Jump to content

Recommended Posts

Posted

I have a few issue with both the stats and the article.

 

Once again, Schools Week take a swipe at DfE on data protection without taking into account the history of what has gone on, where volunteers are actively involved in doing things and where priorities have been. Anyone would think it is political opportunism to take a swipe.

 

I would rather there are good news stories about guide practice, designed to raise people up rather than fear monger and slap people down. I’m not saying things are perfect, but maybe I’m a glass half full person.

 

As for the stats, ICO have not provided this in their disclosure log so it is unclear where those stats are from. I have an updated FOI request in at the moment to see if we can get the same data set and do a bit more drilling into it.

 

What we do know though is where no action is required is because the school may have already dealt with it, and ICO is taking no further action. That severely skews that stats when you take it into account.

Posted

The article is not very good at all. This section in particular annoys me:

 

Almost half the ICO’s GDPR school cases were self-reported, while the rest came from third parties. Of the 665 self-referrals from schools, about 80 per cent required no action.“It does reflect a misunderstanding of what the GDPR actually means for schools,” said Mark Orchison, the managing director of 9ine Consulting, who believes the number of reports to the ICO will increase.“It may be that the schools that are self-reporting just don’t understand what they’re doing,” he said, as he called for more schools to “upskill” their staff.“If you don’t know whether it’s a breach, you’re likely to report it because you don’t want to get told off. But until you upskill the profession to understand the difference between a breach and a near-miss, you’re going to continue to see a high level of reporting of potential breaches.”

 

We make up 2 of those schools that self reported, with no further action required. 1 report was due to a widespread phishing email scam that a number of staff had clicked on and logged into. No action was required as we had already disabled the accounts, had them checked, checked all machines for malware, changed passwords and then implemented a new training programme - all staff now undergo online phishing/gdpr/malware etc... training.

 

The other one was a laptop that had been left on a pavement. The laptop was encrypted, but we weren't sure if the case also contained personal information that was printed out - the teacher wasn't sure if it contained reports and a diary. We reported it because it could potentially have been a breach. Luckily, we got the laptop back 2 days later as the person's neighbour had found it and got it back to her. No further action required because we got it all back and the case turned out to not have any personal data printed in it.

 

Both were most definitely requiring reporting. We certainly didn't report prematurely, and the ICO were clear with that also.

  • Thanks 1
Posted
Schoolsweek have a good track record of poor reporting, bias and factual errors.

 

But there are times when do it really well ... that’s the thing that annoys me so much.

 

As already shown though, there is a different story behind this and the experience schools are seeing.

 

Hopefully, over the summer, we will be able to get the full picture and dive in a bit deeper to point out areas that schools can work on.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...