DPO Service
Description
Under the UK GDPR, public sector organisations must appoint an independent Data Protection Officer (DPO). To support schools the Data Protection Service is offered via de-delegated budgets to maintained Enfield schools to offer provision of an independent DPO function to ensure your school meet its statutory duties ( UK GDPR Section 4 Article 37-39)
Scope of Services
The DPO service will inform and advise maintained Enfield schools and its employees about its obligations to comply with the UK GDPR, and other data protection laws. Below are details of the areas of support that the Data Protection Service will provide.
Details
- Appointment of a qualified DPO in accordance with Article 37 of UK GDP
- Providing up to date school policy templates.
|
Policy |
|
Article 30 Record of Processing Activities |
|
Bring Your Own Device Policy |
|
CCTV Policy |
|
Cyber and Information Security Policy |
|
Data Protection Policy |
|
Freedom of Information Policy |
|
Information Security Policy |
|
Privacy Notice Enfield Schools |
|
Safeguarding Checks on Adults Who Have Contact with Pupils |
|
School Photo Image and Video Consent Form |
|
School Police Disclosure Form |
|
School ROPA |
|
School Subject Access Policy and Procedure |
|
Retention Schedule |
|
Breach & Incident Response Policy |
|
Child Protection & Safeguarding Policy |
|
Online Safety & Filtering/Monitoring Policy |
|
Records Management Policy |
- Providing up to date Register Templates
- ROPA template
- Retention schedule
- Breach Log (maintained centrally by DP team for the school)
- Providing up-to-date documents
- Data breach reporting form
- Data Protection Impact Assessment
- Data Sharing Agreement
- Data Processing Agreement
- Providing general advice such as advice on privacy Notices, advice on consent forms
- Advising on Data Protection Impact Assessments (DPIAs) DPIA screening, advice, and oversight for new systems, tools and projects and higher-risk processing.
- Acting as first point of contact for the Information Commissioner’s Office (ICO)
- Advice on handling Subject Access Requests (SARs) and Freedom of Information requests.
- Assessment of reports on data breaches, advising on risk assessment and obligation to report to the ICO.
- Advising on individual rights requests.
- Raising awareness of data protection issues and providing training and awareness sessions for staff and governors.
- Maintaining a data protection portal for documentation.
Benefits of the DPO Services
- No need to have own in-house Data Protection Officer
- Expert advice from an experienced data protection team offering specialist schools advice
- Practical advice on UK GDPR and DPA 2018
- Collaborative working with other Council services
3. Roles and Responsibilities
- DPO Team
- - Ensure independence and impartiality of the DPO.
- - Provide expert advice and timely support.
- - Maintain confidentiality and data security.
- Schools
- School remains the data controller and implements decisions
- Provide access to necessary data and personnel.
- Implement recommended actions and policies.
- Ensure operational cooperation with the DPO.
- Remain ultimately responsible for compliance.
- Notify the DPO service early about new systems, suppliers, data sharing, and international transfers (pre-procurement and pre-go-live).
4. Service Levels
Hours of Service – 9am-5pm excluding bank holidays.
Services timescales for Schools and Data Protection Team
|
Service |
School requirement |
DP Team Response Time |
|
Information request Handling Advice (SAR, FOI) |
Request advice as soon as possible after receiving the request. |
Acknowledgement within 2 working days Establish response time based on the request |
|
Breach Reporting |
Immediate notification via data breach reporting form on suspected or confirmed data breach for risk assessment and ICO reporting (which should be 72 hours from knowledge of breach)
|
Immediate risk assessment review on receipt of data breach reporting form Investigation timescale max within 5 working days |
|
DPIA Advice |
Prior to processing activity taking place |
Response within 5 working days.
|
|
Training |
Annual requests for training |
Provide schools annual training plan published in Winter Term each year. Training session scheduled within school term
|
Packages
DPO Service Package - 2025/2026
Price per pupil based on your last census
Sign In for pricing