GDPRiS from Groupcall helps schools answer the following 4 key questions around personal data for GDPR:
GDPRiS documents the data flows and all of the places you store and process school data. It records whether data is in school or with 3rd party suppliers.
GDPRiS logs the reasons for using the data, the legal basis for processing it and how the rights of the individual are protected. Data stored that has no value will be highlighted.
GDPRiS records the processes you and your 3rd party suppliers use to protect personal data. It helps guide ALL school staff to a new level of data protection understanding.
As well as enabling you to easily conduct internal audits and report on data breaches, all the evidence you need to demonstrate your compliance is in one place.
If not managed properly, GDPR can be very complex. GDPRiS helps schools in manageable steps, with access to practical guidance on GDPR compliance.
GDPRiS is easy to use to provide simple and intuitive data protection management, enabling schools to streamline subject access requests (SARs) and data breach reporting.
Through GDPRiS, you can easily manage all 3rd party suppliers that process your school data, ensuring that they are demonstrating their own GDPR compliance. GDPRiS currently maps over 800 leading EdTech suppliers (and counting!) to save you the time and effort manually mapping your suppliers.
GDPRiS provides evidence-based accountability and peace of mind, including a self-assessment questionnaire (SAQ) to all members of staff to ensure full accountability.
GDPRiS allows you to store policy documents, training records and materials all in one place, with all staff members having access for a whole-school approach to data protection.
GDPRiS offers schools a highly secure, cloud-based platform, providing a low-cost and budget friendly solution to full GDPR compliance.
GDPRiS is a secure, cloud-based tool which reflects existing processes in schools and pro-actively prompts them to meet and exceed the new GDPR.
We're on hand to offer friendly and timely guidance to help schools meet and exceed GDPR requirements, advocating accountability and demonstrating compliance.
Groupcall has a
Does the GDPR really affect schools?
Yes, every organisation or business that handles personal data needs to review its data protection policies and bring them in line with the General Data Protection Regulation.
What is classed as personal data in the GDPR?
Any information that can identify a natural person (‘the data subject’). This person can be identified, directly or indirectly, such as – name, email address or where they are, but also online identifiers such as IP address, types of website cookies and other device identifiers. Thus, an email from a parent carrying data such as their name, email address, and their child’s name can clearly identify both the child and the parent.
Just a UPN or an MIS identifier in a specific school is also personal data as it points to the child’s and in the case of the MIS identifier, to also the parent/carer’s information.
What is a data audit?
A data audit is a step-by-step process that examines every stage of a data processing mechanism. As data controller, a school must be 100% satisfied that everything a data processor says it is doing is true and can be seen clearly and checked.
An audit should highlight any issue that arises at any step of the processing. Moreover, an audit will produce comprehensive records and reports to demonstrate that the data controller has done everything in its power to check that its personal data is processed safely, legally and ensures that the full rights of the data subject are met.
Does my school need a Data Protection Officer (DPO)?
Yes, as a public sector organisation you are obliged to have a DPO. However, you shouldn’t allow the fact that you don’t have a DPO yet delay your journey to compliance with the GDPR. The DPO oversees GDPR compliance, independently, and acts as an intermediary between the organisation, data subjects, and the supervisory authority, ICO. The minimum tasks of a DPO are defined as: