Hi !
On Monday, we held a webinar with Narvik Municipality, where we were fortunate enough to have them share their experiences with adapting and finalizing the national DPIA for the use of Google Workspace for Education.
As you may know, the national DPIA exists in an 80% version, and itâs necessary for the data controllerâtypically the school ownerâto complete it into a full 100% version to make it their own.
Unfortunately, we experienced some technical difficulties and were unable to record the webinar.
But! We're summarizing the discussion in this newsletter!
The most time-consuming part: creating and following up on the action plan that results from the DPIA
Narvik Municipality has learned that the most time-consuming aspect of the DPIA process is not necessarily completing the DPIA itself, but creating and then working through the action plan that comes out of it.
If youâve attended any of our many webinars where we assisted Ullensvang Municipality with conducting the actual data protection impact assessment within the DPIA, youâve probably noticed that we frequently identify "action points."
These are steps or measures the data controller (school owner) must take to reduce the risk of privacy breaches. These actions can range from something as simple as adjusting a configuration, to something as complex as deciding how to inform students about how their privacy is protected.
As this example shows, some actions from the action plan may need to become ongoing responsibilities. Informing students is one such example. A privacy policy alone may not be sufficientâstudents may need more active communication.
And since the student population changes regularly, the school owner must decide how to ensure students continue to receive this information over time.
To sum up: what takes time is developing and following up on the action plan.
This process takes even longer if the municipality, as the data controller, does not already have a general system for, for example, informing data subjects (in this case, teachers, students, parents, and other staff) about how their data protection rights are ensured.
Or if the municipality hasnât yet decided who will handle deletion requests under the GDPR.
In that case, this needs to be addressed as part of the Google DPIAâeven though this issue clearly extends beyond just the use of Google Workspace for Education.
Collaborationâespecially between IT and education departmentsâis essential for success
Narvik Municipality describes an exemplary collaboration between their IT (operations) and education departments. At SkoleSec, weâre aware of other school owners who donât have this type of cooperation, making it much harder to succeed with data protection and information security.
But thatâs not the case in Narvik. The municipality describes how IT and education staff work closely together to develop and follow up on the action plan mentioned earlier.
They also recognize that this is work that must be done together.
And that makes perfect sense!
IT typically takes responsibility for implementing technical measures to reduce privacy risks, while the education department has historically been more involved in so-called organizational measures.
These two types of measures need to be seen as interconnected. They depend on one another and must be coordinated.
This kind of collaboration takes time, but it's also a key prerequisite for succeeding with the compliance work necessary to improve privacy protections for school owners.
With so much work involved, leadership support is crucial
Narvik Municipality points out that developing and following up on an action plan is time-consuming. Time that could have been used elsewhere.
Yesâweâre now talking about leadership buy-in. To be able to spend time on this work, many of us depend on our leaders making it clear that this is a priority.
This is especially important when IT and education must work together, as these departments are usually under different leadership structures.
This work takes timeâso take breaks, celebrate milestones, and get back on track when you lose it
Letâs start with the last point. I once heard that what separates amateurs from professionals is the ability to pick up a task again after neglecting it for a while.
That feels particularly relevant in this kind of compliance work. Things will happen that cause the long-term work of following up on the action plan to be pausedâat least temporarily.
The problem isnât that this happens. In the busy reality of municipal work, it will happenâagain and again. It only becomes a problem if we donât have the ability to pick up the work again afterward.
I could use a lot of clichĂ©s about how privacy and information security compliance work is a long journey. Itâs a marathon. Weâre Frodo and Sam heading to Mordor. But the point is: this takes time.
So make sure to take breaks. Refill your energy and motivation. Take time to do other things, while gradually moving forward step by step.
The last thing I want to emphasize is to celebrate every milestone. And not just the big onesâcelebrate the tiny things that might seem too insignificant to celebrate.
As mentioned, this is a long process, and youâre never truly âdone.â There will always be room for improvement in your management system, for example. Thatâs why itâs even more important that you decide whatâs worth celebrating.
I recommend celebrating often! It makes the long road more enjoyableâand easier!
I wish you a wonderful, privacy-friendly week-end!
Best regards,
Ida Thorsrud
Project manager national DPIA
This newsletter was translated from Norwegian to English with assistance from ChatGPT by OpenAI. While it guided our translation, we made independent editorial choices. Any discrepancies result from this combined approach.