Jump to content

Recommended Posts

Posted
At the moment within Sims more or less all permissions groups have access to the Ethnic/Cultural panel of a students record including "Class Teacher" and "Registration Tutor", I'm thinking of re-creating the templates for general teaching staff so that they can't see this data in order to limit the risk of a data breach containing "special data" and to ensure minimal necessary access. I can't think of a reason for general staff to need access to this, we've not collected this data until the EYFS census changed. is this a concern for anyone else? or am I over thinking it
Posted

No, you aren’t over thinking ... you are thinking and that is perfect.

 

What is the data collected for? Is it only collected for the return? (That’s before we get into discussion about whether the collection of the data is needed ... but that’s a different argument). If only collected for the return then yes, lock access. If collected for more then control access for who needs it.

 

However, have the class teachers and SLT been including in the conversation about what the data is used for. There may be a need and until you as the question you can’t be sure about what the requirements are so cannot really complete your DPIA on it.

 

Good work on asking the question.

Posted

^ It's not just viewing in SIMS though.

 

You need to check Groupcall Exporter report definitions in SIMS to see what data is being pulled from SIMS into other applications / services and whether the fields are appropriate and necessary.

 

(Reports > Design Report > Existing Report > Categories > Groupcall Xporter)

 

I've spoken to a couple of suppliers who've attempted to blame unnecessary (ethnicity, for example) extra fields on Groupcall.

 

Checking with Groupcall (because the supplier excuse seemed unlikely), any reports they build are to the customer's spec and they've had quite a few customers amend their report definitions for GDPR compliance.

  • Thanks 2
Posted (edited)

We've previously not collected the Ethnicity info as it was optional on the census but our new registrar began collecting it when the EYFS census changed, I'm sure we can get away with using the not obtained code but I guess if we've been submitting it for the last year or so it'd look odd to suddenly say we haven't got the data, I'd much rather not have the data at all

 

We're at the beginning of our GDPR journey so haven't started DPIA's as yet

 

I'll take a look at the group call report, it'll be interesting to see what everything is importing, we found an issue with MLS exporting too much recently so tightened who had backend access. Group Call Emerge on demand looks to be a far better solution.

 

Edit: thanks for the heads up on Groupcall reports, I assumed they were pulled via the db direct rather than via reports. Interesting to see a couple of ours are pulling ethnicity data but not showing it on their management interfaces...

Edited by Jamman960
Posted

Morning from the BETT stand! I wanted to just say thank you for the support (For want of a better word!) around this. Every integration with a third party, via Xporter, is bespoke and tailored to the requirements of the partner, whatever they tell us they would like in the data extract is what we will have been commissioned to do. Any queries around the data being extracted and transported will need to be directed to the partner themselves.

 

With the newer Xporter-on-Demand, which is an API that partners call and write against, they have even more say in what they pull, but importantly every school has to authorise every data scope for every partner - meaning schools know what is being asked for, and can say yes or no to each data scope. There is a data dashboard for schools (no cost) to show this visually, which is great for GDPR, show everything going anywhere, and with big buttons at any time to switch bits or all of it off (the data that is).

 

Hope that helps explain our position in this. Any queries just shout or PM.

Posted

You need to check Groupcall Exporter report definitions in SIMS to see what data is being pulled from SIMS into other applications / services and whether the fields are appropriate and necessary.

 

(Reports > Design Report > Existing Report > Categories > Groupcall Xporter)

 

That's empty for me. When I wanted to know this, I manually ran each task in Xporter, noted the name of the SIMS report then checked that. Am I missing something?

Posted
Morning from the BETT stand! I wanted to just say thank you for the support (For want of a better word!) around this. Every integration with a third party, via Xporter, is bespoke and tailored to the requirements of the partner, whatever they tell us they would like in the data extract is what we will have been commissioned to do. Any queries around the data being extracted and transported will need to be directed to the partner themselves.

 

Thanks Graham. As you know from our conversations on this, one thing which can be a bit confusing is when the report extracts a particular field from SIMS which is then stripped out within Xporter then strips out before sending to the third party. It would be useful if the console could show us what is actually being sent to the supplier.

Posted
You're welcome, I saw a brief demo of the dashboard yesterday and its fantastic, the ability to see which categories of data are being stored by who and where as well as the ability to control data flow down to the individual pupil level on a per supplier basis is exactly what we need - just need to start pestering our suppliers to take it on now :)
  • Thanks 1
Posted
Thanks Graham. As you know from our conversations on this, one thing which can be a bit confusing is when the report extracts a particular field from SIMS which is then stripped out within Xporter then strips out before sending to the third party. It would be useful if the console could show us what is actually being sent to the supplier.

 

Old Xporter used to do this on very rare occasions, new Xporter On Demand does not do this is only provides exactly the data scopes you authorise and the data the partner requests. TO that end, the console will show for XOD integrations, only what is moving.

Posted
You're welcome, I saw a brief demo of the dashboard yesterday and its fantastic, the ability to see which categories of data are being stored by who and where as well as the ability to control data flow down to the individual pupil level on a per supplier basis is exactly what we need - just need to start pestering our suppliers to take it on now :)

 

School Portal will be going to pilot in the next week or so, and then past that with fingers crossed, out to the wide world. ANY school with at least one XOD linked product will have access to this for their school. Will be free, to all. Happy GDPR!

Posted
Old Xporter used to do this on very rare occasions, new Xporter On Demand does not do this is only provides exactly the data scopes you authorise and the data the partner requests. TO that end, the console will show for XOD integrations, only what is moving.

 

Is there an upgrade I should be doing somewhere then, to get the new Xporter on Demand?

Posted
No, this is for your third party to do/work with us on. Just like you got xporter from the partner, you would also with XoD if/when they decide to use this newer method.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...