Jump to content

Recommended Posts

Posted
My understanding is the quantity isn’t but company size but by data size. If you have data on enough data subjects or data which is really sensitive (like pretty much every school, independent or not) you had to have a DPO. There isn’t a fixed size, so any independent school should be getting a DPO in my opinion.
Posted

From the regulation:

 

The controller and the processor shall designate a data protection officer in any case where:

(a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity;

(b) the core activities of the controller or the processor consist of processing operations which, by virtue of their

nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale;

or

© the core activities of the controller or the processor consist of processing on a large scale of special categories of

data pursuant to Article 9 and personal data relating to criminal convictions and offences referred to in Article 10.[/Quote]

 

I haven't put it there to prove my point, as having read that it's not clear to me. Glad it's not my decision.

Posted
Don’t kiss her she think that you’re a past member of presidents club! Would be helpful for those links also what changes did you make to your mis and filter and why had the provider not built these in?

 

In fact capita sims isn’t yet gdpr compliant until the spring reports are in for subject access requests. They have just released the free parent lite app for data audit and consent revocation etc which is good.

In terms of filtering, you’re not compliant with gdpr if you don’t document why you are recording students internet traffic by name etc and you need to be able to report it for a subject access request. So in theory this applies to all filtering solutions - smoothwall have a very good document on the matter.

 

I’m actually booking me and the dpo on a course which I hope to find soon as she needs it and I can assist with privacy impact assessments, data classifications and ict security - so I might as well tag along ... anyone got any ideas?

 

Past presidents club :)

Posted (edited)
In fact capita sims isn’t yet gdpr compliant until the spring reports are in for subject access requests. They have just released the free parent lite app for data audit and consent revocation etc which is good.

In terms of filtering, you’re not compliant with gdpr if you don’t document why you are recording students internet traffic by name etc and you need to be able to report it for a subject access request. So in theory this applies to all filtering solutions - smoothwall have a very good document on the matter.

 

I’m actually booking me and the dpo on a course which I hope to find soon as she needs it and I can assist with privacy impact assessments, data classifications and ict security - so I might as well tag along ... anyone got any ideas?

 

Past presidents club :)

 

I have to say i like to see the school that taken to court over GDPR for that issue. Should safeguard or GDPR be the top trumps legislation? I also interested as to the first school to fall foul of GDPR what will happen to them will they get taken over by an Academy group?

Edited by nicholab
Posted
Has it been confirmed that schools definitely need a DPO yet?

 

It is the case that schools *do* need a DPO, and there has yet to be an amendment carried through that changes this.

Posted
It is the case that schools *do* need a DPO, and there has yet to be an amendment carried through that changes this.

 

We have a local solicitor firm who are telling schools in our area that they don't need a DPO, but that conflicts with practically everything else I've heard/read.

Posted
Food for thought...

 

I phoned the ICO directly to ask:

“Can a IT manager and business manager share the DPO role with one being the “primary”. So that any conflicts are offloaded onto the other. “

The ICO confirmed to me that:

“Although preferably it would go to one single person, if you feel that this is the best option for you, then there are no laws or guidance, stopping you from doing so, and this would satisfy the ICO”

Went to our LA GDPR briefing on Tuesday and was told the same thing. According to our LA they have been advised by ICO that they would accept this scenario.

I have it confirmed in an email from the LA so I have it in writing! ;)

Posted
This whole situation is a shambles for schools with conflicting information everywhere. One person says one thing, someone else says another. Trying to advise schools on this is difficult!
Posted

Sorry to hijack this thread, but I also have some concerns about GDPR. I have a “feeling” that the school will expect me to manage the GDPR in the school as anything IT related get pushed in my direction even when staff have gone ahead and ordered the software/hardware, without me looking at it first.

 

Also I don’t think the school will be purchasing any software or hiring any DPO as the school is very tight on funds.

 

I haven’t heard anything from SMT about what they are doing to be prepared for GDPR and I fully expect all this to fall on my head when GDPR comes into effect.

Posted

I've just rang the ICO (40 minutes on hold!), and they pointed me to their guidance here.

 

In particular, this point:

When does a Data Protection Officer need to be appointed under the GDPR?

Under the GDPR, you must appoint a DPO if you:

 

* are a public authority (except for courts acting in their judicial capacity);

 

*edit* I understand that I'm stepping on the toes of people who have much more expertise in this area, but I'm particularly annoyed that our schools are being told incorrect information.

  • Thanks 1
Posted
This whole situation is a shambles for schools with conflicting information everywhere. One person says one thing, someone else says another. Trying to advise schools on this is difficult!

Yep its a mess.

I am given to understand that GDPR is mostly aimed at tackling abuses by big business and I have heard the phrase "schools are collateral damage" being used.

I think (hope) that after a lot of badgering by LAs, MATs and Governing Bodies, the chorus is starting to be heard. I also think that there is little political will to start forcing schools to pay (out of their deficit budgets) for a DPO so a more liberal interpretation of the DPO rules will be allowed.

 

Just what I've heard :)

Posted
will expect me to manage the GDPR in the school as anything IT related get pushed in my direction

 

Mistake number 1. GDPR is not IT related. It is whole-school, all data. 'Data' does not just mean digital. Do you manage all of the school paperwork as well? And if you do, that's also a conflict of interest!

 

This. Is. Not. An. IT. Job. You will need to work with the DPO for any data you do control.

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...