-
Posts
12,876 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by GrumbleDook
-
To be honest, alter the general staff one as a range of staff will need access to protected and sensitive systems. Then make sure you have a process in place for permission to be requested and a record of authorisation and subsequent granted access. This will apply to SLT, SENDCO, IT staff, site staff, caterers, MIS manager, exams officer, timetables, Governors, etc.
-
Belated Hippy Bathday!!!!!
-
GDPR Responsibility in your school
GrumbleDook replied to prad-ucs's topic in Data Protection & Information Handling
I tend to do my reviews of Hansard before going to bed (it helps) but haven’t seen anything new yet ... It may be that a group is lobbying DCMS on this, but we’ve heard nothing from DfE on that ... We have spoken with a few more GDPR notables and have some possible options but need to get them checked out before suggesting them. However, one thing is becoming clear ... and it is something we’ve raised already. A lot of the tasks don’t need a DPO in place right now ... you can start without one for data discovery, data minimisation, etc. -
GDPR Responsibility in your school
GrumbleDook replied to prad-ucs's topic in Data Protection & Information Handling
Having had a chat with a few folk about the ‘compliance’ comment ... many are putting in statements about what they will do in their policies but devil is in the detail within their processes ... and also there are folk who will be near to GDPR compliance, but not DPA 2018. It is getting to be a grey area and we suggest that suppliers say ‘to Support GDPR compliance’ and we’ll feedback to Purple Mash on your comments (though they do lurk on here). -
The amendment to clause 6 is withdrawn and so it is agreed as the original draft. Schools, colleges and universities are still regarded as public bodies. Amendments get raised, altered and withdrawn at several stages throughout a bill’s passage through Parliament. At committee stage you get some serious discussion, and once it gets to the Commons you will see more lobbyists get involved. Because this is a major piece of work, it will get reported on in the tech press ... this won’t be the first or last time we have to think about implications. The best thing to do is wait to see why amendments are raised and see what happens when they are discussed.
-
Just reading through the notes too .... and we can see that the amendment was to allow Universities to raise money, but they will still be able to do that anyway, so the amendment is dropped. The Minister is going to push on ensuring advice on that section around fundraising, so that will be helpful to many school ... but it is surprising noone raised about the impact around needing / not needing a DPO. We'll continue to ask questions on it and see what gets said. Remember, if you and your schools feel that this is an issue, you can also approach your MPs and engage with them on this. It might be best to do so through your Governing Bodies.
-
Schools sharing DPOs is pretty much what is expected ... and even with that we know that it will be difficult, it not impossible. MATs may appoint a DPO, or buy the service in so that they can remain independent ... remembering that the IT Director may have already had made decisions on behalf of schools and so have a conflict of interests.
-
FOI and DP are separate but linked items and have separate laws. In some countries the ICO deals only with FOI and not DP, but in UK the ICO deals with both. FOI will still be in place. Without a DPO it will work the same as any other company with less than 250 employees ... a Data Protection Manager will dthe the operational bits and everyone mucks in for the rest, but with no independent oversight ... the difference is that in schools we already have mechanisms for dealing with this and it is called the governing body. As I mentioned above, it is interesting but there are risks ... and we’ll have to see what is mentioned about it at committee and other stages. If anyone has followed the progression of a law through Parliament ... it ones to always make sense as tto what is decided ... and that is down to politics.
-
Yep, we are trying to find the root of the amendment now, to see how it stands up in committee. Remember that all amendments have a number of hurdles to cross so it will be interesting to see where this one goes. It would open more opportunities and also allow make thing fit into the general scheme of governance ... but also opens up the chances of corners being cut. I’m watching this with interest but until there is a firm reason for the amendment it is hard to say how it will hold up.
-
Hippy Bathday. Hope you have a good day.
-
GDPR IT Department - What should we be doing
GrumbleDook replied to dastrix's topic in Data Protection & Information Handling
Yep, we raised it in this thread too. Data Processing Agreement - What Is Required? /showthread.php?t=189255 The consultation on it has closed now but we have been highlighting it to EdTech suppliers as much as we can. https://www.besa.org.uk/insights/edtech-suppliers-need-engage-ico-schools/ -
GDPR IT Department - What should we be doing
GrumbleDook replied to dastrix's topic in Data Protection & Information Handling
Policy is written by everyone but with the advice / direction of the DPO, and then agreed by Governors / trustees. Processes are based on these policies and give the framework for any decisions (it has to for consistency) and the general decisions are verified by the DPO. Decisions will be based on the outcomes of Data Protection Impact Assessments, and as part of the school's general risk assessment process, will be dealt with accordingly ... so most things will carry on as normal. The best advice I can give at the moment (and this is me, personally and based on if I was back in school with little or no info about what is to come next) is to look at what you are doing at the moment, check you have processes and policies in place for what you are doing already, see who makes decisions on things, see if it fits in with risk management. Check the list of suppliers you have and give them a nudge (or ask someone to give them a nudge). Bookmark the relevant websites and set up calendar alerts to go and check on a regular basis for any updates. Look at the 12 steps, look at the readiness tools, look at the timeline infographic we just put up ... do the bits you can get on with and note the bits you can't. When a DPO comes in, whoever they are, they will thank you for starting this and then play catch up. If an excemption is granted, or some other solution is put in place, then you have already started doing what is needed anyway so the efforts will not be in vain. -
GDPR IT Department - What should we be doing
GrumbleDook replied to dastrix's topic in Data Protection & Information Handling
*EVERYONE* is responsible for data protection. But, for understandable reasons, areas that need auditing are not signed off by the people that did the original work. The MIS Manager will tell people this is specifically the functions that you need to look at around data protection (special categories, for example), *you* may tell people how to handle virus alerts .... The DPO is not Gandalf confronting the Data Breach Balrog on the bridge of Khazad-we'realldûm, shouting, "I am a servant of the Secret CABAL, wielder of the flame of GDPR. You cannot pass! The dark fire will not avail you, inconsiderate user of USBdûn!" If a DPO was not a thing, what would you be doing now as a System Owner? -
GDPR IT Department - What should we be doing
GrumbleDook replied to dastrix's topic in Data Protection & Information Handling
A drama teacher can go online and order Conc. Hydrochloric acid as they clean some paint off props. A science teacher can go and order a batch of knock off bunch of lab coats that are found to be full of nylons. A site supervisor can order a batch of chairs that couldn't take the weight of a pregnant gnat. Yet it is not that case of someone watching over them 24/7 that stops this, but training, policies and making people think before doing. In the same way H&S advisors may cover a range of areas, they will know schools and their risks. The balance will be getting someone with sufficient education understanding, but will not allow that to be an excuse to cut corners and be non-compliant. -
GDPR IT Department - What should we be doing
GrumbleDook replied to dastrix's topic in Data Protection & Information Handling
The ICO have clear guidance on DPO under GDPR, however the DP Bill there are areas that differ slightly (actually it is a bit harsher as it doesn't mention *any* exceptions yet), but they will (understandably) be coming from the problems of schools finding someone who has no conflict of interests. It will be extremely difficult for someone within a school to take on the role but keep an eye out on the ICO site and info from the DP bill. We will share information as we have it as well. -
Let's get our voice heard in the DfE
GrumbleDook replied to maturelady's topic in Data Protection & Information Handling
Cannot happen, a conflict of interests. Please see the resources thread which has links to articles on who can/cannot be DPO. Personally I'd like to know what state/ LA schools have to do in comparison to academies - are LA's responsible for ensuring schools are compliant or is it solely upto each school independently? The responsibility is with the Legal Entity. In the case of maintained schools, that will be the school themselves. With Academies, you need to chat to your trust and see who is set as the legal entity and registered with the ICO. The DPO has to be named, as they are "the first point of contact for supervisory authorities and for individuals whose data is processed (employees, customers etc)" (from ICO's https://ico.org.uk/for-organisations/data-protection-reform/overview-of-the-gdpr/accountability-and-governance/ page). The DPO is not liable under GDPR, it is the Data Controller (but they may be contractually responsible) and Data Processors who are.- 35 replies
-
- 1
-
-
- data protection
- dfe
-
(and 3 more)
Tagged with:
-
GDPR Responsibility in your school
GrumbleDook replied to prad-ucs's topic in Data Protection & Information Handling
There are a raft of folk doing various levels of training. We don’t do it ourselves but have partners and contacts who do. GroupCall have been sessions but I’ll see if one of our other contacts has anything on local to you. Would it be helpful for members if we put up a page on our site about training? -
GDPR Responsibility in your school
GrumbleDook replied to prad-ucs's topic in Data Protection & Information Handling
The position of independent schools interesting ... and this is where we start looking at the draft DP bill. Sections 67-69 deals with DPO. Section 67 actually says that all controllers must appoint a DPO. This goes further than the public bodies as stated in GDPR, and it is subject to change, but at this point we would say that it is something independent schools should at least prepare for, rather than leave it too late should that section stand as it is. -
For marketing contacts, they are the data controller and you are the data subject, so that is a slightly separate (but interesting) conversation. For where the data processor is asking you to share parent / guardian contacts so they can have a direct relationship too (I.e. they become the data controller and the parent becomes the data subject), then that would be part of the data sharing agreement they have with you and subsequent agreement they have with the parent. The list is principally concerned with companies that are the data processor on behalf of the school, or where they provide you a system to allow you to process data yourself.
