Hi !
Next week, we are launching the project group tasked with completing a DPIA covering 80% of the use of Microsoft 365 in schools. This is a project we are truly excited about, and this time, we have gathered an incredible and highly skilled team.
Project Group
We are fortunate to have participants with technical, legal, and pedagogical expertise from:
-
Bergen Municipality, GjĂžvik Municipality, Kinn Municipality, Oslo Municipality, Sarpsborg Municipality, and TromsĂž Municipality,
- Nordland County Municipality and Vestfold County Municipality,
- The municipal ICT collaborations IKT Agder and IKT Valdres,
-
SIKT, and
- Bergen Private Gymnasium.
This is a diverse group representing both small and large school owners, covering primary and secondary education, from both public and private schools, with broad geographical representation.
An observant reader will notice that only two organizations from the Google DPIA project are involved this time. This provides a balance between continuity and fresh perspectives, as most participants are new.
We welcome thisâit is beneficial for us to bring in new voices, and it also means that the project will contribute to broader competence-building. Thatâs a great thing!
What Issues Will We Address?
Similar to the Google DPIA, our goal is to produce a DPIA covering 80% of the necessary work. It will then be up to each school owner to take the M365 DPIA from 80% to 100%. Additionally, we will address third-country data transfers, provide guidance, and offer a step-by-step guide for completing the remaining 20% of the DPIA.
For reference: How to complete the DPIA
We have compiled a preliminary list of key issues that we know need to be covered, including:
- Third-country data transfers (including how to handle the weakening of EO 14086 now that nearly all members of the Privacy and Civil Liberties Oversight Board (PCLOB) have been dismissedâŠ)
-
Roles and responsibilities per service (i.e., when is Microsoft a data processor vs. a data controller?)
- Description of processing activities / M365 Record of Processing
- Tenant-related issues (access control, data minimizationâŠ)
-
Necessity assessment â The rights of data subjects, licensing models, privacy by design, and how pedagogical services are used
- Change management
Some of these are not even clearly defined issues yet. "Tenant-related issues," for example, is a broad topic we know we need to cover, but we are still figuring out how.
Our question to you: What is missing from this list? What specific issues do you want the M365 DPIA to address?
If you have conducted a DPIA for M365, which issues have been the most challenging? What made you feel completely stuck?
Send us your feedback by replying to this email.
Reference Group
We have also established a reference group for the project. The reference groupâs responsibilities are as follows:
-
Its primary role is to provide input and feedback on the DPIA work to ensure that the final DPIA meets the needs of school owners as data controllers.
- Ensure that the DPIA takes into account both privacy concerns and the practical needs of using M365 in schools.
-
Additionally, it will consider the DPIA for M365 in schools in relation to similar assessments needed in other sectors beyond education.
The reference group includes representatives from BĂŠrum Municipality, SIKT, Norsk Helsenett, NTNU, the municipal ICT collaboration Det Digitale Gardermoen, and an independent security consultant.
We have reached out to several other municipalities and some private schools but have not yet received final confirmations from them. This means we still have room for more representatives, especially from school owners in county and municipal governments.
If you work in a county or municipal government, are involved in education, and have insights on how this DPIA should be structured and what it should address to ensure it is useful for school owners, please get in touch by replying to this email!
I wish you a wonderful, privacy-friendly week-end!
Best regards,
Ida Thorsrud
Project manager national DPIA
This newsletter was translated from Norwegian to English with assistance from ChatGPT by OpenAI. While it guided our translation, we made independent editorial choices. Any discrepancies result from this combined approach.