The GDPR was enacted into UK Law as the Data Protection Act 2018.  As for many organisations it imposes legal obligations on schools and the ways they must manage and process personal data.

The legislation gives the Information Commissioner’s Office (ICO) powers to impose significant financial penalties, Ofsted now includes data protection compliance within their inspection criteria and there is a greater chance of reputational damage from bad publicity.

This page explains what the new legislation means for schools and the main areas that need to be considered. It is based on the DPO Centre’s experience from working with over 120 schools and colleges.

WHAT DOES NEW DATA PROTECTION LEGISLATION MEAN FOR SCHOOLS?

Like other organisations, all schools must:

ok2
Be transparent in the way they process personal data and accountable for doing so
ok2
Appoint a designated data protection officer if they are a state school or a private school processing personal data on a large scale
ok2
Understand the data they have, where it is stored and who has access to it
ok2
Implement robust processes and procedures to protect personal data
ok2
Allow pupils, staff members, governors, parents, guardians and suppliers to:

  • have access to their personal data
  • ensure it is correct and modify it as necessary
  • have it deleted (unless needed for legitimate reasons)

ok2
Be able to detect, manage, report and respond to data breaches including, if necessary, liaising with the ICO

SCHOOL ACTIVITIES USING PERSONAL DATA

Schools must protect personal data in a wide range of areas.  These include :

DPO_School_Icons

Educational Software

  • SIMS, ScholarPack, Arbor etc.
  • 2Simple, Tapestry early years systems

DPO_School_Icons2

Communications and consent management

  • Photography and displaying pictures
  • Social media, posting images
  • Parent communications, satchel post, Teachers2Parents, ParentMail etc.

DPO_School_Icons3

Policies

  • Privacy, retention and data
    protection policies
  • Staff handbooks

DPO_School_Icons4

Administration

  • Network security
  • Email systems
  • Staff payroll, pension and other HR records
  • Paper records
  • Visitors’ book and access systems
  • Managing CCTV/Video

DPO_School_Icons5

Managing Sensitive Information

  • Special educational needs
  • Medication and medical data
  • Safeguarding and family issues
  • DBS Checks

DPO_School_Icons6

Teaching and getting the job done

  • Children’s workbooks
  • Wall displays and name badges
  • Pupil premium data
  • eports and taking data home
  • School printing facilities

DPO_School_Icons7

Sharing data with others

  • School trips, peripatetic learning
  • Supply teachers
  • Feeder and transitional schools
  • References for employers and other institutions

If you would like to speak to us about any of our Data Protection consultancy services

 

Contact Us