CSH Consulting logo

Tel: 07834 601124  |  Email: caroline@cshconsulting.co.uk   |  8:00 am - 7:00 pm Monday to Friday

Data Protection Services in Education

Data Protection Officer (DPO)

CSH Consulting provides affordable, outsourced Data Protection Officer services to the education sector based on the actual requirement of the schools.  

Some schools or Trusts require a full service DPO provision that covers every area of compliance from staff training, provision of front line telephone support for all staff, handling of complex or contentious subject access requests, handling of personal data breaches and subsequent reporting, provision and implementation of compliant documents and procedures.

Whilst others require only occasional support and guidance for particularly complex situations, or specific projects such as 'what to do with the mountain of hard copy documents in the resources cupboard'.


We believe we have a unique approach to the provision of outsourced DPO services, not only because we have an enormous depth of knowledge in this sector, but because we truly understand that each school will have different requirements and budgets, different stakeholders and challenges, and that is fine.

We are interested in the successful outcome of the service, not the size of the invoice at the end of the project.  So if you have a query or a concern, just get in touch and we can talk it through without obligation.

SERVICES FOR EDUCATION

Personal Data Breach

Personal Data Breaches will always happen, especially within education when you are processing the personal and sensitive (special category) data of students.   


It is how you deal with them that matters.  We provide advice and guidance, damage assessment, reporting and investigation services, right when you need it.

Subject Access Request (SAR)

Subject access requests can be overwhelming.  What do you release, when is it not in the best interest of the student to release certain information, what forms of ID do you need to collect from the requestor?  Is it contentious, is it vexatious, does it form part of an ongoing investigation?


We can help unravel and deal with all of the above and provide real time training on how to manage SAR's for your data teams.

GDPR Training

Yes, you need to do this, and you should make it interesting and relevant to your audience.  It has to mean something to the individual and their day to day role.


Or you could just ask us to do it for you and say no to dull, boring and irrelevant training just because you need to tick the compliance box.

Data Protection Impact Assessment (DPIA)

The DPIA is an important document that your DPO either writes or signs off based on the risk factors identified when you intend to share personal data with third parties.


They are living documents that contain key information for your IT teams, your administrators and your project leads within the school.


They are also complicated to write so that everybody understands them and very rarely done well.


We do them well, and you will love them.

GDPR Compliance Audit

One of the key questions asked by schools and their Governors is "are we compliant?" and "how do we know if we are doing it right?".


Those are the questions that we can answer for you with our GDPR Compliance Audit. The audit is a deep dive into all areas of compliance that your schools should be either working on or have in place. The audit will provide a detailed RAG rated report highlighting the areas you are doing well, those areas which may need more work, and those areas that you might need support with. 



This is not a self-service audit, we visit and take you through every section of the audit, evidencing current processes, procedures and documentation, followed by recommendations and presentations to senior leaders if required. Don’t hesitate to contact us if you would like to know more.

 

Retention & Destruction of Data

Schools create store and process huge amounts of personal and sensitive (special category) data on both students and staff, and in most cases will “keep it just in case you might need it”. This results in several issues from storage space for both hard copy and electronic data to not adhering to your retention and destruction schedule against set retention periods.

How many times has the resources cupboard become an accidental storage room for all those student files that no-one is quite sure what to do with.

We can provide you with the most current and recommended retention schedule for education and train your teams on how to apply the schedule and complete the appropriate paperwork, or we can do the job for you. If you are considering what to do with the vast amount of data that you hold, get in touch and we can talk through the best options.

Share by: