Hello all,
Our MAT has revealed its plans for GDPR, I'd be interested in your thoughts:
One DPO role as defined by the GDPR tagged onto an existing high-up admin post, the person has not had any DPO role before and presumably is taking it on as a necessary evil.
Each school to retain their existing DP person in a similar role with similar responsibilities, presumably reporting upwards but with no additional authority and no consideration of the GDPR role definitions, because they aren't DPOs..
My initial thoughts are that this is a weak attempt to circumvent the GDPR requirements, though I can see the attraction for the MAT itself - minimal upheaval.
Have any other MATs played their hand on this yet?