{"schema_version":"ICEQC_NEWS_ARTICLE_V1","id":"iceqc-news-f752e8b729b20308","slug":"2018-05-28-data-protection-obligations-now-applying-to-education-providers","language":"en","publication_status":"READY_FOR_IMPORT","publication_date":"2018-05-28","last_modified_date":"2018-05-28","title":"Data protection obligations now applying to education providers","summary":"Explains the regulatory context for data protection obligations now applying to education providers and the responsibilities, evidence and safeguards relevant to implementation.","category":{"code":"POLICY_AND_REGULATORY_INTERPRETATION","label":"Industry Policy and Regional Regulatory Interpretation"},"article_type":"Policy and regulatory analysis","publisher":"International Council for Education Quality Certification (ICEQC)","jurisdictional_scope":"International","historical_reference_basis":"General Data Protection Regulation applicable from 25 May 2018","reference_authority":"European Union institutions and relevant national authorities","sections":[{"heading":null,"paragraphs":["Current consideration of data protection obligations now applying to education providers is informed by the General Data Protection Regulation applicable from 25 May 2018, with consequences for governance, evidence and the treatment of affected learners. The analysis of the implementation question proceeds on the basis that a policy instrument has practical effect only when its scope, responsible actors and relationship with existing law are understood. Proportionality is demonstrated where learner safeguards and decision reliability correspond to the assessed risk."]},{"heading":"Status and scope","paragraphs":["The applicability described by the General Data Protection Regulation applicable from 25 May 2018 changes the implementation context for data protection obligations now applying to education providers. Entry into force or applicability establishes an operative reference point, but the resulting duties must still be traced to the persons, services and jurisdictions covered. Authorities should distinguish immediate duties from staged provisions, and providers should retain the legal and operational basis for any conclusion about application.","The General Data Protection Regulation applies from 25 May 2018. Education providers processing personal data within its scope must connect each use to an appropriate legal basis and comply with principles governing fairness, transparency, purpose, minimisation, accuracy, retention and security. Rights and accountability are operational matters: notices, access controls, correction, supplier oversight, incident response and records of decision-making should function in practice.","The governing expectation for the policy matter should be capable of consistent application. A decision concerning the implementation question should recognise that where responsibilities are divided across ministries, regulators, funders and providers, the interfaces between those responsibilities should be explicit. Definitions should provide a stable basis for decisions while allowing relevant differences to be identified and justified.","A narrow control over the relevant measure may create false assurance. In the present context, uncontrolled supplier access or transfer, inaccurate data affecting decisions and collection without a defined educational or legal purpose may produce acceptable aggregate reporting while individual learners remain exposed to material disadvantage. The test should deliberately include exceptions and cases in which the expected outcome was not achieved.","The technical issue within the policy matter concerns the basis on which a conclusion is reached. Oversight of the implementation question should reflect the principle that implementation requires more than dissemination. Responsible actors must understand the change, receive the authority and resources to apply it, and be able to identify cases that require advice, exception or escalation. In relation to data protection obligations now applying to education providers, the judgement should state its supporting evidence and any condition limiting application to the declared scope.","The evidential record for the relevant measure should permit a reviewer to trace the matter from decision to outcome. This may require data-quality and correction controls, a register of information assets and purposes, role-based access and access reviews, and lawful authority and consent records where relevant, supported by retention and secure disposal evidence and supplier and transfer arrangements."]},{"heading":"Public-interest implications","paragraphs":["The analysis of data protection obligations now applying to education providers should remain within the limits of the evidence. A decision concerning the relevant measure should recognise that public authorities should avoid imposing administrative activity that cannot be connected to a defined risk, right or educational outcome. The analysis of the policy matter proceeds on the basis that security, privacy and data quality are related but distinct. A secure record may still be inaccurate or used without adequate authority, and a lawful use may still be poorly governed. If uncertainty could change a consequential decision, additional evidence or a narrower conclusion is required.","The assurance record for the policy matter should retain the date of the evidence, the source responsible for it, the scope examined and the version of any instrument or definition applied. A later reviewer should be able to identify whether the condition changed or the evidential record was corrected. Earlier conclusions should remain traceable if they affected a learner, provider or public decision."],"bullets":["Assign accountable data owners before using it to determine a learner or provider outcome.","Provide accessible correction and complaint routes before it is relied on for a decision with material effect.","Minimise collection.","Control third-party processing, with responsibility, scope and timing recorded.","Verify accuracy where information affects learners."]},{"heading":"Institutional responsibilities","paragraphs":["For operational review of data protection obligations now applying to education providers, authorities and providers should proceed in a defined sequence. The method for the implementation question is to translate the policy objective into controlled procedures and decision criteria, prepare affected staff and learners, test readiness, monitor early cases and correct ambiguity promptly. Review whether implementation differs across sites or delivery partners. Findings should state the affected scope and required action; an observation should not be represented as evidence of conformity or effectiveness.","A policy conclusion on the relevant measure should state who is required or expected to act, the source of that expectation and the consequence of non-implementation. Jurisdictional variation should be identified wherever it narrows the reach of the conclusion. Communications should preserve the legal status and effective date of each expectation described."],"bullets":["Are responsibilities and resources in place?","What do early cases show?","What operational decision changes?","Where is implementation inconsistent?","Have affected users received clear information?"]},{"heading":"Continuing review","paragraphs":["For data protection obligations now applying to education providers, governing bodies should receive a concise account of the intended result, affected scope, principal risks, evidence limitations and unresolved exceptions. In relation to data protection obligations now applying to education providers, material action requires a named responsible function and a defined completion point.","The system and institutional dimensions of the relevant measure should be considered together. A decision concerning the affected arrangements should recognise that education information should be collected for a defined purpose, protected in proportion to its sensitivity and retained only for an authorised period. Public authorities establish the legal and policy setting; providers remain accountable for the quality and integrity of provision within their control. The allocation of responsibility should prevent gaps between system oversight and institutional operation.","The appropriate response to the issue is therefore one of controlled implementation and review. A clear objective, proportionate evidential basis and account of affected learners are required. Where evidence cannot support assurance, the limitation should be reported and corrective work should remain open."]}],"word_count":1023,"content_hash":"sha256-149c281df6811f92f3ce4acb67221dd34eca9e94d2f2ce60c78ce0a7727deb4a","seo_keywords":["data protection obligations now applying to education providers","education policy and regulation","education quality","ICEQC"],"schema_type":"AnalysisNewsArticle"}
