dastrix Posted October 10, 2017 Posted October 10, 2017 Hi All, Hoping you can all help, i have flagged the upcoming changes with my SLT team. However things are going a little too slow for my liking. So i want to make sure our team in the IT Support dept has done everything we can. Is anyone able to give some advise on what we should be doing. 1
synaesthesia Posted October 10, 2017 Posted October 10, 2017 What you "should" be doing is absolutely nothing, you should be being led by your DPO. However, morally speaking it obviously helps us all to be vigilant and start thinking about where data is going a little more. Ask the questions to new suppliers "Are you compliant with the GDPR regulations, what are you doing with our data and why?" and perhaps use the interim time to audit your software and services so when/if the DPO starts asking questions, you have answers. 2
GrumbleDook Posted October 10, 2017 Posted October 10, 2017 You are going to be considered a 'systems owner' for want of a better phrase ... it means that you have a range of systems / solutions / products that are under your general control. You are going to be asked what data you collect, process, etc. You will be asked where do you get it from, where do you store it, for how long. You will even be asked why you have the data and what is is it used for. As @synaesthesia says, use the time now to start thinking about these questions. 2
DavR Posted October 10, 2017 Posted October 10, 2017 (edited) There's a lot that needs doing and to be aware of, but the organisational changes should really be down to management and your DPO. In terms of the IT Dept though, I would say you need to be looking at the following: - System security: the level of "reasonably expected security measures" is likely to be raised, so check up on passwords, screen locking, etc - Data transfer: as with the above, reasonable security expectation on transfer of data is likely to increase, so look at encrypting USB sticks and secure file transfer - Data sharing: who you share data with, what data do you share, and is there an agreement in place covering this - Equipment disposal: if you use a third party to wipe data on disposed equipment, they are now considered a data processor, and you will need a signed agreement with them - Student photos: if you routinely use photos on your website etc, be aware parents need to give specific consent, not assumed. Over the age of 13 you may need the student's consent directly. - Privacy notice: you will need to create and share this with the school community, explaining what you do with their data, including listing what data you share with which third parties (listed by name). Edited October 10, 2017 by DavR 2
elsiegee40 Posted October 10, 2017 Posted October 10, 2017 - Privacy notice: you will need to create and share this with the school community, explaining what you do with their data, including listing what data you share with which third parties (listed by name). The DPO should be doing this... you can help by preparing the list of what is shared 2
DavR Posted October 10, 2017 Posted October 10, 2017 The DPO should be doing this... you can help by preparing the list of what is shared Fair point, but yes, you would be feeding into it, and presumably displaying it on your website somewhere. 1
gshaw Posted October 10, 2017 Posted October 10, 2017 Do you know where your data resides? Think of any cloud and hosted services if you get asked the question. Best summary I saw the other day was about being aware of your situation; what people have access to which type of data and where is it stored? Ultimately responsibility does rest with the DPO but that's no excuse to not be engaged with the legislation and actively trying to help improve processes etc.
enjay Posted October 11, 2017 Posted October 11, 2017 All of the above is relevant - the list of things you could/should be doing, but also the fact it is ultimately the DPO's responsibility (remember GDPR isn't just digital data, every sheet of paper is also subject to the GDPR (just as it is to the DPA...)) so my advice would be not to do much without direction from HT/SLT/DPO. If you think they're moving too slowly, have a discussion with them in which you highlight how much you think needs doing and why you're worrying about it over 6 months ahead of implementation, then present the list of things you think your team could start on to support the DPO in their role. Also, your HT/SLT need to be aware what you're doing, so when they do appoint a DPO, they don't task people with doing what you've already done. You can't be the DPO, and if your school doesn't have one on 28th May 2018, your school will not be GDPR-compliant, regardless of how much work the IT Manager has done.
ITBadger Posted October 11, 2017 Posted October 11, 2017 How many schools have already appointed a DPO or have restructured their staffing to allow for one? Wouldn't it be in our interests to have this role lie within the LEA / MAT and for this person to audit our procedures and advise on what we need to do as a school to become compliant? Obviously we as techies would need to feed into this process, but as previously stated we cannot be the DPO as we are data controllers. Furthermore, we don't have the money to employ someone with specialist knowledge.
MatZeRO Posted October 11, 2017 Posted October 11, 2017 We are about to advertise a job for this role. It is a very short amount of time to get up to speed before the GDPR comes into force so I don’t envy the person that gets the job.
MrWrighty Posted October 19, 2017 Posted October 19, 2017 We are about to advertise a job for this role. It is a very short amount of time to get up to speed before the GDPR comes into force so I don’t envy the person that gets the job. What level of remuneration is deemed applicable for such a role with the potential responsibilities as DPO, any thoughts.
mjk Posted October 19, 2017 Posted October 19, 2017 What level of remuneration is deemed applicable for such a role with the potential responsibilities as DPO, any thoughts. My thoughts are that it would be roughly equivalent to the Designated SafeGuarding Lead (DSL) or Health and Safety Officer.
MrWrighty Posted October 19, 2017 Posted October 19, 2017 My thoughts are that it would be roughly equivalent to the Designated SafeGuarding Lead (DSL) or Health and Safety Officer. I think the role is more far reaching than the two you mention above. Someone taking on this level of responsibility will want to be well rewarded.
mjk Posted October 19, 2017 Posted October 19, 2017 Yes it is more far reaching, but the consequences to the school in terms of fines/ damaged reputation if things go awry are pretty equal. The level of seniority required for negotiating/directing staff is also similar. I don't think that a job evaluation would put a DPO over H+S or safeguarding lead. Just my opinion.
TMBS Posted October 19, 2017 Posted October 19, 2017 You can't be the DPO, and if your school doesn't have one on 28th May 2018, your school will not be GDPR-compliant, regardless of how much work the IT Manager has done. We were told by our LEA that the ICO have still not confirmed that school's legally require a DPO. There was also a bit of scare mongering by them and the offer of a 'DPO service'! They also said that no one in school could be the DPO as it would be a conflict of interest but I couldn't find that on the ICO website either...
PotNoodleTech Posted October 19, 2017 Posted October 19, 2017 I don't think that a job evaluation would put a DPO over H+S or safeguarding lead. Just my opinion. But in 90% of schools those two roles are SLT (Assistant Head or Business Manager level) are they not? I don't know what kind of money you guys are on but that isn't a similar salary to IT Managers in Wales.
mjk Posted October 19, 2017 Posted October 19, 2017 But in 90% of schools those two roles are SLT (Assistant Head or Business Manager level) are they not? I don't know what kind of money you guys are on but that isn't a similar salary to IT Managers in Wales. Without any doubt this is a SLT position, it's not something a network manager should or could do.
enjay Posted October 19, 2017 Posted October 19, 2017 They also said that no one in school could be the DPO as it would be a conflict of interest but I couldn't find that on the ICO website either... They're possibly right, although you won't see it spelled out quite so clearly. The DPO needs to be very senior within the organisation (I've seen statements like "must answer directly to the board of directors" which in a school context presumably means SLT) but not have decision-making or policy-making responsibilities for any data processing. So, what that seems to mean is they must be senior but without operational responsibility! Maybe some large corporations have people who are suitably removed from the coal-face but schools don't.
PotNoodleTech Posted October 19, 2017 Posted October 19, 2017 They're possibly right, although you won't see it spelled out quite so clearly. The DPO needs to be very senior within the organisation (I've seen statements like "must answer directly to the board of directors" which in a school context presumably means SLT) but not have decision-making or policy-making responsibilities for any data processing. So, what that seems to mean is they must be senior but without operational responsibility! Maybe some large corporations have people who are suitably removed from the coal-face but schools don't. It looks that way to me. A reason why it can not be given to teachers is that it is a permanent "admin" role thus would fall foul of their workload agreement / unions?
GrumbleDook Posted October 19, 2017 Posted October 19, 2017 (edited) We were told by our LEA that the ICO have still not confirmed that school's legally require a DPO. There was also a bit of scare mongering by them and the offer of a 'DPO service'! They also said that no one in school could be the DPO as it would be a conflict of interest but I couldn't find that on the ICO website either... The ICO have clear guidance on DPO under GDPR, however the DP Bill there are areas that differ slightly (actually it is a bit harsher as it doesn't mention *any* exceptions yet), but they will (understandably) be coming from the problems of schools finding someone who has no conflict of interests. It will be extremely difficult for someone within a school to take on the role but keep an eye out on the ICO site and info from the DP bill. We will share information as we have it as well. Edited October 19, 2017 by GrumbleDook
enjay Posted October 19, 2017 Posted October 19, 2017 It will be extremely difficult for someone within a school to take on the role but keep an eye out on the ICO site and info from the DP bill. True, but it will also be extremely difficult for someone outside the school to fully understand what is actually happening on the ground and be able to spot bad practice. A teacher could easily go and sign up for some new service and create user accounts for all the students. Someone within the school (IT Mgr or academic DH, for example) would probably know about this, but I'm not convinced someone in an office in London who provides 2 hours a week DPO service would find out about it. I'm coming round to the idea no-one can adequately do the job!
GrumbleDook Posted October 19, 2017 Posted October 19, 2017 True, but it will also be extremely difficult for someone outside the school to fully understand what is actually happening on the ground and be able to spot bad practice. A teacher could easily go and sign up for some new service and create user accounts for all the students. Someone within the school (IT Mgr or academic DH, for example) would probably know about this, but I'm not convinced someone in an office in London who provides 2 hours a week DPO service would find out about it. I'm coming round to the idea no-one can adequately do the job! A drama teacher can go online and order Conc. Hydrochloric acid as they clean some paint off props. A science teacher can go and order a batch of knock off bunch of lab coats that are found to be full of nylons. A site supervisor can order a batch of chairs that couldn't take the weight of a pregnant gnat. Yet it is not that case of someone watching over them 24/7 that stops this, but training, policies and making people think before doing. In the same way H&S advisors may cover a range of areas, they will know schools and their risks. The balance will be getting someone with sufficient education understanding, but will not allow that to be an excuse to cut corners and be non-compliant. 1
MrWrighty Posted October 19, 2017 Posted October 19, 2017 (edited) If we are to recruit a DPO we need to start now. Taking applications, interviews, notice periods etc we would be hard pushed to get anyone employed before February 2018 which is not leaving much time left for meeting the needs of GDPR and that person getting up to speed with internal systems, paperwork, policies etc. We need more guidance of whether or not we need a DPO. Edited October 19, 2017 by MrWrighty
mavhc Posted October 19, 2017 Posted October 19, 2017 The ICO have clear guidance on DPO under GDPR, however the DP Bill there are areas that differ slightly (actually it is a bit harsher as it doesn't mention *any* exceptions yet), but they will (understandably) be coming from the problems of schools finding someone who has no conflict of interests. It will be extremely difficult for someone within a school to take on the role but keep an eye out on the ICO site and info from the DP bill. We will share information as we have it as well. This is the law that came into effect 1.5 years ago that they have nothing finished for?
enjay Posted October 19, 2017 Posted October 19, 2017 Yet it is not that case of someone watching over them 24/7 that stops this, but training, policies and making people think before doing. True, but the difference is we are allowed to appoint someone who can provide that training and write those policies, and get that person to oversee the H&S around the school and speak to staff involved if they see evidence of people not thinking before doing. Not so under the GDPR, where we're told the people best placed to shape data handling practices, train staff and spot the Bad Things cannot have that responsibility.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now