Jump to content

Recommended Posts

Posted

Hi all,

 

We're in the same position as many of you I suspect, awaiting firm guidance in school while trying to be prepared for GDPR! We have no DPO yet, but have had a few meetings internally, and will probably sign up to the LA or an external SLA once the Principal has been to some courses by her Union and Head's briefings.

 

Our Data Manager is mapping data flow, and we've identified our external connectors and suppliers etc., and filled in the supplier form on here.

 

Admin staff are on with paper records, personnel files and application forms etc, and as IT we already, or are going to, do the following:

 

1. All staff laptops in SCCM, need domain Username/Password. Can't save to local machine, use Direct Access for SIMS and Network saves, and OneDrive remotely. Only other remote access is via Foldr and Firefly, needing authentication.

2. USB's advised against, but bitlockered anyway.

3. Any staff device connected to O365 has password/pin enforced along with remote wipe, and all staff ipads are in InTune MDM.

4. We're going to delete all user mailbox and network data for all students and staff who have been gone a year (network storage, not records/personnel etc.). We can't find any guidance on saving it longer, or deleting it earlier?????

5. All backups stay on our sites, nothing taken home (we have several buildings separated by roads, yards etc. so have backup in each).

6. Principal will instruct all staff (and give them time) to do their own email/storage housekeeping this term, with reference to student data extracts and historical storage. Awaiting firmer guidance on this once DPO appointed in whatever form!

 

I'm hoping we're on the right track, but welcome all advice and criticism! It's hard to know how far to go before we get a DPO or guidance from above!

 

Thanks, enjoy BETT if you're going (First I've missed in 15 years....)

  • Thanks 3
Posted
How did they take this when you told them?

 

We enforced it when we introduced O365, and as we provide them with an iPad anyway they don't need it on personal devices unless they're very keen!

Posted
3. Any staff device connected to O365 has password/pin enforced along with remote wipe, and all staff ipads are in InTune MDM.

 

This is something I want to do with our Google Apps too (currently it is staff policy but not technically enforced), although I'm yet to see a staff or student phone which doesn't have a PIN code on anyway.

 

Why just staff, though? Students possibly have some sensitive information in their accounts too, I don't think any more than access to a list of other students' names, but still...

 

4. We're going to delete all user mailbox and network data for all students and staff who have been gone a year (network storage, not records/personnel etc.). We can't find any guidance on saving it longer, or deleting it earlier?????

 

I think the guidance is "keep it as long as you can justify". We delete students Years 7-10 in the summer break after they leave, Year 11 the following February once exam appeal deadlines have passed, and staff in the summer holiday one full academic year after they leave (so in summer 2018, I'll delete all staff who left anywhere between September 2016 and August 2017). Network and Google accounts are disabled automatically by Salamander as soon as the person leaves, Mathswatch etc. accounts done manually, typically in the next holiday after they leave.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...