Michelmores Michelmores
Michelmores Michelmores
  • Home
  • Expertise
  • People
  • Insights & Events
  • Careers
  • About
  • ESG
  • Contact
Share
Published November 28th 2017
Home > News & Insights > Article

GDPR: The emerging trends

Author
Stephen Newson
Stephen Newson

When it comes to GDPR, Donald Rumsfeld’s famous quote seems very appropriate:

“There are known knowns; there are things we know we know. We also know there are known unknowns; that is to say we know there are some things we do not know. But there are also unknown unknowns – the ones we don’t know we don’t know.”

This can make getting ready for GDPR difficult. Based on many conversations with many schools, we want to set out some of the emerging trends.

When it comes to the “known knowns” we are clear on some basic points. It is coming into force on 25th May 2018, some of the requirements are similar to current data protection law, it is necessary to give people information about how their data is processed, stored and used, people will have rights around access to that data, ensuring it is accurate and so on. It will be necessary to record and (subject to conditions) report breaches to the ICO. It will also be necessary  for some organisations, including schools, to appoint a Data Processing Officer (DPO).

However there are some emerging themes when it comes to “known unknowns”. Two key points which come up several times relate to the DPO and retaining data.

For the DPO, it is clear that the DPO must have expertise to fulfil their role and act independently. What exactly that means in practice for schools, is still not clear.  There are suggestions that it definitely could not be a headteacher or other senior leader. However, it is our view, that at this stage, while it is important to consider potential conflicts and independence, we would caution against adopting a fixed position at this time. A DPO will be necessary and it will be permissible to buy in a DPO and share a DPO across more than one school. At this stage, we know it will be necessary but we don’t have enough information to reach fixed conclusions when it comes to schools.

Another key area is data retention. Ask any school how long data should be kept for and there are numerous different answers from different schools in different local authority areas. The ICO is also not giving a fixed answer. The point is there is no clear answer at this time. However, what is clear is that if data is being kept there needs to be a reason for it. While more guidance is needed, our view is to focus on having a complete understanding of what data you have and having a clear rationale for why you are storing it for a particular length of time.

For more information, please contact a member of our Education team.

Share
Author
Stephen Newson
Stephen Newson

Contact us

+44 (0) 333 004 3456

enquiries@michelmores.com

Subscribe to updates

  • Quick Links
    • Online Payments
    • People
    • About
    • Careers
    • Staff Login
  • Legal & Regulatory
    • View all policies
    • Privacy Policy
    • Website Terms
    • Cookie Policy
    • Modern Slavery Act

Locations:

  • london
  • cheltenham
  • bristol
  • exeter

© Michelmores LLP is a Limited Liability Partnership, authorised and regulated by the Solicitors Regulation Authority (SRA authorisation number 463401) and registered in England and Wales under Partnership No. OC326242.
The registered office is Woodwater House, Pynes Hill, Exeter, EX2 5WR. A list of the members (all of whom are solicitors or barristers) is available for inspection at the registered office and at michelmores.com

  • © 2025 Michelmores LLP. All rights reserved
  • Website maintained by Appeal Digital