ITGURU Posted May 5, 2017 Posted May 5, 2017 Where's the best place to find out what schools need to have in place to comply with the new GDPR policy that is coming out, such as do we have to only allow encrypted usb devices etc to comply , do staff laptops have to be encrypted etc etc... Thanks
synaesthesia Posted May 5, 2017 Posted May 5, 2017 Exam boards are easily some of the worst offenders with regards to data protection, and the trouble is the only way they're likely to change is either a force from above or enough schools saying "Oi, this isn't good enough" - but the latter pretty much requires schools to use student data as a hostage, which isn't fair on the pupil should something go wrong.
3s-gtech Posted May 5, 2017 Posted May 5, 2017 Yup, and I suspect the only thing that will make them act is a humunculous fine or the threat of one. My impression is that ease of use/convenience for the examiners comes before data security - I wonder how the law would view that one...?
GrumbleDook Posted May 5, 2017 Posted May 5, 2017 There isn't anywhere at the moment ... the ICO are still not giving out specifics yet. There are smatterings of guidance out there that can be dug out ... but nothing education specific
localzuk Posted May 5, 2017 Posted May 5, 2017 Somerset County Council have been running some advice sessions for schools recently (I'n going to one next Wednesday morning). There's nothing firm yet though I think, as the ICO haven't really given out much info!
pcstru Posted May 5, 2017 Posted May 5, 2017 Where's the best place to find out what schools need to have in place to comply with the new GDPR policy that is coming out, I'd say the ICO is the best place to start. such as do we have to only allow encrypted usb devices etc to comply , do staff laptops have to be encrypted etc etc... The GDPR seems to be similar to DPR in that respect. It is very unlikely that legislation will dictate what in any detail constitutes "appropriate technical means" (or even appropriate organisational means) - it would be very difficult to do so without either hobbling organisations or ending up in a few years time with out of date techniques specified. However, if you look at the actual judgements the ICO has made against organisations it is quite clear that NOT encrypting data is seen as a failure to provide "appropriate technical means". Subtle, 'eh?
ITGURU Posted May 5, 2017 Author Posted May 5, 2017 What do other schools do? Do you encrypt staff laptops and only allow encrpyted usb devices ?
pcstru Posted May 5, 2017 Posted May 5, 2017 (edited) What do other schools do? Do you encrypt staff laptops and only allow encrpyted usb devices ? We encrypt laptop hard drives using Bitlocker. We have policy that, if followed, would prevent staff from using unencrypted USB as data storage. I think I'll extend encryption to admin desktops, to cover break-ins. Overall if we lost data, it would be failure of the "organisational measures" (policy/procedure) that would kill us! (ETA - next May of course, what will kill us is management spending 2017 doing the Ostrich thing ) Edited May 5, 2017 by pcstru 1
ITGURU Posted May 5, 2017 Author Posted May 5, 2017 We encrypt laptop hard drives using Bitlocker. We have policy that, if followed, would prevent staff from using unencrypted USB as data storage. I think I'll extend encryption to admin desktops, to cover break-ins. Overall if we lost data, it would be failure of the "organisational measures" (policy/procedure) that would kill us! (ETA - next May of course, what will kill us is management spending 2017 doing the Ostrich thing ) What about servers - is it necessary?
Bob_the_Goon Posted May 5, 2017 Posted May 5, 2017 Earlier this year I attended an ICO webinar focused on how the GDPR will affect schools. It was very useful. They posted it online for future use (see link below): https://ico.org.uk/about-the-ico/news-and-events/events-and-webinars/data-protection-for-the-education-sector-webinar/ 2
GrumbleDook Posted May 5, 2017 Posted May 5, 2017 Just to note that I have been joining a number of GDPR webinars over the last 6 months. I'm collating the information together and will be sharing in June. Please note that this is aimed at helping people raise awareness of what to look for or important questions to ask, not on what they are legally obliged to do. (IANAL)
GrumbleDook Posted May 5, 2017 Posted May 5, 2017 Earlier this year I attended an ICO webinar focused on how the GDPR will affect schools. It was very useful. They posted it online for future use (see link below): https://ico.org.uk/about-the-ico/news-and-events/events-and-webinars/data-protection-for-the-education-sector-webinar/ They have a massive caveat of "We will give you firm information when we decide it" though ... and I can't blame them.
maturelady Posted May 7, 2017 Posted May 7, 2017 Back to the original question. I think we all should understand that ICO is never going to say to us – “Yes, you need to encrypt teachers’ laptops, No, you don’t have to encrypt data sticks.” Or anything similar. What they will say is that it is a school’s responsibility to take all steps necessary to keep personal data safe. It will be up to individuals to define what keeping data safe entails. If nothing goes wrong you will never know if you have got it right. Sadly, it will be the first school to be fined for a data breach under GDPR that will give us many of the answers we want. I believe you must apply common sense and logic and of great importance, maintain a full log of the steps you have taken. Thus in my opinion if any device which stores any personal data that allows an individual to be identified must be protected. If it is paper it must be secured and if it is electronic it must be encrypted, password protected or locked away in a big vault! If you can demonstrate that you have taken every appropriate step to protect your data then I believe any breach will be investigated with sensitivity. It’s going to be a learning curve for all and that’s why it’s vital that we continue to share experiences and good practices.
GrumbleDook Posted May 7, 2017 Posted May 7, 2017 One of the problems is that historically both Ofsted and ICO have failed to take tough action on schools. No school has been fined yet though several have signed undertakings. Ofsted, at one point, did say that such a failure would also mean that it would be a failure on Safeguarding. But then nothing happened and they then came back and said it was up to other agencies, such as ICO, to deal with this. I'm hoping that GDPR makes some difference on this.
pcstru Posted May 8, 2017 Posted May 8, 2017 What about servers - is it necessary? IMO, it depends - mostly on the risk of theft, but not all. Servers should generally have good physical security such that it is only possible for authorised people to access them. Those people generally have enough logical access that they essentially have access to the data and that is a trust based relationship (they are trusted with that level of access). So in that case the risk of theft is largely mitigated by trust in the people who do access the equipment and physically denying access to those without that trust. At the end of the equipment life is the risk of disposal - ensuring discs are properly wiped is essential. Which may highlight the biggest single risk - many people have policy and procedure which exists in document form only (i.e. it is written down that people should do X, but few know about it and fewer actually do it). Here, we do not encrypt server discs; we have reasonable physical security and disposal procedure is fair (discs always removed from equipment and handled separately). It does occur to me thinking about it that we need to be tighter on upgrades which can leave discs kicking about (which need to be wiped) and failed discs (which should be physically destroyed).
maturelady Posted May 8, 2017 Posted May 8, 2017 Data protection is about all personal data that is stored and shared in schools. I agree with pcstru that schools’ physical servers and access should meet the requirement and if they don’t someone is not doing their job. However, it’s all the stuff taken out on paper, sent to 3rd parties and extracted for everyday use is where breaches will occur. Do you know if the school canteen prints off any names from the cashless system or the PE staff emails the mini bus driver with kids names to pick up? ...and what do they do with them when they finish with the information? That’s the scary bit.
mikemcsharry Posted May 24, 2017 Posted May 24, 2017 I've been looking in to GDPR a lot for primary schools. Oddly I seem to be the only person who has mentioned it to them. Last week I did a fairly 'easy' introduction for a small group and wrote a web page to follow it up. A lot of the stuff out there is absolute scaremongering "you'll all go to hell" - yep, if you generate 75 million unsolicited text messages you deserve to. Handled the right way GDPR is a huge opportunity for schools (and world+dog) to actually sort a lot of stuff out at last! Here's the webpage I made plus the slides of the presentation - hopefully you'll find it useful. Like grumbledook (I may re-write that, as it looks like an instruction) - I have collated a list of links to various websites - I'll share them in next few days. https://funtorun.co.uk/gdpr-for-primary-schools/ Ignore that it says Primary schools - I actually prepared it for a secondary network meeting. I'm too late to book for the June conference but I live near Leicester - happy to talk through this with the conference if you want. 2
GrumbleDook Posted May 24, 2017 Posted May 24, 2017 Hi Mike I'll be popping down from York the day before, so might pop into to catch up and chat through the presentation if you fancy a cuppa? Maybe if @maturelady is free too?
maturelady Posted May 24, 2017 Posted May 24, 2017 A meeting with 2 hansom young gentlemen – how can a girl resist that! I live less than an hour away. DM where you are staying Tony and sort out the time between you guys.
PotNoodleTech Posted May 25, 2017 Posted May 25, 2017 2 handsome young gentlemen - and gumbledook??!! Whatever you guys figure out let us all know as it will help out people like me who are not trained lawyers work out what to tackle next :-/
PotNoodleTech Posted May 25, 2017 Posted May 25, 2017 I've been looking in to GDPR a lot for primary schools. Oddly I seem to be the only person who has mentioned it to them. Last week I did a fairly 'easy' introduction for a small group and wrote a web page to follow it up. A lot of the stuff out there is absolute scaremongering "you'll all go to hell" - yep, if you generate 75 million unsolicited text messages you deserve to. Handled the right way GDPR is a huge opportunity for schools (and world+dog) to actually sort a lot of stuff out at last! Here's the webpage I made plus the slides of the presentation - hopefully you'll find it useful. Like grumbledook (I may re-write that, as it looks like an instruction) - I have collated a list of links to various websites - I'll share them in next few days. https://funtorun.co.uk/gdpr-for-primary-schools/ Ignore that it says Primary schools - I actually prepared it for a secondary network meeting. I'm too late to book for the June conference but I live near Leicester - happy to talk through this with the conference if you want. That's really useful thanks for posting it!!
mikemcsharry Posted May 25, 2017 Posted May 25, 2017 Am I too late to book for the conference and/or does anyone want me to work through this. As any previous victims of one of my presentations could testify I don't read the slides!
GrumbleDook Posted May 25, 2017 Posted May 25, 2017 2 handsome young gentlemen - and gumbledook??!! Whatever you guys figure out let us all know as it will help out people like me who are not trained lawyers work out what to tackle next :-/ IANAL ... just a person with a passion! Oh, and I like chocolate too!
mikemcsharry Posted May 28, 2017 Posted May 28, 2017 Regarding the conference - I'd love to come along but I'm a "commercial entity" so it would be out of order for me to try to grab a remaining ticket - unless anyone knows otherwise. I'm not booked out anywhere (yet) on that day and I do live quite local and I do like rockets. Anyway, the reason for this post is that I've got myself into an arm wrestle with somebody who has been spouting the GDPR rules at me. he's been on the internet and then explained why the service I give him (on a voluntary basis) is not effected by the GDPR. So, I checked his sources. THIS is very, very worrying. Be prepared for this. If anyone can offer me any more info for this webpage, please do (I'll credit anyones information) here's my findings - https://funtorun.co.uk/gdpr-home-page/
GrumbleDook Posted May 29, 2017 Posted May 29, 2017 I've asked around and they do seem like opportunists.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now