Jump to content

Recommended Posts

Posted

Hi all,

 

Has anyone had an audit on GDPR compliance and can offer any advice on what exactly they were looking for and things they picked up on that needed to be reviewed?

 

Our internal auditors have added this to the scheme of works in January so want to be as prepared as I can be for things that might not be on my radar.

 

Thanks in advance!

Posted
We've just had our internal report and although GDPR wasn't looked at specifically they did ask about our policies and how we put measures in place to protect our data. We were able to provide a copy of the policy and they were happy with that.
  • Thanks 1
Posted

Odd that Internal Audit are looking at this rather than your Data Protection Officer?

 

The DPO should be reviewing compliance regularly - checking that policies are being complied with and that required records are in place, monitoring whether they are effective, etc.

 

The ICO site lists the functions of a DPO, including conducting internal data protection audits, at https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/accountability-and-governance/data-protection-officers/

Posted
Odd that Internal Audit are looking at this rather than your Data Protection Officer?

 

The DPO should be reviewing compliance regularly - checking that policies are being complied with and that required records are in place, monitoring whether they are effective, etc.

 

The ICO site lists the functions of a DPO, including conducting internal data protection audits, at https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/accountability-and-governance/data-protection-officers/

 

I've seen internal auditors who are not specifically just financial working within schools and trusts ... covering everything from ISO9001/IiP/finance/safeguarding/DP ... often with legal and operational support.

 

I'll use those infamous words from the ICO helpine ... "It Depends!" :D

 

:getmecoat:

Posted
Just had a quick watch of the GDPR Guidance for Schools video - did anyone else notice this subliminal message .. should we all be praying ?

 

[ATTACH=CONFIG]51170[/ATTACH]

 

I’ll send that on to Iain (if he hasn’t already seen it).
  • Thanks 1
Posted

We had one on Cyber Security. Some of the things they picked up on

 

- While we have encrypted memory sticks issued to staff, we still allow unencrypted to be used (not my choice)

- They picked up on that not all doors where equipment is were locked

- Cyber security training for staff was lacking

 

Overall, we were found to have substantial assurance, which was one off their top level, so I was quite pleased.

Posted

We had a GDPR audit and totally worth it.

 

They sit down and go through everything:

-What your school does to be protected (data managers/DPO)

-Training/teasers you give to staff and how often

-Policies in place

-What progress you plan on making

-Look at your audit data sheet

 

You can ask any question and they will give a straight forward answer.

 

This was something they did over a day or two. The peace of mind alone is worth it.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...