Jump to content

Recommended Posts

Posted

I've been searching for a Data Audit Template, to see what is 'best practice' for auditing what data we hold in school, how we got it, keep it, update it, dispose of it etc, in readiness for GDPR.

 

I see lots of mention of Data Audits but no examples of what they should look like in practice.

 

I appreciate they will vary across different industries, and some companies are probably busy developing online systems to record this information, but I'm sure many schools are currently wondering how they can best perform this task.

 

So, attached is my initial version, based on the various bits of information I have found.

 

I would welcome your views on its effectiveness as a GDPR Data Audit tool, it's accuracy in terms of the guidance/definitions used, and it's balance in terms practical usability-versus-requirements.

 

Information Audit draft v1.xlsx

 

Thank you

  • Thanks 1
Posted

Do you really delete your staff from SIMS after 6 years? Doesn't that really upset SIMS?

 

Being pedantic, but I'm not sure if "SIMS" is a valid data source for the information you're sharing with Show My Homework. I think you'd be better saying where you got the data itself from, i.e. the data source when you put it in SIMS.

Posted
I would welcome your views on its effectiveness as a GDPR Data Audit tool, it's accuracy in terms of the guidance/definitions used, and it's balance in terms practical usability-versus-requirements.

I think it is a good start but I think we will need to get down to field level in some instances. If aggregating into collections, I'd look at people entities - Staff, Students, Parents, Contacts, Members of the Public and then start to break down into functional chunks like Contact Data (Addresses, emails, telephones). There is an issue that the same data might be processed in a number of different ways, requiring different basis - for example you will process contact information to send reports which might be "legal compliance", but if you also send out invitations to events then that is just marketing and will need to be done with consent.

Posted
but if you also send out invitations to events then that is just marketing and will need to be done with consent.

Unless you could argue "public interest" as we're saving money by emailing not posting information. I accept that might be thin ice, though.

Posted

Although I've seen mention that it's good to start with the 'Who', I was working in the theory that if carrying out an audit 'from scratch' it would be easiest to start with thinking 'where do we hold/store personal data?'

 

Being pedantic, but I'm not sure if "SIMS" is a valid data source for the information you're sharing with Show My Homework. I think you'd be better saying where you got the data itself from, i.e. the data source when you put it in SIMS.

 

For this I wanted to show where the data flowed from (and in this case automatically synced with SIMS). Although not the original data source, if we put 'individual' here that wouldn't reflect the route.

 

There is an issue that the same data might be processed in a number of different ways, requiring different basis

I agree this could be an issue. Just taking SIMS (or whatever MIS is used), the data held could be used for a number of purposes (educational, promotional etc) ... but I'm not sure how best to show this, without duplicating loads of data and making it extremely complicated.

Posted
Unless you could argue "public interest" as we're saving money by emailing not posting information. I accept that might be thin ice, though.

AIUI A "Public Interest" as it relates to GDPR will need to be backed by law, i.e. your bring and buy sale or other event is somehow enacted in EU or UK legislation.

Posted
I agree this could be an issue. Just taking SIMS (or whatever MIS is used), the data held could be used for a number of purposes (educational, promotional etc) ... but I'm not sure how best to show this, without duplicating loads of data and making it extremely complicated.

 

Plus of course the data in SIMS comes from a variety of sources, so you might be passing on information from SIMS which has different original sources. Our seating planner product, for example, includes name (from the parent/CTF), form group, current and target grades (internally assigned), then SEN status, EAL, FSM-eligibility, PP status, CATs score and Fischer Family Trust estimated grade (all from different third parties). Recording that in our audit document is going to a challenge!

 

Plus you then get the information field which is provided from multiple sources or where the source is genuinely unknown, e.g. which personal details came in on the CTF and which were entered in-house?

Posted
AIUI A "Public Interest" as it relates to GDPR will need to be backed by law, i.e. your bring and buy sale or other event is somehow enacted in EU or UK legislation.

 

I think you misunderstand. I'm not suggesting the event we're advertising is in public interest (although your examples of fundraisers would be, of course), I am suggesting our use of email rather than post to advertise the event is in the public interest.

Posted
I think you misunderstand. I'm not suggesting the event we're advertising is in public interest (although your examples of fundraisers would be, of course), I am suggesting our use of email rather than post to advertise the event is in the public interest.

I sort of of understood that - but it is wrong.

 

The reason you are processing their data is to communicate about a (say) fund-raising event. That processing and the fairness of it does not change just because you communicate via email, rather than letter. You can't say the processing becomes fair because the cost goes down (or even if it went to zero). What processing costs you does not impact the rights of the data subject and there is no basis to claim that such processing could be justified by claiming "public interest".

Posted
Okay, I see your point. We have a problem then, as our messaging system doesn't allow us to record who has opted in or out of marketing communication...
  • 1 month later...
Posted

Just touching back on the original point does anyone else have any other examples of how they are collating their information audits? I am about to start one for out ICT systems and looking for best practice on how to organise it and what information that needs to be collected.

 

Thanks

Posted
Just touching back on the original point does anyone else have any other examples of how they are collating their information audits? I am about to start one for out ICT systems and looking for best practice on how to organise it and what information that needs to be collected.

 

Thanks

 

Some templates were discussed / shared here http://www.edugeek.net/forums/data-protection-information-handling/184433-gdpr-data-audit-3.html

  • Thanks 2
Posted

LGfL published their template @ https://www.lgfl.net/ct?name=Online%20Safety%20Resource&url=http://static.lgfl.net/LgflNet/downloads/online-safety/LGfL-GDPR-Data-Audit-Log-10-2017.xlsx&source=Online%20Safety%20Section

 

They've also filled in some data that schools might store e.g. Staff personal file until Termination of employment + 6 years as an example. I know there lawyers + ICO office was having a dialogue, so whilst only examples, I'm equally assuming that either a lawyer or the ICO believe that might be good example data.

  • Thanks 1
Posted

 

I note it just says "pupil records" as a line item - can we be that vague? I'd been assuming we'd need to give a bit more detail about that, e.g. name, DoB, address, contact details. "Pupil records" could be anything.

Posted
I note it just says "pupil records" as a line item - can we be that vague? I'd been assuming we'd need to give a bit more detail about that, e.g. name, DoB, address, contact details. "Pupil records" could be anything.

Yeah I am wondering this too. I have seen a few templates that are this broad but I would have thought we needed more detail?

Posted
I think we have to. If someone asked us "what type of data do you hold on me?" (but didn't go for a full SAR), I can't imagine them being satisfied with "we hold records" as an answer!
Posted

Whilst you say they only say "pupil records" - to be fair, they also list out other information under the "Pupil data (within MIS)" category:

 

Pupil records

Safeguarding / Child Protection data

SEN

EAL

Exclusion, behaviour

Reports

Examination results / Statutory Assessments

Attendance registers

Student photos

 

Hopefully one of the others who have been getting legal advice can speak up here - but i'd hope the purpose here is to identify the general theme of the data e.g. pupil records / SEN - as opposed to listing out thousands of individual fields. Whilst "pupil records" is particularly vague, I'd like to hope that "Pupil Records: Basic details of the pupil e.g. name, address and parental information". The sentence that I've written there is quite similar to what the DfE have put in their updated privacy notice at https://www.gov.uk/government/publications/data-protection-and-privacy-privacy-notices

  • Thanks 2
  • 3 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...