Appointing a data protection officer
A simple guide to understand the role of a DPO in schools and who is and who is not suitable for the role.
Whatever the size and setting of your school, the GDPR (General Data Protection Regulation) places high expectations on you to protect the personal data in your care. You are accountable and must demonstrate your commitment to the Regulation by putting in place appropriate processes and procedures and, under Article 37(1), appointing an appropriate DPO (data protection officer).
- The DPO is an independent monitoring and advisory role that supports your compliance with the Regulation and helps you understand your obligations.
- They act as the point of contact for data subjects, e.g. pupils, parents and staff, and supervisory authorities like the ICO (Information Commissioner’s Office).
- They should be an independent, experienced GDPR practitioner, with knowledge of data protection law. They should be adequately resourced, and report to the highest leadership level.
- They can be external and shared across a group of schools, including schools with formal relationships (such as trusts) and those without.
- They can be an employee, but there cannot be a conflict of interest with other roles.
- They provide advice regarding DPIAs (data protection impact assessments). A DPIA must be carried out where a planned or existing processing operation “is likely to result in a high risk to the rights and freedoms of individuals”. If you are introducing a new system such as an MIS (management information system), or a catering or parents’ payment system, a DPIA must be carried out.
What to do if Your School Suffer a Data Breach
Data Breach: What to do if your school suffers a data breach: Our growing reliance on technology has been compounded and increased by the coronavirus pandemic . From working remotely, to communicating with family, to test and trace apps, to online shopping, our...
What Schools Must do to Tackle Ransomware Crisis
What schools must do to tackle ransomware crisis! Cyber criminals are increasingly using ransomware to attack the education sector. The trend is most noticeable in the US, with criminals locking up school’s systems and demanding a payment to release the data, but...
Support for UK Education Sector After Growth in Cyber Attacks
The NCSC has updated an alert following the increase in ransomware attacks against the education sector National Cyber Security Centre (NCSC) provides additional support for education establishments following rise in ransomware attacks since late February Spike in...