Jump to content

Recommended Posts

Posted
If you're appointing your DPO right at the end of that process wont they be able to say "Xn solutions were put into place without my input so I'm not responsible"? Sorry if I'm misunderstanding that roll.
Posted

How will staff be able to assess the data they're responsible for if they're supposed to audit / clear out before they've had basic training? Have they already had a cheatsheet to work from? (I'm assuming someone's not been crazy enough to volunteer to go through every department's stuff and do it for them).

 

We've done basic (Data Protection Courses and GDPR course via Educare) training for staff and we've also had in-person meetings by department where we give them actionable things to do and how to apply the training (with prompts and examples of data they are likely to hold/need to assess).

Posted
How will staff be able to assess the data they're responsible for if they're supposed to audit / clear out before they've had basic training? Have they already had a cheatsheet to work from? (I'm assuming someone's not been crazy enough to volunteer to go through every department's stuff and do it for them).

 

We've done basic (Data Protection Courses and GDPR course via Educare) training for staff and we've also had in-person meetings by department where we give them actionable things to do and how to apply the training (with prompts and examples of data they are likely to hold/need to assess).

 

 

I don't think staff will need any training to answer a few simple questions to asses whether they are responsible for holding any data....it will then be up to a "working party" to action the next steps once we know what data we're holding.

Posted

We are currently split responsibility here, I'm dealing with the audit and discussing with the controllers on the big questions (what we have, security, who has access etc).

 

My spreadsheet is currently 20 columns and 50 sub categories (half of these are simple tick boxes like staff, student, parent - personal, sensitive etc).

 

60+ items on this audit so far.

Posted
I don't think staff will need any training to answer a few simple questions to asses whether they are responsible for holding any data....it will then be up to a "working party" to action the next steps once we know what data we're holding.

 

We thought that initially too. You already have an idea of teachers are likely to hold (markbooks, school trip info, absence notes (medical data), SEN assessments/cheatsheets etc). The question is whether they'll realise those count as personal data.

  • Thanks 1
Posted
[ATTACH=CONFIG]46757[/ATTACH]

 

Any comments most appreciated on our draft.

 

This is great to see action planning! You know your site and why you can't have the DPO in place and responsible for leading this now.

The three things I'd suggest are to support how you chnage from current (non GDPR compliant) to future (compliant) process and actually make sure that you can maintain good practice easily in future - and - have a way of demonstrating accountability and practice as will be needed by your DPO:

 

1. As you do any audit now,

a)write down any processes in the school that have significant personal data transfers involved. I.e Staff hire, Pupil Admissions, School Census, NHS NCMP visit, Begin a new third party contract (cashless system/biometrics/CCTV/sign up class for new app) and

b) for the data parts of the process, draw up a flow chart of the process where and when it happens, and where there is accountability for the data transfer, communication to data subject, ways to correct. audit etc. Draw in the people / roles involved of who must do what in each process.

2.Plan beyond May 2018. Include a review with all staff and audit again, how is it going? And take one or two processes each month after GDPR and ask staff to review what they do now after GDPR, compared with the model process. Are there gaps? Anything unclear? Are privacy notices clear?

3. Incorporate documents into future new staff onboarding / training.

 

 

I'm happy to help with drawing up and review if anyone uses this and wants to. We'll be including 'global GDPR process maps' (For adapting to loacl needs) in our free report to come out in Spring and if anyone wants to help us review them and spot what we are missing, I'd be thrilled.

  • Thanks 1
Posted

Agree with a great deal of this. The devil is in the detail. I have been charged with carrying out our audit, but not yet been given any mandate to seek out “grey data”; and I’m sure that will be one of or biggest problems.

 

Yes, we need to get teachers to understand what constitutes personal data, how ever the biggest issue I’ve ever found in education is that some teachers feel they are above the law and wouldn’t necessarily divulge to a ‘non-teacher’ what they are holding. This is a big issue for management.

Posted
What do you typically do about children's personal data on staff personal devices? Are there contract terms or employment rules to cover this, and are tehri revision a step in the planning, or is everywhere different?
Posted

We were strongly advised by our legal counsel not to recruit a DPO, at least until or if it becomes mandatory for a school. I am the Compliance Officer (Data) which is our way of skirting around having a DPO. It requires specialist legal knowledge and no-one in the school is qualified.

 

Good plan. You're missing one important bit: consent. From students, staff, parents and alumni. There's quite a mechanism behind it. We even have separate consent for permission to publish photos.

  • Thanks 1
Posted
I understand why you may not be selecting to appoint the DPO until the end (and indeed you don't need one until the deadline day) but who is co-ordinating everything in the meantime, and making sure the working party are on task, on schedule and appropriately equipped?
Posted
I understand why you may not be selecting to appoint the DPO until the end (and indeed you don't need one until the deadline day) but who is co-ordinating everything in the meantime, and making sure the working party are on task, on schedule and appropriately equipped?

 

An assistant head.

  • Thanks 1
Posted
I understand why you may not be selecting to appoint the DPO until the end (and indeed you don't need one until the deadline day) but who is co-ordinating everything in the meantime, and making sure the working party are on task, on schedule and appropriately equipped?

 

That would be me :(

Posted
Agree with a great deal of this. The devil is in the detail. I have been charged with carrying out our audit, but not yet been given any mandate to seek out “grey data”; and I’m sure that will be one of or biggest problems.

 

Yes, we need to get teachers to understand what constitutes personal data, how ever the biggest issue I’ve ever found in education is that some teachers feel they are above the law and wouldn’t necessarily divulge to a ‘non-teacher’ what they are holding. This is a big issue for management.

 

Every week the school assistants send out a newsletter to staff. I include an IT one which has had parts of GDPR for the last 6 weeks or so. Course not everyone is reading them.

 

Sort of:

CCTV reminders (what's there for)

Locking PCs, classrooms

Taking extra care what sensitive data is (more than just names, looked after children, medical, addresses etc)

 

Reminders really and in small doses.

 

Similar to child protection, they will need training and refreshers every year at least. It will be a pain but it helps them realise that names on student folders on staff desks don't matter so much (but still lock classrooms) because it's education. Sensitive data areas though will be told to lock their doors, not leave their machines logged on and risk assessments will be undertaken by a site walk at random times.

Posted
... but still lock classrooms. Sensitive data areas though will be told to lock their doors, not leave their machines logged on ...

 

Emphasise this applies even if you're only "popping out of your room for a moment". A moment is all it takes for someone to nip in, plus you don't know when you'll get delayed or called away elsewhere while you're out.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...