* authority!” You don’t have to be SLT, but simply be senior enough to report into the Head and Governors. 2
ronnoco Posted November 30, 2017 Posted November 30, 2017 (edited) You could outsource but then that means every time you bring in a new system, you are gong to need your consultant to review. I've lost count of many we have installed this past year. Probably not going to be an option for small Primary schools either. They just don't have the budget. I've even heard of schools asking for voluntary donations. As IT Manager of 10+ years, I would 'feel' I have the seniority to check in with the Governors. Baring in mind they are ultimately going to be the Data Owners for the school, surely they would want to know about any problems. It depends what is classed as having the authority. It's very tricky as others have said before, the 'conflict of interest' seems to apply to anyone who may want to undertake the role. I spoke to a Chair Of Governors last night who didn't even realise that the Governors would the Data Owners and legally responsible. The same was discovered on the course. Edited November 30, 2017 by ronnoco
kennysarmy Posted November 30, 2017 Posted November 30, 2017 Following this thread with interest. I've just been informed one of our Assistant Heads will be "in charge" - seeking clarification on what that means - if it's that they are going to be the "DPO" - if I don't believe they have the necessary in terms of “expert knowledge of data protection law and practices.” - what do I gain by challenging their appointment?
sparkeh Posted November 30, 2017 Posted November 30, 2017 You could outsource but then that means every time you bring in a new system, you are gong to need your consultant to review. I've lost count of many we have installed this past year. I'm not entirely sure that's true. The way I see it is that initially the DPO will have a lot of involvement reviewing what the school has in place, and putting a procedure in place for the school to become compliant. Once the right procedures are in place, the school *should* be able to proceed down the right path following those procedures. If you procure a new system in the correct way then you should be ok. Down the line I see the DPO reviewing things every so often and being there for to advice on particular situations. The DPO is a supervisory role and not an operational one. Probably not going to be an option for small Primary schools either. They just don't have the budget. I've even heard of schools asking for voluntary donations. I agree with the budget comment. But regardless, currently, there will be a requirement to have a DPO that conforms to the statutory requirements so its not an option to not do it :/As IT Manager of 10+ years, I would 'feel' I have the seniority to check in with the Governors. Baring in mind they are ultimately going to be the Data Owners for the school, surely they would want to know about any problems. It's very tricky as others have said before, the 'conflict of interest' seems to break it. Its not really tricky, the rules, as they stand, are pretty clear.
pete Posted November 30, 2017 Posted November 30, 2017 (edited) Following this thread with interest. I've just been informed one of our Assistant Heads will be "in charge" - seeking clarification on what that means - if it's that they are going to be the "DPO" - if I don't believe they have the necessary in terms of “expert knowledge of data protection law and practices.” - what do I gain by challenging their appointment? Depends, are they willing to learn and develop their skills? Do they pick up information quickly? Sometimes you have to work with what you've got and you'll have to guide and educate them as they go. Edited November 30, 2017 by pete
DavR Posted November 30, 2017 Posted November 30, 2017 Following this thread with interest. I've just been informed one of our Assistant Heads will be "in charge" - seeking clarification on what that means - if it's that they are going to be the "DPO" - if I don't believe they have the necessary in terms of “expert knowledge of data protection law and practices.” - what do I gain by challenging their appointment? Probably not very much - ultimately, it's the school / DPO who carry the can if data protection is not implemented right, not the IT dept. You can only tell them, it's up to them if they listen. The more poignant question is whether you can work with this person and implement your end successfully. Very few SLT, if they're taking on this role, actually have the expert knowledge, so someone somewhere is going to be making a good buck on training courses.
GrumbleDook Posted November 30, 2017 Posted November 30, 2017 You could outsource but then that means every time you bring in a new system, you are gong to need your consultant to review. I've lost count of many we have installed this past year. Probably not going to be an option for small Primary schools either. They just don't have the budget. I've even heard of schools asking for voluntary donations. As IT Manager of 10+ years, I would 'feel' I have the seniority to check in with the Governors. Baring in mind they are ultimately going to be the Data Owners for the school, surely they would want to know about any problems. It depends what is classed as having the authority. It's very tricky as others have said before, the 'conflict of interest' seems to apply to anyone who may want to undertake the role. I spoke to a Chair Of Governors last night who didn't even realise that the Governors would the Data Owners and legally responsible. The same was discovered on the course. I would suggest you have a look at the sticky threads and have a read through some of the resources that have been linked to on there. I would also suggest that you put aside any idea of you being DPO, no matter what your experience. There will be a conflict. I have yet to see any scenario in a school where the IT Manager could be the DPO for that school without there being a conflict. It has been widely discussed in other threads too ... please, don’t go down that route. The school is the Data Controller. The Governor Body, as the strategic body of the school, has a responsibility but it is the school, as a legal entity, that is the Data Controller and holds the liabilities ... unless you are in a MAT, in which case (in general) the MAT is the legal entity and becomes the data Controller for all their schools (there are a few exceptions). The DPO is not going to do all the work. They are the oversight person ... The school should do the same as it does for H&S, teach people about risk assessment and then making decisions based on predefined boundaries, keeping the DPO in the loop. When looking at new software or systems there are common things you can ask ranging from “do you have a data sharing agreement?” to “do you conform to and are accredited for any recognised standards?” The DPO would review your assessment and make suggestions on risk mitigation, but they do not have to do every item of work! Also, if you are changing that much software each year then you *really* need to get the school to stop and think about what is going on with their choices. 2
GrumbleDook Posted November 30, 2017 Posted November 30, 2017 Following this thread with interest. I've just been informed one of our Assistant Heads will be "in charge" - seeking clarification on what that means - if it's that they are going to be the "DPO" - if I don't believe they have the necessary in terms of “expert knowledge of data protection law and practices.” - what do I gain by challenging their appointment? Remembering that there are no accredited courses yet ... However there are some really good courses and schools, like the rest of the country, need to balance the need to have someone support them against waiting and waiting for courses. This is where DPO as a service comes in, as a good service can give you access to a range of folk who *really* know there stuff and have been doing it across a range of sectors ... folk who been doing information management, infosec, public sector governance, privacy, etc. for 10+ years each! I can share more that in the next week or so, if people are interested. 1
ronnoco Posted November 30, 2017 Posted November 30, 2017 (edited) @GrumbleDook - I completely understand what you are saying and based on what I have read, fully agree. You clearly really know your stuff and i'm sure you are right, the IT manager can't be the DPO. You can however see the problems that many schools are going to be up against if they go with their findings on a course. Some of these people on the course will have walked away with a summary of: 1.) It was a course provided by our LEA 2.) The staff were qualified Solicitors who work for the LEA advising on all legal matters 3.) They haven't said the NM or BM can't do the role, they say further guidance is needed/it's a grey area. 4.) The PowerPoint explained the roles, i.e. Governors are the Controllers/Owners - it didn't say the school. I'm doing my own research and thankfully, know to come to places like this....many wont! I could answer your question about new systems but we'd be here all day - completely new SLT, changes galore that unfortunately are mostly beyond my control. I'm sure others have been there. Edited November 30, 2017 by ronnoco 1
forkies Posted November 30, 2017 Posted November 30, 2017 I would suggest you have a look at the sticky threads and have a read through some of the resources that have been linked to on there. I would also suggest that you put aside any idea of you being DPO, no matter what your experience. There will be a conflict. I have yet to see any scenario in a school where the IT Manager could be the DPO for that school without there being a conflict. It has been widely discussed in other threads too ... please, don’t go down that route. The school is the Data Controller. The Governor Body, as the strategic body of the school, has a responsibility but it is the school, as a legal entity, that is the Data Controller and holds the liabilities ... unless you are in a MAT, in which case (in general) the MAT is the legal entity and becomes the data Controller for all their schools (there are a few exceptions). The DPO is not going to do all the work. They are the oversight person ... The school should do the same as it does for H&S, teach people about risk assessment and then making decisions based on predefined boundaries, keeping the DPO in the loop. When looking at new software or systems there are common things you can ask ranging from “do you have a data sharing agreement?” to “do you conform to and are accredited for any recognised standards?” The DPO would review your assessment and make suggestions on risk mitigation, but they do not have to do every item of work! Also, if you are changing that much software each year then you *really* need to get the school to stop and think about what is going on with their choices. Just to clarify, could an IT manager be the Data Protection Lead (liable) but not the DPO (not liable) from what I understand?
enjay Posted December 1, 2017 Posted December 1, 2017 There is a saying in the army... “I’m sorry Sir/Ma’am, you seem to be confusing *your* rank with *my* authority!” You don’t have to be SLT, but simply be senior enough to report into the Head and Governors. Our Librarian reports directly to HT - maybe we do have an internal person who could be DPO. Ah, hang on - she selected the library system, so no!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now