Pencil

Hybrid learning and GDPR: maintaining security and compliance in disruptive times

Vânia Neto

Vânia Neto

Education Sr. Product Marketing Manager | Microsoft Western Europe

Read Time, 4 min.

Like most areas of society, over the past six months the education sector has had to face challenges unlike any before.

Students thrive when they have access to personalized learning. As schools have moved quickly to adapt to remote learning, using technology to create new experiences that meet students’ needs has become more important than ever. At the heart of the new learning experience is a strong foundation of security, privacy and compliance, empowering both students and educators to work within a safe and secure environment, and open up new opportunities for innovation.

The education sector has a large, complex landscape to navigate when it comes to security, compliance, and laws like General Data Protection Regulation (GDPR) which brings with it some unique challenges for hybrid teaching and learning. It can be difficult to know where to start. A typical school handles lots of personal data – much of it about minors – and it must therefore adhere to stricter regulations when handling personal information.

To help educational institutions manage this new reality, Microsoft has put together a set of guidelines aimed at assisting with GDPR compliance. They require institutions to update personal privacy policies, implement or strengthen data protection controls and breach notification procedures, deploy highly transparent policies, and further invest in IT and training.

Using the new guidelines

The purpose of the new guidelines is to help educational institutions manage the threats that have arisen out of the disruption this year, while also helping them work toward compliance.

The guidelines expand on the concrete examples and to-do lists from the existing GDPR for Education Kickstart Guide – and they need to be read in conjunction with that document. Both assets are aimed at IT staff with basic knowledge of how to manage Microsoft 365.

The new guidelines aren’t meant to be read from top to bottom, either. Instead, each topic that’s referenced in the GDPR for Education Kickstart Guide has a corresponding section in the new document which includes examples and step-by-step assistance on how to do the actual configuration.

That way, readers get a good configuration baseline to build upon for meeting GDPR compliance.

GDPR applies to institutions that have a physical presence in the European Union, organisations that provide goods and services to EU citizens, or that collect and analyse data tied to EU residents. However, educational institutions anywhere in the world can use these documents as a valuable best practice guide, since GDPR are some of the strictest rules globally.

Four clear steps to compliance

In conjunction with the existing GDPR for Education Kickstart Guide – the new guidelines give clear best practice for how to implement GDPR. The process consists of four key steps:

1. Discover – Identify what personal data you have and where it resides

Personal data is often stored in multiple locations, including emails, documents, databases, removable media, metadata, log files, and backups. The first job is to identify where personal data is collected and stored.

2. Manage – Govern how personal data is used and accessed

The first step in managing personal data is to define why you need to collect it in the first place. Ask yourself how it helps the delivery of education. Consider how it should be gathered, where it will be stored, what entities will support that process, who should access it, and how you will enable changes and deletions.

3. Protect – Establish security controls to prevent, detect and respond to vulnerabilities and data breaches

Security is one of the key attention points in our digitalised world. GDPR requirements include physical protection, network security, storage security, computer security, identity management, access control, encryption and risk mitigation. Look at the way you monitor systems, identify breaches, calculate the impact of any breaches, then respond and recover from them.

4. Report – Keep required documentation, and manage data requests and breach notifications

A key principle of GDPR is accountability. You will need to create clear audit trails on processing, classifications, and third parties with access to personal data, including organisational and technical security measures, as well as data retention times. You may need to conduct Data Protection Impact Assessments (DPIAs). A DPIA requires organisations to identify and analyse the impact of a proposed processing activity on the protection of personal data.

Hybrid learning and GDPR: maintaining security and compliance in disruptive times

Discover all the latest guidance and best practice for educational institutions on maintaining IT security and compliance.

Managing security and compliance while transitioning to the ‘new normal’

Our two on demand webinars provide guidance on the management of Microsoft Teams and how to comply with GDPR

Education

  • a person sitting at a table using a laptop

    How to enhance traditional teaching methods with Microsoft Teams

    COVID-19 has had a huge effect on the daily routines of millions of educators and students across the world. The Microsoft Education team has remained committed to helping everyone stay connected and engaged through remote learning. And now, as countries begin to emerge from the crisis, Microsoft is helping schools shift to ‘blended learning’ – […]

  • a woman looking at a computer

    How Griftland College is putting technology at the heart of remote learning

    “When COVID-19 was on the verge of breaking out, we had to make a choice about how to go further,” says Kees Versteeg, the principle of Griftland College. The secondary school, located in the Dutch town of Soest, was one of the first in the Netherlands to close and start teaching 100% remotely. He describes […]

Government

  • Iceland runs on Trust

    How the cloud helped a small nation realise big ambitions

    In December 2015, the Icelandic government kicked off a digital infrastructure review. With more than 100 different suppliers managed by over 100 IT managers in each public institution, the brief was clear; to simplify operations and streamline IT for over 20,000 users. The solution: Fast forward two and a half years, and a decision was […]

  • a group of people performing on stage in front of a crowd

    City of Liège: Facilitating decision making in difficult times

    For many organizations, social-distancing measures brought about by COVID-19 have drastically slowed day-to-day operations – and for some, even stopped them altogether. But for local governments across Europe, like the Belgian city of Liège, slowing down hasn’t been an option.  From supporting citizens and businesses to protecting frontline workers, Liège city had to quickly provide stability during this crisis and ensure important decisions could still be made in a democratic […]

Healthcare

  • a person sitting in front of a laptop computer

    The ‘Big Bang’ approach to digital transformation – and how to make it work

    These days there’s no such thing as ‘business as usual’. Change and disruption are the new normal. Just think of the changes affecting your organization right now, with new technology and techniques driving new attitudes and expectations from employees and customers alike. Everything is changing. And the one thing all those changes have in common […]

  • Healthcare professionals operating on a patient

    Maasstad Hospital: Working as one medical team during a crisis

    In times of crisis, an organization looks to its leadership for guidance. As COVID-19 spread through Europe in early 2020, Maasstad Ziekenhuis Hospital CEO Peter Langenbach had planned to lead his hospital’s crisis response as he would any other – being present and visible, leadership traits instilled in him during his time in the Dutch […]

Manufacturing

  • a woman smiling for the camera

    Etex Group: Future-proofing employees to work anywhere across the world

    When COVID-19 spread across Europe in early 2020, businesses entered a new digitally-dependent age. Social distancing measures had asked offices of all shapes and sizes to close their doors, sparking organizations to quickly find other virtual ways for colleagues to meet and collaborate remotely. But for Belgium building material specialist Etex, this was a step they were ready for – having already implemented a cloud-based infrastructure and collaboration tools […]

  • Mais on a sunny day

    COFCO International: How cloud technologies ensured business continuity during challenging times

    “I have worked at COFCO for 12 years, always in an office. But I have spent the last 63 days working from home.” Marcus Seelbach, Chief HR Officer at global agribusiness COFCO International, is talking from his home via video call about the transition he and all his colleagues have undergone since COVID-19 led to the closure of the company’s offices worldwide. “But thanks to the preparation and […]

Retail