Jump to content

Recommended Posts

Posted
True, but the difference is we are allowed to appoint someone who can provide that training and write those policies, and get that person to oversee the H&S around the school and speak to staff involved if they see evidence of people not thinking before doing. Not so under the GDPR, where we're told the people best placed to shape data handling practices, train staff and spot the Bad Things cannot have that responsibility.

 

*EVERYONE* is responsible for data protection.

 

But, for understandable reasons, areas that need auditing are not signed off by the people that did the original work. The MIS Manager will tell people this is specifically the functions that you need to look at around data protection (special categories, for example), *you* may tell people how to handle virus alerts ....

 

The DPO is not Gandalf confronting the Data Breach Balrog on the bridge of Khazad-we'realldûm, shouting, "I am a servant of the Secret CABAL, wielder of the flame of GDPR. You cannot pass! The dark fire will not avail you, inconsiderate user of USBdûn!"

 

If a DPO was not a thing, what would you be doing now as a System Owner?

Posted
*EVERYONE* is responsible for data protection.

 

I never said otherwise. When I used the word "responsibility", I was referring to the responsibility for writing policy and delivering training, not the responsibility for data protection.

 

What I don't see is why we can't have someone on staff and on site who writes policy, oversees process and makes the big decisions, and then have someone external come in to audit that. Exactly as we do with finance. Or even Ofsted, if you will.

Posted
I never said otherwise. When I used the word "responsibility", I was referring to the responsibility for writing policy and delivering training, not the responsibility for data protection.

 

What I don't see is why we can't have someone on staff and on site who writes policy, oversees process and makes the big decisions, and then have someone external come in to audit that. Exactly as we do with finance. Or even Ofsted, if you will.

 

Policy is written by everyone but with the advice / direction of the DPO, and then agreed by Governors / trustees.

 

Processes are based on these policies and give the framework for any decisions (it has to for consistency) and the general decisions are verified by the DPO. Decisions will be based on the outcomes of Data Protection Impact Assessments, and as part of the school's general risk assessment process, will be dealt with accordingly ... so most things will carry on as normal.

 

The best advice I can give at the moment (and this is me, personally and based on if I was back in school with little or no info about what is to come next) is to look at what you are doing at the moment, check you have processes and policies in place for what you are doing already, see who makes decisions on things, see if it fits in with risk management. Check the list of suppliers you have and give them a nudge (or ask someone to give them a nudge). Bookmark the relevant websites and set up calendar alerts to go and check on a regular basis for any updates. Look at the 12 steps, look at the readiness tools, look at the timeline infographic we just put up ... do the bits you can get on with and note the bits you can't.

 

When a DPO comes in, whoever they are, they will thank you for starting this and then play catch up. If an excemption is granted, or some other solution is put in place, then you have already started doing what is needed anyway so the efforts will not be in vain.

Posted
The best advice I can give at the moment (and this is me, personally and based on if I was back in school with little or no info about what is to come next) is to look at what you are doing at the moment, check you have processes and policies in place for what you are doing already, see who makes decisions on things, see if it fits in with risk management. Check the list of suppliers you have and give them a nudge (or ask someone to give them a nudge). Bookmark the relevant websites and set up calendar alerts to go and check on a regular basis for any updates. Look at the 12 steps, look at the readiness tools, look at the timeline infographic we just put up ... do the bits you can get on with and note the bits you can't.

 

Solid advice, and this is broadly what we've been doing. I've started DPIAs for the companies I'm involved with (although this is guesswork a bit, as I haven't found clear statements on exactly what I should be looking for - do we care where the data is held any more? Are sentences like "we take reasonable technical and operational measures to ensure privacy" sufficient, or should we ask them to expand upon or prove that?). We know the third parties with whom we're sharing data, we've started re-reviewing what we're actually sharing with them and why. Similar work is happening among my colleagues who are also heavily involved (finance, HR, etc.). We haven't started a data audit on everything in SIMS yet and the core operational data processing as we're hoping DfE or others will come up with something on that for us.

  • Thanks 1
Posted (edited)
I never said otherwise. When I used the word "responsibility", I was referring to the responsibility for writing policy and delivering training, not the responsibility for data protection.

What I don't see is why we can't have someone on staff and on site who writes policy, oversees process and makes the big decisions, and then have someone external come in to audit that. Exactly as we do with finance. Or even Ofsted, if you will.

As I understand it we can. The school staff can do every single little bit of work and the DPO can act as basically an audit/compliance officer with the power to say "go back and re-do this or that because it's not good enough" and in an advisory role where needed. The DPO isn't personally liable for breaches or anything like that, they are not ultimately responsible for anything legally, they are a safety measure against everyone else getting it wrong.

 

Edit - they are also a point of contact, but I've seen nothing in the rules that they can't delegate requests from data subjects to the relevant person within the organisation. For example DPOs won't be going into your systems at a technical level to perform records erasure (if appropriately asked for), that will be the Network Manager or other IT staff, the DPO will just ask for it to be done (and probably check afterwards that it's been done right).

Edited by crispybits
Posted

 

Yep, we raised it in this thread too.

Data Processing Agreement - What Is Required?

 

https://www.edugeek.net/showthread.php?t=189255

 

The consultation on it has closed now but we have been highlighting it to EdTech suppliers as much as we can.

 

https://www.besa.org.uk/insights/edtech-suppliers-need-engage-ico-schools/

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...