HomePrinciples And Lawful BasisProcessed in a manner that ensures appropriate security
 

Processed in a manner that ensures appropriate security

Processed in a manner that ensures appropriate security of the personal data

Whenever personal data is processed by the school, technical and organisational measures are implemented to safeguard the privacy of data subjects.  The school as controller is obliged to take its security responsibilities seriously, employing the most appropriate physical and technical measures, including staff training and awareness.  These security procedures should be subject to periodic review.

 Schools/ETBs must:

  • Make sure they have appropriate physical and technical security, backed up by appropriate organisational measures such as robust policies and procedures and reliable and well-trained staff.
  • Be clear about who in your school/ETB is responsible for ensuring information security and ensure that someone is responsible for the development and review of these procedures.
  • Verify that manual and computer processes ensure high levels of data security.
  • Take measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage, and use appropriate technical or organisational measures ('integrity and confidentiality'),
  • Consider the risk associated with any processing that is being undertaken on behalf of the school by other individuals or organisations (Data Processors).  Only processors who provide sufficient guarantees about the implementation of appropriate technical and organisational measures can be engaged.