Jump to content

Recommended Posts

Posted

According to The Reg, there has been amendment tabled that would mean schools, colleges and universities were no longer classed as public authorities - and therefore wouldn't need to appoint a DPO and make things supposedly simpler for them.

 

Interesting idea, but I can see it as another step towards schools being thought of as businesses.

  • Thanks 2
Posted

Yep, we are trying to find the root of the amendment now, to see how it stands up in committee.

 

Remember that all amendments have a number of hurdles to cross so it will be interesting to see where this one goes.

 

It would open more opportunities and also allow make thing fit into the general scheme of governance ... but also opens up the chances of corners being cut.

 

I’m watching this with interest but until there is a firm reason for the amendment it is hard to say how it will hold up.

  • Thanks 1
Posted (edited)
I'm sure I was told this was signed into law already for may 2018.

Is this the same bill ?

Yup, same bill. Not signed into law yet. The GDPR regulations have been agreed by the EU so come into force in the EU in May 2018, and the government over here indicated that they were going to implement it regardless of Brexit, and that everyone should prepare anyway (as the core tenets of it will apply whatever the weather).

Edited by elsiegee40
  • Thanks 1
Posted
Is this in other words saying GDPR will not apply to schools?

 

It looks like it gives an exception for educational records.

I assume schools are still subject to GDPR (esp employee data) but we will be able to do what we like with educational records.

Posted

The clause that has been changed is about needing a DPO. All other aspects still apply.

 

The amendments in Schedule 3 appear to be clarifications on types of school.

 

It also raises an interesting prospect about Legitimate Interest now being an option for processing ...

Posted

So without a DPO, how will GDPR requirements be fulfilled? It just doesn't add up...

 

If they are proposing/changing the legal status of schools, then theoretically, FOI requests would no longer apply either.

Posted

I seem to recall that the GDPR defines data controllers and data processors as a role - then says DPO checks strategy and compliance (for large companies).

 

Presumably the proposal is that schools would only need to define data controllers/processors, and to ensure they are looking after personal data as per the act - but not appoint a designated DPO.

 

Having a DPO in a every school (especially small primary schools) is probably overkill. And if every DPO contacted capita to ask their own questions to ensure they are happy with how capita cover the GDPR - that's 11,000 conversations - that doesn't really make that much sense either. Presumably you'd move to a model where an academy trust appointed a single DPO and an state schools were covered by the LA's DPO.

Posted
So without a DPO, how will GDPR requirements be fulfilled? It just doesn't add up...

 

If they are proposing/changing the legal status of schools, then theoretically, FOI requests would no longer apply either.

 

FOI and DP are separate but linked items and have separate laws. In some countries the ICO deals only with FOI and not DP, but in UK the ICO deals with both. FOI will still be in place.

 

Without a DPO it will work the same as any other company with less than 250 employees ... a Data Protection Manager will dthe the operational bits and everyone mucks in for the rest, but with no independent oversight ... the difference is that in schools we already have mechanisms for dealing with this and it is called the governing body.

 

As I mentioned above, it is interesting but there are risks ... and we’ll have to see what is mentioned about it at committee and other stages.

 

If anyone has followed the progression of a law through Parliament ... it ones to always make sense as tto what is decided ... and that is down to politics.

Posted
I seem to recall that the GDPR defines data controllers and data processors as a role - then says DPO checks strategy and compliance (for large companies).

 

Presumably the proposal is that schools would only need to define data controllers/processors, and to ensure they are looking after personal data as per the act - but not appoint a designated DPO.

 

Having a DPO in a every school (especially small primary schools) is probably overkill. And if every DPO contacted capita to ask their own questions to ensure they are happy with how capita cover the GDPR - that's 11,000 conversations - that doesn't really make that much sense either. Presumably you'd move to a model where an academy trust appointed a single DPO and an state schools were covered by the LA's DPO.

 

Schools sharing DPOs is pretty much what is expected ... and even with that we know that it will be difficult, it not impossible. MATs may appoint a DPO, or buy the service in so that they can remain independent ... remembering that the IT Director may have already had made decisions on behalf of schools and so have a conflict of interests.

Posted
Without a DPO it will work the same as any other company with less than 250 employees ... a Data Protection Manager will dthe the operational bits and everyone mucks in for the rest, but with no independent oversight ... the difference is that in schools we already have mechanisms for dealing with this and it is called the governing body.

 

So, pretty much what you and I were discussing last week, @GrumbleDook ...

  • Thanks 1
Posted

Considering this is now so close to implementation and the rules are still being ratified it does not leave us much time to employ a DPO and get them up to speed come May 2018. As I understand it as it stands now if you do not have a DPO by the 25th May 2018, you have not met the criteria of GDPR.

 

If we do need to employ someone then we need to start now and even then with the best will in the world and individuals notice periods it could be February 2018 before a DPO actually starts their new role. The ICO should not be changing the rules at this late stage as it leaves us in limbo not knowing whether to employ or not to employ.

 

I would say that sharing a DPO is an even bigger task as the DPO will certainly have their work cut out trying to get a number of schools up to GDPR expectations.

Posted

So just reading through the hansard notes from yesterday's debate;

 

". . . with the reassurance from the Minister that we can have a meeting to discuss this further, I beg leave to withdraw the amendment.

Amendment 10 withdrawn.

Clause 6 agreed.

Clause 7: Lawfulness of processing: public interest etc . . ."

https://goo.gl/PtDzGB following on from https://goo.gl/sCUw9q

 

(clause 6 being "“( ) A college, school or university is not a public authority or public body for the purposes of the GDPR.”)

 

IANAL, so am i reading it right that it has actually been agreed by HoL?

 

JB.

Posted
Considering this is now so close to implementation and the rules are still being ratified it does not leave us much time to employ a DPO and get them up to speed come May 2018. As I understand it as it stands now if you do not have a DPO by the 25th May 2018, you have not met the criteria of GDPR.

 

If we do need to employ someone then we need to start now and even then with the best will in the world and individuals notice periods it could be February 2018 before a DPO actually starts their new role. The ICO should not be changing the rules at this late stage as it leaves us in limbo not knowing whether to employ or not to employ.

 

I would say that sharing a DPO is an even bigger task as the DPO will certainly have their work cut out trying to get a number of schools up to GDPR expectations.

 

This is not the ICO changing the rules ... this is the process of Lords and MPs, including working with lobbying groups, to decide and implement a law.

Posted
This is not the ICO changing the rules ... this is the process of Lords and MPs, including working with lobbying groups, to decide and implement a law.

Sorry yes my error, but it still doesn't help our cause yet about employing a DPO.

Posted
So just reading through the hansard notes from yesterday's debate;

 

". . . with the reassurance from the Minister that we can have a meeting to discuss this further, I beg leave to withdraw the amendment.

Amendment 10 withdrawn.

Clause 6 agreed.

Clause 7: Lawfulness of processing: public interest etc . . ."

https://goo.gl/PtDzGB following on from https://goo.gl/sCUw9q

 

(clause 6 being "“( ) A college, school or university is not a public authority or public body for the purposes of the GDPR.”)

 

IANAL, so am i reading it right that it has actually been agreed by HoL?

 

JB.

 

As I understand it, these are possible amendments. Nothing has been agreed yet and we won't know until it has been agreed with HoL and HoC and given royal assent. At least that's what I remember from when I was following the Protection of Freedoms act in great detail. With that, there were loads and loads of possible amendments which never saw the light of day (in the case of that act, fortunately!).

 

Meldrew.

Posted
So just reading through the hansard notes from yesterday's debate;

 

". . . with the reassurance from the Minister that we can have a meeting to discuss this further, I beg leave to withdraw the amendment.

Amendment 10 withdrawn.

Clause 6 agreed.

Clause 7: Lawfulness of processing: public interest etc . . ."

https://goo.gl/PtDzGB following on from https://goo.gl/sCUw9q

 

(clause 6 being "“( ) A college, school or university is not a public authority or public body for the purposes of the GDPR.”)

 

IANAL, so am i reading it right that it has actually been agreed by HoL?

 

JB.

 

Just reading through the notes too .... and we can see that the amendment was to allow Universities to raise money, but they will still be able to do that anyway, so the amendment is dropped.

 

The Minister is going to push on ensuring advice on that section around fundraising, so that will be helpful to many school ... but it is surprising noone raised about the impact around needing / not needing a DPO.

We'll continue to ask questions on it and see what gets said.

 

Remember, if you and your schools feel that this is an issue, you can also approach your MPs and engage with them on this. It might be best to do so through your Governing Bodies.

Posted
So just reading through the hansard notes from yesterday's debate;

 

". . . with the reassurance from the Minister that we can have a meeting to discuss this further, I beg leave to withdraw the amendment.

Amendment 10 withdrawn.

Clause 6 agreed.

Clause 7: Lawfulness of processing: public interest etc . . ."

https://goo.gl/PtDzGB following on from https://goo.gl/sCUw9q

 

(clause 6 being "“( ) A college, school or university is not a public authority or public body for the purposes of the GDPR.”)

 

IANAL, so am i reading it right that it has actually been agreed by HoL?

 

JB.

Also not a lawyer, but....

 

Having read the Hansard transcript linked above, it looks to me like the driver for the amendment is to enable schools and colleges to continue with their fundraising activities without seeking consent opt ins for existing contacts. It looks like removal of the requirement to have a DPO is an unintended consequence of using the mechanism of not treating schools/colleges as public authorities to achieve the change to consent requirements.

 

Also in the notes was the comment that it is very unlikely that any guidance on how the law should be interpreted will be released before the bill passes into law - which won't be any time soon...

 

Also an "interesting" discussion on how the regulation will affect small businesses. The proposal is to exempt businesses with fewer than 5 employees. It strikes me that that doesn't work for consumers - companies with fewer than 5 employees can easily abuse the data of many thousands of consumers - or for slightly bigger businesses. We're focused on how difficult this will be for schools, but I can't imagine many businesses with 5 to 50 employees have the resources to employ a DPO...

 

Clear as mud...

Posted
It's the "Clause 6 agreed" bit that jumps out to me, as that is specifically the line that deals with School not being a Public Authority or Public Body for the purposes of the GDPR.

 

Jut unclear that it states "agreed", but the amendment 10 was withdrawn, and according to the https://publications.parliament.uk/pa/bills/lbill/2017-2019/0066/18066-I.pdf , (page 3) amendment 10 is clause 6??

 

:confused:

JB.

 

The amendment to clause 6 is withdrawn and so it is agreed as the original draft. Schools, colleges and universities are still regarded as public bodies.

 

Amendments get raised, altered and withdrawn at several stages throughout a bill’s passage through Parliament. At committee stage you get some serious discussion, and once it gets to the Commons you will see more lobbyists get involved.

 

Because this is a major piece of work, it will get reported on in the tech press ... this won’t be the first or last time we have to think about implications. The best thing to do is wait to see why amendments are raised and see what happens when they are discussed.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...