Jump to content

Recommended Posts

Posted
Imagine this scenario. Headteacher at a small primary school is away on holiday and her neighbour tells her that her house has been broken into and her laptop bag is stolen along with some tracking documents that she was planning on working on. A reportable breach but with the whole school shutdown and the business manager who is acting as DPO (don’t go there!) also on holiday. What is the situation regarding reporting that breach, because I can’t see it happening in 72 hours?
Posted
"The head and DPO are on holiday" isn't an exception to the reporting rule, so I guess we either need a process that can adapt to situations like that or a way for the head to keep private documents at home secure (her laptop is encrypted anyway ofc, so that's not a reportable breach anyway).
Posted
I'd expect it to be "Tough, pay the fine for late reporting" combined with "at least one member of senior management should be contactable at any point in the holidays" going forwards.
Posted
"The head and DPO are on holiday" isn't an exception to the reporting rule, so I guess we either need a process that can adapt to situations like that or a way for the head to keep private documents at home secure (her laptop is encrypted anyway ofc, so that's not a reportable breach anyway).

 

Oh agreed, the point was that reportable breaches can occur during holidays when primary schools are shut and all staff are officially on holiday.

Posted
Breach on a Friday and breach in the school holidays - ICO don't care where you are or what you are doing....72 hours still applies
Posted

As the laptop was encrypted and the keys secured has the data been stolen?

 

Consider this: Sending the data over the internet if it is encrypted, is not a data breach(*) even though you have no idea if anyone had swiped a copy of the encrypted bits in transit.

 

(*) Assuming you state that you will be doing this in your various policies / DPIA / Privacy Statement etc.

Posted
As the laptop was encrypted and the keys secured has the data been stolen?

 

Consider this: Sending the data over the internet if it is encrypted, is not a data breach(*) even though you have no idea if anyone had swiped a copy of the encrypted bits in transit.

 

(*) Assuming you state that you will be doing this in your various policies / DPIA / Privacy Statement etc.

I assumed that "along with some tracking documents that she was planning on working on." meant some paper stuffed in the side of the bag containing pupils' personal data, turning it from just "stolen encrypted laptop" into a breach.

  • Thanks 1
Posted

In fairness about the 72hours still applies don't not caring about your situation or holidays.

 

Looking at the other end, neither do the perpertrators selling your data, and neither do the people whos leaked data is being exploited.

GDPR is a pain in the ass but it is done for good reasons, hope the GPO/GPL roles are getting paid enough to get interupted in holidays.

Posted

What happens at said primary if (for example) there's a safeguarding incident during the holidays and the DSL (or their deputy) needs to be available?

 

Or the school catches fire?

 

What does the critical incident plan say?

Posted
I agree you need to have a Data Breach Response Plan that clearly details who is available in these instances. We have a DPO email address that is a group and comes to 3 of us (two of whom are full time 52 weeks a year member of staff and don't take annual leave at the same time) and if one was away for a period of time a 4th/5th person would be added to the group such as the SLT member responsible for Safeguarding etc who is on call/rota for being around that week during the holidays.
Posted
I agree you need to have a Data Breach Response Plan that clearly details who is available in these instances. We have a DPO email address that is a group and comes to 3 of us (two of whom are full time 52 weeks a year member of staff and don't take annual leave at the same time) and if one was away for a period of time a 4th/5th person would be added to the group such as the SLT member responsible for Safeguarding etc who is on call/rota for being around that week during the holidays.

 

As with all things GDPR, this is pretty straightforward in a large school. The requirements are the same on a small primary school which has no full time staff

Posted

Do your hypotheical SLT not own mobile phones? We're in pretty much constant contact with each other even during the holidays.

 

Even if it's the BM sending everyone a photo of herself sipping cocktails on the beach in Tenerife...

Posted
As with all things GDPR, this is pretty straightforward in a large school. The requirements are the same on a small primary school which has no full time staff

 

Then we have to raise further questions about the proliferation of term-time only contracts, especially for senior staff.

Posted
neighbour tells her that her house has been broken into and her laptop bag is stolen along with some tracking documents

 

I am curious, if the neighbor reported the brake-in, but nobody new the laptop and work had been stolen until the Headteacher returns, would the 72 hour deadline not start at the point they realized it was missing, until then its just a house break-in.

Posted
I am curious, if the neighbor reported the brake-in, but nobody new the laptop and work had been stolen until the Headteacher returns, would the 72 hour deadline not start at the point they realized it was missing, until then its just a house break-in.

 

This is correct.

Posted (edited)

And if they are aware immediately (while still on holiday) that the laptop bag is stolen they they have methods to communicate with their neighbour then they also have a method to contact the ICO and say "hey, my house got broken into, pretty sure this has been stolen with X, Y, Z personal data, I'll fill in all the details when I get back in a week..."

 

I can't remember exactly where but there was definitely some stuff in the training I did that said that you need to report the breach asap but they will be sensible and reasonable when it comes to filling in every detail and/or working to rectify whatever went wrong, it's not like you have 72 hours from noticing the breach to know every detail of what is missing, contact the data subjects (if necessary), rewrite policy and procedure documents, re-do staff training, and be back to being totally compliant in every imaginable way.

 

The 72 hours is just so stuff does get reported. You can imagine without it somebody sitting on the knowledge of this laptop burglary and thinking "I'll gather all the data together that might have been in that bag and work out if the laptop was properly encrypted first so I can give a thorough report in", and then waiting for email responses from the outsourced IT contractor a week goes by, and then waiting for someone to answer one or two other questions takes another week, and the incident kinda just edges out of focus and then it becomes "ah, well that was a coupla months ago now and nobody has said anything and it's gonna look pretty bad on me if I report it this late" and the thing doesn't get reported at all. The ICO need to know that something went wrong immediately. The details can follow later.

Edited by crispybits
Posted

^^ I think you've hit the nail on the head with this one ^^

 

The most important thing is to engage with the regulator, even if it is to say you've been broken into, it's likely there may have been a breach but I don't actually know until I get home and assess the situation. I'm back on X date so will endeavour to update you by X date with confirmation if there was a breach or not.

 

There are always mitigating and aggregating factors to a situation, and if you work with the ICO, there preference is to improve your data safe guarding procedures rather than thinking how we will punish you.

Posted

This question was asked at the SSAT conference which I recently attended. The speaker from the ICO said that while the school would technically be in breach, the ICO would not normally envisage fining the school in these circumstances, as long as the school had taken reasonable steps to avoid such a breach. They do understand that not all schools have full time staff. In the above scenario I would expect the school to have put in place laptop encryption (if not prohibitively expensive), and to have clear procedures for staff on the secure storage of any confidential paperwork outside of school.

 

She said that she would expect the school to have identified risks around availability of staff for complying with data protection law during holiday periods and have made whatever plans they could to manage these risks - for example, a notice on their website requesting people to submit SARs during term time only. They do, apparently, take into account the cost of measures such as extra staff, software etc which might be the ideal answer to an identified risk - so a school could say "We know that ideally we should do x, but the cost is prohibitive, so instead we have done y and z to manage this risk".

  • Thanks 1
Posted

Just in case I've got the wrong end of the stick....

 

If I could show that a missing/stolen laptop had been encrypted, is there a breach to report? I was working on the assumption that we wouldn't need to do anything.

 

I appreciate that if the staff member admits that they also had an unencrypted USB stick and a big wodge of paper reports in the bag containing the laptop, it'd be different.

Posted

The general advice is if in doubt, log it.

 

With that said, if you know the laptop is encrpyted with a strong password/encryption algorithm, imo that wouldn't be a breach and I personally wouldn't report it.

Posted
In that case you've still lost a device that contains the data - I'd report it to be on the safe side knowing that the ICO would look at the fact it's encrypted etc - no encryption is 100% unbreakable, and humans are very vulnerable to social engineering to get passwords etc...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...