Data Protection in Schools

Slides:



Advertisements
Similar presentations
Administrative Systems and the Law What you need to know to produce an oral presentation for Unit 7 When the presentations will take place Resources you.
Advertisements

Data Protection & Freedom of Information The Practical Implications of Data Protection and Freedom of Information Caroline Dominey Data Protection Officer.
Duncan Woodhouse – Assistant Registrar for Information Security, Risk Management and Business Continuity Helen Wollerton – Administrative Officer (Legal.
Anglican Province of Canada Privacy Policy. Commitment to Privacy The Privacy Policy, including the Web Privacy Statement, is the Anglican Province of.
Data Protection Act Description The Data Protection Act controls how your personal information can be used and protects from the misuse of your.
Confidentiality… important facts to know and critical things to do!
DATA PROTECTION AND PATIENT CONFIDENTIALITY IN RESEARCH Nic Drew Data Protection Manager University Hospital of Wales   
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Act. Lesson Objectives To understand the data protection act.
FORCE INFORMATION MANAGEMENT. INFORMATION MANAGEMENT Aim: To provide students with an awareness of the Force Information Management and legislation that.
 The Data Protection Act 1998 is an Act of Parliament which defines UK law on the processing of data on identifiable living people and it is the main.
Professional Values and Basic Business Legislation.
OCR Nationals Level 3 Unit 3.  To understand how the Data Protection Act 1998 relates to the data you will be collecting, storing and processing  To.
The Data Protection Act (1998). The Data Protection Act allows you to Check if any organisation keeps information about you on computer or in paper form.
Processing personal health data: the regulator’s perspective Ken Macdonald Assistant Commissioner Information Commissioner’s Office.
What is personal data? Personal data is data about an individual which they consider to be private.
Data Protection Act (1984, 1998). 2 Data Protection Act There are many organisations which hold personal information about individuals Examples: Loyalty.
The Data Protection Act What the Act covers The misuse of personal data by organisations and businesses.
THE DATA PROTECTION ACT Data Protection Act 1998 DPA 1. Reasons2. People3. Principles 4. Exemptions 4 key points you need to learn/understand/revise.
LEGISLATION. DATA PROTECTION ACT (1998) The aim of this act give people the right to know what information is held about them. It also sets out rules.
Data Protection Act (1998).
Computing, Ethics & The Law. The Law Copyright, Designs and Patents Act (1988) Computer Misuse Act (1990) Data Protection Act (1998) (8 Main Principles)
INFORMATION GOVERNANCE AND CONFIDENTIALITY Information Governance Facilitator.
Data Protection and research Rachael Maguire Records Manager.
What is the Data Protection Act (DPA)? 1998 The Data Protection Act 1998 seeks to strike a balance between the rights of individuals and the sometimes.
Data Protection Philip Reed. Introduction What is data? What is data protection? Who needs your data? Who wants your data? Who does not need your data?
DATA PROTECTION AND RUNNING A COMPLIANT PUB WATCH SCHEME Nigel Connor Head of Legal –JD Wetherspoon PLC.
Workshop Understanding your responsibilities under the Data Protection Act 1998 and the Freedom of Information Act 2000 Adele Rhodes Girling.
The Data Protection Act 1998
The Data Protection Act 1998
Data protection and data sharing
Making the Connection ISO Master Class An Overview.
PowerPoint presentation
Trevor Ellis Trainee Programmer (1981 – 28 years ago)
Handout 2: Data Protection and Copyright
Privacy Impact Assessments (PIAs)
General Data Protection Regulation
Data Protection Act.
The Data Protection Act 1998
Nina Barakzai November 2017
Data Protection & Freedom of Information- An Introduction
GENERAL DATA PROTECTION REGULATION (GDPR)
The Data Protection Act & ICT Law
Pam Millington Area 4 co-ordinator
Data Protection Act.
Information Governance
G.D.P.R General Data Protection Regulations
Data Protection and Running a Compliant Pub Watch SCHeme
General Data Protection Regulation
Data Protection principles
Data Protection and You
Data Protection in Schools
Identify the laws and guidelines that affect day-to-day use of IT.
Legal and Ethical Issues
How we use Your Health Records
Information management and communication
Data protection and data sharing
General Data Protection Regulations 2018
General Data Protection Regulations (GDPR) Training
What is the Data Protection Act (DPA)? 1998
GDPR Quiz Today’s trainer: Click here to use Kahoot! 1
#eaThinkData Get Ready for GDPR #eaThinkData.
Hot Topic 1: GDPR and Traffic Data Systems
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
Identify the laws and guidelines that affect day-to-day use of IT.
Caring for People and their Data
General Data Protection Regulation Community Councils
e-security in an e-school 20 September 2008
European Computer Driving Licence Syllabus version 5.0
Presentation transcript:

Data Protection in Schools Slides are aimed at providing a 15-20 minute overview of Data Protection Under new regulations schools have greater accountability and improved processes © eLIM 2018

What is personal data? Anything that identifies a living individual! Think of 5 items of data held about learners? What data should be kept secret? Ask them to think if 5 items of personal data held about learners. Ask for ideas and get them to state who should see that item of data.

New Data Protection Bill Principles processing be lawful and fair purposes of processing be specified, explicit and legitimate adequate, relevant and not excessive accurate and kept up to date kept for no longer than is necessary processed in a secure manner Data belongs to the person – not the school We all have the right to see the data stored about ourselves Go through these slowly explaining each one Personal data shall be processed fairly and lawfully – we have to process data according to the laws and smile about it Personal data shall be obtained only for one or more specified and lawful purposes – we must have a reason to process the data and tell people what we are doing Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed. Personal data shall be accurate and, where necessary, kept up to date – quite difficult but we must all try to make sure that everyones data is up to date Personal data shall not be kept for longer than is necessary – think about your old mark books and photos Processed in a secure manner – not just the hardware but all the actions that go on around it. Think about the way in which we issue the Data Collection sheets Then click to reveal that data belongs to the person (data subject) which gives them the right to see the information held about them https://publications.parliament.uk/pa/bills/lbill/2017-2019/0066/lbill_2017-20190066_en_3.htm

Where is there personal data in schools? Paper files Information on servers/hard drives emails Little discussion about which of these can be seen as disclosable – what can be seen by the data subject. Most of these are disclosable. Temporary notes do not have to be kept once the information has been recorded properly. Lesson plans should be disclosed if they hold personal information. Notes made by a teacher for only their use do not have to disclosed – but if they are used in a meeting or for report writing then they should be (Why would you take notes if you are not going to use them or record them somewhere else!). Notebooks ‘Temporary’ notes Online Services and apps

Disclosure – Subject Access Request SEN information and evaluation Bullying incident Playground fight Safeguarding issue Incident with a teacher Long term disagreements with school Estranged parent 15 school days to provide an educational record SAFEGUARDING ALWAYS TAKES PRECEDENT What could be redacted redacted or exempt? Everything recorded should be professional in nature! Schools only get asked to disclose information when there is an issue. In general everything has to be disclosed – only safeguarding and if a crime could be committed do things get withheld. What could be withheld in a document? Other children’s names You only have 15 school days to release the information!!!!

New processes Respond to request for personal data as soon as you can We only have 15 days! Any new use of personal data in a webservice or App Fill in a Privacy Impact Form and discuss Data Breach Let the Data Protection Lead know as soon as possible We need to also have a couple more things to help us in our efforts to be secure If you want to use a new service then fill in a PIA form and then discuss with DPL If you lose data then let the DPL know as soon as possible, © eLIM 2018