Jump to content

Recommended Posts

Posted (edited)
As title says, been asked to head this and really need some advice on whether I should accept or not. Edited by maxrebo
Posted
The latest video released by dfe directly Aimed at education suggest not. No harm in having an overview of ict security etc but I would imagine the role too big with other duties too. Huge responsibility. I know what i would say.
  • Thanks 1
Posted
I have been helping our dpo with the ict related criteria’s and it’s been a big enough task. You only have to look at some of the roles advertised on here and the salaries associated. Ok I think a lot of organisations are very worried about it and that fear factor alone if forcing them to offer huge salaries for the role, but it’s not a new thing. We still have a responsibility under current legislation.
  • Thanks 1
Posted

Thanks for the views on this.

I have been offered a payrise`should I accept this, can anyone offer me an insight on what kind of payrise they would accept should they take on the role!

 

thanks

Posted
Thanks for the views on this.

I have been offered a payrise`should I accept this, can anyone offer me an insight on what kind of payrise they would accept should they take on the role!

 

thanks

The ones I have seen with salaries have been in the £30-40k area depending on experience and geographical area. However, a few have been readvertised with "Competitive" and "negotiable" suggesting they're not easy posts to fill and the candidates are naming their price.

 

These roles are not always full time... So the salary is pro rated.

  • Thanks 1
Posted
I wouldn’t want to do it for love nor money! I quite like what I do now without the headaches and politics of dpo!
  • Thanks 1
Posted
The pay shouldn't be related, it would be a shift of role as it's in their interests for you not to do it due to the aforementioned conflict of interests. It's obvious they haven't been given the correct information or haven't been looking into it seriously enough, especially at this late stage. Make it known you're looking after the interest of the school and if possible get together some information for them to help. Certainly offer to help, but don't be the DPO unless you have a background in data protection.
  • Thanks 1
Posted

This is a very interesting question.

 

I wholeheartedly agree with all the points made here about DPO being a conflict of interest for IT Managers. However unfortunately not everyone shares the view.

 

For example, in our county, the Legal adviser for GDPR has stated there is no reason why the IT Manager or SBM cannot be DPO - they have said that it is not a conflict of interest because it is the Headteacher who has the responsibility for what and how data will be processed - basically implying that any other roles are simply making recommendations and that the final decision rests with the HT, and so it is only them who has a conflicting interest. The only other role they rule out for DPO is the Safeguarding Lead.

 

This is very frustrating in the light of so much information from multiple sources that says we can't be DPO, but unfortunately people tend to take county's legal word as gospel and so it is very hard to argue that point.

 

I feel that a better argument to take is that the DPO needs to be someone on the SLT in order to have sufficient influence over the policies and procedures of the school to carry out the role. Otherwise, anything the DPO tries to enforce can just be over-ruled anyway. Obviously this doesn't work if you are an IT Manager who is on SLT!

Posted

Food for thought...

 

I phoned the ICO directly to ask:

“Can a IT manager and business manager share the DPO role with one being the “primary”. So that any conflicts are offloaded onto the other. “

The ICO confirmed to me that:

“Although preferably it would go to one single person, if you feel that this is the best option for you, then there are no laws or guidance, stopping you from doing so, and this would satisfy the ICO”

Posted

Was that on a call out via the chat?

 

If via the chat I would love a copy of the transcript because it conflicts with the answer I get on the same question I ask on a nearly fortnightly basis.

Posted

It doesn't sound like a bad idea to me. I'm concerned of where the dfe thinks schools are going to fund the appointment of a dpo at 30k plus a year.

 

I'd rather see it being a joint effort between data aware staff than dropped on a deputy head who was a former pe teacher who is just about capable of wordart.

Posted
Was that on a call out via the chat?

 

If via the chat I would love a copy of the transcript because it conflicts with the answer I get on the same question I ask on a nearly fortnightly basis.

 

Nope, that was a direct phone call with the ICO.

Posted
It doesn't sound like a bad idea to me. I'm concerned of where the dfe thinks schools are going to fund the appointment of a dpo at 30k plus a year.

 

I'd rather see it being a joint effort between data aware staff than dropped on a deputy head who was a former pe teacher who is just about capable of wordart.

 

This is my thought process.. at the end of the day. We are schools. Budgets are tight. I’m more than 100% sure that the ICO would understand why we share or ask an employees to do it. Which is what the ICO confirmed on the phone..

 

If that employee doesn’t document any “clashes” or “interests” then fair enough.. fine away and close the school down.. because at the end of the day that’s what any fine will do! Personally I don’t see any company or organisation wanting a closed school on there hands!

 

We can do our best, with what we have. Unfortunately an extra 30k post in our school is not feasible.. hence why we checked with the ICO that the conflicts share was alright..

  • Thanks 2
Posted

At a GDPR seminar a couple of weeks ago, the trainer and we as a room came to the concensus that nobody senior enough in a school would be free from conflict of interest issues. Head/Principal plus SLT: all would get covered by the "means and methods" language, as would business managers/bursars, data managers and IT managers as they would all have some influence in the use/appointment of data processors. An MPS teacher might be able to do it, but as an administrative role, their T&Cs pretty much rule them out. That leaves admin staff, technical staff, site staff and cleaners, none of whom would have any of the requisite technical and legal knowledge and/or "clout" within an organisation to be able to carry out the role properly.

 

We did agree though that if you're in any kind of schools partnership (either management agreement or MAT) that someone from SLT in one school might be able to get away with being DPO for another school in the partnership. Most of us, though, felt that the safest way forwards was to buy in a DPO and some initial consultancy.

  • Thanks 1
Posted (edited)
In our trust our safeguarding compliance officer has accepted. I want to kiss her. Anyway I told her, I’ll report and you action ... I’ve completed the servicetrust.microsoft.com portal (has anyone used it - seems great way of meeting compliance from an ict point of view). I have also spent 6 months getting my filtering gdpr compliance sorted, mis, data breach reporting, financial accreditation for pci dss and on and on and on. It has been hard work just listing the high risk streams for audit. Staff have been asked to fill in my privacy impact assessments and say no more. I’m head of IT for a trust and I had a link to a comment made in the House of Lords in September that lists all the roles which can’t be a dpo. I will find it again if you need evidence. Network managers/ IT leaders are one of them as mentioned in the above posts. So n.o spells NO, help but don’t be the dpo as you will ultimately help them fail gdpr in one fail swoop. Edited by johnpd
Posted (edited)
In our trust our safeguarding compliance officer has accepted. I want to kiss her. Anyway I told her, I’ll report and you action ... I’ve completed the servicetrust.microsoft.com portal (has anyone used it - seems great way of meeting compliance from an ict point of view). I have also spent 6 months getting my filtering gdpr compliance sorted, mis, data breach reporting, financial accreditation for pci dss and on and on and on. It has been hard work just listing the high risk streams for audit. Staff have been asked to fill in my privacy impact assessments and say no more. I’m head of IT for a trust and I had a link to a comment made in the House of Lords in September that lists all the roles which can’t be a dpo. I will find it again if you need evidence..

 

Don’t kiss her she think that you’re a past member of presidents club! Would be helpful for those links also what changes did you make to your mis and filter and why had the provider not built these in?

Edited by nicholab
  • Thanks 1
Posted
How does that work in an Independent school? Also that document also seems to state that no one in a School can do that roll of DPO.
Independent schools aren't yet required to have a DPO unless they're so big that they qualify by size like any other business. They still have to obey all the same rules, just don't have to have a DPO. Some are taking it seriously though - elsiegee posted a link to an ad for a data security manager job at Uppingham school. If you've got the qualifications, it sounded good as judging by the ad they've understood the scope and importance of the role - backed up by the amount they're paying.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...