Jump to content

Recommended Posts

Posted
How will that work with a school? We have to share data with outside agencies on a daily basis!

 

The good, old-fashioned Fair Processing Notice is going to take a beating ... If only there was a way of having a central system that could classify and manage data, including adding meta-data about where it was being shared with and how it was being processed (IIRC, originally suggested as a requirement for MIS at a Becta Working Group in 2008 ... and pretty sure it has been a regular mention over the years at SIFA(UK) sessions ... remembering that portability is important under GDPR)

Posted
Just thinking ahead but wondering how this is going to effect things like the children's index, where data is held about children in possible abusive situations. Lots of personal data about children and parents that can be accessed by schools, hospitals etc, and would it be theoretically possible for a parent to request the data is deleted?
Posted

No certain data will be protected. Individuals can request removal of data but the controller has the right to refuse in certain instances. The regulations state:

"When can I refuse to comply with a request for erasure?

 

You can refuse to comply with a request for erasure where the personal data is processed for the following reasons:

 

1 to exercise the right of freedom of expression and information;

2 to comply with a legal obligation for the performance of a public interest task or exercise of official authority.

3 for public health purposes in the public interest;

4 archiving purposes in the public interest, scientific research historical research or statistical purposes; or

5 the exercise or defense of legal claims."

 

The scenario you suggest would apply to at least 2 of these categories as will data in statutory returns that schools have to do.

  • Thanks 1
  • 4 weeks later...
Posted

I missed this first time around but it answers a lot of questions regarding the new GDPR initiative. Its an area in which I have a particular interest.

The Webinar is worth listening to if you have an hour to spare! If not there's a PowerPoint that summarises it all and will be useful to use to get the message across that DP is about to change big time.

https://ico.org.uk/about-the-ico/news-and-events/events-and-webinars/data-protection-for-the-education-sector-webinar/

Hope its useful.

  • Thanks 3
  • 3 months later...
Posted
Bitlocker can enforce it too

Interesting, we might consider this!

 

Because we didn't have a way to differentiate between encrypted and unencrypted USB sticks, we were gonna ban the lot (still might).

  • Thanks 1
Posted
Impero policies can enforce this to all deployed workstations.

 

How does that work with Cameras and SD cards? or does it effectively ban these ?

Posted
Interesting, we might consider this!

 

Because we didn't have a way to differentiate between encrypted and unencrypted USB sticks, we were gonna ban the lot (still might).

 

Ban memory sticks (or make them fiddly to use with encryption) and you will simply migrate people over to emailing files to themselves.

  • Thanks 1
Posted
Or uploading to a cloud storage service ... which is fine, because you can control which one they use and still maintain accountability.

 

That too. We see very few memory sticks here since getting Google Apps.

 

Hang on - if a particular parent refused to have their child's data shared with Google, would that not prevent the teachers from keeping the document in their own Google Drive...?

Posted

The data is not being shared with Google (as a data processor, to re-use as they see fit) but as a cloud provider of services.

If the school systems are based on Google (who have the EU model contracts in place, have been vetted for cloud services by U.K. Govt and it is being processed as requested by the school) then there is little ground for refusal.

 

Saying "we don't trust company x" is not a valid reason for refusal.

  • Thanks 1
Posted
Saying "we don't trust company x" is not a valid reason for refusal.

 

Thanks, that's certainly reassuring. I suppose it does raise the next question, what IS a valid reason for refusal?

Posted
Ban memory sticks (or make them fiddly to use with encryption) and you will simply migrate people over to emailing files to themselves.

Yeah, that's a fair point. You can't outright ban memory sticks without having something nice and simple in place to replace that function.

 

We're implementing G Suite soon, so that's an online storage option, or we do have a few other options.

Posted
Thanks, that's certainly reassuring. I suppose it does raise the next question, what IS a valid reason for refusal?

 

To be honest, it is more a case of refusing to allow a school to process the data because of lack of policy, failure to follow policy, inappropriate policy ...

 

An example would be that school chose product A from company X, it wasn't on the Privacy Notice and it is known the the T&Cs of company x are not compatible with use for under a certain age.

 

We all read the T&Cs, don't we?

 

The importance of being cleared what we sign learners up for is an element to look at as part of your GDPR readiness.

  • 10 months later...
Posted
Personal all the GDPR should be in place anyway with Data Protection , have always said USB are the worst form to save any data for the chance of Loss and Damage if encrypted or not plus the biggest risk to a network for infection and virus spreading, Personally a lot is a Cash cow for company and LEA scaring school in to wasting money, when they have 365 office Free and each user have access and it secure and there accountable to the data if they share , plus backed up and safe and cant loss, along with data stored in UK ,
Posted

Is anyone using Impero to enforce the use of Encryted USB drives?

 

We're about to roll it out, but we need to make exceptions for things like BBC MicroBits etc. This can be done with the "Device Allow List" in the USB Management section, but we're struggling to enable specific SD cards.

 

We do a lot of digital arts and photography, so we need to let the students transfer the photos they take from the cameras to the PCs via SD card. Impero will only seem to "allow" the SD card reader/camera, and not the SD card itself. This creates a big open door in our "enforce encryption" policy - as effectively any SD card can be used to copy/transfer data via one of the "allowed" SD card readers.

 

I was just wondering if any of you guys were experiencing the same dilemma, or if you had any bright ideas on a workaround?

 

Cheers!

  • Thanks 1
Posted
Can you allow the readers but only let the staff use them? Students give the card to the teacher, teacher copies the files off and emails them to the student.
Posted
We're about to roll it out, but we need to make exceptions for things like BBC MicroBits etc.

 

Ah crap. About to implement USB encryption here, but had not take cameras into account. Especially given the new online safety policy says only use school cameras to take pictures, never your mobile!

 

Ta for the heads up, need to factor that in!

Posted
Especially given the new online safety policy says only use school cameras to take pictures, never your mobile!

 

We tell staff to use their iPads. School property, and wifi-enabled so photos can be emailed or uploaded to Drive, no faffing with cables.

Posted
We tell staff to use their iPads. School property, and wifi-enabled so photos can be emailed or uploaded to Drive, no faffing with cables.

 

Sadly staff don't have iPads here, the shared iPads we do have are always in high demand!

 

I think we should be OK, I'm going for the option of 'prompt to encrypt', which the user can cancel and still read the drive, just not write to it. Needs to be tested though.

  • Thanks 1
Posted
Ah crap. About to implement USB encryption here, but had not take cameras into account. Especially given the new online safety policy says only use school cameras to take pictures, never your mobile!

 

Ta for the heads up, need to factor that in!

Is that your own policy or a national one?
Posted
I think we should be OK, I'm going for the option of 'prompt to encrypt', which the user can cancel and still read the drive, just not write to it. Needs to be tested though.

 

So that option solves your camera problem but... what about a staff member who saves sensitive data to an unencrypted memory stick at home then brings that into school? Wouldn't that option mean the data could be read of the memory stick by any student who happened to pick it up?

Posted
Is that your own policy or a national one?

 

School policy. I did initially argue against it, because why supply staff with cameras when every one of them already has one in their pocket? But then the very good point was raised of what happens if a teacher is ever brought to question and that's on their phone, or they lose their phone with those images on... Basically safest not to, for the liability it could place on staff as much as anything.

 

Not national policy, but seems to be the norm in schools in our area.

  • Thanks 1
Posted
So that option solves your camera problem but... what about a staff member who saves sensitive data to an unencrypted memory stick at home then brings that into school? Wouldn't that option mean the data could be read of the memory stick by any student who happened to pick it up?

Theoretically yes, but staff shouldn't be generating confidential data at home anyway, and if they are they should be looking after that USB stick. We're quite good here in that we have a minimum of people working at home.

 

That encryption policy doesn't cover all bases, but it's the best fit for us as a primary.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...