Jump to content

Recommended Posts

Posted

Hi All,

 

Hoping you can all help, i have flagged the upcoming changes with my SLT team. However things are going a little too slow for my liking.

 

So i want to make sure our team in the IT Support dept has done everything we can.

 

Is anyone able to give some advise on what we should be doing.

  • Thanks 1
Posted
What you "should" be doing is absolutely nothing, you should be being led by your DPO. However, morally speaking it obviously helps us all to be vigilant and start thinking about where data is going a little more. Ask the questions to new suppliers "Are you compliant with the GDPR regulations, what are you doing with our data and why?" and perhaps use the interim time to audit your software and services so when/if the DPO starts asking questions, you have answers.
  • Thanks 2
Posted

You are going to be considered a 'systems owner' for want of a better phrase ... it means that you have a range of systems / solutions / products that are under your general control. You are going to be asked what data you collect, process, etc. You will be asked where do you get it from, where do you store it, for how long. You will even be asked why you have the data and what is is it used for.

 

As @synaesthesia says, use the time now to start thinking about these questions.

  • Thanks 2
Posted (edited)

There's a lot that needs doing and to be aware of, but the organisational changes should really be down to management and your DPO.

 

In terms of the IT Dept though, I would say you need to be looking at the following:

- System security: the level of "reasonably expected security measures" is likely to be raised, so check up on passwords, screen locking, etc

- Data transfer: as with the above, reasonable security expectation on transfer of data is likely to increase, so look at encrypting USB sticks and secure file transfer

- Data sharing: who you share data with, what data do you share, and is there an agreement in place covering this

- Equipment disposal: if you use a third party to wipe data on disposed equipment, they are now considered a data processor, and you will need a signed agreement with them

- Student photos: if you routinely use photos on your website etc, be aware parents need to give specific consent, not assumed. Over the age of 13 you may need the student's consent directly.

- Privacy notice: you will need to create and share this with the school community, explaining what you do with their data, including listing what data you share with which third parties (listed by name).

Edited by DavR
  • Thanks 2
Posted

- Privacy notice: you will need to create and share this with the school community, explaining what you do with their data, including listing what data you share with which third parties (listed by name).

 

The DPO should be doing this... you can help by preparing the list of what is shared

  • Thanks 2
Posted
The DPO should be doing this... you can help by preparing the list of what is shared

 

Fair point, but yes, you would be feeding into it, and presumably displaying it on your website somewhere.

  • Thanks 1
Posted

Do you know where your data resides? Think of any cloud and hosted services if you get asked the question.

 

Best summary I saw the other day was about being aware of your situation; what people have access to which type of data and where is it stored? Ultimately responsibility does rest with the DPO but that's no excuse to not be engaged with the legislation and actively trying to help improve processes etc.

Posted

All of the above is relevant - the list of things you could/should be doing, but also the fact it is ultimately the DPO's responsibility (remember GDPR isn't just digital data, every sheet of paper is also subject to the GDPR (just as it is to the DPA...)) so my advice would be not to do much without direction from HT/SLT/DPO. If you think they're moving too slowly, have a discussion with them in which you highlight how much you think needs doing and why you're worrying about it over 6 months ahead of implementation, then present the list of things you think your team could start on to support the DPO in their role.

 

Also, your HT/SLT need to be aware what you're doing, so when they do appoint a DPO, they don't task people with doing what you've already done.

 

You can't be the DPO, and if your school doesn't have one on 28th May 2018, your school will not be GDPR-compliant, regardless of how much work the IT Manager has done.

Posted
How many schools have already appointed a DPO or have restructured their staffing to allow for one? Wouldn't it be in our interests to have this role lie within the LEA / MAT and for this person to audit our procedures and advise on what we need to do as a school to become compliant? Obviously we as techies would need to feed into this process, but as previously stated we cannot be the DPO as we are data controllers. Furthermore, we don't have the money to employ someone with specialist knowledge.
Posted
We are about to advertise a job for this role. It is a very short amount of time to get up to speed before the GDPR comes into force so I don’t envy the person that gets the job.
Posted
We are about to advertise a job for this role. It is a very short amount of time to get up to speed before the GDPR comes into force so I don’t envy the person that gets the job.

 

What level of remuneration is deemed applicable for such a role with the potential responsibilities as DPO, any thoughts.

Posted
What level of remuneration is deemed applicable for such a role with the potential responsibilities as DPO, any thoughts.

 

My thoughts are that it would be roughly equivalent to the Designated SafeGuarding Lead (DSL) or Health and Safety Officer.

Posted
My thoughts are that it would be roughly equivalent to the Designated SafeGuarding Lead (DSL) or Health and Safety Officer.

I think the role is more far reaching than the two you mention above. Someone taking on this level of responsibility will want to be well rewarded.

Posted
Yes it is more far reaching, but the consequences to the school in terms of fines/ damaged reputation if things go awry are pretty equal. The level of seniority required for negotiating/directing staff is also similar. I don't think that a job evaluation would put a DPO over H+S or safeguarding lead. Just my opinion.
Posted
You can't be the DPO, and if your school doesn't have one on 28th May 2018, your school will not be GDPR-compliant, regardless of how much work the IT Manager has done.

We were told by our LEA that the ICO have still not confirmed that school's legally require a DPO. There was also a bit of scare mongering by them and the offer of a 'DPO service'! They also said that no one in school could be the DPO as it would be a conflict of interest but I couldn't find that on the ICO website either...

Posted
I don't think that a job evaluation would put a DPO over H+S or safeguarding lead. Just my opinion.

 

But in 90% of schools those two roles are SLT (Assistant Head or Business Manager level) are they not? I don't know what kind of money you guys are on but that isn't a similar salary to IT Managers in Wales.

Posted
But in 90% of schools those two roles are SLT (Assistant Head or Business Manager level) are they not? I don't know what kind of money you guys are on but that isn't a similar salary to IT Managers in Wales.

Without any doubt this is a SLT position, it's not something a network manager should or could do.

Posted
They also said that no one in school could be the DPO as it would be a conflict of interest but I couldn't find that on the ICO website either...

 

They're possibly right, although you won't see it spelled out quite so clearly. The DPO needs to be very senior within the organisation (I've seen statements like "must answer directly to the board of directors" which in a school context presumably means SLT) but not have decision-making or policy-making responsibilities for any data processing. So, what that seems to mean is they must be senior but without operational responsibility! Maybe some large corporations have people who are suitably removed from the coal-face but schools don't.

Posted
They're possibly right, although you won't see it spelled out quite so clearly. The DPO needs to be very senior within the organisation (I've seen statements like "must answer directly to the board of directors" which in a school context presumably means SLT) but not have decision-making or policy-making responsibilities for any data processing. So, what that seems to mean is they must be senior but without operational responsibility! Maybe some large corporations have people who are suitably removed from the coal-face but schools don't.

 

It looks that way to me. A reason why it can not be given to teachers is that it is a permanent "admin" role thus would fall foul of their workload agreement / unions?

Posted (edited)
We were told by our LEA that the ICO have still not confirmed that school's legally require a DPO. There was also a bit of scare mongering by them and the offer of a 'DPO service'! They also said that no one in school could be the DPO as it would be a conflict of interest but I couldn't find that on the ICO website either...

 

The ICO have clear guidance on DPO under GDPR, however the DP Bill there are areas that differ slightly (actually it is a bit harsher as it doesn't mention *any* exceptions yet), but they will (understandably) be coming from the problems of schools finding someone who has no conflict of interests. It will be extremely difficult for someone within a school to take on the role but keep an eye out on the ICO site and info from the DP bill.

 

We will share information as we have it as well.

Edited by GrumbleDook
Posted
It will be extremely difficult for someone within a school to take on the role but keep an eye out on the ICO site and info from the DP bill.

 

True, but it will also be extremely difficult for someone outside the school to fully understand what is actually happening on the ground and be able to spot bad practice. A teacher could easily go and sign up for some new service and create user accounts for all the students. Someone within the school (IT Mgr or academic DH, for example) would probably know about this, but I'm not convinced someone in an office in London who provides 2 hours a week DPO service would find out about it.

 

I'm coming round to the idea no-one can adequately do the job!

Posted
True, but it will also be extremely difficult for someone outside the school to fully understand what is actually happening on the ground and be able to spot bad practice. A teacher could easily go and sign up for some new service and create user accounts for all the students. Someone within the school (IT Mgr or academic DH, for example) would probably know about this, but I'm not convinced someone in an office in London who provides 2 hours a week DPO service would find out about it.

 

I'm coming round to the idea no-one can adequately do the job!

 

A drama teacher can go online and order Conc. Hydrochloric acid as they clean some paint off props.

A science teacher can go and order a batch of knock off bunch of lab coats that are found to be full of nylons.

A site supervisor can order a batch of chairs that couldn't take the weight of a pregnant gnat.

 

Yet it is not that case of someone watching over them 24/7 that stops this, but training, policies and making people think before doing.

 

In the same way H&S advisors may cover a range of areas, they will know schools and their risks.

 

The balance will be getting someone with sufficient education understanding, but will not allow that to be an excuse to cut corners and be non-compliant.

  • Thanks 1
Posted (edited)

If we are to recruit a DPO we need to start now. Taking applications, interviews, notice periods etc we would be hard pushed to get anyone employed before February 2018 which is not leaving much time left for meeting the needs of GDPR and that person getting up to speed with internal systems, paperwork, policies etc.

 

We need more guidance of whether or not we need a DPO.

Edited by MrWrighty
Posted
The ICO have clear guidance on DPO under GDPR, however the DP Bill there are areas that differ slightly (actually it is a bit harsher as it doesn't mention *any* exceptions yet), but they will (understandably) be coming from the problems of schools finding someone who has no conflict of interests. It will be extremely difficult for someone within a school to take on the role but keep an eye out on the ICO site and info from the DP bill.

 

We will share information as we have it as well.

 

This is the law that came into effect 1.5 years ago that they have nothing finished for?

Posted
Yet it is not that case of someone watching over them 24/7 that stops this, but training, policies and making people think before doing.

 

True, but the difference is we are allowed to appoint someone who can provide that training and write those policies, and get that person to oversee the H&S around the school and speak to staff involved if they see evidence of people not thinking before doing. Not so under the GDPR, where we're told the people best placed to shape data handling practices, train staff and spot the Bad Things cannot have that responsibility.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...