Jump to content

Recommended Posts

Posted

Hi,

 

Could someone clarify Personal liability in respect to GDPR.

So school has appropriate policies in place and that teachers were aware of and signed upto. Teacher X then makes a faux pas causing a breach which needs to be reported to ICO.

My initial understanding was that the school could be fined and that the teacher also had personal liability and cloud be fined by the ICO.

 

We are looking at outsourcing the DPO role and a couple of companies have said that their is no personal liability. So should teacher X leave a load of SIMS reports on a train the school could be fined but not the teacher. Although the teacher would be dealt with by the school.

 

Any thoughts

 

Cheers

Posted

Hi.

We are outsourced DPOs and we have no liability unless we have instructed a school to undertake something that is unlawful.

The ultimate responsibility for the staff is with the school. That it is why they must be accountable in regularly training staff and reviewing and updating policies.

 

The staff handbook and contract should include information around good practices for data protection and if the individual is in breach of this the school can respond accordingly.

  • Thanks 1
Posted
That all makes sense to me. If the school can show the ICO they have undertaken certain measures to become GPDR compliant and the individual has breached their contract/ignored training etc. I can't imagine the school would be fined. I may be very wrong though!
  • Thanks 1
Posted

Liability is determined by a range of things but the important thing to remember is that the Data Controller/Data Processor now share liability ... how much depends on the balance of actions leading to a breach. Where the Data Controller and Data Processor are the same organisation (the example of teacher leaving their mark book on the bus), then the liability is with the Organisation.

 

For individuals, you need to also look at the criminal offences within the Data Protection Act 2018. This is before you get to organisations taking direct actions against individuals who breach their contracts.

Criminal Offences are primarily in sections 170 - 173 of UK DPA 2018, but there are others dotted throughout the act (providing false statements to ICO during investigations, the confidentiality of current and former ICO staff, etc.)

 

As Andy has said, the DPO role has some special rules though with regards to their responsibilities ... that is to protect DPOs from being blamed for the organisation not following their advice. It is the organisation's responsibility to make sure that they have the right DPO and that they are correctly resourced ...

 

Happy to have a chat with anyone on this.

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...