Jump to content

Recommended Posts

Posted
Presumably this is "incase they email the staff member and then we get a SAR or deletion request", by the same logic you could say "pupils are not allowed to write anything down on paper and leave it in the building"
Posted

As described? Boy cow waste.

 

As @Katy mentions, a SAR could encompass staff personal email accounts if there's evidence they're dumb enough to use personal email for school business (not to mention safeguarding / accountability issues). But there's no reason kids shouldn't know and email work-provided staff email accounts.

Posted

I hold my head in my hands and let forth a shriek if despair.

 

Please find out who they got this advice from and PM it too me ... I will add it to the anonymous examples we are feeding back to DfE and ICO.

 

Ask whether this was a result of a risk assessment and could you see a copy?

  • Thanks 2
Posted
Hi

 

I have been told that "because of GDPR" our pupils are not allowed to know the staff e-mail accounts. Is this correct?

 

Nonsense of the highest order!

 

This policy would mean staff cannot email students or share resources via Google Classroom. In fact, it would probably make any VLE unusable, as they typically allow you to view the "profile" of someone who posts or uploads something.

 

Also, unless your staff have different email address formats to the students, they can work them out anyway.

Posted

As most schools will have a naming format for staff emails, ie [email protected], it seems a bit pointless if true as students will just work it out. (Edit: already beaten to that point above!)

 

Sounds like someone is trying to be busy and sound important.

  • Thanks 1
Posted

Thanks to all.

 

I suspect it is the result of older staff being paranoid that is pupils find out the staffs' full names then the pupils can cast spells on them or some such :)

Posted
Thanks to all.

 

I suspect it is the result of older staff being paranoid that is pupils find out the staffs' full names then the pupils can cast spells on them or some such :)

 

Or sign them up for inappropriate mailing lists, which I've seen done...

 

Seriously though, if students can see/find out staff email addresses, it would probably be sensible to coach them a bit in appropriate contact - will teachers respond to requests for homework help via email? If so, what is the expected response time? What can/can't you email teachers about? (Our HT said she had a lot of emails from students during the snow days asking if school would be open the next day!).

Posted

Difference between personal and school email; typically staff are not expected to answer an email outside certain hours and therefore hold no obligations.

I will echo the above, user management should cover it. An email address is there for a reason, to contact someone directly. If someone needs to be private, then perhaps they need to have a generic address like [email protected] for example.

Posted
What about this one? I am being told that Google Mail/Suite is not GDPR compliant as there servers are located in ROI. Whereas, Microsoft. Office 365 are compliant as there servers are in the UK? Confused ??????????
Posted
What about this one? I am being told that Google Mail/Suite is not GDPR compliant as there servers are located in ROI. Whereas, Microsoft. Office 365 are compliant as there servers are in the UK? Confused ??????????

 

Google's servers are all over the place (https://www.google.com/about/datacenters/inside/locations/index.html), and your data is on any number of them, BUT... there's nothing in GDPR which says data must be held in UK or EU. GDPR regulates what data should be held and how it should be held, it says nothing about where. As long as you are happy with how Google are treating your data, you're fine.

  • Thanks 1
Posted
Thanks for that that was my understating to!! My Head, CEO & CF0 of the MAT have been commenting on this most recently at an all staff meeting. So was looking for some clarification. Thanks
Posted
What about this one? I am being told that Google Mail/Suite is not GDPR compliant as there servers are located in ROI. Whereas, Microsoft. Office 365 are compliant as there servers are in the UK? Confused ??????????

 

Google have an extensive GDPR satement. https://www.google.com/cloud/security/gdpr/

 

How do people get the ldea that Google are going to not comply and therefore be unable to operate in Europe ? I mean what planet are they living on ?

Posted
How do people get the ldea that Google are going to not comply and therefore be unable to operate in Europe ? I mean what planet are they living on ?

 

Possibly by thinking GDPR is something UK schools have to do, not something any business operating in EU has to do.

Posted
Possibly by thinking GDPR is something UK schools have to do, not something any business operating in EU has to do.

 

Every teacher is going to think this is all level 10 blockery by their sysadmin anyway.

  • Thanks 1
Posted
We've just had safeguarding training by the local authority and the trainer said that images on websites needed to be on UKservers for GDPR compliance. Correct??
Posted
We've just had safeguarding training by the local authority and the trainer said that images on websites needed to be on UKservers for GDPR compliance. Correct??

 

No. You can store photos on servers in Tibet if you wish, as long as you can justify why it is there and know the person hosting it there isn't letting anyone else access it.

  • Thanks 1
Posted
By the sounds of it, some of these local authorities are getting their training in from these spamming muppets that all our inboxes are full of constantly claiming to be Gods Gift to GDPR.

 

Worrying, isn't it, especially if people have paid for this "training". Also, there seems to be a lot of hoohah about photos amidst all the GDPR stuff, when (correct me if I'm wrong) we need to do handle photos any differently to any other data.

Posted
Worrying, isn't it, especially if people have paid for this "training". Also, there seems to be a lot of hoohah about photos amidst all the GDPR stuff, when (correct me if I'm wrong) we need to do handle photos any differently to any other data.

Not as far as I'm aware, the one that struck me as the most insane was the "photos on the website" one a few posts back - what's it matter where the server is when anybody in the world can access them? (that being the point of a website)

  • Thanks 1
Posted
Not as far as I'm aware, the one that struck me as the most insane was the "photos on the website" one a few posts back - what's it matter where the server is when anybody in the world can access them? (that being the point of a website)

 

Ha, good point. I'd missed the obviousness of that error!

  • Thanks 1
Posted
Playing devils advocate but loading a picture from China website server gives a 200 get request. Ah success I have the picture. But. Do you have a privacy policy that states you won’t divulge their IP address for other purposes? IN WHICH CASE you can’t host the data anywhere as it’s going to get pulled by the Great Wall of China and used to track. Sorry for being a sod about it :) but I liked your answer and thought about it some more. Patriot act anyone?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...