How the Record of Processing Can Help You

The Record of Processing can often seem like a daunting process to undertake- but it’s important to view it as exactly that- a process. Documenting the processes your organisation carries out is an ongoing project that you continue to evolve and develop as those processes change. The value you can get out of spending some time and care by completing various ones shouldn’t be underestimated. We’ve spoken to some of the people who have used the RoP tool on the Knowledge Bank, and asked them what they found challenging, and what they found the most useful parts of the tool, in the hope that it will help some of you who may feel that carrying out the Record of Processing is a daunting task.

Information Security Basics: What are VPN's?

VPN’s have become commonplace over the past couple of years, with every content creator out there having at some point been sponsored by Nord VPN (other VPN providers are available). VPN's are mostly used so that we can watch content on streaming platforms that would otherwise be blocked in the UK. However, as well as allowing you to watch Pulp Fiction on Canadian Netflix, VPN’s have excellent security benefits that can help prevent data breaches and cyber attacks. 

the words data breach in navy, outline of computer, coffee cup and book, outline of books, harry the hacker looking in a filing cabinet, and hacking into a computer

Recently there has been an annual study published by Ponemon Institute (sponsored by Experian) entitled “Is Your Company Ready for a Big Data Breach?”. The study looks at the state of breach preparedness across organisations over a period of a year,

Due diligence process: assessing data protection and security measures for schools' vendor contracts.

At Data Protection Education, we have an ongoing project to assess potential organisations that our schools are either currently contracted with to supply a product or service, or may in the future be in contract with.

The words records management in blue text, harry the hacker looking in a filing cabinet and standing next to a shelf of folders

For most organisations, a lot of thought and care goes into ensuring that when you’re collecting data, you are complying with the relevant data protection legislation- that it’s being collected with consent where required, that you have a lawful basis etc. However,

Cyber attack in blue, harry the hacker looking at computer screens and phishing (fishing) a laptop. data protection education logo

A recent study conducted by Check Point Research which can be found at the bottom of this article has found that there has been a 29% increase in cyberattacks on organisations in the education sector since 2020, the highest increase of any sector. 

Cyber attacks in navy text with Data Protection Education log, harry the hacker looking at computer screens and phishing (fishing) a laptop

Cyber attacks are on the up, and with the education sector seeing the highest number of cyber attacks of any sector since the start of the pandemic, as well as the highest increase in attacks in that same period

The Children's Code

The Children’s Code

The first update from the ICO is that the transition year for the introduction of The Children’s Code (also known as The Age Appropriate Design Code) has passed, with the code having come into effect on September 2nd.

Freedom of information in black text on a key on a white keyboard

Schools in Brighton and Hove have received the following Freedom of Information request:

1. Please send me copies/scans/digital files that record individual racist/religious incidents/bullying incidents in terms of numbers of incidents and their

Cyber attacks in navy, harry the hacker looking at computer screens and phishing (fishing) a laptop

The National Cyber Security Centre has today upgraded it's advice to schools relating to the prevalence of cybers attacks in the sector:

Protocol for Setting Up and Delivery of Online Teaching and Learning

These protocols aim to ensure that online lessons with pupils when working from home, are safe, secure and continue to provide high-quality education using a virtual platform. 

This is guidance for setting up and managing online lessons using the school’s chosen platform ie  Zoom; Google or Microsoft teams.

Freedom of information text on a white keyboard

It is a requirement under the Freedom of Information Act and ICO to set out your commitment to making certain classes of information routinely available, such as policies and procedures, minutes of meetings, annual reports and financial information.

Child friendly privacy notices

Updated 22 March 2021

The ICO gives the following advice when communicating privacy matters to children:

What information should we give to children?

Transparency written in pen, with the Data protection education logo above, a hand holding a pen on the left and a reflection of the hand below it

What Is Transparency

Transparency is about being clear, open and honest with your users about what they can expect from you.

Photo of a person's arm and putting a letter in the post box.  Data Protection Education logo on the bottom right of the image

We've recently had more than one breach reported where physical files have got lost in the post.

In such cases, the sender remains the data controller and is responsible for ensuring that the optimum data security measures are in place during transfer. Where possible, consider whether a physical drop-off (and get a receipt) is a more secure option.

Emergency contact information sheet with a yellow pencil above it, Data protection education logo on the sheet

Do I need consent for emergency contacts?

Actually no, and here's why.

We know that we must have a lawful basis for processing any data, and consent is one of the six lawful bases that can be used.

computer keyboard with due diligence on a blue key

Adapted from: The Irish Data Protection Commissioner

The UK GDPR does not prescribe the exact process for carrying out a DPIA beyond the minimum features outlined above, allowing for flexibility and scalability in line with your organisation’s needs. Although there is no one prescribed approach to take, the following steps can guide you through the process:

Freedom of information on a white key on a white keyboard

We have added publication scheme model templates in the FOI Best Practice area for academies as well as maintained schools.

Difference between the High Level and Detailed Publication Scheme

Photograph of a young girl taking a photo on a camera in a country lane. Data protection education logo is bottom left

In light of recent ICO reprimands to schools it is important schools remember best practice for managing photos. The formal legal warnings issued by the ICO recently to schools both related to the processing of photos where no consent had been given. 

National child measurement programme

Updated operational guidance has been produced by Public Health England for local commissioners and schools on running the national child measurement programme (NCMP)

Compliance Manager released

We've released version 1 of the Compliance Manager tool.

What is it?
The Compliance Manager allows you to assign any document to staff and enable the following interactions

  • I have read and understood
  • I have used this in practice

or

Any standard document type can be uploaded and interactions selected. Then select the users to assign the document too and a date by which the users should have responded.

computer keyboard with a white envelope on a pink key on the keyboard

 By changing the culture of email use within an organisation will not only benefit the organisation towards GDPR compliance and beyond, it will also save a significant amount of time by reducing staff workload and hopefully support staff wellbeing too.

Search

Guest Subscription

** If guest, Please enroll your name and email for Subscription

Privacy notice