Pencil

Hybrid learning and GDPR: maintaining security and compliance in disruptive times

Vânia Neto

Vânia Neto

Education Skills Lead | Microsoft Western Europe

Read Time, 4 min.

Like most areas of society, over the past six months the education sector has had to face challenges unlike any before.

Students thrive when they have access to personalized learning. As schools have moved quickly to adapt to remote learning, using technology to create new experiences that meet students’ needs has become more important than ever. At the heart of the new learning experience is a strong foundation of security, privacy and compliance, empowering both students and educators to work within a safe and secure environment, and open up new opportunities for innovation.

The education sector has a large, complex landscape to navigate when it comes to security, compliance, and laws like General Data Protection Regulation (GDPR) which brings with it some unique challenges for hybrid teaching and learning. It can be difficult to know where to start. A typical school handles lots of personal data – much of it about minors – and it must therefore adhere to stricter regulations when handling personal information.

To help educational institutions manage this new reality, Microsoft has put together a set of guidelines aimed at assisting with GDPR compliance. They require institutions to update personal privacy policies, implement or strengthen data protection controls and breach notification procedures, deploy highly transparent policies, and further invest in IT and training.

Using the new guidelines

The purpose of the new guidelines is to help educational institutions manage the threats that have arisen out of the disruption this year, while also helping them work toward compliance.

The guidelines expand on the concrete examples and to-do lists from the existing GDPR for Education Kickstart Guide – and they need to be read in conjunction with that document. Both assets are aimed at IT staff with basic knowledge of how to manage Microsoft 365.

The new guidelines aren’t meant to be read from top to bottom, either. Instead, each topic that’s referenced in the GDPR for Education Kickstart Guide has a corresponding section in the new document which includes examples and step-by-step assistance on how to do the actual configuration.

That way, readers get a good configuration baseline to build upon for meeting GDPR compliance.

GDPR applies to institutions that have a physical presence in the European Union, organisations that provide goods and services to EU citizens, or that collect and analyse data tied to EU residents. However, educational institutions anywhere in the world can use these documents as a valuable best practice guide, since GDPR are some of the strictest rules globally.

Four clear steps to compliance

In conjunction with the existing GDPR for Education Kickstart Guide – the new guidelines give clear best practice for how to implement GDPR. The process consists of four key steps:

1. Discover – Identify what personal data you have and where it resides

Personal data is often stored in multiple locations, including emails, documents, databases, removable media, metadata, log files, and backups. The first job is to identify where personal data is collected and stored.

2. Manage – Govern how personal data is used and accessed

The first step in managing personal data is to define why you need to collect it in the first place. Ask yourself how it helps the delivery of education. Consider how it should be gathered, where it will be stored, what entities will support that process, who should access it, and how you will enable changes and deletions.

3. Protect – Establish security controls to prevent, detect and respond to vulnerabilities and data breaches

Security is one of the key attention points in our digitalised world. GDPR requirements include physical protection, network security, storage security, computer security, identity management, access control, encryption and risk mitigation. Look at the way you monitor systems, identify breaches, calculate the impact of any breaches, then respond and recover from them.

4. Report – Keep required documentation, and manage data requests and breach notifications

A key principle of GDPR is accountability. You will need to create clear audit trails on processing, classifications, and third parties with access to personal data, including organisational and technical security measures, as well as data retention times. You may need to conduct Data Protection Impact Assessments (DPIAs). A DPIA requires organisations to identify and analyse the impact of a proposed processing activity on the protection of personal data.

Hybrid learning and GDPR: maintaining security and compliance in disruptive times

Discover all the latest guidance and best practice for educational institutions on maintaining IT security and compliance.

Managing security and compliance while transitioning to the ‘new normal’

Our two on demand webinars provide guidance on the management of Microsoft Teams and how to comply with GDPR

Discover more related articles per industry:

Education

  • a person sitting on a chair in a room

    Bridging the education gap in challenging times

    Across the globe, teachers, students and parents are dealing with a new reality: how to adapt to an educational environment that has moved from the classroom to the internet. As in many countries, the remote Faroe Islands, more than 300 kilometres off the coast of Scotland in the North Sea, has found the lives of […]

  • a young boy using a laptop computer

    Escolaglobal: a digital-first school for blended classroom and remote learning

    “This weekend, our preschool teachers created another video for the students – just saying hi and checking everyone was ok at home. Each teacher has their own Microsoft Stream channel, and the feedback from the kids and parents is amazing: “Hi, teacher! How are you? I remember you so well!” Nuno Moutinho, CEO of Portuguese […]

Government

  • Iceland runs on Trust

    How the cloud helped a small nation realise big ambitions

    In December 2015, the Icelandic government kicked off a digital infrastructure review. With more than 100 different suppliers managed by over 100 IT managers in each public institution, the brief was clear; to simplify operations and streamline IT for over 20,000 users. The solution: Fast forward two and a half years, and a decision was […]

  • How VR Group is using automation to secure Finland’s railways

    How VR Group is using automation to secure Finland’s railways

    “Being at the helm of a critical piece of infrastructure, we have a huge responsibility towards our partners and clients. That’s why safety and security are crucial elements of what we do and how we operate.” Mikke Maronen, CISO at Finnish railway company VR Group, is talking about the importance of protecting his business from […]

Healthcare

  • a person preparing food in a kitchen

    Humanitas-DMH: empowering key workers with a secure digital support

    “Our goal is to create an environment where people with mental disabilities can feel safe, secure and happy.” Marcella van Kraaij, Digital Transformation Advisor at Dutch healthcare provider Humanitas-DMH, is discussing her organization’s key objectives – and how the technology her team recently adopted is helping it to achieve them. Every day, the carers and […]

  • Two female nurses having a virtual conversation through Microsoft Teams

    Belfast Trust: Reimagining patient care

    “There have been many heroic actions by our staff but we’re not heroes for what we’ve done – I’m just glad we could do our bit to help.” Paul Duffy, Co-Director of IT and Telecommunications at Belfast Trust, is talking about the monumental impact COVID-19 has had on the healthcare sector and how virtual consultations […]

Manufacturing

  • a woman smiling for the camera

    Etex Group: Future-proofing employees to work anywhere across the world

    When COVID-19 spread across Europe in early 2020, businesses entered a new digitally-dependent age. Social distancing measures had asked offices of all shapes and sizes to close their doors, sparking organizations to quickly find other virtual ways for colleagues to meet and collaborate remotely. But for Belgium building material specialist Etex, this was a step they were ready for – having already implemented a cloud-based infrastructure and collaboration tools […]

  • Mais on a sunny day

    COFCO International: How cloud technologies ensured business continuity during challenging times

    “I have worked at COFCO for 12 years, always in an office. But I have spent the last 63 days working from home.” Marcus Seelbach, Chief HR Officer at global agribusiness COFCO International, is talking from his home via video call about the transition he and all his colleagues have undergone since COVID-19 led to the closure of the company’s offices worldwide. “But thanks to the preparation and […]

Retail

  • HeadBrands is ready for the future with Microsoft 365 Business

    HeadBrands is ready for the future with Microsoft 365 Business

    Since its creation in 2010, HeadBrands has continued to grow, rapidly becoming the leading retailer of hairdressing products in Scandinavia. HeadBrands needed a modern IT solution to increase its business productivity and improve collaboration, both within the company and externally. Its response to this challenge was to replace most of its previous services with Microsoft […]

  • Picture from the back of a person attending a Teams meeting with 2 colleagues, discussing about a furniture fabric.

    Zuiver: Supporting both business and culture through technology

    “Since moving to the cloud, there are no limitations anymore. And I’m certain without this technology, we would not have seen the growth we have today.” Jaap Landsaat, CFO and Head of IT at Dutch furniture designer Zuiver, is talking about the profound impact technology has had on the business he co-founded more than 20 years ago. “Back then, we had 100 orders a week […]

Discover more related articles per dossier:

Customer Stories

  • a man wearing a suit and tie

    Supporting employees across the world with a virtual desktop solution

    “It’s always good to see that you have made the right technology choices, and when you need something to happen – it can happen.” Stefan De Boer, Global IT Head at recruitment specialist Brunel, is talking about his company’s ethos to embracing new technologies and how it helped them quickly adapt to remote working during the COVID-19 crisis. “We were […]

Digital Transformation

  • Picture from the back of a person attending a Teams meeting with 2 colleagues, discussing about a furniture fabric.

    Zuiver: Supporting both business and culture through technology

    “Since moving to the cloud, there are no limitations anymore. And I’m certain without this technology, we would not have seen the growth we have today.” Jaap Landsaat, CFO and Head of IT at Dutch furniture designer Zuiver, is talking about the profound impact technology has had on the business he co-founded more than 20 years ago. “Back then, we had 100 orders a week […]

Security & Privacy

  • SMB employee working remotely from an airport

    Don’t let IT get in the way of your growth

    Today’s small businesses face enough challenges without IT being a barrier to their success. But how do you make sure your system is a help and not a hindrance? As consumers, we demand seamless connectivity to give us whatever we need, wherever we need it. It is an attitude that most of us take into the workplace. We expect to use tools intuitively and expand our knowledge with the minimum of effort. So, if you […]

Tips

  • a group of people sitting at a table

    A single collaboration hub to help sales soar

    Do you know Microsoft’s secret to sales success? Collaboration. It’s at the heart of its culture and solutions. Today, companies investing in teamwork are five times more likely to be high-performing, so collaboration could be the difference between profit and loss. When compared to five years ago, an average information worker spends 50% more time […]