Jump to content

gdprconfusesme

Members
  • Posts

    1
  • Joined

  • Last visited

Reputation

5 Neutral

About gdprconfusesme

  1. Okay, so I'm looking for some general advice / guidance. I'm an IT tech at a small SEN primary and only have very basic knowledge about GDPR. I'm quite sure that Data Protection Act wise our compliance doesn't go much further than "we have a data protection policy." Anyway, I know the SLT are vaguely aware of the GDPR as I've bought it up with them, though as far as I can tell they've taken no action other than arranging for a company to come in and do a private audit in the coming weeks, in which I strongly suspect we're going to get eaten alive and suddenly we'll be at panic stations (which it seems like we should have been at for about a year now). I have an awful lot of very basic questions, but I'll try to keep them minimal. 1) It seems like we need to ensure our data processors are GDPR compliant. I'm quite unsure of how we're supposed to do that - is it just a case of firing off an email to them and asking "are you GDPR compliant?" or is there more to it? 2) I've seen a lot of talk about data flow maps, but I don't really know how to make one. Anybody have any useful examples they could share? 3) Our Office network share is a freaking mess, with data still lurking from decades ago, though I'm quite sure that this is partly because nobody knows quite how long they're supposed to keep anything. I assume that once the pupils leave, that means their data / work / parent contacts must also be deleted. If that's true, what about safeguarding data? I've also heard in training sessions that any restraint logs must be kept for something crazy like 70 years, but I don't know how that stacks up against the GDPR as obviously the logs will include names and sensitive information. 4) Subject Access Requests: Can pupils request access to specific documents relating to them? E.g could an older pupil theoretically request to see their risk assessment? The notes of a meeting with their parents when the meeting was about them? CCTV footage of an incident? 5) What technical measures have you implemented for data protection? Banning USB drives is an example, but I'm definitely interested about how you protect and manage your data, keep track of Office document passwords, keep on top of removing old data etc. I'm sure there's more, but that'll do.. for now.. Thanks, and yes, I know we're screwed
×
×
  • Create New...