All public authorities, including schools and academies have been expected to be fully compliant with the General Data Protection Regulation (GDPR) since Friday 25th May 2018. GDPR replaced the Data Protection Act 1998. All public authorities, including schools and academies, must have a Data Protection Officer (DPO). The DPOs can work across multiple schools but each school must have a named DPO.
The role of the DPO is to act as the data protection expert within the organisation and form the link with both the public and the organisation’s employees in relation to the processing of personal information held. The DPO also acts as the person that data protection queries are directed to.
- The Headteacher of a school/academy cannot be the DPO as the role has to be filled by someone independent of the Data Controller.
- The DPO must have no conflict of interest so appointing existing school staff to the role is potentially difficult.
Northumberland Local Authority School Governance team offer a service level agreement to schools to provide a named, independent Data Protection Officer. Please contact Vicki Evans for further information.