Jump to content

Recommended Posts

Posted
I have been asked about the time frame on responding to a SAR during a school holiday. The school have been told that as it's a holiday they can basically "ignore" the request until they school term starts as they are not in school they can say they didn't receive it till the first day back and start the 30 days from there, I'm a bit sceptical about this advice and wouldn't like to put it in practice, anyone seen anything to support their argument?
Posted
It’s a similar discussion to the one I opened on data breaches, in a large school with AYR staff there’s no reason to not fulfil the request in a small primary with no staff, other than a caretaker around, it’s not achievable. Common sense has to prevail.
Posted

Common Sense!!! thats hopeful :-)

My concern is that the response they would take is that if the DPO is not picking up emails about SAR requests how are they picking up any emails about Data Breaches during the holidays to be able to report them

Posted
Common Sense!!! thats hopeful :-)

My concern is that the response they would take is that if the DPO is not picking up emails about SAR requests how are they picking up any emails about Data Breaches during the holidays to be able to report them

 

A data breach would likely be reported up the line management structure to SLT who would phone the DPO.

Posted

Our advise was to notify up front that any requests during holiday periods would be deemed complex (due to unavailability of all staff involved) and so would be responded within 2 months.

 

This was endorsed by our LA legal team as an acceptable solution.

 

They didn't not offer any similar solution for the matter of breach reporting in holiday times - the standard timescales apply to these at all times.

Posted (edited)

There's nothing in the GDPR or Data Protection Bill that I can see that exempts a data controller from the response times just because your staff are all on holiday. As it's the ICO that'll be enforcing this kind of thing, I'd say the best thing to do is ask them how they'd view this situation.

 

edit: crc-ict's solution seems to me to be a good one.

Edited by djrscally
Posted
I would guess it also depends on what the SAR asks for. "Please give me all the information you have about me" is a very different and more complex request than "what contact details do you have on file for me" - I think it's reasonable that whoever is acting as DPO would have, or would be able to call on someone who has, access to information like just current contact details within the 30 day timeframe even in the holidays. The summer holidays is 44 days long, but do even the smallest schools shut down completely over that time? Isn't there someone in the office for a day here and there dealing with admissions / progressions to other schools or paying bills and invoices with 30 day payment terms, etc? I think it has to be a case by case thing.
  • Thanks 1
Posted
I got told by the ICO for schools its 20 school days or 60 "normal days". I've not seen them out right publish this in guidance but this came from their FOI representative.
Posted
I have been asked about the time frame on responding to a SAR during a school holiday. The school have been told that as it's a holiday they can basically "ignore" the request until they school term starts as they are not in school they can say they didn't receive it till the first day back and start the 30 days from there, I'm a bit sceptical about this advice and wouldn't like to put it in practice, anyone seen anything to support their argument?

 

Basic practice needs to be considered: if a data breach has occurred, surely some one will be investigating it? Unless the school is completely closed and no one is reachable.. well technically no one will know about the breach anyway?

 

Whats the procedure for a fire or a break in etc?

 

This is a question we have not been given a direct answer on either but the ICO seems willing to be flexible according to their videos (not answered this particular question though).

 

Not sure how many schools do a complete shutdown throughout the holiday but in my experience there is usually an SLT member on site enough to follow procedure?

Posted
The advice I was given at a course was to make sure everyone has an out-of-office message pointing people with SARs to one of the addresses which is checked over the holidays. They also said in reality the ICO aren't likely to be issuing fines to schools for late response to SARs which come in over the holidays, as long as you do it within 30 days of someone seeing it. Personally I preferred their first bit of advice!
Posted
The summer holidays is 44 days long, but do even the smallest schools shut down completely over that time? Isn't there someone in the office for a day here and there dealing with admissions / progressions to other schools or paying bills and invoices with 30 day payment terms, etc?.

 

We have people here year-round, but I do know some primaries which shut down completely expect for Head's PA a few days before term restarts. Even if there were someone in to pay bills, etc. they might not have the expertise or permission to respond to an SAR - it takes quite a high level of access across SIMS and the network, remember.

 

There's an interesting thought, actually - who in your school, outside of IT, has the ability to access and compile everything needed for a "give me everything you have on me" SAR?

Posted
I've done my internal ICO FOI training with the senior policy advisor for FOI and asked that question - she confirmed that for schools they allow 20 school days or 60 working days which ever is shorter. I asked about putting on an auto-reply saying the school was closed so please fwd your email to X person, the line was that once the request is submitted that person shouldn't have to do anything else so they wouldn't be under any obligation to do so.
Posted
I've done my internal ICO FOI training with the senior policy advisor for FOI and asked that question - she confirmed that for schools they allow 20 school days or 60 working days which ever is shorter. I asked about putting on an auto-reply saying the school was closed so please fwd your email to X person, the line was that once the request is submitted that person shouldn't have to do anything else so they wouldn't be under any obligation to do so.

 

Those timescales are the case for FOI requests, yes. This is defined in the Freedom of Information act though, which is separate to the GDPR.

 

Subject Access Requests and Data Breach Notifications under GDPR operate with different rules unfortunately. With no concession for schools on the response time.

Posted
Those timescales are the case for FOI requests, yes. This is defined in the Freedom of Information act though, which is separate to the GDPR.

 

Subject Access Requests and Data Breach Notifications under GDPR operate with different rules unfortunately. With no concession for schools on the response time.

 

Yeah I agree they fall under different frameworks of the law but the logical decision behind it is still the same. Why does the ICO allow schools extra time for FOI request? They do so because they realise it will not be practical for a school to complete the FOI under the same terms as, lets say, a local authority. The same would be true for SAR, if the ICO accept its unrealistic for a school to fulfil a FOI because they are shut, it follows the same would be true for a SAR.

 

The data breach is slightly different, my advice for a data breach would be to engage with us as much as possible. There has never been a time when I've heard the ICO say "tough, we don't care what your mitigating circumstances are, that's the law and if you don't follow it we will fine you". We take reasonable and pragmatic approaches given the circumstances, taking into account what the data is, who the controller is, the mitigating factors, the aggregating factors etc.

Posted (edited)

Just finished my GDPR Practitioners course, no exceptions for anyone!

 

SAR MUST be actioned within 30 calendar days (not even working days) We were told (again by a speaker from the ICO) that we must have in place the facility for staff to be recalled in the event of a SAR

Your only clock stopper is validation of the data subject as step 1 is recognition you've had a SAR, followed by verification of the subjects identity...by means you see fit....

 

Steve

Edited by Ex-MGSTech

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...