tubbsy Posted May 22, 2018 Posted May 22, 2018 Am I the only one here who receives little support from the head, SLT or key staff members regarding GDPR. I am the Director of IT (roles include, network manager and some business manager roles) with one techie. We have purchased our LA DPO service costing £1000 where all we seem to get are emails with bulletins and tasks to do before the 25th May. One of these many tasks is the massive job of data mapping - I've been adding data to this on and off for nearly 3 weeks now. Anyway - I asked for a meeting with a governor, head, an SLT member and a member of safeguarding as recommended by a GDPR trainer a month ago. The only staff who turned up were the head and safeguarding lead and I was given 15 minutes of their time and didn't feel any further forward really. The purpose of the meeting was to discus GDPR and what needed to be done - like changing policies, staff handbook, privacy notices and go through some of the data mapping. We touched on Policies and that was it. I have had to email the head with MY example of a privacy notice to go on our website for him to check and send back with a yes or no. I am trying to get this GDPR sorted with a mountain of paper work to read through at the same time as making sure the network is running smoothly etc etc. What do you recommend I do? Please help!
elsiegee40 Posted May 22, 2018 Posted May 22, 2018 (edited) Who is the DPO? (Hopefully not you) You need to get hold of them (by somewhere painful like the size of the fine if necessary) and get them to do their job. If SLT isn't doing their job it smacks of poor training and leadership. If you have no DPO, put your concerns in writing, do what you can to ensure that your piece of the puzzle is compliant and wait for brown stuff to hit the fan. Edited May 22, 2018 by elsiegee40 2
tubbsy Posted May 22, 2018 Author Posted May 22, 2018 Thank you for your reply. Our DPO is at the local authority and we pay for their support. I am the school's Data Protection Controller (sprung on me in March) and am supposed to oversee that all this GDPR is adhered to I presume. The LA has two DPOs one who works Mon-Wed and the other Thu-Fri and each time I call I get told they are in court, at a meeting or just not in today and could I email. If I email, I'm lucky to get a response the same day in fact their automatic response says the words 'we aim to respond to your query with 48 hours'. No good if you're writing an AUP to be passed the same day! Would be good if anyone on here could post their Data Mapping Tool though. The GDPR website is good and does explain the terms in detail but it's which terms to use and when. All the best
CC359 Posted May 22, 2018 Posted May 22, 2018 You are not alone. I'm at a small school so I took the initiative to do the research, carry out audits, make records, propose changes in school operations, and re-wrote or created some policies from scratch, and have simply been emailing updates to the SLT as I've gone along. I've been at it for a year so colleagues eventually realised what I was doing and why it was important. Nobody here would've had the time to do it otherwise and I get the impression that in most places people hear the word "data" and just assume it's an IT issue. I believe my school has also bought into your LA's DPO service so I'm waiting to see what they can actually do for us when a situation happens where the school calls on their support - advice on something legal, or a data breach, etc. 1
mavhc Posted May 22, 2018 Posted May 22, 2018 Sounds like you need to threaten to resign the DPC job as you can't do it without proper cooperation, that'll get their notice. 1
edmokeski Posted May 22, 2018 Posted May 22, 2018 I thought that NM responsibilities were viewed to be a conflict of interest with these GDPR roles? Or is it just that an NM can't be DPO, but can be data controller? 1
tubbsy Posted May 22, 2018 Author Posted May 22, 2018 Hi yes I can be the controller but not the officer. The officer can not be anyone in school who has access to any data but the controller can. I am now looking at purchasing GDPRis - a tool which does most of the hard work for you - apparently!??
Edutech98 Posted May 22, 2018 Posted May 22, 2018 The data controller is the school rather than an individual. If someone is asking you to be the data controller you can go back to them and tell them this isn't possible. I'd email the DPO with your concerns and cc SLT into it. If you don't get any reply all you can do is make sure that the IT side of things are secure. Look at Article 32 which details the security requirements. Then document all your procedures such as access controls, encryption, update processes etc. I hate washing my hands with things because I care, but if you don't get the support from the top you are destined to fail. I try too pitch it in the same way as you would child protection as they go hand in hand - stress your protecting data to protect the children as well as staff's personal data. 1
tubbsy Posted May 22, 2018 Author Posted May 22, 2018 Thank you Edutech98 for this much appreciated and I really appreciate all the messages from you all. If anyone has a completed or part complete data mapping tool or alike I can view but not copy would be good please.
mthomas08 Posted May 23, 2018 Posted May 23, 2018 (edited) What do you recommend I do? Please help! I think it's time to start giving them examples of the type of fines occurring. I'd also do my own risk assessments that if a potential breach occurs you will have no choice to report it. I was able to do a list and present it to the DPO.. it was long.. Although I doubt the fines will be huge for education, it will occur and it'll be in the sum of £100K+. And even worse if it hits the press/social media. On the GDPR training there is a big bullet point on "Need support from SLT". I could send you a copy of our data mapping spreadsheet. I've worded it in a way that makes sense to me and the DPO while still understandable by a GDPR auditor. PM me if interested. I'd look at getting an auditor - don't know what any tools are like, we didn't use them but the audit was incredibly useful. We got a report simply stating we are on course very well to be GDPR compliant. The things we are finalising should cover us being compliant. We just have to continue to prove we are covering future angles, new staff training and refreshers, while also doing site walks to double check people are listening and understanding. Edit: I'm surprised the LEA DPO don't seem to be that bothered? you are paying for a service? yet not getting one? 48 hours to respond when there is a 72 hour time limit for reporting breaches? giving them 24 hours to do something about it? Maybe shop around and see if you can get something better... the DPO in my view should be there telling the school to get their act together. And you'd think they would listen more to an LEA DPO if they refuse to listen to you.. you've got a challenge though.. Edited May 23, 2018 by mthomas08 1
tubbsy Posted May 23, 2018 Author Posted May 23, 2018 Hi, thank you for your response this is a big help. I'll send you my details if you would be as so kind to send the data map. THANK YOU !
edmokeski Posted May 23, 2018 Posted May 23, 2018 Greenwich University fined £120,000 for data breach - BBC News £120,000 fine for Greenwich University can be your first example. And this was issued under the "lenient" pre-GDPR rules! Fines under GDPR have the potential to be orders of magnitude higher. 1
JordanT91 Posted May 24, 2018 Posted May 24, 2018 Our LA DPO (through an SLA) is visiting us at the end of June to provide guidance. So far, we have done nothing towards becoming compliant other than taking away the visitor sign-in book and replace it with sign-in slips. Nobody can be bothered to make a start without the DPO (assigned to us last week and only works 3 days a week and I'm guessing has very little time to dedicate to DPO duties based on their official job title), so there has been no data audit and therefore no privacy notices or anything. The funny thing is nearly a year ago, when I found out about GDPR, I told the business manager and headteacher that it would require a lot of work to become compliant and that they should look into it as soon as possible. Instead they've just been waiting for the LA to get up to speed, which is never a good idea!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now