Data protection for the education sector 4pm Tuesday 28 February The Information Commissioners Office The UKs independent body set up to uphold information rights

Enforce and regulate freedom of information and data protection laws Provide information and advice Promote good practice data which relate to a living individual who can be identified (a) from those data, or (b) from those data and other

information which is in the possession of, or is likely to come into the possession of, the data controller Personal data The Data Protection Act 1998 ICO data protection enforcement

0 0 0 , 0 0 5 Fair and lawful

Make sure you have a legal basis to process personal data Only collect what you need Clearly tell individuals what personal data you are collecting and why Privacy notice

What information is being collected? Who is collecting it? How is it collected?

Why is it being collected? How will it be used?

Who will it be shared with? Individuals rights Security of personal data Seventh principle: Appropriate technical and organisational measures

shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data. Guidance for the education sector The future of data protection: GDPR The General Data Protection Regulation Same basic principles as current DP law, but strengthened

Accountability New rights for individuals, and strengthening of existing rights

Breach reporting Data Protection Impact Assessments Higher penalties for non-compliance Minimise the risk Assess the risk what personal data do you process, and how? Policies Responsibilities Training and awareness Demonstrating compliance The controller shall be responsible for, and be able

to demonstrate compliance with the Principles Article 5(2) Requirement to implement appropriate technical and organisational measures Requirement to appoint a data protection officer Maintaining records on

processing activities Data protection by design and default Data protection impact assessments Codes of conduct and certification schemes

What can I do to prepare? ICO guidance 12 steps Overview of the GDPR Privacy notices code of practice EU guidance Right to data portability

DPOs Identifying a lead supervisory authority Where to start? Information asset audit What data do we process? For what purposes? What legal basis do we use? Who do we share data

with? Keep in touch ICO helpline: 0303 123 1113 Subscribe to our e-newsletter at or find us on @iconews

