Jump to content

Recommended Posts

Posted

Thanks Seb1780 for the spreadsheet, gives me good format to start to work with.

Thought I would share how my SLT are dealing with GDPR

 

headinsand.JPG

  • Thanks 4
Posted

Information Audit.xlsx

 

That's what I've come up with based on @DavePa and @TechMonkey suggestions and a bit of general thievery from @Seb1780

 

The "fundamental" change I've made from Seb's is to list individual pieces of data eg phone numbers, address, allergy rather than the document that that data is obtained from eg admissions paperwork

 

I'm not sure if either is the correct way to go - I can see my way generating a much bigger spreadsheet! And the headache of the address is on SIMS, admissions paperwork, schoolcomms etc and god knows where else. Right that's home address done, now telephone number.... email address.....

 

Fun times...

  • Thanks 1
Posted
Sorry, I should have been clearer. I wasn't saying it was illegal to use disposal companies, we use them often. I was pointing out that even currently if you send devices out to be recycled, not for data destruction, and you leave sensitive data on them you would be in breach of the DPA. How many stories have we seen of an old HDD on eBAY containing a treasure trove of data?

 

I've bought refurbished machines that were supposed to have been wiped but some still had data from the last owner, in fact they still booted to the logon screen.

Posted
You have wiped the drives, made them inaccessible to general recovery and they remain an asset within the organisation. As long as you have something in your policies about not trying to access deleted data / only IT Support can run recovery software, then the only risk is the loss of the device and it being recovered by someone else. Possibly look at doing more than a reformat?

 

If you can find examples of drives being recovered after doing this (i.e. there are) then it isn't good enough.

 

To some extent, it is dependent on the level of personal information held on the device ... even desktop devices will have copies of files, roaming profiles, etc ... so you need to make an assessment on that.

 

I've seen data formatted with the highest possible level via Blancco; way beyond the requirements of CESG, MOD etc recovered as part of a proof of concept that even the designated data handlers would be unable to guarantee total destruction. (from my history in secure data destruction)

No idea why you'd bother scoring platters of a HDD ; a couple of whacks with a lump mallet will disintegrate a 3.5" hard drive, and a couple of good hits with the blunt end of a long screwdriver will do the same for a 2.5" drive.

At least in 2007 when I was last dealing with this, it would be near impossible for anyone to say such a damaged drive is capable of storing any data, unless you count the dents in the case as boolean logic (dent=1 or true for a succesful hit of a hammer, no dent=0, no hit from a hammer). Unless someone has changed their mind and found a way to word that which is EXTREMELY unlikely. no court in the land would have a leg to stand on if you were dragged up in front of them with a 2.5" drive sounding like a maraca because you chucked it in with your WEEE.

That isn't condoning being careless by the way.

 

 

Use proper PPE when destroying hard drives.

Posted
...No idea why you'd bother scoring platters of a HDD ; a couple of whacks with a lump mallet will disintegrate a 3.5" hard drive, and a couple of good hits with the blunt end of a long screwdriver will do the same for a 2.5" drive.

 

Having a lump mallet at my desk might tempt me to threaten the next person who tells me GDPR is an IT problem although I guess that the screwdriver that I use to score the platters could also be used as a weapon...

  • Thanks 1
Posted
[ATTACH]44246[/ATTACH]

 

That's what I've come up with based on @DavePa and @TechMonkey suggestions and a bit of general thievery from @Seb1780

 

The "fundamental" change I've made from Seb's is to list individual pieces of data eg phone numbers, address, allergy rather than the document that that data is obtained from eg admissions paperwork

 

I'm not sure if either is the correct way to go - I can see my way generating a much bigger spreadsheet! And the headache of the address is on SIMS, admissions paperwork, schoolcomms etc and god knows where else. Right that's home address done, now telephone number.... email address.....

 

Fun times...

 

Has anyone made a good start on an Information Audit and if so would they mind sharing what their spreadsheet currently looks like via PM. I haven't started yet and want to make sure we are starting on the right lines!

 

Thanks,

Dean.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...