Appointing a data protection officer
A simple guide to understand the role of a DPO in schools and who is and who is not suitable for the role.
Whatever the size and setting of your school, the GDPR (General Data Protection Regulation) places high expectations on you to protect the personal data in your care. You are accountable and must demonstrate your commitment to the Regulation by putting in place appropriate processes and procedures and, under Article 37(1), appointing an appropriate DPO (data protection officer).
- The DPO is an independent monitoring and advisory role that supports your compliance with the Regulation and helps you understand your obligations.
- They act as the point of contact for data subjects, e.g. pupils, parents and staff, and supervisory authorities like the ICO (Information Commissioner’s Office).
- They should be an independent, experienced GDPR practitioner, with knowledge of data protection law. They should be adequately resourced, and report to the highest leadership level.
- They can be external and shared across a group of schools, including schools with formal relationships (such as trusts) and those without.
- They can be an employee, but there cannot be a conflict of interest with other roles.
- They provide advice regarding DPIAs (data protection impact assessments). A DPIA must be carried out where a planned or existing processing operation “is likely to result in a high risk to the rights and freedoms of individuals”. If you are introducing a new system such as an MIS (management information system), or a catering or parents’ payment system, a DPIA must be carried out.
Cyber Essentials
Is it worth all the hassle and cost As outsourced DPOs for a number of schools, we have spent a great deal of time advising clients to gain Cyber Essential accreditation. We are well aware that it is not the highest level of IT security accreditation but it does...
New ICO Surveillance Guidance
New ICO guidance for Video Surveillance The ICO has published guidance on the processing of personal data by video surveillance systems, click here to go to the ICO website The guidance outlines how data protection principles must be complied with when using certain...
Privacy Snakes and Ladders
Play this game to learn how to make smart privacy choices We would like to thank our friends at the “Office of the Privacy Commissioner of Canada for sharing these great games. How to play activity sheet You need a game piece for every player and a die. The person who...