Jump to content

Recommended Posts

Posted

Hi everyone,

 

Our appointed DPO has asked all departments to fill out an information data audit spreadsheet themselves and save it onto a shared drive for them to look at. Is this normal?

 

The concern for me is how can the DPO then verify the information is accurate if they have not been involved with gathering this information for the audit? People could lie or not know what they are being asked, no one has been trained on how to answer these questions.

Posted
This is similar to how we did it here, but we did include some examples of what we were looking for so that people have a starting point.
Posted
I'd normally do that as a starting point to try and map out what data a school processes. Once I get that info then I'd use the Network Managers Infrastructure document to identify any systems within their that could process personal data. That should give the DPO a rough outline and they can work on that to refine it.
Posted

To be honest, I think the departments are the only people who can tell you everywhere they share information, especially with so many free services now there's no reason IT or Finance would know about all data processors.

 

Here, the HT and I did most of the audit, then involved other key users to add what we'd missed. We will take it out to HODs for a final sweep.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...