gopher_1999 Posted January 22, 2018 Posted January 22, 2018 Hi I have been told that "because of GDPR" our pupils are not allowed to know the staff e-mail accounts. Is this correct?
Katy Posted January 22, 2018 Posted January 22, 2018 Presumably this is "incase they email the staff member and then we get a SAR or deletion request", by the same logic you could say "pupils are not allowed to write anything down on paper and leave it in the building"
djrscally Posted January 22, 2018 Posted January 22, 2018 Unless they mean personal email accounts or something. If it's work emails; definitely nonsense.
pete Posted January 22, 2018 Posted January 22, 2018 As described? Boy cow waste. As @Katy mentions, a SAR could encompass staff personal email accounts if there's evidence they're dumb enough to use personal email for school business (not to mention safeguarding / accountability issues). But there's no reason kids shouldn't know and email work-provided staff email accounts.
GrumbleDook Posted January 22, 2018 Posted January 22, 2018 I hold my head in my hands and let forth a shriek if despair. Please find out who they got this advice from and PM it too me ... I will add it to the anonymous examples we are feeding back to DfE and ICO. Ask whether this was a result of a risk assessment and could you see a copy? 2
enjay Posted January 22, 2018 Posted January 22, 2018 Hi I have been told that "because of GDPR" our pupils are not allowed to know the staff e-mail accounts. Is this correct? Nonsense of the highest order! This policy would mean staff cannot email students or share resources via Google Classroom. In fact, it would probably make any VLE unusable, as they typically allow you to view the "profile" of someone who posts or uploads something. Also, unless your staff have different email address formats to the students, they can work them out anyway.
spacebar Posted January 22, 2018 Posted January 22, 2018 As most schools will have a naming format for staff emails, ie [email protected], it seems a bit pointless if true as students will just work it out. (Edit: already beaten to that point above!) Sounds like someone is trying to be busy and sound important. 1
gopher_1999 Posted January 26, 2018 Author Posted January 26, 2018 Thanks to all. I suspect it is the result of older staff being paranoid that is pupils find out the staffs' full names then the pupils can cast spells on them or some such
enjay Posted January 26, 2018 Posted January 26, 2018 Thanks to all. I suspect it is the result of older staff being paranoid that is pupils find out the staffs' full names then the pupils can cast spells on them or some such Or sign them up for inappropriate mailing lists, which I've seen done... Seriously though, if students can see/find out staff email addresses, it would probably be sensible to coach them a bit in appropriate contact - will teachers respond to requests for homework help via email? If so, what is the expected response time? What can/can't you email teachers about? (Our HT said she had a lot of emails from students during the snow days asking if school would be open the next day!).
synaesthesia Posted January 26, 2018 Posted January 26, 2018 Difference between personal and school email; typically staff are not expected to answer an email outside certain hours and therefore hold no obligations. I will echo the above, user management should cover it. An email address is there for a reason, to contact someone directly. If someone needs to be private, then perhaps they need to have a generic address like [email protected] for example.
jimmckenna Posted January 26, 2018 Posted January 26, 2018 What about this one? I am being told that Google Mail/Suite is not GDPR compliant as there servers are located in ROI. Whereas, Microsoft. Office 365 are compliant as there servers are in the UK? Confused ??????????
enjay Posted January 26, 2018 Posted January 26, 2018 What about this one? I am being told that Google Mail/Suite is not GDPR compliant as there servers are located in ROI. Whereas, Microsoft. Office 365 are compliant as there servers are in the UK? Confused ?????????? Google's servers are all over the place (https://www.google.com/about/datacenters/inside/locations/index.html), and your data is on any number of them, BUT... there's nothing in GDPR which says data must be held in UK or EU. GDPR regulates what data should be held and how it should be held, it says nothing about where. As long as you are happy with how Google are treating your data, you're fine. 1
jimmckenna Posted January 26, 2018 Posted January 26, 2018 Thanks for that that was my understating to!! My Head, CEO & CF0 of the MAT have been commenting on this most recently at an all staff meeting. So was looking for some clarification. Thanks
mjk Posted January 26, 2018 Posted January 26, 2018 What about this one? I am being told that Google Mail/Suite is not GDPR compliant as there servers are located in ROI. Whereas, Microsoft. Office 365 are compliant as there servers are in the UK? Confused ?????????? Google have an extensive GDPR satement. https://www.google.com/cloud/security/gdpr/ How do people get the ldea that Google are going to not comply and therefore be unable to operate in Europe ? I mean what planet are they living on ?
enjay Posted January 26, 2018 Posted January 26, 2018 How do people get the ldea that Google are going to not comply and therefore be unable to operate in Europe ? I mean what planet are they living on ? Possibly by thinking GDPR is something UK schools have to do, not something any business operating in EU has to do.
strawberry Posted January 26, 2018 Posted January 26, 2018 Possibly by thinking GDPR is something UK schools have to do, not something any business operating in EU has to do. Every teacher is going to think this is all level 10 blockery by their sysadmin anyway. 1
MkII Posted January 26, 2018 Posted January 26, 2018 We've just had safeguarding training by the local authority and the trainer said that images on websites needed to be on UKservers for GDPR compliance. Correct??
enjay Posted January 26, 2018 Posted January 26, 2018 We've just had safeguarding training by the local authority and the trainer said that images on websites needed to be on UKservers for GDPR compliance. Correct?? No. You can store photos on servers in Tibet if you wish, as long as you can justify why it is there and know the person hosting it there isn't letting anyone else access it. 1
Michael Posted January 26, 2018 Posted January 26, 2018 Another doing the rounds is that data cannot be stored on USB flash drives; again complete nonsense.
synaesthesia Posted January 26, 2018 Posted January 26, 2018 By the sounds of it, some of these local authorities are getting their training in from these spamming muppets that all our inboxes are full of constantly claiming to be Gods Gift to GDPR.
enjay Posted January 26, 2018 Posted January 26, 2018 By the sounds of it, some of these local authorities are getting their training in from these spamming muppets that all our inboxes are full of constantly claiming to be Gods Gift to GDPR. Worrying, isn't it, especially if people have paid for this "training". Also, there seems to be a lot of hoohah about photos amidst all the GDPR stuff, when (correct me if I'm wrong) we need to do handle photos any differently to any other data.
Katy Posted January 26, 2018 Posted January 26, 2018 Worrying, isn't it, especially if people have paid for this "training". Also, there seems to be a lot of hoohah about photos amidst all the GDPR stuff, when (correct me if I'm wrong) we need to do handle photos any differently to any other data. Not as far as I'm aware, the one that struck me as the most insane was the "photos on the website" one a few posts back - what's it matter where the server is when anybody in the world can access them? (that being the point of a website) 1
enjay Posted January 26, 2018 Posted January 26, 2018 Not as far as I'm aware, the one that struck me as the most insane was the "photos on the website" one a few posts back - what's it matter where the server is when anybody in the world can access them? (that being the point of a website) Ha, good point. I'd missed the obviousness of that error! 1
johnpd Posted January 26, 2018 Posted January 26, 2018 Playing devils advocate but loading a picture from China website server gives a 200 get request. Ah success I have the picture. But. Do you have a privacy policy that states you won’t divulge their IP address for other purposes? IN WHICH CASE you can’t host the data anywhere as it’s going to get pulled by the Great Wall of China and used to track. Sorry for being a sod about it but I liked your answer and thought about it some more. Patriot act anyone?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now