Jump to content

Recommended Posts

Posted

So - in my local area I have yet to see a school that is going to even be anywhere close fully complying with GPDR when it comes in to effect.

 

The reason I used the word "crisis" is because it appears we have no real strategic leadership in this matter from Government, Local Government, Local Education Quango, or Inter-Headteacher / Inter-SLT meets.

 

So where is the country wide leadership and guidance on what schools HAVE to implement over the next 8 months. Surely schools should be being told from high above "you have to hire a DPO, you have to do at the very minimum A, B, C" to even stand a chance of complying?

Posted

The problem is the leadership on this comes from ICO and DCMS.

They have to work out what needs to be done, get relevant Acts of Law in place and existing ones updated.

 

The relevant departments will work with DCMS to ensure that secondary legislation is updated and relevant guidance is put out *when they know what guidance to give*.

 

There is enough guidance out now to make a start.

 

Whilst I know many want to wait and be told what they need to do, that is not a helpful approach, for yourself or your school.

 

We’ll be putting together a timeline shortly with things you can crack on with whilst we all wait for other things.

 

Most of this *will* be things you should be doing already as a school and as IT Managers.

 

Think back to the earlier Becta materials and look at what you are doing for security, managing your infrastructure, auditing what data you have already ...

 

We all know that you will be asked about this by a DPO when they are appointed so don’t wait ... crack on with it.

 

Remember that the DPO is not going to do all the work, the system owners will do the bulk of it so that means you, the MIS manager, the SENCO, the DSL, the finance manager, the HR manager, etc.

 

Unions are starting to give more guidance to Leadership in schools, GroupCall and others are running awareness and training sessions.

 

Yes, there are still questions to be answered, but there are still lots to be getting on with.

  • Thanks 4
Posted (edited)

There is definitely a crisis looming, based on my experiences to date.

 

What I have seen over the last few years in schools is a million miles away from the requirements of the GDPR regime that comes into being in May: very poorly drafted privacy notices, implied consent/opt-in by default, little/no breach reporting, poor contracts with suppliers, no supplier due diligence, little understanding of who data is shared with externally, over-sharing of sensitive data (e.g. ethnicity).

 

Despite a 2 year run-up, most organisations I have dealt with, schools included, will not be ready to face the harsh reality of GDPR in May:

 

- co-liability between controllers & processors

- mandatory breach reporting

- fines for administrative breaches not just data loss

- consent must be explicit, freely given, auditable & informed i.e. no assumed consent

 

The big change that has been under-reported is the ability of data subjects to claim compensation for 'distress' following a GDPR breach - which can be administrative with no actual data loss and no actual harm for the data subject. This is the next PPI in my opinion.

 

Given that most schools send out privacy notices in September at the start of the school year, which has already passed, there is a lot of work to do prior to May in terms of consent from pupils/parents/guardians. There is no scope for opting in by default unlike at present.

 

In cases where 'personally identifiable information' (PII) is shared externally - such as extracts out of an MIS like SIMS - unless there is a legal requirement to do so, it seems likely that each and every pupil record that leaves the premises will require explicit consent. Any other basis for non-mandated PII data sharing brings the very real risk of a fine for both the controller and the processor, and opens the door for compensation claims from the data subject - in this case the pupils.

 

For a bit of perspective, consider the fact that JD Wetherspoons have binned their marketing database as the risk is too high to warrant using it come next May: Wetherspoons just deleted its entire customer email database ? on purpose | WIRED UK

 

Schools simply can't afford to run the risk of a fine under GDPR. My advice is quite simple - current data processing/sharing activities should only persist beyond May if legally required. Anything else runs the risk of a large fine, which schools can ill afford. Arguing 'public interest' or 'essential processing' is a very risky strategy in all but a few very specific cases. Externally provided whizzy analytics or MI will require explicit consent from every data subject. Good luck with that!

Edited by GeekyDad
  • Thanks 1
Posted

Sorry, but consent is only one legal reason for processing. If you have another reason to process and can justify it, then it is not risky.

 

Yes, we are asking for clarification on how far this goes, but consent is not going to be the default position.

 

Opt out being used instead of explicit opt in, where consent is needed, is a big no-no ... and it is shameful to see some schools still doing it that way.

 

The rhetoric on fines has now been brought into line as part of the ICO myth busting blogs, as has reporting everything ...

 

But all of the above has to go hand in hand with DPIAs, good audits and good record keeping.

 

It is also hard to say that we have had a 2 year run up ... we haven’t. But schools *should* have been working with good DP principles already anyway.

Posted
Schools simply can't afford to run the risk of a fine under GDPR. My advice is quite simple - current data processing/sharing activities should only persist beyond May if legally required. Anything else runs the risk of a large fine, which schools can ill afford. Arguing 'public interest' or 'essential processing' is a very risky strategy in all but a few very specific cases. Externally provided whizzy analytics or MI will require explicit consent from every data subject. Good luck with that!

I agree with a lot of what you say but the bit I've bolded is not obviously true. Being able to record assessment data and analyse that data is so fundamental to a school in the performance of their duty that I doubt it needs explicit consent other than the choice to come to the school or not. It will need to be notified and tracked which will be an unwelcome constraint in most schools.

  • Thanks 1
  • 4 weeks later...
Posted
How far would the GDPRiS cloud-based solution help us to get up and running with all this? Does it cover the whole spectrum of GDPR? Does it do anything that we couldn't easily do ourselves in school?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...