Jump to content

Recommended Posts

Posted

Hi,

 

I'm swimming under the GDPR wave as I dont seem to be getting much help but hey ho.

 

I've currrently

 

Updated our Privacy policy inclusing age specific ones

Renewed all consent for photos

Updated and distributed new AUP policies for staff and pupisl (age specific again)

Created new policies including Data Retention, SAR, Data Breach - still need to do a data controller one.

Created a data control map inclusing SIMS premisisons

Enabled MFA and Bitlocker for data protection.

Using GDPRis to record suppliers

 

I'm struggling with the data audit, I know where everything is and my data control map shows the flow of data but how are you guys recording this? Is it server by server?

Also consent, what other consent are you collecting.. I've got the photo consent and AUP for computers. Should I be collecting consent for “special category” personal data aswell.

 

I got this from our Bursars website

 

(This cannot be covered by “legitimate interests”, nor the parent contract: it might be lawful if the school is acting under a statutory right or obligation, including in connection with employment or some other duty of care; or if urgent e.g. medical grounds exist; or if it is covered under one of the special conditions of the Data Protection Bill concerning safeguarding or social care)

 

I have done staff training but not the governors yet.. or appointed a DPO.. no one is looking at this so I want to outsource it.

 

Anything else I'm missing?

 

Really appreciate any help

Posted

Two options for approaching the data map, I think. Either make a list of every staff member or a list of every application and web service (start with a conversation with Finance to see who you pay, then ask the HODs about free ones). Then for each one, go through the Ws - what information do they handle? who do they share it with? why do they share it? where do they keep it? If you're going by application, you also have who internally has access to it?

 

As for recording it, we went with the LGfL template which starts with the data item, i.e. the "what" (e.g. student medical information") then has columns for the other Ws. We considered grouping it by the internal person responsible, but found that duplicated a lot of rows due to the number of different people who handle medical information.

 

You will then need to show the audit to every HOD and senior admin person, as you will undoubtedly have missed some. The HT and I did ours, but we still managed to miss key areas!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...