Data Protection

GDPR in schools

A personal touch to achieving compliance

Who can be my Data Protection Officer (DPO)?

This can be anyone who has no strategic or operational decision-making role with regards to data and data systems in your school. It doesn’t have to be a member of your own staff.

Examples of roles that are likely to not be able to be your DPO include the Headteacher, School Business Manager, Data Manager, IT Manager and most other senior leadership roles.

How We Can Help

As an education provider, you have a responsibility to protect your students, staff and school. However, the responsibility isn’t just with protecting the physical form – it also comes down to the protection of any information or data you hold about said individuals and how it’s managed and controlled within your environment.

SchoolPro TLC provides the role of Data Protection Officer (DPO) as a service for schools to demonstrate an enhanced level of data protection compliance to the Information Commissioner’s Office. Our DPO Service is intended to assist schools and multi-academy trusts (MATs) in complying with the requirement to appointment such a role with the responsibilities set out in the Data Protection Act 2018.

Our staff are experienced school leaders so understand the data flows and need for data in different areas of the school. Our support as DPO includes a free online recording and reporting system for all relevant GDPR information, so you don’t have to pay additionally for another expensive system.

We also provide a great deal of functions compared to some other purchased services, including completed Data Privacy Impact Assessments and compliance checking of supplier data privacy agreements.

 

How It Works 

Our delivery of the Data Protection Officer role shall include:
  • Providing advice and guidance when required
  • Supporting and monitoring the maintenance of data records
  • Drafting data policies and procedures
  • Providing training for employees
  • Acting as the first point of contact with authorities
  • Supporting the management of Subject Access Requests and those under the Freedom of Information Act 2000
  • Supporting the management, including investigation, reporting and review, of data breach incidents
  • Conducting an internal audit of your data processes up to twice a year
  • Providing you with access to our specifically designed Data Protection Portal
What are the advantages of outsourcing the DPO role for my school?

Access to high-levels of expertise and banks of resources. It also gives you an impartial view of your systems, processes and practice. In the event of a data protection incident, impact on the day-to-day running of the school will be minimal as school staff can continue to carry out their roles. It is likely that this will also be a more cost effective approach than using an existing member of staff when compared to additional non-contact time, training and, possibly, a TLR. The support is also available outside normal school working hours and during the school holidays.

A Cost Neutral Solution for GDPR in Schools

Our DPO service is cost-neutral compared to other, alternative solutions. For a school to appoint their own DPO, they will need to fund training for that individual and give them time to complete the role effectively. They will possibly also need to provide a financial incentive (such as a TLR) to them. Our experience and knowledge base (as well as economies of scale due to working with hundreds of schools) allow us to dramatically cut down these costs as well.

For example, a school senior leader earning £50k p.a. who is given an hour a week across the year to complete their DPO work is costing a school at least £2k which is more than our most expensive rate.

Data Protection Audits

One of our DPOs will carry out audits to provide an assessment of whether you and your school are following good data protection practice. The audits will look at whether they are following your policies and procedures and make recommendations for improvements, including any new guidance from the ICO. The audits can be undertaken alone or in conjunction with your DPO.

Data Protection Portal

In line with the Data Protection Act 2018 and in conjunction with the ICO published audit reports from MATs, we have designed a portal that enables schools and MATs to hold and log all relevant data protection information in one place. This includes all of our policy and document templates as well as the logging and reporting of data breaches, subject access requests and data decisions. All school-specific documents are hosted here including audit reports and all logs are also easily downloadable for review at governor or trustee level.

    The portal is split into five distinct sections:
    • Breaches – log and report on any data breaches that may occur in your schools.
    • Subject Access Requests – log and report on any subject access requests that may occur in your schools.
    • Data Decisions – log and report on any data decisions made where data is processed in such a way that could create risks to the rights and freedoms of individuals, or it involves special categories of data. It can also be used to log incidences of one-off data sharing.
    • Global Documents – access and download all of our supporting material for data protection including policy templates, training resources, privacy notices, retention schedules and data protection impact assessments.
    • School Documents – access and download any school-specific documents once completed such as audit reports and your data maps.

    Our online tool is hosted and secured on servers located in the UK. Our systems and processes anonymise all data where possible so it is not personally identifiable and we have a regular routine for deletion of any identifiable information.

    Data Protection Training / CPD

        Aims of this session are to:
        • Develop an understanding of the statutory responsibility to monitor and evaluate data processing within your setting
        • Develop a greater awareness of the potential pitfalls
        • Share good practice in relation to data protection using case studies from schools we currently work with
        • Raise awareness of how data protection is everyone’s concern

        All of our CPD sessions can be delivered to a whole staff body or we offer bespoke sessions for different groups of staff, for example governors, senior leaders, admin, SENDCO, new starters, or as refresher training. Here is an example of our Data Protection Training for SENDCOs and DSLs.

          The aim of the session is to:
          • Develop an understanding of the statutory responsibility to monitor and evaluate data processing with specific focus on SEN and Child Protection (CP) pupils
          • Develop a greater awareness of the potential pitfalls of processing SEN and CP data
          • Share good practice in relation data protection using case studies from schools we currently work with
          • Raise awareness of the retention schedules for SEN and CP data

          Our CPD sessions are delivered on site with staff, so they can fully engage and ask questions that are directly relevant to school staff and their specific role. As we are experienced school leaders, we do understand the need for all roles in school, so our advice and guidance is education- and role-specific.

          Whole staff sessions run for about an hour, other bespoke sessions can vary in length depending on need. Where INSET time does not allow for one of our sessions, we will provide materials for all content and keep you informed of any relevant updates.

          As we don’t want to hold too much personal data, we do not hold lists of names of staff that attended courses but we will record when school training took place and the content delivered.

          We have also recently launched our online training platform. You can purchase courses for individual members of staff in our shop or use the link below to purchase group licences for your whole school. Our training platform hosts role-specific training courses including:

          • Data Protection for Education Staff
          • Data Protection for Child Protection Leads
          • Data Protection for Governors/Trustees (maintained schools and standalone academies)
          • Data Protection for Lunchtime, Cleaning and Site Staff
          • Data Protection for School Administrators

          Courses typically take an hour to complete and can be used as annual refreshers for staff. Staff will receive a SchoolPro TLC Ltd certificate upon completion.

          For more information and to order licences, click below:

          Please note – access to our online training platform is FREE for organisations that are signed up to our Data Protection Officer service.

          Frequently Asked Questions

              How often will you be onsite?

              You can expect to see your DPO twice a year for routine visits (audits and training) but they will also be available whenever needed in the event of a data protection incident.

              Will I get remote support when they are not onsite?

              Yes, your DPO will be available via phone and email when not visiting your site. You will also have access to our online portal for reporting breaches and subject access requests, logging data decisions and downloading document templates.

              What about school holidays?

              Our DPOs will be available to provide support both during term-time and during the school holidays.

              We provide all schools with a data sharing agreement to include necessary guarantees about data.

              Customer Stories

              Rhian Cockwell

              It gave a good framework to plan through

              Thank you, I am very grateful to you for this. I used the document with my online governors meeting and it gave a good framework to plan through. I’d also added notes where we sectioned things and what we had done so made me feel better seeing what we had already put in place.

              It gave a good framework to plan through

              Thank you, I am very grateful to you for this. I used the document with my online governors meeting and it gave a good framework to plan through. I’d also added notes where we sectioned things and what we had done so made me feel better seeing what we had already put in place.

              Rhian Cockwell

              Stephen Trobridge

              We could not have asked for a better quality partner

              Chilton Foliat primary school were looking for a solution to providing compliance with the new GDPR framework as mandated by the department of education, and I was asked to research and advise a suitable organisation to provide this role. I reached out to a number of organisations that I was able to...
              Read More

              We could not have asked for a better quality partner

              Chilton Foliat primary school were looking for a solution to providing compliance with the new GDPR framework as mandated by the department of education, and I was asked to research and advise a suitable organisation to provide this role. I reached out to a number of organisations that I was able to find on Google who provided GDPR solutions, both in the form of software and training to manage the GDPR tasks, or a Data Protection Officer (DPO) capability for schools and academies. I ended up with a shortlist of 4 organisations who were promoting a GDPR solution, two of which provided software and backup and advisory capabilities, and two that provided a discrete DPO service without the need for costly software products and the training needed to implement an In-house tailored solution. After the school governing body had reviewed the 4 prospectuses, SchoolPro TLC were the unanimous choice to provide a DPO capability that suited our modest needs and which had the most flexible and cost effective solution to help us achieve those objectives. We have found the responses we have received from SchoolTLC to be exemplary thus far and are looking forward to nurturing this partnership as we move forward. We could not have asked for a better quality partner to help us overcome our initial concerns and confusion of developing a GDPR process in such a timely and ordered manner. We have no hesitation in highly recommending this organization to other school looking to achieve GDPR compliance by way of their professional ism, value for money and attentiveness to our initial requirements.’

              Stephen Trobridge

              Julia White

              The cost is affordable and the service very good.

              We have used SchoolPro’s DPO service for 2 academic years. The cost is affordable and the service very good. Ian Arkell has been really helpful with some complicated GDPR issues and SAR requests, as well as the more routine annual inspections and staff training.

              The cost is affordable and the service very good.

              We have used SchoolPro’s DPO service for 2 academic years. The cost is affordable and the service very good. Ian Arkell has been really helpful with some complicated GDPR issues and SAR requests, as well as the more routine annual inspections and staff training.

              Julia White

              Kevin Parker

              I cannot recommend them highly enough

              As we approach 2 years working with SchoolPro TLC I cannot recommend them highly enough. They are our Schools DPO and offer a fantastic service which is great value for money. As well as being your Schools DPO and undertaking annual audits, data mapping, completing DPIA and staff training – Th...
              Read More

              I cannot recommend them highly enough

              As we approach 2 years working with SchoolPro TLC I cannot recommend them highly enough. They are our Schools DPO and offer a fantastic service which is great value for money.

              As well as being your Schools DPO and undertaking annual audits, data mapping, completing DPIA and staff training – They also offer a wide range of other services including curriculum, governance, school improvement and leadership. They have recently completed a detailed website audit for us in line with the new statutory guidance, which is in the process of being actioned – This is also included in the annual cost.

              I have personally worked with Richard Morley for 7+ years in various capacities, and his ability to inspire, proven track record of achieving great results teamed alongside his personality and knowledge has led me to build up a great working partnership with him.

              If you would like to enquire about SchoolPro TLC services, please don’t hesitate to get in contact with them either via their website – https://schoolpro.uk/ or LinkedIn. You will not be disappointed!

              Kevin Parker

              Rob Sharpe

              Rest assured that you need look no further for any DPO needs than with SchoolPro.

              Along with some of our partner primary schools we have utilised the services of SchoolPro as our Data Protection Officer (DPO) to support our school in all of our GDPR matters. The advice and support that we have received as a school can’t be faulted. We have shared ideas with SchoolPro and ha...
              Read More

              Rest assured that you need look no further for any DPO needs than with SchoolPro.

              Along with some of our partner primary schools we have utilised the services of SchoolPro as our Data Protection Officer (DPO) to support our school in all of our GDPR matters. The advice and support that we have received as a school can’t be faulted. We have shared ideas with SchoolPro and have been highly satisfied with all advice that has been offered. The customer service is outstanding with there being swift responses to any queries that are brought to the attention of the DPO by phone or e-mail and there is always a response within 24 hours and less (this has been most helpful when dealing with a SAR request on the penultimate day of a term where Ian Arkell supported us in the response. He also gave us peace-of-mind in dealing with a GDPR matter where, once briefed, he then made contact with relevant subjects to resolve a matter to the satisfaction of all concerned. Rest assured that you need look no further for any DPO needs than with SchoolPro. BTW…no payment has been received for this review!

              Rob Sharpe

              Karen Cromwell

              I have no hesitation in recommending SchoolPro to any of the schools in my area

              Thank you again for your help and your generosity… I have been so pleased with your service that I have no hesitation in recommending SchoolPro to any of the schools in my area.

              I have no hesitation in recommending SchoolPro to any of the schools in my area

              Thank you again for your help and your generosity… I have been so pleased with your service that I have no hesitation in recommending SchoolPro to any of the schools in my area.

              Karen Cromwell

              Lisa Silva

              Primary School Business Manager

              Once again you have helped us rectify the issue promptly and effectively

              Thank you for your help on this matter, once again you have helped us rectify the issue promptly and effectively.

              Once again you have helped us rectify the issue promptly and effectively

              Thank you for your help on this matter, once again you have helped us rectify the issue promptly and effectively.

              Lisa Silva

              Primary School Business Manager

              Rachel Heffer

              It is so reassuring to know we can call on you for advice and guidance when we most need it.

              Thanks for the recent documents that have been sent through to the schools – they have been very well received… I have certainly found them useful. Thank you for providing the peace of mind we all need in a profession, where we are constantly under scrutiny. It is so reassuring to know we can...
              Read More

              It is so reassuring to know we can call on you for advice and guidance when we most need it.

              Thanks for the recent documents that have been sent through to the schools – they have been very well received… I have certainly found them useful.

              Thank you for providing the peace of mind we all need in a profession, where we are constantly under scrutiny. It is so reassuring to know we can call on you for advice and guidance when we most need it.

              It certainly puts my mind at rest!

              Rachel Heffer

              Benji Rogers

              Thank you for the clarity and detail of the advice

              Just wanted to say a big thank you for the clarity and detail of the advice ….. it’s hugely appreciated.

              Thank you for the clarity and detail of the advice

              Just wanted to say a big thank you for the clarity and detail of the advice ….. it’s hugely appreciated.

              Benji Rogers

              Our Schools, Colleges and MATs

              If you’d like to discuss how we can provide you with a Data Protection Officer, arrange a conversation with us today.