blueday Posted November 10, 2021 Posted November 10, 2021 The ICO have just published updated schemes on their website regarding the information that schools and academies should make available (either on website or copy on request) under Freedom of Information. It's about time, as the previous scheme for schools was dated from 2013. Some 'interesting' additions - more on data protection to be made available, in particular DPIAs and policies around data protection and data retention. The one that surprised me was CCTV - it says 'Details of the locations of any overt CCTV surveillance cameras operated by us or on our behalf'. Isn't that helping anyone who wants to break in? P.S. Although the ICO's website has really useful information, I have a real issue with the fact that they don't actually tell you what's been updated and when, which means you've no way of knowing what has actually changed in the text or in documents. This actually goes against their own advice on having document control in place for policies etc. 4
blueday Posted November 10, 2021 Author Posted November 10, 2021 Ah, just seen that in the definition document it does qualify this, saying: Details of the locations of any overt CCTV surveillance cameras operated by you or on your behalf. You should decide on the level of detail which is appropriate. This could be by building or more general geographic locations, eg postcodes or partial postcodes, depending on the security issues raised.
enjay Posted November 11, 2021 Posted November 11, 2021 Some 'interesting' additions - more on data protection to be made available, in particular DPIAs and policies around data protection and data retention. I think that's fair. I'm sure we've all seen bad DPIAs completed, and many instances where they've not been completed at all (especially retrospective DPIAs for systems which were in place pre-GDPR), so holding schools to account is important. It possibly opens us up a bit to people who want to challenge them or who disagree with the school's assessment, but in my experience that will be a very small number of people. I don't think I'd publish all our DPIAs on our website, but I would provide one if requested.
GrumbleDook Posted November 12, 2021 Posted November 12, 2021 I think that's fair. I'm sure we've all seen bad DPIAs completed, and many instances where they've not been completed at all (especially retrospective DPIAs for systems which were in place pre-GDPR), so holding schools to account is important. It possibly opens us up a bit to people who want to challenge them or who disagree with the school's assessment, but in my experience that will be a very small number of people. I don't think I'd publish all our DPIAs on our website, but I would provide one if requested. Don’t forget that some sanitisation and redaction may be needed to protect the privacy of some data subjects affected and also to reduce publication of certain security factors. 1
TechMonkey Posted November 12, 2021 Posted November 12, 2021 The one that surprised me was CCTV - it says 'Details of the locations of any overt CCTV surveillance cameras operated by us or on our behalf'. Isn't that helping anyone who wants to break in? Label all CCTV cameras as covert cameras. Sorted
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now