Jump to content

Recommended Posts

Posted

Dont shoot the messenger.

 

According to ISBA with the backing of Farrar and Co for legal advise Independant schools 'probably' wont need a DPO.. but rather have a Privacy Officer or simialr named position.

 

Extract from their document...

 

The ICO acknowledges (as it did at the ISBA Cyber Security conference in October 2017) that for independent schools this position is by no means certain. Neither the GDPR wording nor the current EU working party guidance discloses a clear basis to suppose that most independent schools would be intended to be caught by the strict requirement.

This is contrast to the much clearer position with maintained schools, because all public authorities do indeed require a DPO. It may be that a single individual DPO will affix to the local authority as a whole rather than to each school, according them a degree of independence (as well as being cheaper of course, allowing oversight of numerous maintained schools): but this will depend on levels of access and capacity to deal with issues. As set out below, there may be lessons to learn for independent schools in observing what works best

 

Any other Independant schools in a similar position?

Posted
Our Bursar had been told (possibly through ISBA) that we don't need a specific DPO but that he would be the "lead" for any situation involving a GDPR issue. So, he's basically the DPO but ignoring the lack of training and the conflict of interest...
Posted (edited)

I presume this is because the GDPR states there are certain situations where a data protection officer must be designated. The one that is particular to schools is that if you are a public authority you must have a DPO in place.

 

This wouldn't include independent school as they are not a public authority, they are private.

 

But, there are other times when you require a DPO. For example, if you process large scales of special category data. If the private school is large, they could well need a DPO because of this, depending on how you interpret "large scale". The other criteria where a DPO is required is if the school regularly or systematically monitors data subjects on a large scale - again most schools do but a small private school may not need to because they are not doing it on a large scale.

Edited by Edutech98
Posted

The advice and that extract is a little out of context as the wider piece ISBA have advised on is around correct practices, as I understand it.

 

They are correct that the formal DPO role is not stipulated as applicable to them as they are not public authorities and they advise against appointing one (once appointed then the DPO role has to adhere to the roles and responsibilities as aligned to the GDPR guidance from folk like the WP29 group and as set out by ICO as a result).

 

By having a ‘lead’ they get around some of the restrictions including being more relaxed on restrictions due to conflicts of interest.

 

It will be an interesting world for independent schools ... and until issues arise some will take a more *relaxed* approach as a result ...

Posted
We're the same, our bursar remains as our data protection lead - there isn't really enough work to justify a full time member of staff (380 students) or at least there won't be once we've finished getting policies into place etc
Posted

We have deliberately not assigned a DPO based on the same advice. I've been to ISBA, Farrer and Veal Wasbrough seminars and they are all in agreement. No-one in a typical independent school has someone with the skills required for the job and no-one (me especially) wants the liability with no upside.

 

I am project managing GDPR through and I can tell you it's like walking through treacle trying to get staff to understand new procedures or sympathise with, say, enforced encryption of USB sticks.

Posted

Having worked in an independent school as assistant bursar, I can honestly say that if anyone is likely to start legal action it is private school parents.

 

They will be very intolerant of any breaches of GDPR. If the schools have any sense they’ll appoint a DPO and do things properly.

 

I have seen a few of the big independents advertising for “Compliance Officers” to ensure compliance with GDPR, H&S and the other legal compliance areas so they aren’t all following ISBA advice

Posted

Yes, but DPO is a specific position recognised by the ICO. Compliance Officer is just the person ensuring GDPR compliance (which is pretty much what I'm doing).

 

There's an important distinction.

Posted
Yes, but DPO is a specific position recognised by the ICO. Compliance Officer is just the person ensuring GDPR compliance (which is pretty much what I'm doing).

 

There's an important distinction.

I should have been more clear.

 

The roles advertised have said the duties of compliance officer combines that of DPO with other compliance roles... I think it’s a way of making the DPO a full-time year-round position and possibly more attractive as a result.

Posted
Indeed, our person leading on GDPR is our Compliance Officer, but the job wasn't created specifically w/ GDPR in mind, but rather compliance with all of the ISI regs/guidance, H&S, etc., etc.. She is very specifically not our DPO, and we do not have a DPO (as per guidance mentioned above). I think this is probably pretty much the standard across the independent sector, until such time as guidance changes or precedents are set that suggest there is more to be gained than lost in having a voluntary DPO (or that some schools are big enough or data processing is "core" enough to make it a legal requirement to have one).
Posted

I heard something like this a little while ago - one of those things that never got confirmed or denied...

 

No matter what - have a lead on data, DPO or something similar. This covers you.

 

Our SBM is still the DPO and we've still NOT got a definite answer he can/can't be it (even though he's line manager to multiple data crucial staff/areas). The one thing that popped up was to separate him self when needed.

 

I think the best thing to do is have a leader as a DPO or similar. Show you are moving forward and working towards GDPR compliance.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...