Jump to content

Recommended Posts

Posted

Okay, so I'm looking for some general advice / guidance. I'm an IT tech at a small SEN primary and only have very basic knowledge about GDPR. I'm quite sure that Data Protection Act wise our compliance doesn't go much further than "we have a data protection policy."

 

Anyway, I know the SLT are vaguely aware of the GDPR as I've bought it up with them, though as far as I can tell they've taken no action other than arranging for a company to come in and do a private audit in the coming weeks, in which I strongly suspect we're going to get eaten alive and suddenly we'll be at panic stations (which it seems like we should have been at for about a year now).

 

I have an awful lot of very basic questions, but I'll try to keep them minimal.

 

1) It seems like we need to ensure our data processors are GDPR compliant. I'm quite unsure of how we're supposed to do that - is it just a case of firing off an email to them and asking "are you GDPR compliant?" or is there more to it?

 

2) I've seen a lot of talk about data flow maps, but I don't really know how to make one. Anybody have any useful examples they could share?

 

3) Our Office network share is a freaking mess, with data still lurking from decades ago, though I'm quite sure that this is partly because nobody knows quite how long they're supposed to keep anything. I assume that once the pupils leave, that means their data / work / parent contacts must also be deleted. If that's true, what about safeguarding data? I've also heard in training sessions that any restraint logs must be kept for something crazy like 70 years, but I don't know how that stacks up against the GDPR as obviously the logs will include names and sensitive information.

 

4) Subject Access Requests: Can pupils request access to specific documents relating to them? E.g could an older pupil theoretically request to see their risk assessment? The notes of a meeting with their parents when the meeting was about them? CCTV footage of an incident?

 

5) What technical measures have you implemented for data protection? Banning USB drives is an example, but I'm definitely interested about how you protect and manage your data, keep track of Office document passwords, keep on top of removing old data etc.

 

I'm sure there's more, but that'll do.. for now..

 

Thanks, and yes, I know we're screwed :o

  • Thanks 1
Posted (edited)

For someone that is new to GDPR these are the four questions that I would be telling the SLT to concentrate on. Once these are done you'd be 90% on your way!

 

 

Do we know what personal data we hold?

 

Do we know where this data is stored?

 

Is it kept securely? (If so, how)

 

Are we transparent with parents/students on what data we have and why we require it?

 

 

 

1) Whenever a school uses a processor it should look at putting in place a written contract between both parties so you can set out what you expect of the processer and both of your responsibilities. Take a look at this for some info on what should be in the contract: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/accountability-and-governance/contracts/

 

The section that says "take appropriate measures to ensure the security of processing", if I was in the school I'd specifically want to know what security measures have been put in place rather than just the general statement that the data processor should have put appropriate measures in place.

 

2) This doesn't have to be complex, it could literally be in a word document. It's a tool to see what systems process personal data and how they feed into other systems. For example you'd have a box with your MIS in it, then coming off that box any data that is synced from the MIS. For example the school that I came from had Sims then off Sims an auto sync that provided data to our child protection software, text message service, payment service etc. Then we had Sims to Active Directory via a manual csv/powershell import, and from AD a sync into Google Apps.

 

3) When a student leaves it doesn't necessarily mean that their data should be deleted. The school just need to be able to justify why they still hold the data. If they can provide reasonable justification then generally speaking it is fine. For example safeguarding data, you would justify holding longer than a persons personal data for your cashless catering system.

 

4) Generally speaking a persons personal data belongs to them so they should be able to have access to it*. There would be rare examples within a school when for example you were investigating a child protection incident and didn't want to expose the data as it might prejudice the investigation or cause undue harm. I think in these cases a practical approach is necessary but generally speaking personal data belongs to the person and they should be able to access it. *pinched this from another thread to see if it helps - The Education (Pupil Information) (England) Regulations 2005

 

 

5) enforced bitlocker of pen drives, bitlocker encryption of any staff laptop, encryption of servers, MDM enrolment of mobile phones that have gmail configured, stronger password policies for teaching/slt staff, Windows autolock, 12 month auto email deletion, we did general audits of what personal data was stored in staff personal drives, implemented SCCM for auto windows updates and app locker(general security consideration rather than specefic to data protection.)

Edited by rom1984
  • Thanks 1
Posted

1) Whenever a school uses a processor it should look at putting in place a written contract between both parties so you can set out what you expect of the processer and both of your responsibilities. Take a look at this for some info on what should be in the contract: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/accountability-and-governance/contracts/

 

The section that says "take appropriate measures to ensure the security of processing", if I was in the school I'd specifically want to know what security measures have been put in place rather than just the general statement that the data processor should have put appropriate measures in place.

 

That's all well and good, but the likes of Google aren't about to sign a specific data processing contract with us, they're going to say "these are our terms, agree to them or close your account, your choice".

Posted
That's all well and good, but the likes of Google aren't about to sign a specific data processing contract with us".

 

lol no I don't think they would! :) I think in these cases you'd just have to take a practical and realistic approach to the situation.

Posted
lol no I don't think they would! :) I think in these cases you'd just have to take a practical and realistic approach to the situation.

 

In which case, if we're happy with reviewing Google's published privacy policy rather than getting a specific contract, why do we need contracts with our other suppliers (assuming their privacy policies are also up-to-scratch of course)?

Posted

The best way to ensure that a data controller and processor both know their responsibilities is via a contract. That way it is clearly set out in a contract what the data controller expects of the data processor and is the easiest way of getting sufficient guarantees that the data processor is complying with the GDPR. If the data processor goes against the contract, then the data controller can show that they had a contract in place and the liability would weigh heavier on the data processor.

 

But, if your dealing with huge corporate organisations it just wouldn't be realistic to expect this, so you would do the next best thing which would be to check their privacy policy and make sure your happy with it.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...