Jump to content

Recommended Posts

Posted

Well I don't know what to think now... We have had an independent auditor in to review our data protection compliance and it isn't looking good.

 

In the year I have worked on the project which I didn't want to do in the first place I have had several major IT projects running at the same time.

 

My view we have come a long way in a year we have a breach procedure, assessment form and register, a subject rights request procedure, form and register. We have privacy notices a data protection policy, a very good draft of a retention schedule thanks to the IRMS toolkit and the DfE document. Staff are being trained in GDPR and information security and are starting to ask questions around data and whether they should send it or not.

 

Two main points the auditor has a problem with is our data mapping isn't great so our article 30 record or whatever you want to refer to it as. And 3rd party agreements my thought was that the larger company always imposes their terms and conditions on us instead of us sending them our terms and conditions around data protection... I don't know what should we be doing with 3rd party processors such as Groupcall, Go 4 Schools etc? Any ideas.

Posted

Hi. It doesn't sound that bad to me.

From our experiences most of the larger companies have sent us Controller/Processor type agreement letters stating their compliance with GDPR. This should suffice. For smaller companies you deal with such as photographers you should get a written confirmation from them. All of these things show that you are taking appropriate measures.

In terms of mapping you could put together a fairly straightforward spreadsheet outlining your various processes, where data is stored, shared with etc. If you have access to The Key they have a basic template.

Posted

Article 30 compliance is a Record of Processing Activities and you need your Information Asset Register to go along with that. It will something that you will build over time or find tools to help (usual declaration of interest here as we do stuff in this area).

 

As a Data Controller you will get contracts / T&Cs / DPAs from suppliers (where they are your data processor) and you work out what data they need to use to deliver youthe service ... but you are making the choice on that. Ulitmately, the choice is to use a different supplier / tool! Groupcall, etc. generally have that available for you. Where there is shared decisions on the data use then you are joint DCs ... and so on. Your auditor will be interested if you have worked all of this out. Did they mention anything on risk assessments? DPIAs?

 

The rest of it ... sounds like you are making some good progress.

  • Thanks 1
Posted

Doesn't sound too bad to me.

 

For your information audit, good starting points are a) what products do teachers ask for assistance getting student names into? b) meet with all HODs and key admin personnel and ask them who they share data with. Keep reminding people about b, as there are various data submissions which only happen once a year so might be overlooked when you ask.

 

As for the data sharing agreements, our DPO also says we should contact ALL our processors and ask them to sign our terms. Of course in reality, Google, Microsoft, Capita, etc. are never in a million years going to sign your contract, but apparently the fact you've sent it is sufficient. Personally, I think a review of their data protection and privacy notices is better, but there you have it.

Posted
I agree, you have made great progress with what you already have in place. I've looked at it as an on-going project and to increase compliance over time
Posted

Hi all,

 

Sorry for the silence on this, been rather busy since I posted this.

 

So the auditor in the end said we have every document you could need under the GDPR just they aren't quite finished or some of them don't contain the correct wording. The A30 record it has been recognised does need to go out to department heads really to be filled out in more detail so not to bad.

 

As for the 3rd party stuff he didn't seem to impressed that all we had were the T&C's that came with the service as my thought process always has been we would agree with the 3rd party wording. He wanted us to have submitted our T&C's for data protection and even if they refused them then he would have been happier with it.

 

Other than that I'm just trying to push GDPR up to our compliance director who is higher up the picking order than me and therefore will have more clout in the academies to get things done which is where I have struggled. Also working on re-wording policies so that the department responsible is the exec not the IT department.

Posted
I forgot to mention they didn't look at any of the DPIA's we had done, we still have a few to do but we have the majority of our systems done.
Posted

"As for the 3rd party stuff he didn't seem to impressed that all we had were the T&C's that came with the service as my thought process always has been we would agree with the 3rd party wording. He wanted us to have submitted our T&C's for data protection and even if they refused them then he would have been happier with it."

 

 

This is where I think that is rather unreasonable for schools to have to contact all 3rd party companies and ask for them to agree to terms. What would make life a lot easier is if ALL 3rd parties would take the checklist that the ICO publishes regarding data processor responsibilities and provide answers/statements confirming that they comply. Too many bury the answer inside one or more documents on their website (privacy notice, data sharing agreement, terms and conditions etc.). Some don't provide the information until you actually take out a contract with them, which makes it very difficult to carry out compliance checks before adopting the software.

Posted

As for the 3rd party stuff he didn't seem to impressed that all we had were the T&C's that came with the service as my thought process always has been we would agree with the 3rd party wording. He wanted us to have submitted our T&C's for data protection and even if they refused them then he would have been happier with it.

 

I agree with you. To me, it seems really odd to say "we've seen how you want to process our data and we don't like it, so we've suggested an alternative... but you can keep doing it your way for now, possibly for ever if you choose to ignore our correspondence".

Posted

Below is the scope that was sent by the auditors, which should give an idea of what they wanted to see.

 

 

1.1 Scope of the review

The scope of the assignment has been agreed by management as follows:

1 Business processes and data discovery

Based on the documentation and information provided inspection of the management control processes designed to identify and document all in scope data across the organisation. Related data inflows and outflows focussing in particular on:

· the existence of process and data mapping;

· processes to classify data;

· identification of data flows to third parties; and

· methods of data storage and transfer.

2 Third parties

Based on the assessment set out at (1), we will carry out the following:

· inspection of the methods used to identity third parties to whom the ‘in scope’ data is transferred.

· identification of methods used to assess contractual data confidentiality existence and coverage.

3 Data ownership

· Based on the documentation and information at 1 above, note the existence of processes used to identify/allocate data owners.

4 Data security system level controls

· Test data security controls agreed by you over data inflow, data repository and data outflow and report results by reference to recognised good practice.

5 Data storage and retention

· Based on documentation and information at 1 above, comment on the existence of data retention and storage policies.

6 Awareness

· Based on the documentation and information at 1 above, comment on the existence of GDPR awareness processes.

7 Data policy, roles and responsibilities

· Based on the documentation and information at 1 above, comment on the existence and scope of current data policies.

· Based on the documentation and information at 1 above, comment on the existence and designation of data protection roles and responsibilities.

· Comment on current roles by reference to recognised good practice.

8 Individuals’ rights

· Based on the documentation and information at 1 above, comment on the existence of procedures for updating, deleting, and reporting personal data at department and organisation level.

9 Consent

· Based on the documentation and information at 1 above, comment on the existence of processes in place to capture data consent.

10Data breaches

· Based on the documentation and information at 1 above, comment on processes in place for the detection, reporting and investigation of personal data breaches

 

 

1.2 Limitation to the Scope of our work

[TABLE=width: 699]

[TR]

[TD]· The assignment is delivered as ‘agreed upon procedures’ and therefore will not result in a formal assurance level or opinion.

· We will not confirm compliance with GDPR and/or provide any legal or regulatory advice.

· Our work does not provide absolute assurance that material errors, loss or fraud do not exist.

Please note that the full scope of the GDPR assignment can only be completed within the budget if all the requested information is made available at the start of the assignment, and the necessary key staff are available when required. If the requested information and staff are not available, we may have to reduce the scope of our work and/or increase the budget. If this is necessary, we will agree this with the Chief Financial Officer during the assignment.

[/TD]

[/TR]

[/TABLE]

 

 

1.3 Requested documents

To enable us to commence our fieldwork on the agreed start date, we will require access to the following information or records in advance of the assignment start date:

· Full listing of IT systems that manage data which falls under the scope of GDPR;

· Documentation and evidence of data mapping including a listing of designated data owners mapped to the data for which they are responsible;

· Documentation and evidence of third party contract data confidentiality assessment(s);

· Documentation of processes used to capture data consent;

· Key policies and procedures relating to data policies and procedures;

· Data breach incident response procedures;

· GDPR / data governance awareness programs; and

· Data Protection/GDPR role job descriptions.

Posted
We use an independent data controller and at no time have they asked me about backup retention or what data we send to third parties. Dread to think what an audit would say about us.
Posted
We use an independent data controller and at no time have they asked me about backup retention or what data we send to third parties. Dread to think what an audit would say about us.

 

You DPO hasn't asked you who you share data with?!

Posted
You DPO hasn't asked you who you share data with?!

 

The office manager has been dealing with the data controller and the only contact I've had with him was on inset day when I sat and listened to his speech.

Posted
The office manager has been dealing with the data controller and the only contact I've had with him was on inset day when I sat and listened to his speech.

 

This gets worse! So not only have they not asked about third party data sharing, they've not asked about any IT practices?!

Posted
I don't know how much but I'm sure a private company wouldn't do it for free.

 

I don't know about that. Given what they seem to have done for you, free might be the fair price! That, or your office manager has been answering all their questions without speaking to you.

Posted
Probably the latter.

 

Hopefully your office manager understands the questions, and knows enough about the technology to be able to answer them.

  • Thanks 1
Posted
We use an independent data controller and at no time have they asked me about backup retention or what data we send to third parties. Dread to think what an audit would say about us.

 

You mean an external DPO?

 

They cannot be data controller ... only the school / trust can be data controller (including where they are joint data controller).

Posted
You mean an external DPO?

 

They cannot be data controller ... only the school / trust can be data controller (including where they are joint data controller).

 

Yes DPO.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...