Jump to content

Recommended Posts

Posted

Hi all,

 

I know there's a variety of threads regarding various internal school staff being designated as the DPO, so my apologies if this goes over an already discussed topic.

 

As usual our school has left things till the last moment, and this evening I've had a call from the head asking me who would be a suitable temporary DPO until they buy some support in. Eventually it settled (mostly directed by the head) on my colleague in the IT department, as there doesn't seem to be anyone else suitable. I'm not happy nor convinced this is the best choice for the DPO role, but the head has given the following reasons:

  • Any data-related tasks and permissions could be removed from their job (e.g. no access to SIMS) but can still perform tasks like resetting passwords and fixing hardware
  • It would only be a temporary position until there is someone appointed
  • They are already aware of the systems that we use and how they are set up
  • All other staff in school need to use data in some way for their day-to-day job (teachers, LSAs, admin). The maintenance department doesn't, but they don't know enough about how data is used in school to be suitable
  • The DPO role will mostly be watching a mailbox for any email requests (paraphrasing a bit here), with a weekly meeting with the head advising him of any compliance issues and changes to be made as to how data is used

So far I can come up with the following arguments as to why it won't be suitable:

  • I am aware the DPO cannot be the NM, but I'm not sure about IT technicians (we essentially do the same job, I've just been there longer). Various agencies who have given basic staff training have said that it can't be anyone from the IT department
  • Once various access permissions are removed it's essentially now a different role, but then I'm not sure how they would then be able to do most of the IT jobs logged
  • They haven't been on any training for a DPO role
  • If there is an IT-related data breach, they would sort-of be investigating themselves
  • My colleague will be on holiday next week (half term) so there won't be anyone monitoring for requests (unlikely we'll get any, but we do have a few parents who like to cause problems)
  • Personally it doesn't feel right to have the role "forced" on them (I'm assuming there won't be any financial incentive to take the role either, as it hasn't been mentioned, but that's a different discussion to have)

Does anyone have any suggestions as to why this wouldn't be a suitable option, or have I got some bad news to break to my colleague in the morning?

 

(Thanks in advance for any responses, I appreciate it's late-ish when I'm posting this)

Posted
The DfE guidance states the DPO needs to expert in data protection law and IT security, understand how data flows across school and also to be in a senior position in school with enough clout to tell people what to do and to be listened to. Is your technician all of these. If not then he can't be the DPO. Could be worse, we have the same issue as you, SLT have left everything till last minute and now panicking, we've no DPO, head teacher tells me she will do it temporarily.
Posted

The guidance since around Christmas has been that as long as the school has made a start, and has some idea of what it is doing, nobody is going to get into too much trouble in year 1.

 

However you need a DPO and of all the internal candidates your Tech is probably the least worst option right now. Flag you concerns. get documented concessions. Make sure the SLT and the interim DPO have a RAG existing compliance issues (the acting DPO being one of them!) This checklist is a good start. Get a Privacy Notice up. Then get an outsourced DPO, which shouldn't take more than a few weeks.

 

The Head *MUST* work the half term to procure the permanent DPO.

Posted

I think this is the big one "•If there is an IT-related data breach, they would sort-of be investigating themselves"

 

It would not be in the interest of the DPO to report a breach if they knew the breach was caused by something under their remit. I don't know the stats but I'd be willing to guess most breaches occur with some sort of technology involved in them. I wouldn't report a breach if I knew I was partially responsible for it, I'd be more likely to sweep it under the rug and "forget" about it. Likewise they may feel under pressure not to report a breach relating to tech if they knew this could effect their direct line manager. Imagine reporting your direct line manager then a week later having your performance review with them :D

Posted
I think this is the big one "•If there is an IT-related data breach, they would sort-of be investigating themselves"

 

This should be covered up front in the agreement with the HT around the temporary nature of the role assignment. The IT Tech would recuse themselves from the investigation. Data breach investigation is a paid for additional for all outsourced DPO services I've seen, so this wouldn't be hard to bring in a third party for this.

 

The risk to the organisation for having an unreported breach discovered in an audit is almost certainly dramatically worse than the fines/remediation that would be levied on prompt reporting. Nobody in a school should be fired for a data breach if they haven't had the training - and in this case I'm pretty confident that the school has not adequately trained its staff at this point.

Posted (edited)
I think this is the big one "•If there is an IT-related data breach, they would sort-of be investigating themselves"

 

It would not be in the interest of the DPO to report a breach if they knew the breach was caused by something under their remit. I don't know the stats but I'd be willing to guess most breaches occur with some sort of technology involved in them. I wouldn't report a breach if I knew I was partially responsible for it, I'd be more likely to sweep it under the rug and "forget" about it. Likewise they may feel under pressure not to report a breach relating to tech if they knew this could effect their direct line manager. Imagine reporting your direct line manager then a week later having your performance review with them :D

 

Surely that's the exact reason the DPO needs to be someone with enough seniority/clout to not end up being in the position of having to take action against people who are effectively their line managers and those who outrank them? As you say nobody who wants to be in a job for long is going to report a breach or take action where it implicates their line managers or senior management and puts their own position at risk. Giving someone like a technician that level of responsibility without the authority to go along with it is surely just setting them up to take the fall when something goes wrong?

Edited by flyinghaggis
  • Thanks 1
Posted

What I was trying to say is:

It is a temporary assignment, a breach is unlikely during this time.

Nobody has been properly trained - so nobody is going to get fired.

Recusal in the event of a conflict of interest is a normal.

A 3rd party consultant can be called in to manage/guide the process.

 

 

As long as the HT is working to get an external DPO put in place a soon as possible (they should be able to appoint by mid June TBH), they understand the legal obligations placed on the interim DPO, and this is all covered in writing (and checked by HR/Legal) there really shouldn't be a problem.

 

It would be more of a problem to not have a DPO at all.

Posted
Our school's approach has been "who in the school doesn't process data?" The site manager? ok, we'll announce in staff briefing that the site team manager is now the DPO.
Posted (edited)

Maybe it would be a good idea to list the tasks of a Data Protection Officer and then put a note next to it why a tech wouldn’t be suitable, something like:

 

a) To inform and advise the school of the data protection obligations – Tech is not trained so wouldn’t be able to do this.

b) To monitor compliance with this regulation – Tech doesn’t know enough about the regulation so how can they monitor. They would recuse from investigation about tech breaches which we are presuming are pretty much how all breaches occur

c) To provide advice and guidance – The tech doesn’t know enough about DP to do this and may cause more problems than they resolve with doggy advise (at no fault of the tech!)

d) To cooperate/act as the contact point with the ICO – would recuse from contacting them about anything tech related, which we are presuming would be the majority.

 

 

Maybe it would be better to just not have one for the time being, and any DP concerns go straight to SLT. I’m imaging which would be better, to let someone loose on a server with little to no training and get them to fix the problem, or just leave it till someone that knows what they are doing comes along.

Edited by Edutech98
Posted (edited)

As usual our school has left things till the last moment, and this evening I've had a call from the head asking me who would be a suitable temporary DPO until they buy some support in. Eventually

 

Does anyone have any suggestions as to why this wouldn't be a suitable option, or have I got some bad news to break to my colleague in the morning?

 

- GDPR isn't just about electronical data, he/she will still need to understand what other jobs involve. This includes personnel, finance, attendance, SEN and data managers.

- GDPR is about understanding all data and IT knowledge is a bonus not the priority.

- Does the technician have administrator access? As a DPO & techie he/she would have keys to everything electronically which is questionable and could seriously be a conflict of interest. Main reason why we can't be the DPO is because of all the 'god' access we have. If your techie has the same level.............. he is no different to an NM..... the conflict of interest isn't about 'budget planning' or that you build/install a server.... it's about the data related issues.... it's about data security.. access to the logs.. the backups.. the data areas.. we really do hold all the keys (so do all my technicians).

- Discuss with a union because the technician would have a altered job description/contract change? So technician could refuse - causing a restructure of the IT techie job by the HT.

- That Technician will have the authority to investigate every member of staff and have the final say on what's considered to be breaches etc. This means he/she can over rule the HT on DPO matters.

- Also the authority to risk assess and tell people to be safe etc

- Able to raise matters with the Governors.

 

It's possible but JD/Contracts need to be resolved between employer/employee along with the conflict of interest roles.

 

Remove administrator access, remove the techie ability to have data access - effectively just another member of staff...

 

P.s. Ask your self this.. would he/she have to investigate their own position... I'm assisiting our DPO but I can't be it.. I can help make sure my guys are following simple staff procedures but also.. we take extra care because we are 'gods' of data.. likewise for the Data Managers etc. There are currently about 15 staff here that can't be the DPO and my team are 3 of them.

Edited by mthomas08

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...