Jump to content

Recommended Posts

Posted
Unfortunately I won't, what I will get from schools in Kent is a refusal on the grounds of cost. The standard calculation they are all producing will be massaged so that the time per pupil multiplied by the number of pupils will always be slightly greater than 25 hours, even if the data is available in a database on SIMs or whatever else they are using. The approach is quite obviously being coordinated to avoid answering the request.

 

I assume you're doing the whole internal review / complaint to ICO thing for those?

Posted
Anyway, back to more serious issues, if you want to protect your data, use what the ICO's "expert" called an "air break machine", a dedicated, clean machine connected to the internet via a guest network or some other means which prevents infection to you machines with sensitive data. Tablets are very cheap these days, you can get a new one for less than £30. Then you can click away on links in emails as much as you like, just clean the machine off afterwards.

 

It's nice to know you would cover the cost of installing a Guest system and a suitable tablet/device purchase. ;) Not everyone has this in place, and why should schools fork out more money they don't have just because you want to make life easier for yourself?

  • Thanks 1
Posted (edited)
Unfortunately I won't, what I will get from schools in Kent is a refusal on the grounds of cost. The standard calculation they are all producing will be massaged so that the time per pupil multiplied by the number of pupils will always be slightly greater than 25 hours, even if the data is available in a database on SIMs or whatever else they are using. The approach is quite obviously being coordinated to avoid answering the request.

 

Where does 25 hours come from?

 

I thought it was max £450 for schools at £25 per hour = 18 hours.

 

EDIT

7. Regulation 3 of the Fees Regulations states that the appropriate limit for central government, legislative bodies and the armed forces (in other words, those bodies covered by Part 1 of Schedule 1 of the Act) is £600.

 

8. For all other public authorities, the appropriate limit is £450.

 

Source

 

The school and the LA fall into bullet 8

Edited by elsiegee40
Posted
It's nice to know you would cover the cost of installing a Guest system and a suitable tablet/device purchase. ;) Not everyone has this in place, and why should schools fork out more money they don't have just because you want to make life easier for yourself?

 

For the twitter tribunal that he has referred to they found that a public authority shouldn't have to do the additional work of clicking on a person’s twitter account to find out the person’s name to make it a legitimate FOI request.

 

So surely it follows that a public authority shouldn't need to create a separate network with suitable tablets/mobile devices that are formatted after use just to make his FOI request legitimate. From what I can gather this is actually one of his arguments that they should!!!

 

Here is to hoping the tribunal lays down some common sense :D

  • Thanks 2
Posted
It's nice to know you would cover the cost of installing a Guest system and a suitable tablet/device purchase. ;) Not everyone has this in place, and why should schools fork out more money they don't have just because you want to make life easier for yourself?

 

I have explained that schools already have this facility in the equipment they have to have to teach the KS2 curriculum. I get a guest network for free with my home broadband, the cost is minimal.

Posted
I have explained that schools already have this facility in the equipment they have to have to teach the KS2 curriculum. I get a guest network for free with my home broadband, the cost is minimal.

 

For a home user that may be the case... now if you think about something as big a a school we need at least 1 switch that require VLANs and possibly Layer 3 routing, at least 1 WAP that need to support VLANs (if they are only going to be doing this from once specific area), etc...

 

As for teaching KS2 curriculum, I don't remember where it says 'let the kids click links in e-mails from an untrusted source'.

Posted
I have explained that schools already have this facility in the equipment they have to have to teach the KS2 curriculum. I get a guest network for free with my home broadband, the cost is minimal.

 

Sorry, but not all schools teach KS2 so do not have the equipment or the infrastructure to have an isolated piece of equipment for the odd FoI request that requires a weblink. We'd rather spend our limited funds on Staff costs and teaching the students.

  • Thanks 4
Posted

https://ico.org.uk/media/for-organisations/documents/1164/recognising-a-request-made-under-the-foia.pdf

"FOIA requests made via online forums and social media will be valid provided they meet the criteria in Section 8(1). If it is not reasonably practicable for the authority to provide a response through the website concerned, it should ask the requester for an alternative address for correspondence."

 

The defence relied up on is that it is not reasonably practicable to expect a public authority to click on a link in an email. However once they have done that to correspond with me in a request for clarification they have proven it is reasonably practicable to click on the link and have undermined their own argument. It won't make much difference in the end.

Posted
Sorry, but not all schools teach KS2 so do not have the equipment or the infrastructure to have an isolated piece of equipment for the odd FoI request that requires a weblink. We'd rather spend our limited funds on Staff costs and teaching the students.

 

The vast majority of primary schools are teaching KS2, are you referring to secondary schools?

Posted
it should ask the requester for an alternative address for correspondence

Was requested. Received no answer. Again, we all have responsibilities under the act on both sides. Two way street and all that ;)

  • Thanks 1
Posted
https://ico.org.uk/media/for-organisations/documents/1164/recognising-a-request-made-under-the-foia.pdf

"FOIA requests made via online forums and social media will be valid provided they meet the criteria in Section 8(1). If it is not reasonably practicable for the authority to provide a response through the website concerned, it should ask the requester for an alternative address for correspondence."

 

The defence relied up on is that it is not reasonably practicable to expect a public authority to click on a link in an email. However once they have done that to correspond with me in a request for clarification they have proven it is reasonably practicable to click on the link and have undermined their own argument. It won't make much difference in the end.

 

So if someone say clicked the link by accident before remembering good cyber security practice and closing it, it would be a good idea for them to click the link again and spend some time on it so they could possibly get infected? :thumb:

Posted
Quick tip, on the house: those guest networks on your home router are insecure as all hell. Don't use them. Like, ever.

 

Which ones are insecure? All the ones I've used are fine.

Posted
The vast majority of primary schools are teaching KS2, are you referring to secondary schools?

 

Well unless your FoI request was specifically targeted to Primary schools, you previous post neglected to account for the fact that a significant number of us are Secondary school support so some of your assumptions of IT provisions for use in cases such as these may be slightly skewed. But until the tribunal has made a decision I guess it's all quite a mute point.

Posted
I have explained that schools already have this facility in the equipment they have to have to teach the KS2 curriculum. I get a guest network for free with my home broadband, the cost is minimal.

 

My School does not have KS2 students, We however do have equipment we could set up but that would take time to do and then time to wipe after. Add that to the time it takes for other staff to collate the data then the time all adds up.

 

As others have said with guest networks.

 

We still havent received the FOI yet so either the email you have of ours is wrong or been deleted by filters or maybe even you havent sent it to us yet.

Posted
The vast majority of primary schools are teaching KS2, are you referring to secondary schools?

 

The vast majority of primary schools do not have a Technician, just a teacher who knows a little bit more than others, I doubt that they would go to all the trouble of setting up equipment just to click on a link to see what it is when policies are to not click on links from unknown sources.

Posted
So if someone say clicked the link by accident before remembering good cyber security practice and closing it, it would be a good idea for them to click the link again and spend some time on it so they could possibly get infected? :thumb:

 

There are no viruses or malware on my site as far as I'm aware. The ICO is specifically not saying my site is a risk of infection.

 

If they've submitted a request for clarification to me using my form then they aren't just visiting it by mistake briefly, they're using it. To then claim they can't use it is absurd. It's like saying I can't post on this site because it's a cyber security risk, it's too late, I've already done it!

 

For those who are actually interested, KS2 national curriculum https://www.gov.uk/government/publications/national-curriculum-in-england-computing-programmes-of-study/national-curriculum-in-england-computing-programmes-of-study

 

 

  • understand computer networks, including the internet; how they can provide multiple services, such as the World Wide Web, and the opportunities they offer for communication and collaboration
  • use search technologies effectively, appreciate how results are selected and ranked, and be discerning in evaluating digital content
  • select, use and combine a variety of software (including internet services) on a range of digital devices to design and create a range of programs, systems and content that accomplish given goals, including collecting, analysing, evaluating and presenting data and information

 

Access the internet use search engines and click on the links the present you with. How is that different to clicking on a link in an email? You think Google check out all the links they present in searches?

Posted (edited)
You think Google check out all the links they present in searches?

Slightly off topic but, actually, yes, they do. Just for the record :) They have automated vulnerability scanners that check sites and look for potential security issues, site forgeries (eg phishing attempts) etc.

 

Edit to be a bit more helpful: Nobody is claiming your Google Form hosts malware. We're pointing out that we specifically make a point of not clicking links emailed to you by people you don't know that you weren't expecting.

 

If a Cover agency emails our Cover Supervisor and it has a link in it, that's a bit more OK in context, because it comes from somebody they know and external resources are expected (eg CV links)

An email from someone you're not expecting any correspondence with, containing links, is a bit more suspicious. Those are the links we encourage users not to click.

Edited by Garacesh
  • Thanks 2
Posted
There are no viruses or malware on my site as far as I'm aware. The ICO is specifically not saying my site is a risk of infection.

 

Err you either haven’t read the decision notice or you are being seriously flaky with the truth! The ICO's decision notice specifically says that they accept that because of security concerns about using your site, it was not reasonably practicable for the school to use the reply button to fulfil the requirement of an address for correspondence, and therefore the request did not meet the requirements of section 8(1)(b) of the FOIA and was not valid.

Posted
Access the internet use search engines and click on the links the present you with. How is that different to clicking on a link in an email? You think Google check out all the links they present in searches?

 

Pull vs push. Everyone is sent emails with malware in every day, it's usually sent to spam, links are disabled etc.

 

If your email is plain text and contains a link to a known website, might be worth clicking.

 

Can't even trust digitally signed emails due to account compromises sending emails from people you know, that's why they hack accounts after all.

 

A theoretical question: would you be happy for the school to publish the answer on their website, and then email you to say they're on the website?

Posted
A theoretical question: would you be happy for the school to publish the answer on their website, and then email you to say they're on the website?

 

Surely this is the best option for the school and future potential FOI requesters?

 

If the school has to do the work, put it somewhere accessible to all. If a FOI comes along that needs the info, it's there. No need for further work on the school's part. Of course, this would need the initial request to be "reply-able".

Posted

Headache of pedantics going on here.

@bmaloney I understand that you've put a lot of thought and time into creating a form to collect the data you need as efficiently as possible, but I believe that what you're encountering is the fact that, as far as I know, schools are chronically understaffed concerning administrative matters. And they're understaffed in this area because of a lack of funding. Admin staff are just not viewed as important in the grand scheme of things, even though they're critical to making a school actually function.

 

I guess the school I work at is lucky to have me as a tech, because I willingly take on work that's not officially my responsibility. Anything the overworked and stressed admin staff cannot handle is delegated to me. For the past year or more I've assumed full responsibility over everything data protection, and that includes subject access requests.

 

Even if schools want to comply, the form is large and intimidating. The office staff and Head at this school were daunted by it, even though they have me available to comb through the data and complete it for them. After consulting other local Heads, whose schools were also daunted by the request (and at the time were waiting to hear back from our LA who had contacted the ICO), this Head decided they didn't want me spending the time on it when there are so many other things that need to be done. The ICO then deemed the request invalid, so I didn't have to do it. You have challenged their decision, so here I am waiting to see what the outcome is.

 

I get that you're frustrated at what looks like incompetence from the schools. It's true that some might be too quick to dismiss the request. But the only reason they'll be avoiding it is because they don't feel like they have the time to complete it.

 

The least you can do is consider schools' situations, and openly listen to their feedback. Friendliness and co-operation goes a long way to achieving results, rather than being defensive and taking everything personally. Don't try telling schools how you think they should be running or doing things if you only have an outside perspective. I too get frustrated at fumbling inefficiency, and what looks like people avoiding responsibilities/workload, (and I have an inside view), but I also understand why things come across as they do. The 3 years I've been working in education have opened my eyes a lot and taught me to be a little more patient and considerate.

  • Thanks 2
Posted
I get that you're frustrated at what looks like incompetence from the schools. It's true that some might be too quick to dismiss the request. But the only reason they'll be avoiding it is because they don't feel like they have the time to complete it.

Feeling like you don't have the time to complete it is not a defence. I know they're scratching around for excuses to refuse my request because they don't want to do it, but that's shortsighted. I will simply come up with a different way of submitting the request and they'll be back where they started. The school's in Kent are a prime example, those in Barnet are another. The FOIA doesn't disappear because you make life difficult for the requester, that's not the point of the Act.

Guest
This topic is now closed to further replies.



×
×
  • Create New...