Jump to content

Recommended Posts

Posted

As i'm sure most of you are, i am looking heavily into the GDPR changes coming in May. I have been in contact with a member of the governing body about it too.

 

I was speaking to a colleague today about it, and they presumed it was something that would come under the "network manager" role. I explained that this is classed as a "conflict of interest" and so i would not be able to fullfill the role. However the colleague had a point which i had not examined.

 

Could the DPO be job shared between two colleagues. IE.. Can the network manager be the primary DPO, and someone else be a secondary DPO for the IT side of things...

 

I said it seemed a bit hodgey - podgy and typing it, is making me question my sanity in even asking.. but thought i would throw it to the forums and see what you think...

Posted (edited)

In my view, no. GDPR is a whole data problem, not something that can be divided neatly into computer and paper.

 

As the “primary” the buck will still stop with you and there is still a conflict of interest.

 

You are responsible for implementation of GDPR regulation. You cannot be responsible for its oversight on your site without conflict.

 

Does your Governing Board understand that GDPR is far from “just being am IT problem?”

 

You need to understand too that no governor can speak or make decisions for the GB; governors may not act alone. By all means talk to one, but their opinion may not be the view of the GB.

Edited by elsiegee40
Posted

Interesting question. I think one of you would need to be designated "lead DPO", so it is clear whose head is on the block should there be a problem. Also, if you were sharing DPO responsibility rather than the other person solely auditing the IT side, you'd need to know who out-ranks who should there be a difference of opinion between you both.

 

I think it is worth exploring further, personally.

Posted
Article 37(5) of the Regulation details what is in effect a mini job description for the role:

 

“The DPO, who can be a staff member or contractor, shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39.”

 

A staff member ..not two.

 

you have ONE named DPO. They can have advisers within the organisation, sure, but the DPO is a specific role akin to CIO, etc

  • Thanks 2
Posted
If you outsource you may have multiple people working on it but you still have 1 DPO and they cannot have a conflict of interests either.

 

Also, you might have someone in a job-share, at which point it is one role but two people. That said, I'm not sure someone senior enough to be DPO would be a job-share role.

Posted
Also, you might have someone in a job-share, at which point it is one role but two people. That said, I'm not sure someone senior enough to be DPO would be a job-share role.

 

We have the HT as a job share, so I wouldn't rule it out.

Posted
I found this, today. https://ico.org.uk/global/contact-us/advice-service-for-small-organisations/

I phoned and asked them the question and they said: "ideally you would find someone with no conflict of interested, however if that is your best option then there is nothing in the legislation that restricts you from doing that"

 

That applies to small organisations - we have a turnover of over £4m and employ over 100 people, so I'm not sure we would be classed as "small"...

Posted

It's pretty simply, if there's a conflict of interest it's a no.

 

You need to either not be the DPO or remove the conflict of interest.

 

We can help, but you are under no obligation to. I am currently helping our DPO move forward and I have right now got our Audit open... it's currently a large list and what action we need to take.. all to make sure we are compliant. As explained to me this week by the KCC rep, I could be the DPO if those 'conflict of interest' responsibilities were passed on (potentially to the technicians just an e.g.) and it would be okay. You've got to ask your self though are you passing on too much, are you still able to perform your own job etc. Likewise for my line manager, if he passed on his conflict of interests on to me.. being the DPO doesn't become a problem for him.

 

At least that's the example he used when explaining to us.

 

Problem is for us, we are administrators that have full access to ALL the data, we permission it ALL, we secure it ALL, we control ALL the backups, we make ALL the system alterations surrounding that data - it's all a minefield of conflicted interests. We do ALL the servers which contain 95% of all the personal data. You also have to realise it's not primarily about personal data (names) but the sensitive data is crucial (health, looked after children, addresses, DOBs etc). And where is 95% of that? on your

Posted
As explained to me this week by the KCC rep, I could be the DPO if those 'conflict of interest' responsibilities were passed on (potentially to the technicians just an e.g.) and it would be okay. You've got to ask your self though are you passing on too much, are you still able to perform your own job etc.

 

I don't think I could pass my conflicts of interest on to my technician, and I don't think he should accept them even if I tried. I am the IT Manager, and part of that role is to be responsible for the things which a conflict of interest with the DPO role. Over-simplifying somewhat, but the IT Manager's job is to do the high-level decision making and planning, the IT Technician's is to fix things which are broken; if I passed all conflicts of interest down, he would then be the manager not me!

Posted
As i'm sure most of you are, i am looking heavily into the GDPR changes coming in May. I have been in contact with a member of the governing body about it too.

 

I was speaking to a colleague today about it, and they presumed it was something that would come under the "network manager" role. I explained that this is classed as a "conflict of interest" and so i would not be able to fullfill the role. However the colleague had a point which i had not examined.

 

Could the DPO be job shared between two colleagues. IE.. Can the network manager be the primary DPO, and someone else be a secondary DPO for the IT side of things...

 

I said it seemed a bit hodgey - podgy and typing it, is making me question my sanity in even asking.. but thought i would throw it to the forums and see what you think...

 

The question is probably less who can we farm it out to, but rather, do IT professionals have the necessary DPO professional's skills? Hats off to all who have both. This is perhaps helpful to some. From Tim Turner's InfoLaw blog his thought is that, "Very few schools need a full-time DPO." He's drawn up a guide, "for those organisations seeking an external, contract-based Data Protection Officer. It is designed to help the small, non-expert organisation to choose the right DPO consultant. You can find it at this link, in the downloads section of my website."

Posted
I don't think I could pass my conflicts of interest on to my technician, and I don't think he should accept them even if I tried. I am the IT Manager, and part of that role is to be responsible for the things which a conflict of interest with the DPO role. Over-simplifying somewhat, but the IT Manager's job is to do the high-level decision making and planning, the IT Technician's is to fix things which are broken; if I passed all conflicts of interest down, he would then be the manager not me!

 

Was used as an example, you may not want to or be able to etc. The SBM/NM example was given to me the KCC rep, I simply altered it to match what we do.

 

I could potentially give those conflict of interest moments to one of my guys but it's question if they would accept them (they would by no means ever be pressured to say yes because that's not my style).

 

:)

Posted (edited)
I could potentially give those conflict of interest moments to one of my guys but it's question if they would accept them (they would by no means ever be pressured to say yes because that's not my style).

 

I really don't think you could. Looking at all the things which make my role a conflict of interest with being DPO, there's no way I could delegate them to my technician as I would basically be delegating the difference between my job spec and his. It may vary sufficiently in your structure to permit this, I don't know what you're responsible for and what your manager does, but I doubt an NM could delegate enough tasks to permit them to be DPO and NM.

Edited by enjay
Posted
Conflicts of interests are not things that can just be picked up and moved around on an ad-hoc basis. What would happen is that you slowly divest yourself of items within your JD which *cannot be picked back up again* and the person who now has them has to have their JD updated and agreed, including any change in pay and conditions.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...