{"id":365595,"date":"2020-08-20T18:33:51","date_gmt":"2020-08-20T17:33:51","guid":{"rendered":"https:\/\/pulse.microsoft.com\/?p=365595"},"modified":"2020-11-19T07:44:14","modified_gmt":"2020-11-19T06:44:14","slug":"fa2-home-schooling-and-gdpr-maintaining-compliance-in-disruptive-times","status":"publish","type":"post","link":"https:\/\/pulse.microsoft.com\/en\/work-productivity-en\/education-en\/fa2-home-schooling-and-gdpr-maintaining-compliance-in-disruptive-times\/","title":{"rendered":"Hybrid learning and GDPR: maintaining security and compliance in disruptive times"},"content":{"rendered":"<p class=\"intro\">Like most areas of society, over the past six months the education sector has had to face challenges unlike any before.<\/p>\n<p>Students thrive when they have access to personalized learning. As schools have moved quickly to adapt to remote learning, using technology to create new experiences that meet students\u2019 needs has become more important than ever. At the heart of the new learning experience is a strong foundation of security, privacy and compliance, empowering both students and educators to work within a safe and secure environment, and open up new opportunities for innovation.<\/p>\n<p>The education sector has a large, complex landscape to navigate when it comes to security, compliance, and laws like <strong>General Data Protection Regulation (GDPR) <\/strong>which brings with it some unique challenges for hybrid teaching and learning. It can be difficult to know where to start. A typical school handles lots of personal data \u2013 much of it about minors \u2013\u00a0and it must therefore adhere to stricter regulations when handling personal information.<\/p>\n<p>To help educational institutions manage this new reality, Microsoft has put together a set of guidelines aimed at assisting with GDPR compliance. They require institutions to update personal privacy policies, implement or strengthen data protection controls and breach notification procedures, deploy highly transparent policies, and further invest in IT and training.<\/p>\n<h2>Using the new guidelines<\/h2>\n<p>The purpose of the new guidelines is to help educational institutions manage the threats that have arisen out of the disruption this year, while also helping them work toward compliance.<\/p>\n<p>The guidelines expand on the concrete examples and to-do lists from the existing <a href=\"https:\/\/pulse.microsoft.com\/uploads\/prod\/2018\/03\/WorkProductivity_GDPRforEducation_KickStartGuide.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">GDPR for Education Kickstart Guide<\/a> \u2013 and they need to be read in conjunction with that document. Both assets are aimed at IT staff with basic knowledge of how to manage Microsoft 365.<\/p>\n<p>The new guidelines aren\u2019t meant to be read from top to bottom, either. Instead, each topic that\u2019s referenced in the <a href=\"https:\/\/pulse.microsoft.com\/uploads\/prod\/2018\/03\/WorkProductivity_GDPRforEducation_KickStartGuide.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">GDPR for Education Kickstart Guide<\/a> has a corresponding section in the new document which includes examples and step-by-step assistance on how to do the actual configuration.<\/p>\n<p>That way, readers get a good configuration baseline to build upon for meeting GDPR compliance.<\/p>\n<p>GDPR applies to institutions that have a physical presence in the European Union, organisations that provide goods and services to EU citizens, or that collect and analyse data tied to EU residents. However, educational institutions anywhere in the world can use these documents as a valuable best practice guide, since GDPR are some of the strictest rules globally.<\/p>\n<h2>Four clear steps to compliance<\/h2>\n<p>In conjunction with the existing <a href=\"https:\/\/pulse.microsoft.com\/uploads\/prod\/2018\/03\/WorkProductivity_GDPRforEducation_KickStartGuide.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">GDPR for Education Kickstart Guide<\/a> \u2013 the new guidelines give clear best practice for how to implement GDPR. The process consists of four key steps:<\/p>\n<p><strong>1. Discover \u2013 Identify what personal data you have and where it resides<\/strong><\/p>\n<p>Personal data is often stored in multiple locations, including emails, documents, databases, removable media, metadata, log files, and backups. The first job is to identify where personal data is collected and stored.<\/p>\n<p><strong>2. Manage \u2013 Govern how personal data is used and accessed<\/strong><\/p>\n<p>The first step in managing personal data is to define why you need to collect it in the first place. Ask yourself how it helps the delivery of education. Consider how it should be gathered, where it will be stored, what entities will support that process, who should access it, and how you will enable changes and deletions.<\/p>\n<p><strong>3. Protect \u2013 Establish security controls to prevent, detect and respond to vulnerabilities and data breaches<\/strong><\/p>\n<p>Security is one of the key attention points in our digitalised world. GDPR requirements include physical protection, network security, storage security, computer security, identity management, access control, encryption and risk mitigation. Look at the way you monitor systems, identify breaches, calculate the impact of any breaches, then respond and recover from them.<\/p>\n<p><strong>4. Report \u2013 Keep required documentation, and manage data requests and breach notifications<\/strong><\/p>\n<p>A key principle of GDPR is accountability. You will need to create clear audit trails on processing, classifications, and third parties with access to personal data, including organisational and technical security measures, as well as data retention times. You may need to conduct Data Protection Impact Assessments (DPIAs). A DPIA requires organisations to identify and analyse the impact of a proposed processing activity on the protection of personal data.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Like most areas of society, over the past six months the education sector has had to face challenges unlike any before. Students thrive when they have access to personalized learning. As schools have moved quickly to adapt to remote learning, using technology to create new experiences that meet students\u2019 needs has become more important than [&hellip;]<\/p>\n","protected":false},"author":372,"featured_media":393977,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1829],"class_list":["post-365595","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-privacy-en","specials-work-productivity-en","verticalIndustries-education-en","stories-how-can-i-work-secure","stories-working-secure-en","businessPriorities-digital-transformation"],"_links":{"self":[{"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/posts\/365595"}],"collection":[{"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/users\/372"}],"replies":[{"embeddable":true,"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/comments?post=365595"}],"version-history":[{"count":4,"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/posts\/365595\/revisions"}],"predecessor-version":[{"id":393650,"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/posts\/365595\/revisions\/393650"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/media\/393977"}],"wp:attachment":[{"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/media?parent=365595"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/categories?post=365595"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}