maxrebo Posted January 24, 2018 Posted January 24, 2018 (edited) As title says, been asked to head this and really need some advice on whether I should accept or not. Edited January 24, 2018 by maxrebo
Liam Posted January 24, 2018 Posted January 24, 2018 The latest video released by dfe directly Aimed at education suggest not. No harm in having an overview of ict security etc but I would imagine the role too big with other duties too. Huge responsibility. I know what i would say. 1
Liam Posted January 24, 2018 Posted January 24, 2018 I have been helping our dpo with the ict related criteria’s and it’s been a big enough task. You only have to look at some of the roles advertised on here and the salaries associated. Ok I think a lot of organisations are very worried about it and that fear factor alone if forcing them to offer huge salaries for the role, but it’s not a new thing. We still have a responsibility under current legislation. 1
Popular Post elsiegee40 Posted January 24, 2018 Popular Post Posted January 24, 2018 (edited) Not. There is a clear conflict of interest between the role of IT Staff and that of DPO. You would be monitoring yourself. You are responsible for how data is stored and managed. You cannot also be the one saying whether or not it’s being done right. It is also a high level position - senior management - you have to be overrule anyone in the school, including the head, about both electronic and paper data. I have moved this to the Data Protection forum and if you browse this forum you will see that the conflict of interest is discussed at length Edited January 24, 2018 by elsiegee40 8
Sylv3r Posted January 24, 2018 Posted January 24, 2018 You can't be the DPO by name - but I suspect you'll be doing 80% of the work regardless ! 2
maxrebo Posted January 24, 2018 Author Posted January 24, 2018 Thanks for the views on this. I have been offered a payrise`should I accept this, can anyone offer me an insight on what kind of payrise they would accept should they take on the role! thanks
elsiegee40 Posted January 24, 2018 Posted January 24, 2018 Thanks for the views on this. I have been offered a payrise`should I accept this, can anyone offer me an insight on what kind of payrise they would accept should they take on the role! thanksThe ones I have seen with salaries have been in the £30-40k area depending on experience and geographical area. However, a few have been readvertised with "Competitive" and "negotiable" suggesting they're not easy posts to fill and the candidates are naming their price. These roles are not always full time... So the salary is pro rated. 1
Liam Posted January 24, 2018 Posted January 24, 2018 I wouldn’t want to do it for love nor money! I quite like what I do now without the headaches and politics of dpo! 1
synaesthesia Posted January 25, 2018 Posted January 25, 2018 The pay shouldn't be related, it would be a shift of role as it's in their interests for you not to do it due to the aforementioned conflict of interests. It's obvious they haven't been given the correct information or haven't been looking into it seriously enough, especially at this late stage. Make it known you're looking after the interest of the school and if possible get together some information for them to help. Certainly offer to help, but don't be the DPO unless you have a background in data protection. 1
Popular Post GrumbleDook Posted January 25, 2018 Popular Post Posted January 25, 2018 (edited) Oh no ... not again. I would love to get every Head and CoG in a room and shout at them loudly, in a Harry Enfield shouty man style ... “Oi! School Leaders! Nooooooo! Whilst I respect your ability to lead schools and ensure that children are learning in an engaging environment I must point out that even the ICO clearly says that the IT Manager is a clear example of a role with conflicts of interest with regards to being DPO. By all means you should work with them to ensure the safety and security of data but you can’t audit your own work!” Edited January 25, 2018 by elsiegee40 6
Popular Post PotNoodleTech Posted January 25, 2018 Popular Post Posted January 25, 2018 "We need to appoint a DPO, what sucker can we pin this on?" "How about the Business Manager?" "No they said they'd quit" "Hmm...How about the IT Manager they're always willing to help, and say yes to everything?" "Perfect. Draft the email." 8
Popular Post maxrebo Posted January 25, 2018 Author Popular Post Posted January 25, 2018 Thanks everyone for your views, invaluable as always! I have read through a number of threads regarding the role and, as mentioned, I cannot (and wont be) taking on the role as this will be a conflict of interest, on top of this I have no experience in Data protection (apart from the basics used in my role as IT manager) It seems this is a massive job and there no way I could devote the time to this and run the school network, and have a life outside of work! Thanks again 6
crc-ict Posted January 25, 2018 Posted January 25, 2018 This is a very interesting question. I wholeheartedly agree with all the points made here about DPO being a conflict of interest for IT Managers. However unfortunately not everyone shares the view. For example, in our county, the Legal adviser for GDPR has stated there is no reason why the IT Manager or SBM cannot be DPO - they have said that it is not a conflict of interest because it is the Headteacher who has the responsibility for what and how data will be processed - basically implying that any other roles are simply making recommendations and that the final decision rests with the HT, and so it is only them who has a conflicting interest. The only other role they rule out for DPO is the Safeguarding Lead. This is very frustrating in the light of so much information from multiple sources that says we can't be DPO, but unfortunately people tend to take county's legal word as gospel and so it is very hard to argue that point. I feel that a better argument to take is that the DPO needs to be someone on the SLT in order to have sufficient influence over the policies and procedures of the school to carry out the role. Otherwise, anything the DPO tries to enforce can just be over-ruled anyway. Obviously this doesn't work if you are an IT Manager who is on SLT!
Wubbalubbadub Posted January 26, 2018 Posted January 26, 2018 Food for thought... I phoned the ICO directly to ask: “Can a IT manager and business manager share the DPO role with one being the “primary”. So that any conflicts are offloaded onto the other. “ The ICO confirmed to me that: “Although preferably it would go to one single person, if you feel that this is the best option for you, then there are no laws or guidance, stopping you from doing so, and this would satisfy the ICO”
GrumbleDook Posted January 26, 2018 Posted January 26, 2018 Was that on a call out via the chat? If via the chat I would love a copy of the transcript because it conflicts with the answer I get on the same question I ask on a nearly fortnightly basis.
ITGuyWestMidlands Posted January 26, 2018 Posted January 26, 2018 It doesn't sound like a bad idea to me. I'm concerned of where the dfe thinks schools are going to fund the appointment of a dpo at 30k plus a year. I'd rather see it being a joint effort between data aware staff than dropped on a deputy head who was a former pe teacher who is just about capable of wordart.
Wubbalubbadub Posted January 26, 2018 Posted January 26, 2018 Was that on a call out via the chat? If via the chat I would love a copy of the transcript because it conflicts with the answer I get on the same question I ask on a nearly fortnightly basis. Nope, that was a direct phone call with the ICO.
Wubbalubbadub Posted January 26, 2018 Posted January 26, 2018 It doesn't sound like a bad idea to me. I'm concerned of where the dfe thinks schools are going to fund the appointment of a dpo at 30k plus a year. I'd rather see it being a joint effort between data aware staff than dropped on a deputy head who was a former pe teacher who is just about capable of wordart. This is my thought process.. at the end of the day. We are schools. Budgets are tight. I’m more than 100% sure that the ICO would understand why we share or ask an employees to do it. Which is what the ICO confirmed on the phone.. If that employee doesn’t document any “clashes” or “interests” then fair enough.. fine away and close the school down.. because at the end of the day that’s what any fine will do! Personally I don’t see any company or organisation wanting a closed school on there hands! We can do our best, with what we have. Unfortunately an extra 30k post in our school is not feasible.. hence why we checked with the ICO that the conflicts share was alright.. 2
KevinB Posted January 26, 2018 Posted January 26, 2018 At a GDPR seminar a couple of weeks ago, the trainer and we as a room came to the concensus that nobody senior enough in a school would be free from conflict of interest issues. Head/Principal plus SLT: all would get covered by the "means and methods" language, as would business managers/bursars, data managers and IT managers as they would all have some influence in the use/appointment of data processors. An MPS teacher might be able to do it, but as an administrative role, their T&Cs pretty much rule them out. That leaves admin staff, technical staff, site staff and cleaners, none of whom would have any of the requisite technical and legal knowledge and/or "clout" within an organisation to be able to carry out the role properly. We did agree though that if you're in any kind of schools partnership (either management agreement or MAT) that someone from SLT in one school might be able to get away with being DPO for another school in the partnership. Most of us, though, felt that the safest way forwards was to buy in a DPO and some initial consultancy. 1
johnpd Posted January 26, 2018 Posted January 26, 2018 (edited) In our trust our safeguarding compliance officer has accepted. I want to kiss her. Anyway I told her, I’ll report and you action ... I’ve completed the servicetrust.microsoft.com portal (has anyone used it - seems great way of meeting compliance from an ict point of view). I have also spent 6 months getting my filtering gdpr compliance sorted, mis, data breach reporting, financial accreditation for pci dss and on and on and on. It has been hard work just listing the high risk streams for audit. Staff have been asked to fill in my privacy impact assessments and say no more. I’m head of IT for a trust and I had a link to a comment made in the House of Lords in September that lists all the roles which can’t be a dpo. I will find it again if you need evidence. Network managers/ IT leaders are one of them as mentioned in the above posts. So n.o spells NO, help but don’t be the dpo as you will ultimately help them fail gdpr in one fail swoop. Edited January 26, 2018 by johnpd
nicholab Posted January 26, 2018 Posted January 26, 2018 (edited) In our trust our safeguarding compliance officer has accepted. I want to kiss her. Anyway I told her, I’ll report and you action ... I’ve completed the servicetrust.microsoft.com portal (has anyone used it - seems great way of meeting compliance from an ict point of view). I have also spent 6 months getting my filtering gdpr compliance sorted, mis, data breach reporting, financial accreditation for pci dss and on and on and on. It has been hard work just listing the high risk streams for audit. Staff have been asked to fill in my privacy impact assessments and say no more. I’m head of IT for a trust and I had a link to a comment made in the House of Lords in September that lists all the roles which can’t be a dpo. I will find it again if you need evidence.. Don’t kiss her she think that you’re a past member of presidents club! Would be helpful for those links also what changes did you make to your mis and filter and why had the provider not built these in? Edited January 26, 2018 by nicholab 1
RS67 Posted January 27, 2018 Posted January 27, 2018 Another view of "who can/can't be DPO": https://www.stoneking.co.uk/literature/other-articles/details-data-protection-officer-role-employment-focused-note
nicholab Posted January 27, 2018 Posted January 27, 2018 How does that work in an Independent school? Also that document also seems to state that no one in a School can do that roll of DPO.
jmak Posted January 27, 2018 Posted January 27, 2018 How does that work in an Independent school? Also that document also seems to state that no one in a School can do that roll of DPO.Independent schools aren't yet required to have a DPO unless they're so big that they qualify by size like any other business. They still have to obey all the same rules, just don't have to have a DPO. Some are taking it seriously though - elsiegee posted a link to an ad for a data security manager job at Uppingham school. If you've got the qualifications, it sounded good as judging by the ad they've understood the scope and importance of the role - backed up by the amount they're paying.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now