Jump to content

Recommended Posts

Posted

Does anyone know if it is ok to be the DPO for a partner school in a MAT. For instance, could the business manager/network manager/SLT of one school be the DPO for a partner school and vice versa?

 

Thanks

Posted

A question I have open at the moment. As the MAT is the legal entity, there are scenarios where centralised decisions have been taken in such a way that the consultation on those decisions may affect what the school judges to be any conflict.

 

The oficial ICO position is that it is down to each school or business to assess, but they need to make sure that they truly do assess it and not try to make a decision and backwardsly justify it.

 

I have provided a few scenarios to be considered and a sticking point looks to be knowledge and understanding of the regulation / law.

  • Thanks 1
Posted
I have provided a few scenarios to be considered and a sticking point looks to be knowledge and understanding of the regulation / law.

 

How should this be assessed though? I mean, I keep my hand in with DP law (and now the implications of the GDPR) because I need to for the job (IT, CCTV, SIMS herding), but there's nothing on paper beyond maybe some appraisal documentation and a few completed online courses.

 

When we and other local schools have had people do/go to GDPR / Data Protection courses the feedback has always been "I already knew that" or "it's too simple" or (looking at you Capita) "terribly misleading".

Posted

Part of the problem is the lack of accreditation. At the moment you have GDPR-P and CIPP/E as the core two most folk would get. Not cheap and the quality of GDPR-P appears to vary.

 

We tend to make sure anyone we work with have a number of years under their belt within the DP/Privacy arena ...

 

It is going to be tough and hopefully the next month will open things up a bit more on the direction things are going.

Posted
Does anyone know if it is ok to be the DPO for a partner school in a MAT. For instance, could the business manager/network manager/SLT of one school be the DPO for a partner school and vice versa?

 

Thanks

 

Yes. As long as you are not needing to investigate your self, not the controller of the data you would be the DPO responsible for - no conflict of interest. Assuming the schools have separate data systems. Potentially even if they merge - you could be the DPO if every data controller responsibility/decision you had normally was 'duck shoved' else where.

 

Luckily enough we know some one who is the GDPR person for our LEA and he really made simple sense of a few things we was unsure of. It was a good listen, he explained that if I was the DPO or even my LM (SBM leadership) - we could 'duck shove' those data controller responsibilities on to each other allowing one of us to be the DPO.

 

As long as you don't have a conflict of interest where you would be investigating your self - it's fine. Hopefully the above makes sense my wording may not be perfect.

 

Guessing we've had no confirmation if a school must employ a DPO yet?

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...