Jump to content

How well does your school comply with it's Data Protection obligations?  

19 members have voted

  1. 1. How well does your school comply with it's Data Protection obligations?

    • *crawls from under rock* Er.....what obligations?
      1
    • It's come up for discussion, not much has happened
      7
    • User awareness has been raised, we're doing what we can in IT to meet obligations
      7
    • Whole-school committment to data protection with some progress
      1
    • Whole-school committment to data protection with significant progress
      0
    • Mostly done, just finishing off a few things
      1
    • We're done (I think)
      2
    • We're uber, everyone's trained, data is secure and other schools ask us for advice
      0


Recommended Posts

Posted (edited)
Just a quick poll to see how everyone's doing wrt data protection. I know it's not an IT-only thing and requires SMT support (or IT/Data Protection Officer poking SMT with a big stick) to work. Edited by pete
Posted
Being pedantic ... you should have a SIRO now, not a Data Protection Officer and it should be a member of your SMT. There will be lots of Information Asset Owners though ... and you will be one of them. But yes ... poking .. stick .. big one.
Posted

SIRO appears to be a board/senior-management level advocate of DP best practises, who (reading between the lines) delegates most of the work to the DP Officers / Asset owners, but takes overall responsibility?

 

I have an informal DP champion in SMT who I pressganged, but nothing official.

Posted

From the Becta Guidance document http://schools.becta.org.uk/upload-dir/downloads/information_handling.pdf from Becta Schools - Leadership and management - Data management - Data handling security guidance for schools

 

2.1 Senior Information Risk Owner (SIRO)

 

The Senior Information Risk Owner (SIRO) is a senior member of staff who is familiar with information risks and the organisation’s response. Typically, the SIRO should be a member of the senior leadership team and have the following responsibilities:

 

• They own the information risk policy and risk assessment

• They appoint the Information Asset Owners (IAOs)

• They act as an advocate for information risk management.

 

The Office of Public Sector Information has produced Managing Information Risk [http://www.nationalarchives.gov.uk/services/publications/information-risk.pdf] to support SIROs in their role.

 

The key chunk is that they *own* the information risk policy. Typically they will be the person registered with the ICO in the role of Data Protection Officer (still used as a legacy term de to legal needs for existing legislation but all new jobs in the public sector taking on this role are covered as SIROs) and they are the first point of legal redress in the institute. Depending on the size of the school you may find it as the Head, the Bursar and even the Chair of Governors at times.

 

You can check with the ICO what is registered in the Register of Data Controllers to see what data you state (as a school) you are using. Information Commissioners - Data Protection Public Register

 

Enforcement cases - Data Protection Act (DPA) - ICO gives you some examples of ICO taking organisations to task.

 

I can't find the relevant docs at the moment which point specifically to the Data Controller (ie the institute or company) being fined and where it refers specifically to the registered SIRO / Data Protection Officer. They are on the ICO site and a few LAs have some really good advice out there.

  • 2 years later...
Posted
SIRO is a generic term used within Data Protection, you will also see the term Data Controller but that is frequently used to specify a person dealing with a set of data, and not always the person who the buck ultimately stops with.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...