Jump to content

Recommended Posts

Posted
Depends on your role in the school. If you're not the DPO, but a Network Manager or similar, then you could do with reading up on some guidance relating to data you control, then doing a data audit on that data. Policy, school data audits etc are for the SLT and DPO to manage.
  • Thanks 2
Posted
At this point your school should have already made steps into making this clear and putting a plan into action, and as IT staff you'd usually have been involved in some way or another - or should have been. However it sounds like that may not have been the case. If that's correct, you need to be speaking to the top bods - business manager, data admin staff should be the best bet if you don't have a DPO. If they're shrugging shoulders too, it's time to bash some heads. If you're strong enough, do the bashing yourself, otherwise governors. Now. It shouldn't be a scary thing but it shouldn't be ignored either and if noone at the school has started making plans, you could be doing them a huge favour. Just don't fall into the trap of being lumbered with it... it's not your responsibility.
  • Thanks 1
Posted
I'm going to try and get a wiki setup with information i've found (from google) of what other schools have published publically - which might then be helpful.
  • Thanks 1
Posted

Ask your DPO to look at GDPRiS (GDPR in Schools). They have done a lot of the work compiling the data maps and pulling together data sharing agreements from suppliers. All you have to do is select which products you use and it helps create the data maps ready for you to audit. It is a central system for all of your data protection elements. Allows staff to report breaches and for the DPO to detail what has been done in response, central repository for all your documentation, training materials etc.

 

http://www.gdpr.school

  • Thanks 1
Posted
Thank-you all for your replies. We currently don't have a dpo and i am more wanting to know what needs to done on the network side of things. Seems like I have alot of reading to do :D
Posted

Firstly, you need a DPO! If you have a breach and don't have one (either employed or an external) the ICO will be slapping your wrists very hard!

 

As a Network Manager you need to ensure data is held securely, access is limited, your systems (internal and external providers) should be secure by design and the data held is minimal for the purposes it is needed for. Are all your staff forced to only use encrypted USB drives? Are all your staff laptop hard drives encrypted by default? Do you enforce a strong password policy? Is your server room secure enough should you be broken into? Have you sufficient technical measures to prevent hackers, viruses, ransomware etc. Are your backups systems robust and tested regularly?

  • Thanks 1
Posted
Firstly, you need a DPO! If you have a breach and don't have one (either employed or an external) the ICO will be slapping your wrists very hard!

 

And the good news if you are part of the IT or Data teams at you school is that it cannot be you!

Posted

The good thing about data proteciton is it's never to late to start as there is never a deadline!

 

These guides might be of some help..

 

ICO's 12 steps to take now for preparing for the GDPR;

 

https://ico.org.uk/media/1624219/preparing-for-the-gdpr-12-steps.pdf

 

If your the Network Manager then the main elements of GDPR that applies to you is Article 32 - Security of Processing. This security guide has just been published which hopefully helps;

 

https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/security/

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...