Jamman960 Posted January 24, 2018 Posted January 24, 2018 At the moment within Sims more or less all permissions groups have access to the Ethnic/Cultural panel of a students record including "Class Teacher" and "Registration Tutor", I'm thinking of re-creating the templates for general teaching staff so that they can't see this data in order to limit the risk of a data breach containing "special data" and to ensure minimal necessary access. I can't think of a reason for general staff to need access to this, we've not collected this data until the EYFS census changed. is this a concern for anyone else? or am I over thinking it
GrumbleDook Posted January 25, 2018 Posted January 25, 2018 No, you aren’t over thinking ... you are thinking and that is perfect. What is the data collected for? Is it only collected for the return? (That’s before we get into discussion about whether the collection of the data is needed ... but that’s a different argument). If only collected for the return then yes, lock access. If collected for more then control access for who needs it. However, have the class teachers and SLT been including in the conversation about what the data is used for. There may be a need and until you as the question you can’t be sure about what the requirements are so cannot really complete your DPIA on it. Good work on asking the question.
pete Posted January 25, 2018 Posted January 25, 2018 ^ It's not just viewing in SIMS though. You need to check Groupcall Exporter report definitions in SIMS to see what data is being pulled from SIMS into other applications / services and whether the fields are appropriate and necessary. (Reports > Design Report > Existing Report > Categories > Groupcall Xporter) I've spoken to a couple of suppliers who've attempted to blame unnecessary (ethnicity, for example) extra fields on Groupcall. Checking with Groupcall (because the supplier excuse seemed unlikely), any reports they build are to the customer's spec and they've had quite a few customers amend their report definitions for GDPR compliance. 2
Jamman960 Posted January 25, 2018 Author Posted January 25, 2018 (edited) We've previously not collected the Ethnicity info as it was optional on the census but our new registrar began collecting it when the EYFS census changed, I'm sure we can get away with using the not obtained code but I guess if we've been submitting it for the last year or so it'd look odd to suddenly say we haven't got the data, I'd much rather not have the data at all We're at the beginning of our GDPR journey so haven't started DPIA's as yet I'll take a look at the group call report, it'll be interesting to see what everything is importing, we found an issue with MLS exporting too much recently so tightened who had backend access. Group Call Emerge on demand looks to be a far better solution. Edit: thanks for the heads up on Groupcall reports, I assumed they were pulled via the db direct rather than via reports. Interesting to see a couple of ours are pulling ethnicity data but not showing it on their management interfaces... Edited January 25, 2018 by Jamman960
GREED Posted January 26, 2018 Posted January 26, 2018 Morning from the BETT stand! I wanted to just say thank you for the support (For want of a better word!) around this. Every integration with a third party, via Xporter, is bespoke and tailored to the requirements of the partner, whatever they tell us they would like in the data extract is what we will have been commissioned to do. Any queries around the data being extracted and transported will need to be directed to the partner themselves. With the newer Xporter-on-Demand, which is an API that partners call and write against, they have even more say in what they pull, but importantly every school has to authorise every data scope for every partner - meaning schools know what is being asked for, and can say yes or no to each data scope. There is a data dashboard for schools (no cost) to show this visually, which is great for GDPR, show everything going anywhere, and with big buttons at any time to switch bits or all of it off (the data that is). Hope that helps explain our position in this. Any queries just shout or PM.
enjay Posted January 26, 2018 Posted January 26, 2018 You need to check Groupcall Exporter report definitions in SIMS to see what data is being pulled from SIMS into other applications / services and whether the fields are appropriate and necessary. (Reports > Design Report > Existing Report > Categories > Groupcall Xporter) That's empty for me. When I wanted to know this, I manually ran each task in Xporter, noted the name of the SIMS report then checked that. Am I missing something?
enjay Posted January 26, 2018 Posted January 26, 2018 Morning from the BETT stand! I wanted to just say thank you for the support (For want of a better word!) around this. Every integration with a third party, via Xporter, is bespoke and tailored to the requirements of the partner, whatever they tell us they would like in the data extract is what we will have been commissioned to do. Any queries around the data being extracted and transported will need to be directed to the partner themselves. Thanks Graham. As you know from our conversations on this, one thing which can be a bit confusing is when the report extracts a particular field from SIMS which is then stripped out within Xporter then strips out before sending to the third party. It would be useful if the console could show us what is actually being sent to the supplier.
Jamman960 Posted January 26, 2018 Author Posted January 26, 2018 You're welcome, I saw a brief demo of the dashboard yesterday and its fantastic, the ability to see which categories of data are being stored by who and where as well as the ability to control data flow down to the individual pupil level on a per supplier basis is exactly what we need - just need to start pestering our suppliers to take it on now 1
GREED Posted January 26, 2018 Posted January 26, 2018 Thanks Graham. As you know from our conversations on this, one thing which can be a bit confusing is when the report extracts a particular field from SIMS which is then stripped out within Xporter then strips out before sending to the third party. It would be useful if the console could show us what is actually being sent to the supplier. Old Xporter used to do this on very rare occasions, new Xporter On Demand does not do this is only provides exactly the data scopes you authorise and the data the partner requests. TO that end, the console will show for XOD integrations, only what is moving.
GREED Posted January 26, 2018 Posted January 26, 2018 You're welcome, I saw a brief demo of the dashboard yesterday and its fantastic, the ability to see which categories of data are being stored by who and where as well as the ability to control data flow down to the individual pupil level on a per supplier basis is exactly what we need - just need to start pestering our suppliers to take it on now School Portal will be going to pilot in the next week or so, and then past that with fingers crossed, out to the wide world. ANY school with at least one XOD linked product will have access to this for their school. Will be free, to all. Happy GDPR!
enjay Posted January 29, 2018 Posted January 29, 2018 Old Xporter used to do this on very rare occasions, new Xporter On Demand does not do this is only provides exactly the data scopes you authorise and the data the partner requests. TO that end, the console will show for XOD integrations, only what is moving. Is there an upgrade I should be doing somewhere then, to get the new Xporter on Demand?
GREED Posted January 29, 2018 Posted January 29, 2018 No, this is for your third party to do/work with us on. Just like you got xporter from the partner, you would also with XoD if/when they decide to use this newer method.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now