SlideShare a Scribd company logo
1 of 35
Download to read offline
Education law conferences 2018
Workshop 1B: The role of the DPO
The role of the DPO
Join the conversation #BJ_EDC
1. Understanding the role
2. Skills and support required
3. Who to appoint
4. Training your DPO
5. Managing a data breach
1. Understanding the role
Join the conversation #BJ_EDC
Understanding the role
Do I need to appoint a DPO?
• Yes
• GDPR requires a DPO to be appointed by public authorities
and (currently) this includes state schools and academies
Understanding the role
Do MATs need a DPO for each school?
• No
• A MAT is a single legal entity so the requirement will be for
one DPO for the MAT
• Consider the team the DPO needs around them
Sli.do – vote now
Have you identified your DPO yet?
• Yes
• No
• Don’t know
Understanding the role
Articles 37-39
• Monitor GDPR compliance and implementation and
application of data protection policies
• Inform/advise school and staff about GDPR obligations
• Advise whether and how to carry out DPIA
Understanding the role
Articles 37-39 (cont.)
• Be the point of contact for the ICO
• Train staff
• Carry out internal data audits
Understanding the role
Data Protection Impact Assessments
DPO should be able to advise on the following in respect to the
Data Protection Impact Assessments:
• whether to carry out a DPIA
• what methodology to follow when carrying out a DPIA
• whether to do it in-house or outsource it
Understanding the role
Data Protection Impact Assessments
DPO should be able to advise on the following in respect to the
Data Protection Impact Assessments (cont.):
• safeguards to apply to mitigate risks to data subjects
• whether the DPIA has been correctly carried out and
whether its conclusions comply with the GDPR
Understanding the role
DPO involvement – You must ensure that:
• The DPO is involved in all issues relating to the protection of
personal data
• The DPO reports to your highest management level – i.e.
school governors/MAT Board
• The DPO operates independently and is not dismissed or
penalised for performing their task
Understanding the role
DPO involvement – You must ensure that (cont.):
• Adequate resources are provided to enable DPOs to meet
their GDPR obligations
• The DPO can be contacted by data subject on all issues
relating to the processing of their personal data
2. Skills and support required
Join the conversation #BJ_EDC
Skills and support required
Qualifications
No precise credentials specified by the GDPR, but….
• DPO must have expert knowledge of data protection law and
practice
• Good quality training will be needed
Skills and support required
Art 29 Working Party – necessary skills & expertise include:
• expertise in national and European data protection laws and
practices including an in-depth understanding of the GDPR
• understanding of processing operations carried out
• understanding of information technologies and data security
• knowledge of the business sector and the organisation
• able to promote data protection culture within organisation
Skills and support required
Support by your school/trust
• Active support of the DPO function by senior management
• Sufficient time and resources for DPO to fulfil their duties
• Communicate designation of DPO to all staff
• Continuous training
Skills and support required
Support by your school/trust (cont.)
• Ensure DPO is involved in all data protection
• DPO reports to SLT/governors/MAT Board
• DPO operates independently
• DPO can be contacted by data subjects
3. Who to appoint
Join the conversation #BJ_EDC
Who to appoint
Who should be your DPO?
• No need to employ new person or make it a sole role
• Consider experience and knowledge of data protection law
and practices
• Can be a DPO for more than one school – but consider:
• Organisation structure and size
• Accessibility of the DPO from each establishment
Who to appoint
What about potential conflict?
GDPR Working Party:
“As a rule of thumb, conflicting positions may include senior
management positions (such as chief executive, chief operating,
chief financial, chief medical officer, head of marketing
department, head of Human Resources or head of IT departments)
but also other roles lower down in the organisational structure if
such positions or roles lead to the determination of purposes and
means of processing.”
Who to appoint
How do I apply this in my school?
• Not about the title held but the role undertaken
• First focus on the abilities of the candidate then address
whether that person – because of the role they undertake –
is conflicted
• IT lead is best example
Who to appoint
Outsourcing
• You can outsource, but no expectation that you do so
• You should consider:
• Cost
• Due diligence
• SLAs
4. Training your DPO
Join the conversation #BJ_EDC
Training your DPO
Initial training
• Training will be required at the outset
• You should consider:
• Cost
• Due diligence
• Skill and expertise
• How the outcomes of the training are objectively measured
Training your DPO
Ongoing updates
• Keeping up to date throughout the role will be important
• Email updates, webinars, conferences, etc.
• Annual refresher training might be worth considering
• Again, consider how you can evidence outcomes
5. Managing a data breach
Join the conversation #BJ_EDC
Managing a data breach
Quick case study
A staff member downloads pupil safeguarding information onto
a memory stick and loses it but doesn’t tell you
The first you hear about it is when the parent concerned tells
you people have been talking about her child’s safeguarding
history on Facebook for the last 10 days or so
You report to the ICO within 48 hours of the parent telling you
Sli.do – vote now
What do you think the ICO response will be?
• Thank you for reporting it
• Issue a formal warning
• Fine you up to £75,000
• Fine you more than £75,000
Managing a data breach
• Must have procedures in place to detect, report and
investigate a personal data breach
• Breach must be reported unless breach is unlikely to result
in a risk to the rights and freedoms of natural persons
• 72 hours from the discovery of the breach to report to ICO
• Notify the affected data subjects
Managing a data breach
What must you tell the ICO?
1. Nature of the breach and where possible
a. Categories and number of data subjects concerned
b. Categories and number of personal data records concerned
2. Name and contacts details of your DPO
3. Describe likely consequences of the data breach
Managing a data breach
What must you tell the ICO (cont.)?
4. Describe measures taken/to be taken to address the breach
and mitigate possible adverse affects
• You can provide this information in stages, but without
undue delay
• What does this look like in practice?
Managing a data breach
In practice
• Drop everything – akin to a serious safeguarding incident
• Follow your data breach procedures
• Seek external legal support as appropriate
• Business critical priority to manage quickly and effectively
www.brownejacobson.com/education
Please note
The information contained in these notes is based on the
position at March 2018. It does, of course, only represent a
summary of the subject matter covered and is not intended to
be a substitute for detailed advice. If you would like to discuss
any of the matters covered in further detail, our team would
be happy to do so.
© Browne Jacobson LLP 2018. Browne Jacobson LLP is a
limited liability partnership.

More Related Content

Similar to Education law conferences, March 2018, Workshop 1B - The role of the DPO

Data Protection – How Not to Panic and Make it a Positive
Data Protection – How Not to Panic and Make it a PositiveData Protection – How Not to Panic and Make it a Positive
Data Protection – How Not to Panic and Make it a PositiveTargetX
 
How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongLouise Owens
 
Iconuk 2016 - IBM Connections adoption Worst practices!
Iconuk 2016 - IBM Connections adoption Worst practices!Iconuk 2016 - IBM Connections adoption Worst practices!
Iconuk 2016 - IBM Connections adoption Worst practices!Femke Goedhart
 
LW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxLW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxTimBee1
 
GDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxGDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxTimBee1
 
Enterprise Data World 2018
Enterprise Data World 2018Enterprise Data World 2018
Enterprise Data World 2018jadams6
 
Where security and privacy meet partnering tips for CSOs and privacy/complian...
Where security and privacy meet partnering tips for CSOs and privacy/complian...Where security and privacy meet partnering tips for CSOs and privacy/complian...
Where security and privacy meet partnering tips for CSOs and privacy/complian...Compliancy Group
 
GDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedGDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedStewart Norriss
 
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018Human Capital Department
 
Implementing and Auditing GDPR Series (3 of 10)
Implementing and Auditing GDPR Series (3 of 10) Implementing and Auditing GDPR Series (3 of 10)
Implementing and Auditing GDPR Series (3 of 10) Jim Kaplan CIA CFE
 
Moral Responsibility of Data Professionals - Whistleblowing
Moral Responsibility of Data Professionals - WhistleblowingMoral Responsibility of Data Professionals - Whistleblowing
Moral Responsibility of Data Professionals - WhistleblowingData Con LA
 
Implementing and Auditing GDPR Series (8 of 10)
Implementing and Auditing GDPR Series (8 of 10) Implementing and Auditing GDPR Series (8 of 10)
Implementing and Auditing GDPR Series (8 of 10) Jim Kaplan CIA CFE
 
GDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc MichaelsGDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc MichaelsPost Media
 

Similar to Education law conferences, March 2018, Workshop 1B - The role of the DPO (20)

Data Protection – How Not to Panic and Make it a Positive
Data Protection – How Not to Panic and Make it a PositiveData Protection – How Not to Panic and Make it a Positive
Data Protection – How Not to Panic and Make it a Positive
 
How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett Long
 
Iconuk 2016 - IBM Connections adoption Worst practices!
Iconuk 2016 - IBM Connections adoption Worst practices!Iconuk 2016 - IBM Connections adoption Worst practices!
Iconuk 2016 - IBM Connections adoption Worst practices!
 
LW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxLW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptx
 
GDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxGDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptx
 
GDPR - Sink or Swim
GDPR - Sink or SwimGDPR - Sink or Swim
GDPR - Sink or Swim
 
Enterprise Data World 2018
Enterprise Data World 2018Enterprise Data World 2018
Enterprise Data World 2018
 
Where security and privacy meet partnering tips for CSOs and privacy/complian...
Where security and privacy meet partnering tips for CSOs and privacy/complian...Where security and privacy meet partnering tips for CSOs and privacy/complian...
Where security and privacy meet partnering tips for CSOs and privacy/complian...
 
Compliance as Culture Strategy
Compliance as Culture StrategyCompliance as Culture Strategy
Compliance as Culture Strategy
 
GDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedGDPR Practicalities - The Data Shed
GDPR Practicalities - The Data Shed
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
 
A2: Getting ready for GDPR (with only one month to go)
A2: Getting ready for GDPR (with only one month to go)A2: Getting ready for GDPR (with only one month to go)
A2: Getting ready for GDPR (with only one month to go)
 
Implementing and Auditing GDPR Series (3 of 10)
Implementing and Auditing GDPR Series (3 of 10) Implementing and Auditing GDPR Series (3 of 10)
Implementing and Auditing GDPR Series (3 of 10)
 
Moral Responsibility of Data Professionals - Whistleblowing
Moral Responsibility of Data Professionals - WhistleblowingMoral Responsibility of Data Professionals - Whistleblowing
Moral Responsibility of Data Professionals - Whistleblowing
 
Implementing and Auditing GDPR Series (8 of 10)
Implementing and Auditing GDPR Series (8 of 10) Implementing and Auditing GDPR Series (8 of 10)
Implementing and Auditing GDPR Series (8 of 10)
 
What is CT- DPO.pdf
What is CT- DPO.pdfWhat is CT- DPO.pdf
What is CT- DPO.pdf
 
What does GDPR mean for your charity?
What does GDPR mean for your charity?What does GDPR mean for your charity?
What does GDPR mean for your charity?
 
Data Analytics Ethics: Issues and Questions (Arnie Aronoff, Ph.D.)
Data Analytics Ethics: Issues and Questions (Arnie Aronoff, Ph.D.)Data Analytics Ethics: Issues and Questions (Arnie Aronoff, Ph.D.)
Data Analytics Ethics: Issues and Questions (Arnie Aronoff, Ph.D.)
 
GDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc MichaelsGDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc Michaels
 

More from Browne Jacobson LLP

Employment law update - Browne Jacobson Exeter - 06 February 2020
Employment law update - Browne Jacobson Exeter - 06 February 2020Employment law update - Browne Jacobson Exeter - 06 February 2020
Employment law update - Browne Jacobson Exeter - 06 February 2020Browne Jacobson LLP
 
Exclusions: keeping you informed
Exclusions: keeping you informed Exclusions: keeping you informed
Exclusions: keeping you informed Browne Jacobson LLP
 
Procurement workshop training slides - Birmingham session
Procurement workshop training slides - Birmingham sessionProcurement workshop training slides - Birmingham session
Procurement workshop training slides - Birmingham sessionBrowne Jacobson LLP
 
Local authority acquisition and disposal of land - July 2019
Local authority acquisition and disposal of land - July 2019Local authority acquisition and disposal of land - July 2019
Local authority acquisition and disposal of land - July 2019Browne Jacobson LLP
 
Your employees, their future employers, and your intellectual property - July...
Your employees, their future employers, and your intellectual property - July...Your employees, their future employers, and your intellectual property - July...
Your employees, their future employers, and your intellectual property - July...Browne Jacobson LLP
 
Public Sector Planning Club - 4 July 2019
Public Sector Planning Club - 4 July 2019Public Sector Planning Club - 4 July 2019
Public Sector Planning Club - 4 July 2019Browne Jacobson LLP
 
Education Law Conference Manchester - Monday 10 June 2019
Education Law Conference Manchester - Monday 10 June 2019Education Law Conference Manchester - Monday 10 June 2019
Education Law Conference Manchester - Monday 10 June 2019Browne Jacobson LLP
 
Education Law Conference Exeter - Thursday 6 June 2019
Education Law Conference Exeter - Thursday 6 June 2019Education Law Conference Exeter - Thursday 6 June 2019
Education Law Conference Exeter - Thursday 6 June 2019Browne Jacobson LLP
 
Redress Schemes for Abuse and Misconduct, March 2019
Redress Schemes for Abuse and Misconduct, March 2019Redress Schemes for Abuse and Misconduct, March 2019
Redress Schemes for Abuse and Misconduct, March 2019Browne Jacobson LLP
 
Claims Club - March 2019 - Birmingham
Claims Club - March 2019 - BirminghamClaims Club - March 2019 - Birmingham
Claims Club - March 2019 - BirminghamBrowne Jacobson LLP
 
Claims Club - March 2019 - London
Claims Club - March 2019 - London Claims Club - March 2019 - London
Claims Club - March 2019 - London Browne Jacobson LLP
 
Admin and Public Law - April 2019 - London
Admin and Public Law - April 2019 - London Admin and Public Law - April 2019 - London
Admin and Public Law - April 2019 - London Browne Jacobson LLP
 
State aid and IP in R&D agreements, March 2019
State aid and IP in R&D agreements, March 2019 State aid and IP in R&D agreements, March 2019
State aid and IP in R&D agreements, March 2019 Browne Jacobson LLP
 
Privileged communications webinar, March 2019
Privileged communications webinar, March 2019 Privileged communications webinar, March 2019
Privileged communications webinar, March 2019 Browne Jacobson LLP
 
Social care forum, March 2019, Manchester
Social care forum, March 2019, ManchesterSocial care forum, March 2019, Manchester
Social care forum, March 2019, ManchesterBrowne Jacobson LLP
 
Public sector breakfast club, February 2019, Exeter
Public sector breakfast club, February 2019, Exeter Public sector breakfast club, February 2019, Exeter
Public sector breakfast club, February 2019, Exeter Browne Jacobson LLP
 
Public sector planning club, February 2019, Nottingham
Public sector planning club, February 2019, NottinghamPublic sector planning club, February 2019, Nottingham
Public sector planning club, February 2019, NottinghamBrowne Jacobson LLP
 
Mental health, capacity and deprivation of liberty case law update, February ...
Mental health, capacity and deprivation of liberty case law update, February ...Mental health, capacity and deprivation of liberty case law update, February ...
Mental health, capacity and deprivation of liberty case law update, February ...Browne Jacobson LLP
 

More from Browne Jacobson LLP (20)

Employment law update - Browne Jacobson Exeter - 06 February 2020
Employment law update - Browne Jacobson Exeter - 06 February 2020Employment law update - Browne Jacobson Exeter - 06 February 2020
Employment law update - Browne Jacobson Exeter - 06 February 2020
 
Exclusions: keeping you informed
Exclusions: keeping you informed Exclusions: keeping you informed
Exclusions: keeping you informed
 
Procurement workshop training slides - Birmingham session
Procurement workshop training slides - Birmingham sessionProcurement workshop training slides - Birmingham session
Procurement workshop training slides - Birmingham session
 
Local authority acquisition and disposal of land - July 2019
Local authority acquisition and disposal of land - July 2019Local authority acquisition and disposal of land - July 2019
Local authority acquisition and disposal of land - July 2019
 
Your employees, their future employers, and your intellectual property - July...
Your employees, their future employers, and your intellectual property - July...Your employees, their future employers, and your intellectual property - July...
Your employees, their future employers, and your intellectual property - July...
 
Public Sector Planning Club - 4 July 2019
Public Sector Planning Club - 4 July 2019Public Sector Planning Club - 4 July 2019
Public Sector Planning Club - 4 July 2019
 
Health tech slides 12 june 2019
Health tech slides   12 june 2019Health tech slides   12 june 2019
Health tech slides 12 june 2019
 
Education Law Conference Manchester - Monday 10 June 2019
Education Law Conference Manchester - Monday 10 June 2019Education Law Conference Manchester - Monday 10 June 2019
Education Law Conference Manchester - Monday 10 June 2019
 
Education Law Conference Exeter - Thursday 6 June 2019
Education Law Conference Exeter - Thursday 6 June 2019Education Law Conference Exeter - Thursday 6 June 2019
Education Law Conference Exeter - Thursday 6 June 2019
 
Redress Schemes for Abuse and Misconduct, March 2019
Redress Schemes for Abuse and Misconduct, March 2019Redress Schemes for Abuse and Misconduct, March 2019
Redress Schemes for Abuse and Misconduct, March 2019
 
Claims Club - March 2019 - Birmingham
Claims Club - March 2019 - BirminghamClaims Club - March 2019 - Birmingham
Claims Club - March 2019 - Birmingham
 
Claims Club - March 2019 - London
Claims Club - March 2019 - London Claims Club - March 2019 - London
Claims Club - March 2019 - London
 
Admin and Public Law - April 2019 - London
Admin and Public Law - April 2019 - London Admin and Public Law - April 2019 - London
Admin and Public Law - April 2019 - London
 
State aid and IP in R&D agreements, March 2019
State aid and IP in R&D agreements, March 2019 State aid and IP in R&D agreements, March 2019
State aid and IP in R&D agreements, March 2019
 
In House Lawyers, March 2019
In House Lawyers, March 2019In House Lawyers, March 2019
In House Lawyers, March 2019
 
Privileged communications webinar, March 2019
Privileged communications webinar, March 2019 Privileged communications webinar, March 2019
Privileged communications webinar, March 2019
 
Social care forum, March 2019, Manchester
Social care forum, March 2019, ManchesterSocial care forum, March 2019, Manchester
Social care forum, March 2019, Manchester
 
Public sector breakfast club, February 2019, Exeter
Public sector breakfast club, February 2019, Exeter Public sector breakfast club, February 2019, Exeter
Public sector breakfast club, February 2019, Exeter
 
Public sector planning club, February 2019, Nottingham
Public sector planning club, February 2019, NottinghamPublic sector planning club, February 2019, Nottingham
Public sector planning club, February 2019, Nottingham
 
Mental health, capacity and deprivation of liberty case law update, February ...
Mental health, capacity and deprivation of liberty case law update, February ...Mental health, capacity and deprivation of liberty case law update, February ...
Mental health, capacity and deprivation of liberty case law update, February ...
 

Recently uploaded

Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptxConstitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptxsrikarna235
 
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTSVIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTSDr. Oliver Massmann
 
Law360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics GuidanceLaw360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics GuidanceMichael Cicero
 
如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书Fir L
 
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书Fir L
 
如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书
如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书
如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书SD DS
 
John Hustaix - The Legal Profession: A History
John Hustaix - The Legal Profession:  A HistoryJohn Hustaix - The Legal Profession:  A History
John Hustaix - The Legal Profession: A HistoryJohn Hustaix
 
如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书Fir L
 
如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书
如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书
如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书SD DS
 
如何办理佛蒙特大学毕业证学位证书
 如何办理佛蒙特大学毕业证学位证书 如何办理佛蒙特大学毕业证学位证书
如何办理佛蒙特大学毕业证学位证书Fir sss
 
如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书SD DS
 
Special Accounting Areas - Hire purchase agreement
Special Accounting Areas - Hire purchase agreementSpecial Accounting Areas - Hire purchase agreement
Special Accounting Areas - Hire purchase agreementShubhiSharma858417
 
Comparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesComparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesritwikv20
 
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Dr. Oliver Massmann
 
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝soniya singh
 
Test Identification Parade & Dying Declaration.pptx
Test Identification Parade & Dying Declaration.pptxTest Identification Parade & Dying Declaration.pptx
Test Identification Parade & Dying Declaration.pptxsrikarna235
 
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书Fs Las
 
POLICE ACT, 1861 the details about police system.pptx
POLICE ACT, 1861 the details about police system.pptxPOLICE ACT, 1861 the details about police system.pptx
POLICE ACT, 1861 the details about police system.pptxAbhishekchatterjee248859
 
Why Every Business Should Invest in a Social Media Fraud Analyst.pdf
Why Every Business Should Invest in a Social Media Fraud Analyst.pdfWhy Every Business Should Invest in a Social Media Fraud Analyst.pdf
Why Every Business Should Invest in a Social Media Fraud Analyst.pdfMilind Agarwal
 
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》o8wvnojp
 

Recently uploaded (20)

Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptxConstitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
 
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTSVIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
 
Law360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics GuidanceLaw360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
 
如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书
 
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
 
如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书
如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书
如何办理(ISU毕业证书)爱荷华州立大学毕业证学位证书
 
John Hustaix - The Legal Profession: A History
John Hustaix - The Legal Profession:  A HistoryJohn Hustaix - The Legal Profession:  A History
John Hustaix - The Legal Profession: A History
 
如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书
 
如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书
如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书
如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书
 
如何办理佛蒙特大学毕业证学位证书
 如何办理佛蒙特大学毕业证学位证书 如何办理佛蒙特大学毕业证学位证书
如何办理佛蒙特大学毕业证学位证书
 
如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书
 
Special Accounting Areas - Hire purchase agreement
Special Accounting Areas - Hire purchase agreementSpecial Accounting Areas - Hire purchase agreement
Special Accounting Areas - Hire purchase agreement
 
Comparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesComparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use cases
 
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
 
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
 
Test Identification Parade & Dying Declaration.pptx
Test Identification Parade & Dying Declaration.pptxTest Identification Parade & Dying Declaration.pptx
Test Identification Parade & Dying Declaration.pptx
 
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
 
POLICE ACT, 1861 the details about police system.pptx
POLICE ACT, 1861 the details about police system.pptxPOLICE ACT, 1861 the details about police system.pptx
POLICE ACT, 1861 the details about police system.pptx
 
Why Every Business Should Invest in a Social Media Fraud Analyst.pdf
Why Every Business Should Invest in a Social Media Fraud Analyst.pdfWhy Every Business Should Invest in a Social Media Fraud Analyst.pdf
Why Every Business Should Invest in a Social Media Fraud Analyst.pdf
 
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
 

Education law conferences, March 2018, Workshop 1B - The role of the DPO

  • 1. Education law conferences 2018 Workshop 1B: The role of the DPO
  • 2. The role of the DPO Join the conversation #BJ_EDC
  • 3. 1. Understanding the role 2. Skills and support required 3. Who to appoint 4. Training your DPO 5. Managing a data breach
  • 4. 1. Understanding the role Join the conversation #BJ_EDC
  • 5. Understanding the role Do I need to appoint a DPO? • Yes • GDPR requires a DPO to be appointed by public authorities and (currently) this includes state schools and academies
  • 6. Understanding the role Do MATs need a DPO for each school? • No • A MAT is a single legal entity so the requirement will be for one DPO for the MAT • Consider the team the DPO needs around them
  • 7. Sli.do – vote now Have you identified your DPO yet? • Yes • No • Don’t know
  • 8. Understanding the role Articles 37-39 • Monitor GDPR compliance and implementation and application of data protection policies • Inform/advise school and staff about GDPR obligations • Advise whether and how to carry out DPIA
  • 9. Understanding the role Articles 37-39 (cont.) • Be the point of contact for the ICO • Train staff • Carry out internal data audits
  • 10. Understanding the role Data Protection Impact Assessments DPO should be able to advise on the following in respect to the Data Protection Impact Assessments: • whether to carry out a DPIA • what methodology to follow when carrying out a DPIA • whether to do it in-house or outsource it
  • 11. Understanding the role Data Protection Impact Assessments DPO should be able to advise on the following in respect to the Data Protection Impact Assessments (cont.): • safeguards to apply to mitigate risks to data subjects • whether the DPIA has been correctly carried out and whether its conclusions comply with the GDPR
  • 12. Understanding the role DPO involvement – You must ensure that: • The DPO is involved in all issues relating to the protection of personal data • The DPO reports to your highest management level – i.e. school governors/MAT Board • The DPO operates independently and is not dismissed or penalised for performing their task
  • 13. Understanding the role DPO involvement – You must ensure that (cont.): • Adequate resources are provided to enable DPOs to meet their GDPR obligations • The DPO can be contacted by data subject on all issues relating to the processing of their personal data
  • 14. 2. Skills and support required Join the conversation #BJ_EDC
  • 15. Skills and support required Qualifications No precise credentials specified by the GDPR, but…. • DPO must have expert knowledge of data protection law and practice • Good quality training will be needed
  • 16. Skills and support required Art 29 Working Party – necessary skills & expertise include: • expertise in national and European data protection laws and practices including an in-depth understanding of the GDPR • understanding of processing operations carried out • understanding of information technologies and data security • knowledge of the business sector and the organisation • able to promote data protection culture within organisation
  • 17. Skills and support required Support by your school/trust • Active support of the DPO function by senior management • Sufficient time and resources for DPO to fulfil their duties • Communicate designation of DPO to all staff • Continuous training
  • 18. Skills and support required Support by your school/trust (cont.) • Ensure DPO is involved in all data protection • DPO reports to SLT/governors/MAT Board • DPO operates independently • DPO can be contacted by data subjects
  • 19. 3. Who to appoint Join the conversation #BJ_EDC
  • 20. Who to appoint Who should be your DPO? • No need to employ new person or make it a sole role • Consider experience and knowledge of data protection law and practices • Can be a DPO for more than one school – but consider: • Organisation structure and size • Accessibility of the DPO from each establishment
  • 21. Who to appoint What about potential conflict? GDPR Working Party: “As a rule of thumb, conflicting positions may include senior management positions (such as chief executive, chief operating, chief financial, chief medical officer, head of marketing department, head of Human Resources or head of IT departments) but also other roles lower down in the organisational structure if such positions or roles lead to the determination of purposes and means of processing.”
  • 22. Who to appoint How do I apply this in my school? • Not about the title held but the role undertaken • First focus on the abilities of the candidate then address whether that person – because of the role they undertake – is conflicted • IT lead is best example
  • 23. Who to appoint Outsourcing • You can outsource, but no expectation that you do so • You should consider: • Cost • Due diligence • SLAs
  • 24. 4. Training your DPO Join the conversation #BJ_EDC
  • 25. Training your DPO Initial training • Training will be required at the outset • You should consider: • Cost • Due diligence • Skill and expertise • How the outcomes of the training are objectively measured
  • 26. Training your DPO Ongoing updates • Keeping up to date throughout the role will be important • Email updates, webinars, conferences, etc. • Annual refresher training might be worth considering • Again, consider how you can evidence outcomes
  • 27. 5. Managing a data breach Join the conversation #BJ_EDC
  • 28. Managing a data breach Quick case study A staff member downloads pupil safeguarding information onto a memory stick and loses it but doesn’t tell you The first you hear about it is when the parent concerned tells you people have been talking about her child’s safeguarding history on Facebook for the last 10 days or so You report to the ICO within 48 hours of the parent telling you
  • 29. Sli.do – vote now What do you think the ICO response will be? • Thank you for reporting it • Issue a formal warning • Fine you up to £75,000 • Fine you more than £75,000
  • 30. Managing a data breach • Must have procedures in place to detect, report and investigate a personal data breach • Breach must be reported unless breach is unlikely to result in a risk to the rights and freedoms of natural persons • 72 hours from the discovery of the breach to report to ICO • Notify the affected data subjects
  • 31. Managing a data breach What must you tell the ICO? 1. Nature of the breach and where possible a. Categories and number of data subjects concerned b. Categories and number of personal data records concerned 2. Name and contacts details of your DPO 3. Describe likely consequences of the data breach
  • 32. Managing a data breach What must you tell the ICO (cont.)? 4. Describe measures taken/to be taken to address the breach and mitigate possible adverse affects • You can provide this information in stages, but without undue delay • What does this look like in practice?
  • 33. Managing a data breach In practice • Drop everything – akin to a serious safeguarding incident • Follow your data breach procedures • Seek external legal support as appropriate • Business critical priority to manage quickly and effectively
  • 35. Please note The information contained in these notes is based on the position at March 2018. It does, of course, only represent a summary of the subject matter covered and is not intended to be a substitute for detailed advice. If you would like to discuss any of the matters covered in further detail, our team would be happy to do so. © Browne Jacobson LLP 2018. Browne Jacobson LLP is a limited liability partnership.