GENERAL DATA PROTECTION REGULATIONS
May 2018
PROTECTION REGULATIONS May 2018 GDPR What is GDPR What is - - PowerPoint PPT Presentation
GENERAL DATA PROTECTION REGULATIONS May 2018 GDPR What is GDPR What is different Principles of of GDPR How does it effect school How are school preparing How does it effect individual staff How can
May 2018
is GDPR
is different
does it effect school
are school preparing
does it effect individual staff
can staff prepare
General Data Protection Regulation (GDPR) is a piece
EU-wide legislation which will determine how people’s personal data is processed and kept safe, and the legal rights individuals have in relation to their
data.
will apply from 25 May 2018
EVERYONE – all staff are responsible for complying with regulations
to the Data Protection Act (DPA)
expands and strengthens the principles
DPA
CHANGE ANGE REQUIRE UIREME MENT NT Subject Access Requests No longer able to charge
access requests and have 1 month to comply Consent Must have consent to process personal data. Data Breaches ICO must be notified within 72hours
data breaches where an individual is likely to suffer some form
damage i.e identity theft. Failure to comply could result in 20 million euro fine. Data Protection Impact Assessments Now a legal requirement to carry
I.A when considering using data in new ways i.e new IT systems Data Protection Officer Must have a designated DPO who will take responsibility for D P
not be member
SLT
Admin staff due to possible conflict
interest.
Processed lawfully, fairly and in a transparent manner 1 Collected for specified, explicit and legitimate purpose 2 Relevant and limited to what is necessary in relation to the purpose for which the data is processed 3 Accurate and kept up to date 4 Kept in a form which permit identification
data subjects for no longer than is necessary for the purposes for which the personal data is processed 5 Processed in a way that ensures appropriate security
personal data. 6
GDPR sets
six princi cipl ples es
data ta proces cessin sing.
se say the personal
data ta must be:
Breach
security
personal data when transmitted, stored
processed leading to:
Accidental Destruction Unlawful Destruction Loss Unauthorised Disclosure
Unauthorised Access Alteration
data controller and data processor school must ensure the security
all data subjects personal information i.e staff, pupils, parents etc.
Analysis
Appointed
Notice for parents/staff updated
plan in place
Signing in system
staff need to be aware
the principles
GDPR
staff must comply with GDPR regulations
staff are responsible for reporting data breaches
should be aware
how school collect and process their individual data
aware
Staff Privacy Notice
aware
and apply GDPR Principles when sharing data
yourself ‘Can I share this information’ – ‘What is the reason for sharing the data’
secure email system is used when sharing information
PIN codes are set
phones/mobile devices especially if you access calendar etc
all IT system when not in use
not leave any pupils/parents personal data (e.g pupil reports, SEN reports, CPOMS printouts etc) lying around school
shredding should be sent to the main
you take work home, ensure security is maintained at all times i.e encrypted pen drives etc.
secure filing systems (manually and electronically)
regular and appropriate data cleansing processes
Data Breaches must be reported IMMEDIATELY to DPO
principles
GDPR are not a new thing.
majority
processes are already taking place in school.
you are unsure
have concerns about anything ask DPO
Fiona
Holden data@englishmartyrs.co.uk