Jump to content

Recommended Posts

Posted

Myself and a couple of staff went to a GDPR training day provided by a consultancy company via our LEA. In it they stated that for staff training you can run it in house. He suggested using material from the ICO website to create our own staff training and deliver it ourselves.

 

Has anyone else been told this too?

 

From what I have found on the ICO website it states

implement appropriate technical and organisational measures that ensure and demonstrate that you comply. This may include internal data protection policies such as staff training, internal audits of processing activities, and reviews of internal HR policies;

 

I have been asked if I would help deliver it, which I don't mind to be honest as it gives a good platform to enforce the ICT changes too. But I wanted to double check this was correct. Anyone have any slide shows or thigns they have used for staff training?

 

Cheers

Posted

I have delivered Data Protection training before and a refresher as part of e-Safety, it isn't an issue and I think is better for it to be in-house as it is more relevant. I think our Complice guy is doing the GDPR talk and from what I gather it will mainly consist of "Follow our policies and think what you would have happen to your own personal data".

Don't get bogged down in the nitty gritty, staff don't need to know and will just turn off. It should mainly be reminding staff of your school's policies, keep it relevant. Maybe highlight some major no nos, or even hunt for some examples of bad practice. You could always throw in a section on know your rights, so it can be counted as CPD?

 

One talk I gave I got a colleague to run around the PCs and count how many had been left unlocked while they were all in the training session. He held up a sign with the number from the back so I could see it and I hit them with the result, which made them think. Maybe be a bit sneaky and see how much data you can 'find' just from things left lying around on desks.

  • Thanks 2
Posted

In-house is definitely best, as you can make it specific to the risks in your school, and omit the things you're already doing. If you already have encrypted laptops, don't bother talking about encryption! Also, you know where the data protection risks are in your school (and if you don't, do a quick site walk looking for them) so talk to those specific situations.

 

The principles of GDPR shouldn't be new to them (they already know about safeguarding and should be familiar with the DPA, in practice if not by name) so don't present this as a new thing, tell them to carry on doing what they already are but with more information than they did previously. Some good pointers from training I went on recently said not to talk about "GDPR" or "data protection" but "information protection" or "information privacy" - two reasons, firstly "data" could be taken to mean digital-only, and secondly "protection" and "protection" are words people understand.

 

If possible, get someone SLT and non-IT to deliver part of the training, to emphasise this is more than just IT.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...