Jump to content

Recommended Posts

Posted

Afternoon,

 

I am struggling keeping on top of GDPR related stuff when it comes to users, admin staff especially. I find I seem to prioritise this stuff lower down and it gets out of date really quickly.

 

I think some of the issues are

-staff signing up to stuff without a clear process for data protection checking ( I can introduce that better)

-New staff - no process to add them to a GDRp audit

 

I just don't seem to have a slick process at all, nor provide one and it's mounting up on top of everything else. It just seems millions of spreadsheets which need updating all the time when I get a chance.

 

We buy in a DPO service and they do an audit annually and answer GDPR questions raised and they have some templates for this and that.

 

Does anyone have a slick process that they would be willing to share?

 

Do you send stuff out annually to each staff member asking the same questions and they fill it in again?

 

Do you provide copies of what they've previously specified and ask them to check for changes?

 

I'm finding it a nightmare to be honest. I would dread an audit that was thorough!

 

Appreciate any pointers and anyone's time to help here

 

 

 

 

sharething have a slick process

emailing everything is out of date and gets prioritised lower, h

Posted (edited)

Having spent yesterday on a data protection seminar where a DPO was lamenting the deluge of COVID-inspired "can we use X?" DPIAs, here were the tips:

 

  • Make the person who wants the thing do the initial work.
  • Have a series of default questions* that they need to get answers to
  • Review those answers for follow-up (insufficient detail, "it's in the privacy document")
  • Optionally** make them fill in the bulk of the DPIA form
  • Finally make it clear you're assessing risk as demonstrated - this is a point-in-time snapshot, not a "well that's definitely safe to use" recommendation from you.

 

Less of a "do all the work" and more "mark/critique their homework" approach.

 

If you use Microsoft Forms (for example) make an "I want to use X service" form and set all the fields as required. Maybe use Flow/Power Automate to feed that into a DPIA template document.

 

*

  • Who are they (company/parent company)
  • What data are they storing?
  • Where?
  • For how long?
  • How is it secured?
  • Is the data shared with anyone else?
  • Is anonymised data shared?
  • Why does the staff member want to use this service (vs existing thing / alternate provider)?
  • What key benefits does it deliver that would justify this data sharing?
  • What is the timeline for implementation?
  • etc

 

** Depending on the staff member.

Edited by pete
punctuation
  • Thanks 1
Posted

Superb Pete, thanks a lot. can get my teeth into that for sure.

 

Any procedures for inbound and outbound data? I can handle inbound within security of devices and systems etc, but more the outbound and save locations really.

 

I sent a massive spreadsheet out to staff (mainly admin) asking who they communicate with in terms of sending out data regarding staff and students. Agencies etc. They (most) completed it. Things like where are they saving files to on the network, where are they emailing sensitive data outside, are they encrypted emails, and a whole lot of stuff for them to think about and input.

 

Those spreadsheets have died a death really as things have been added to no doubt and they send out data to other people not specified at that time. I should probably send this out again annually.

 

Is this what everyone does? Is there a slick way to do this? A proforma and a manageable way to collate?

Posted
Package solution to help perhaps? @GrumbleDook can perhaps talk about options, not just his own. It does sound like you are taking on too much - it's not an IT job, it's that IT are involved. I've had a chat with an outsourced DP firm in the last week, and they (representing some of their schools) have advised us (a charity that works with the school) to have an improved privacy notice. They felt this was sufficient often and does aware with separate agreements. I don't think it means do away with DPIAs, but it's something we need to improve. One other thing came up in discussion. The DPO role preclude lots of capable people in companies from taking on the role due to conflict of interest. They have proposed having a Data Protection Manager with an overseeing (outsourced) DPO. I'm keeping that idea to myself! I don't particularly want to take on more DP responsibility!
Posted
Thanks @Ditto. I do have GDPRis but it doesn't cover everything in terms of getting the info from users and keeping them updated. Like many others, someone has to do the stuff in the background and then the DPO confirms compliance or not, but the data collection needs doing by someone who can do it. I don't want to , but I do feel IT wise I should have more input, and more input means more aware, certainly from the electronic data perspective.
  • Thanks 2
Posted
Thanks @Ditto. I do have GDPRis but it doesn't cover everything in terms of getting the info from users and keeping them updated. Like many others, someone has to do the stuff in the background and then the DPO confirms compliance or not, but the data collection needs doing by someone who can do it. I don't want to , but I do feel IT wise I should have more input, and more input means more aware, certainly from the electronic data perspective.

 

If there is any help you need in getting the implementation running in the school then that can be arranged too. It is more about changing culture and identifying roles than anything else. Once you have that, the rest is a lot easier. Not easy, but easier.

  • Thanks 1
Posted
As @GrumbleDook says its a cultural change that is needed within the school. It is definitely not purely an IT issue. 95% of data breaches we see are from human error not IT issues. Staff need understand that data protection is part of Safeguarding, because the loss of data relating to a child could be very harmful. Stress that whilst you are doing your part of the job in keeping systems secure etc SLT need to ensure policies and procedures are followed and that regular training takes place.
Posted

Thanks for replies.

 

The culture change is there and has been, but it's more the evidencing side and keeping that updated which seems to be my issue. That's what GDPR is all about I thought.

 

There seems soooo many templates everywhere and huge data spreadsheets which staff need to complete and then it needs analysing and formalising surely.

 

Do you send out annual data collection forms? Getting them to complete the form again just adds another massive spreadsheet to the mix and is time consuming.

 

Do staff apply to IT/Someone else if they want to subscribe to a website which they provide student details for logins etc? Maybe an option here. I just get an email saying is it safe to use, then I read the privacy notices and say yes, but it doesn't get updated anywhere. I should add it to GDPRis with details. So that is down to me.

 

It's really the process for getting staff data evidence up to date and kept up to date which is what I'm struggling with. Maybe everyone does it at such a high level, not much changes as it's covered?

Posted

Yes GDPR is all about accountability and to that point the ultimate responsibility rests with Governors then SLT.

Obviously every school is different but there should ideally be one one centrally run data mapping template that lists the various processes within the school, the different products used, lawful bases for processing, where data is stored etc.

Again in the ideal world this is overseen by the DPO but compiled by the area of the school using the process. This is a task in the first place but then relatively simple to update.

 

In terms of teachers wanting to subscribe to websites with student details, this should not be yours or their decision.

They should seek approval from the Head or whoever is responsible for DP in the school. Reading a Privacy Notice does not mean that it satisfies a DPIA.

 

Not sure if this covers all of your points but you really should chat with your DPO.....its their job!

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...