• 0800 0862018
  • This email address is being protected from spambots. You need JavaScript enabled to view it.
  • Mon - Fri 8:00 - 17:00
Transparency written in pen, with the Data protection education logo above, a hand holding a pen on the left and a reflection of the hand below it

What Is Transparency

Transparency is about being clear, open and honest with your users about what they can expect from you.

Camera with man behind a piece of material poking through

We've had a few questions recently about parents and students recording conversations with members of staff, both covertly or overtly without seeking permission. This article only covers recordings made by external individuals, not organisations or individuals acting on behalf of an organisation.

DPE Knowledge Bank dashboard on a laptop screen on a desk

We know the jargon can be confusing. As can the timelines for responding to the various requests that you receive.

Is it a month? Or 30 days? Are those working days?

So here's a little chart to simplify everything:

Photo of a person's arm and putting a letter in the post box.  Data Protection Education logo on the bottom right of the image

We've recently had more than one breach reported where physical files have got lost in the post.

In such cases, the sender remains the data controller and is responsible for ensuring that the optimum data security measures are in place during transfer. Where possible, consider whether a physical drop-off (and get a receipt) is a more secure option.

Emergency contact information sheet with a yellow pencil above it, Data protection education logo on the sheet

Do I need consent for emergency contacts?

Actually no, and here's why.

We know that we must have a lawful basis for processing any data, and consent is one of the six lawful bases that can be used.

computer keyboard with due diligence on a blue key

Adapted from: The Irish Data Protection Commissioner

The UK GDPR does not prescribe the exact process for carrying out a DPIA beyond the minimum features outlined above, allowing for flexibility and scalability in line with your organisation’s needs. Although there is no one prescribed approach to take, the following steps can guide you through the process:

Freedom of information on a white key on a white keyboard

We have added publication scheme model templates in the FOI Best Practice area for academies as well as maintained schools.

Difference between the High Level and Detailed Publication Scheme

Old fashioned typewriter with Fake news types on Data Protection Education headed paper

The Government has provided some guidance on the avoidance of disinformation online.

https://sharechecklist.gov.uk/

What is disinformation?

Disinformation is the deliberate creation or dissemination of false and/or manipulated information

Photograph of a young girl taking a photo on a camera in a country lane. Data protection education logo is bottom left

In light of recent ICO reprimands to schools it is important schools remember best practice for managing photos. The formal legal warnings issued by the ICO recently to schools both related to the processing of photos where no consent had been given. 

Navy cie with an envelope, one with a phone symbol on with @ above a hand. Data protection education logo at the top

The Data Protection Officer (DPO) can provide support in many areas but are you aware of what we do help with?

There are some more well-known areas of data protection that we would be called upon to advise such as subject access requests and breaches but DPO’s don’t only provide advice and support when things go wrong,

Data Protection Education logo with text:Data Protection Education offers a fully-independent and impartial solution for long-term or one-off projects delivered through a team of consultants with a diverse mix of legal, data protection and educational expertise. on photo of laptop, hands and glasses on a desk.  Bottom of image blue on orange with text: Tools, best practice and support for your data protection and information risk management

Please ensure that you register DPE as your DPO with the Information Commissioner's Office. To do so:

To add a Data Protection Officer (DPO) email This email address is being protected from spambots. You need JavaScript enabled to view it. with the subject line ‘Add a DPO’ and include:

Compliance Manager released

We've released version 1 of the Compliance Manager tool.

What is it?
The Compliance Manager allows you to assign any document to staff and enable the following interactions

I have read and understood I have used this in practice

or

I have given consent

Any standard document type can be uploaded and interactions selected. Then select the users to assign the document too and a date by which the users should have responded.

Search