Appointing a data protection officer
A simple guide to understand the role of a DPO in schools and who is and who is not suitable for the role.
Whatever the size and setting of your school, the GDPR (General Data Protection Regulation) places high expectations on you to protect the personal data in your care. You are accountable and must demonstrate your commitment to the Regulation by putting in place appropriate processes and procedures and, under Article 37(1), appointing an appropriate DPO (data protection officer).
- The DPO is an independent monitoring and advisory role that supports your compliance with the Regulation and helps you understand your obligations.
- They act as the point of contact for data subjects, e.g. pupils, parents and staff, and supervisory authorities like the ICO (Information Commissioner’s Office).
- They should be an independent, experienced GDPR practitioner, with knowledge of data protection law. They should be adequately resourced, and report to the highest leadership level.
- They can be external and shared across a group of schools, including schools with formal relationships (such as trusts) and those without.
- They can be an employee, but there cannot be a conflict of interest with other roles.
- They provide advice regarding DPIAs (data protection impact assessments). A DPIA must be carried out where a planned or existing processing operation “is likely to result in a high risk to the rights and freedoms of individuals”. If you are introducing a new system such as an MIS (management information system), or a catering or parents’ payment system, a DPIA must be carried out.
How to Help your Teen Through Exam Result Uncertainty
Helping your Teen through exam result uncertainty. It is less than easy for teens at the moment. All their lives they have been told that their exam results at GCSE and A-level will determine their future and now they are not sitting these exams at all but are relying...
Subject Access Requests- A Common Misconception.
Subject Access Request (SAR) Last week I spoke to a new client and asked if they had ever had any problems in responding to a Subject Access Request. (SAR) To my surprise they told me that they had never had one. I was very surprised by this as experience told me...
Be careful if you are using WhatsApp
Things to consider when staff use WhatsApp From a data protection perspective, schools should be very wary of allowing staff to use WhatsApp for work related conversations. Importantly, WhatsApp only allows its use for personal reasons and so any organisation using...