Best Practice Update

public sector in brown text on cream puzzle pieces held at each end by hands

Computing Magazine recently reported about the ICO reprimanding seven organisation for domestic abuse breaches in the last 14 months.  A collection of public bodies, charitable organisations, law enforcers and lawyers have made personal data slips when handling domestic abuse cases in teh last year, showig abusers where to find their victim is hiding.

Best practice in white chalk on a blackboard, orange background, data protection education logo in blue

We've put all the specific school and trust related data protection guides, documents and queries into one area to make it easier for you.

As data protection is closely linked to cyber security the section covers guidance for raising staff awareness with cyber security and other guidance.

Be cyber aware in orange text on a blue background above a mobile phone and padlock. Also the Data Protection Education logo

The time following a cyber attack can be very stressful, and in the heat of the moment it can be difficult to know what the best thing to do between working out what went wrong, how to recover and what went missing, it can be hard to know where to start first.

We provide some help and guidance in our Information and Cyber Security Best Practice Area, which also includes the checklist:  document What to do immediately after a Cyber Attack.

Child with their hands over their eyes in front of a computer laptop. Yellow background. White desk

The DfE recently published an update to the Keeping Children Safe in Education Document 2023.  The document has a strong emphasis on making sure everyone is aware of the online dangers of using the internet and makes recommendations about how schools and colleges should put processes in place to keep children safe online. 

Blue data breach text on blue cyber background,  and orange reprimand stamp

A reprimand has been issued by the ICO to Parkside Community Primary School in relation to the infringements of Article 5 (1)(f), Article 24 (1) and Article 32 of the UK GDPR. This article discusses the reprimand and looks and what schools can do to avoid this type of breach.

Some of the information in the reprimand document is redacted, but the main details are:
A safeguarding email was shared in the classroom via the electronic whiteboard. The ICO has found that the school

Image of a hand holding a phone with a white keyboard and the word 'Access'

As we are in the last part of the school year, this is often the time that we see a rise in the number of Subject Access Requests received by schools.  This article, therefore, covers guidance and support around subject access requests, how to recognise them and how to respond.

What is the right of access? Commonly referred to as a subject access request (SAR), gives someone the right to obtain a copy of their personal information from your organisation.
Do people have to submit a

  1. Using WhatsApp in Schools
  2. How to contact us for support, subject access requests, data breaches and FOI's
  3. FOI: Reinforced Autoclaved Aerated Concrete
  4. FOI: Henry Jackson Society
  5. Subject Access Requests and Children's Data
  6. FOI: Vaccination Justifications
  7. How the Record of Processing Can Help You
  8. What does a Data Protection Officer Do?
  9. Blog: Best Practice on the Retention of Child Protection Information
  10. Carrying out Supplier Due Diligence
  11. Email and retention periods
  12. Sharing this year’s Nativity play online
  13. How to Handle a Data Breach
  14. A quick introduction to the Phishing Simulation tool
  15. B&H FoI: Racist/religious incidents/bullying
  16. B&H FOI Request: ‘Racial Literacy Training 101’
  17. Protocol for Setting Up and Delivery of Online Teaching and Learning
  18. Class Dojo International Data Sharing
  19. Model Publication Scheme: Amendments, Improvements and Updates
  20. Transparency
  21. Brexit...what we know so far.
  22. Parents and students covertly recording conversations
  23. SAR? ER? FOI?
  24. Research projects and GDPR
  25. Cyber security alert issued following rising attacks on UK academia
  26. Emergency contacts and consent
  27. Quick guide to key contact information: LA and other information
  28. Quick guide to key contact information: Official DfE guidance
  29. Key elements of a successful DPIA
  30. FOI Publication Schemes
  31. Best Practice for Managing Photos and Video
  32. New Drip Feeds: Recognise and Respond to Subject Access Request
  33. When to contact the Data Protection Officer?
  34. National child measurement programme 2019
  35. Make sure DPE is your registered DPO with the ICO
  36. Passwords – simplifying the approach

Search