Jump to content

Recommended Posts

Posted
Under the new GDPR laws coming into effect from 2018, is it going to be necessary for schools to only allow encrypted usb sticks and drives on their systems?
Posted

I've been reading up on this one today and have come to no concrete answers yet... it's another one of those pieces of legislation that makes plenty of broad points, but is going to need someone at central government level to actually translate into what the actual obligations for IT systems will be.

 

Be nice if they could get on with it, I have seen talk about more encryption being required at various points, if so I'd like to get on with given we've only got just over a year to implement it.

Posted
Under the new GDPR laws coming into effect from 2018, is it going to be necessary for schools to only allow encrypted usb sticks and drives on their systems?

In terms of the principles it seems no more so than now, which is to say yes *, if devices are portable and might reasonably be accidentally lost.

 

* it might not be explicit in terms of primary legislation but if you look at the rulings of the ICO on data breaches, they are explicit that not encrypting data is negligent in many cases.

Posted
Under the new GDPR laws coming into effect from 2018, is it going to be necessary for schools to only allow encrypted usb sticks and drives on their systems?

Not seen anything that will force all USB storage to be encrypted but if you have a data loss/breach you need to show you have made best effort to secure your data.

 

In regards to encrypting USB, what if someone decides to email data out, or drop box, or take it out on a mobile device. I would recommend looking at document security rather than endpoint security. That way it doesn't matter what transmission method or physical media are used, the data will be secured.

Posted
One of the biggest changes concerns data sharing. Consent will have to be explicitly obtained on a case by case basis with a detailed consent audit log maintained. Default, assumed or blanket opt-in to data sharing will no longer be allowed under GDPR.
  • Thanks 1
  • 3 weeks later...
Posted
One of the biggest changes concerns data sharing. Consent will have to be explicitly obtained on a case by case basis with a detailed consent audit log maintained. Default, assumed or blanket opt-in to data sharing will no longer be allowed under GDPR.

How will that work with a school? We have to share data with outside agencies on a daily basis!

  • Thanks 1
Posted
I was sent this link by a member of our SLT (I don't read the TES)

 

https://england.magazine.tes.com/editions/edition_edition_edition_5233.england/data/335717/index.html

 

Makes for an interesting read

 

It is very good and I hope will be helpful in getting our SLT to start to act. I was surprised at :

 

"I was recently at a business event for a major hardware supplier, full of people from the corporate world, and discussions quickly drifted to data protection. Everyone at the event was not only aware of the incoming regulation, but also the majority were clearly worried about the workload required to meet it and generally felt that preparation time was running out."

 

I wonder if companies like Parentpay, PiXL, Kerboodle, SIMS, Bromcom, Smoothwall etc, are actually ahead of the game on this? I suspect some have not started, just like most schools.

Posted
It is very good and I hope will be helpful in getting our SLT to start to act. I was surprised at :

 

"I was recently at a business event for a major hardware supplier, full of people from the corporate world, and discussions quickly drifted to data protection. Everyone at the event was not only aware of the incoming regulation, but also the majority were clearly worried about the workload required to meet it and generally felt that preparation time was running out."

 

I wonder if companies like Parentpay, PiXL, Kerboodle, SIMS, Bromcom, Smoothwall etc, are actually ahead of the game on this? I suspect some have not started, just like most schools.

 

SIMS, Bromcom & Smoothwall are.

 

https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/581224/Cloud_services_software_department_advice-22.pdf

Posted
Yup, that was my exciting afternoon read. Sets out all of what is known on the principles, but as yet very little on what it changes for us.

 

Impacts will be from :

 

1. We will have to prove compliance by keeping records of processing activities, training, breaches and impact/risk assessments.

2. Consent will need to be explicit.

3. Sensitive personal data will need additional protections.

4. We will be legally obliged to inform the ICO of any data breaches.

5. The scope of personal data is expanded and will cover most student, staff, parent and contact data we process.

 

1. is likely to be a large change for most organisations since it will require a more bureaucracy to set up and maintain the record keeping required. 2 will likely cause schools some headaches, particularly in relation to external systems such as PiXL etc, and there are likely to be some very interesting questions around Google Apps. 3. Is likely to drive any Data Managers with a spreadsheet fetish (i.e. all of them) crazy, 4, seems almost innocent but it is likely you will have some kind of data breach at some point and this really opens up the risk that the organisation is subject to some scrutiny of their compliance by the ICO - in other words those large fines just got a lot closer. 5. Again Data Managers will now have to consider pretty much all of the information they process as personal information and any documents which show analysis against protected attributes (ethnicity, in care etc) will be sensitive personal data. The only way to prove you are controlling processing will be to track instances of the data (track all the spreadsheets).

Posted

I've been looking at this over the last few days, and apart from the obvious concerns i have another one, what if a parent/student refuses to give us permission to share info with third partys? (like pixl/doddle/gcsepod/etc).

 

I have a feeling none of these systems are set up in a way that exclude certain users from the data transfers...

Posted

One area where schools could really get themselves in trouble is with school meals. You can lock up your MIS data as secure as you want but the cashless system, controlled by the catering staff, is in a kitchen store room It holds FSM data, allergy and dietary needs and religious food requirements.

 

Yes they are secured but look for the username and password its usually on a PostIt note on the wall!

Posted
Yes they are secured but look for the username and password its usually on a PostIt note on the wall!

If that is the case, it is a problem right now, no need to wait for the new regulations before acting (it should be a violation of one or all of : AUP, eSafety, Safeguarding, Professional Conduct etc, assuming you have any of those policies).

Posted

You are absolutely right pcstru. It's a problem that's alway been there and largely ignored. The cashless systems are secured but many head teachers and data managers are unaware of the sensitivity of the data they hold. Of course knowing who's on FSM, if there are dietary needs through health or religion is essential for a school meals service. However in many schools there are outside caterers who are not employed by the school and I'm sure the dinner/kitchen personnel are not part of any data protection training.

Just raising yet another issue that schools may not be aware of.

Posted

Hmm looks like I need to do some serious reading.

 

One thing I do get confused by is that it is to become a hanes crime of the highest order for a pupil to use a system like mathswatch without parental permission - yet on a day to day basis almost every business in the world (and quite often also govermnt depts. that should know much better) routinely sells/gives away/loses peoples personal data and absolutely no one cares.

Posted
Yes but under the new rules even if the third party has the information, its still the company(school) responsible for it?

Under the current 1998 DPA, the school is responsible. Under the new legislation the school will still be responsible! However, there is more emphasis placed on joint responsibility - so the supplier will need to be explicit about what they are processing and why. So when PiXL edge asks for UPN because they are creating unique national identifiers behind the scenes so their software can offer data to other customers when pupils transfer schools, they will need to be absolutely open, honest and transparent about that. You shouldn't be left to find out that as a surprise when you query why their software is demanding UPN or ULN rather than the local admission number.

  • Thanks 3
Posted

Get GDPR compliant with the Microsoft Cloud (see also: www.microsoft.com/en-us/trustcenter/Privacy/GDPR)

 

The new General Data Protection Regulation (GDPR) is the most significant change to European Union (EU) privacy law in two decades. The GDPR requires that organizations respect and protect personal data – no matter where it is sent, processed or stored. Complying with the GDPR will not be easy. To simplify your path to compliance, Microsoft is committing to be GDPR compliant across our cloud services when enforcement begins on 25 May 2018.

 

While Microsoft is committed to helping you successfully comply with the GDPR, it is important to recognize that compliance is a shared responsibility. New requirements – like greater data access and deletion rules, risk assessment procedures, a Data Protection Officer role for many organizations and data breach notification processes – will mean changes for your organization. When it comes to GDPR compliance, it’s not just European organizations that are affected, but also those outside of the EU who process data in connection with the offering of goods and services to, or monitoring the behavior of, EU residents. As such, it’s important to understand your obligations related to GDPR regardless of where your organization resides.

 

It will take time, tools, processes and expertise for you to comply with the GDPR. To do this, you need to make changes to your privacy and data management practices. And failure to do so could prove costly – as companies that do not meet the requirements could face reputational harm and substantial fines of 20 million euros, or 4 percent of annual worldwide turnover, whichever is greater.

  • Thanks 1
Posted

I've been waiting to comment on this one, based on something I am chasing with the ICO, and also concerned that there is still a lot to cover on this so advice is sparse.

 

More guidance for schools will be available and it will be pushed out through a variety of sources, from DfE themselves, ICO, suppliers ... in fact pretty much everyone who has a stake will be shouting at schools about the change ... partly to cover themselves (as per Liam's comment above about 'shared responsibility'.

 

There are a mountain of good practices that should already be in place that only need tweaking or extending (e.g. the opt-in for photographs can apply to more data sets and situations) and most MIS can be customised to cover this. Your CCTV policies and system (which includes access control lists, maintenance schedules, audit logs, etc.) is a good *starting* point ... and remember that the updates will affect CCTV too so expect further guidance on that anyway.

 

The biggest shock is still likely to be forcing people to understand what data is, who is managing it and getting decisions about how/why it is processed. The changes to Sensitive, Personal Data (special categories of personal data) will be interesting to see how some institutes react.

 

Being honest though, until some clarifications and final guidance is made available, it is going to be a tough sell to SLT in school. Realistically, you (the school) will have from August to get started ... and between August 2017 and Feb 2018 I would be prepared to get as much verified advice you can get on it ... and at this point I remove myself from being considered even close to verified advice. Instead, I will probably be blathering on about planning instead ...

 

Get yourself on LA training. If an academy, speak to your MAT now and start asking who is going on training ... and when they will be providing *you* with advice. You can bet the unions will be running training events on this, as part of making sure the school and SLT are covering backsides on this! Start emailing your MIS provider about how they could be supporting the additional needs around managing data and information on GDPR. Start looking making a list of where all data is held (including hard copy) so that you can get a tick list of suppliers / data sets that are covered off. I can almost guarantee that BETT will be interesting around this next year ... as will a few of the other events.

 

If you are concerned, speak to your Governors. If you are a Governor, then start asking your advisory service when they will be running training.

 

Whatever you do though, no matter what your position or role, don't panic. Be logical, be practical and (most of all) be prepared to communicate.

  • Thanks 3

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...