Policy and regulatory analysis

The new European data protection regulation: implications for learner records and cross-border processing

Industry Policy and Regional Regulatory Interpretation

The public-interest questions raised by the new European data protection regulation are assessed through lawful responsibility, implementation evidence and transparent follow-up.

Evidence relevant to new European data protection regulation

For new European data protection regulation, the General Data Protection Regulation was adopted in April 2016 and is to apply from 25 May 2018. It establishes principles including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. Education providers preparing for implementation should identify personal-data purposes, legal bases, individual rights, supplier arrangements, retention and security, particularly where data influence learner decisions.

In reviewing new European data protection regulation, education information should be collected for a defined purpose, protected in proportion to its sensitivity and retained only for an authorised period.

  • Provide accessible correction and complaint routes before it is relied on for a decision with material effect.
  • Control third-party processing.
  • Limit and review access.
  • Verify accuracy where information affects learners before it informs a consequential decision.
  • Assign accountable data owners.

Application to new European data protection regulation

The General Data Protection Regulation adopted on 27 April 2016 provides a policy reference for the new European data protection regulation.

Review of the arrangements should follow a stated and reproducible method. When examining new European data protection regulation, records should remain protected against unauthorised alteration while legitimate amendments remain visible.

Controls for new European data protection regulation

The principal risks in relation to the policy position are excessive access to learner information, collection without a defined educational or legal purpose, retention beyond an identified need, and secondary use without adequate authority. Across the defined scope, a weakness in one part of the control environment may obscure a related failure elsewhere.

  • Is the record attributable?
  • Can records be retrieved throughout the required period?
  • Can an amendment be distinguished from the original?
  • Are access rights proportionate?
  • Are partner records subject to equivalent controls?

Review of new European data protection regulation

This may require a register of information assets and purposes, incident response and notification records, retention and secure disposal evidence, and data-quality and correction controls, supported by lawful authority and consent records where relevant and supplier and transfer arrangements. Further cases should be examined when the initial sample does not represent the affected scope or confirm sustained correction.

Implementation of the issue can be tested without imposing unnecessary reporting. Responsible bodies should specify mandatory fields, source ownership, access rights, retention and correction procedures. In the context of new European data protection regulation, test a sample from creation through use, amendment, reporting and disposal, including records created during disruption or by a delivery partner.

Implications for new European data protection regulation

The implementation record for the new European data protection regulation should identify the instrument being applied, its status, the competent authority, the affected jurisdiction and the action expected of each responsible body. Binding obligations should remain distinct from policy commitments and measures adopted by institutions. A staged implementation record should set out transition dates, interim safeguards and the readiness review point.

The analysis of the arrangements should remain within the limits of the evidence. In the context of new European data protection regulation, a policy direction should not be presented as a uniform legal obligation where national implementation differs.

For new European data protection regulation, the evidential trail should allow an affected decision to be identified, examined and corrected.

In the context of new European data protection regulation, a clear objective, proportionate evidential basis and account of affected learners are required.