Best Practice Update

man in a blue suit with a blue padlock hovering above his hands.  The word governance in white text on a blue background

Governors and Data Best Practice Area Update

The Governors and Data Best Practice area has been updated with some new content from the Norfolk and Suffolk Constabularies.  There is a training video: 'Protecting Yourself and Your School from Cybercrime' and a pdf of the slides from the video. There is input for school governors to highlight the risks presented by cyber crime and the resources and support available to help you improve your organisation's cyber security.

Read more …

Hands typing on a laptop. Laptop screen shows view of the Compliance manager which is part of the Data Protection Education Knowledge Bank portal.

Trust Initial Plan for Data Protection Compliance (for Multi Academy Trusts)

We launched our Schools Best Practice area at the beginning of this term which includes specific guides and support for schools.  There is also a specific area for Trusts and the Central Team.  The Trusts Central Team section is a specific area for additional requirements and guidance for the central team of a trust and should be used in conjunction with the other tabs in the best practice area.  

Read more …

Lettings and Best Practice in Blue text, hand dangling a bunch of keys. Data Protection Education DPO badge in the bottom left

Lettings Best Practice and Guidance

During our data walks we are looking at data breach risks, in terms of 'Who has access to what data?'.  As part of our walk we may ask who has access to the school other than the employees and children attending, for example, Lettings.  As Lettings usually occur outside of the school working day, physical security can be overlooked or not thought about and so raises the risk of a data breach.  This article is launching our Lettings Checklist for schools which is shown at the end o

Read more …

grey computer keyboard with blue key with white text:'Data Migration'

Considerations when migrating to a new MIS

Moving MIS is a daunting task and is no small undertaking for a school. Moving to the cloud from a legacy system means that there are cyber security benefits but may be something new to your organisation. There is often the assumption that the new MIS porvider will seamlessly migrate the data for you, however there is a considerable amount of work that the school must do beforehand in order to make this happen.  This article provides some practical guidance and considerations.

Read more …

public sector in brown text on cream puzzle pieces held at each end by hands

Public bodies and sensitive data

Computing Magazine recently reported about the ICO reprimanding seven organisation for domestic abuse breaches in the last 14 months.  A collection of public bodies, charitable organisations, law enforcers and lawyers have made personal data slips when handling domestic abuse cases in the last year, showig abusers where to find their victim is hiding.

Read more …

Be cyber aware in orange text on a blue background above a mobile phone and padlock. Also the Data Protection Education logo

Help after a Cyber Attack/Incident

The time following a cyber attack can be very stressful, and in the heat of the moment it can be difficult to know what the best thing to do between working out what went wrong, how to recover and what went missing, it can be hard to know where to start first.

We provide some help and guidance in our Information and Cyber Security Best Practice Area, which also includes the checklist:  document What to do immediately after a Cyber Attack (58 KB) .

Read more …

  1. Data Protection and Cyber Security (Inset Day) Training Ideas
  2. How KCSIE is linked to Cyber Strategy
  3. Handling Freedom of Information Requests the right way
  4. Where's Harry the Hacker?
  5. The ICO Reprimands a school
  6. Subject Access Requests (SARs)
  7. Redaction Guidelines Updated
  8. Using WhatsApp in Schools
  9. How to contact us for support, subject access requests, data breaches and FOI's
  10. FOI: Reinforced Autoclaved Aerated Concrete
  11. FOI: Henry Jackson Society
  12. FOI: Vaccination Justifications
  13. How the Record of Processing Can Help You
  14. What does a Data Protection Officer Do?
  15. Blog: Best Practice on the Retention of Child Protection Information
  16. Carrying out Supplier Due Diligence
  17. Email and retention periods
  18. How Long Should You Keep Personal Data For?
  19. Sharing this year’s Nativity play online
  20. B&H FoI: Racist/religious incidents/bullying
  21. Protocol for Setting Up and Delivery of Online Teaching and Learning
  22. Class Dojo International Data Sharing
  23. Model Publication Scheme: Amendments, Improvements and Updates
  24. Transparency
  25. Parents and students covertly recording conversations
  26. SAR? ER? FOI?
  27. Research projects and GDPR
  28. Secure file transfer of files using Royal Mail
  29. Emergency contacts and consent
  30. Key elements of a successful DPIA
  31. FOI Publication Schemes
  32. Best Practice for Managing Photos and Video
  33. New Drip Feeds: Recognise and Respond to Subject Access Request
  34. When to contact the Data Protection Officer?
  35. National child measurement programme
  36. Make sure DPE is your registered DPO with the ICO
  37. Headteacher fined for breach of data protection legislation

Search