We are currently laying the foundations for GDPR, and getting documentation ready for it, and at the same time trying to understand it!
We currently encrypt pretty much any device that leaves the school building, usb sticks, laptops etc. Our photo policy has been revised to only allow photos to be taken on school equipment, ie supplied cameras. My issue is that we are NOT allowed to use our own encrypted, password protected phones to take photos, however must now use unencrypted cameras for take photos. This is more directed when the photos are taken outside the school, ie class/year outings.
If phone is lost then it will be harder to get into, if a camera is lost - take card out and view photos - how is that safe? I can't justify £800 cameras that can encrypt photos. Obviously this loss would need to be reported as a data breach because of the content, and potential fines could be greater as it's not a protected device!
Thoughts most appreciated, this comes from me as the IT side of things - am I just opening a can of worms!