InspireICT Posted February 6, 2018 Posted February 6, 2018 I've just set up the Groupcall Xporter at one of our schools for MLS Connect and noticed that as part of the export process, Groupcall creates two files (MIStoMLS.xml and students.csv) which it stores in the "C:\Program Files (x86)\Groupcall\Xporter\MLS" folder. These files contain the complete data for all pupils in the school and their guardians in plain text format. I've contacted Groupcall and they said this is how it is designed to work and that they are looking at making the exported data encrypted to comply with GDPR. Just thought that you all should know that this is the case and to try to gauge opinion. I'm not particularly comfortable having this scheduled task running if it's going to save all of the pupil data on the c: drive of the server. 1
RLR Posted February 6, 2018 Posted February 6, 2018 This is something I came across recently too. One thing I don't I understand is why the MLS job runs 4/5 reports that takes a shed load of pointless data. The reports take all this information. It doesn't need it and it doesn't need to be uploaded but seems a bit much. Information on Students: Preferred Surname Preferred Forename Legal Forename Legal Surname Gender DOB DOA (date of admission?) Year Registration group School Email Address Ethnicity Photos Phone number Information on Guardians: Title Forname Surname Address Home Phone Number Work Phone Number Mobile Phone Number Email Address Information on Staff: Title Preferred Surname Preferred Forename Legal Forename Legal Surname Gender DOB DOA School email address Ethnicity Phone Number
InspireICT Posted February 6, 2018 Author Posted February 6, 2018 When I asked them about this they said that they assume that the server it's installed on is fairly secure and that access to that folder is restricted. This is quite an assumption and there's no need for this to be installed on the server - it could be on a workstation in which case, how secure would it be then. I'm not aware of any specific warning messages or documentation where it informs users of this which is even more worrying. I'm tempted to disable these tasks. I've just discovered that the MyConcern Groupcall does the same thing but only pulls changed data. @RLR - do you know if the MLS export only pulls changed data or does it pull the whole data set every time? - - - Updated - - - It does seem to be a lot of information for no real reason.
Seb1780 Posted February 6, 2018 Posted February 6, 2018 I raised this with Groupcall at BETT and was told that a new development was in testing whereby we would see all of what was being exported on a case by case basis. This work was being done in conjunction with the third-party users of Groupcall Exporter and would enable us, as data controllers, to better understand where our data is going. This was to be free of cost to schools, I assume the third-party users will cover any costs. I'm wholly with you on the question of why some of the data is being exported, why does the libray system need to record ethnicity?
RLR Posted February 6, 2018 Posted February 6, 2018 When I asked them about this they said that they assume that the server it's installed on is fairly secure and that access to that folder is restricted. This is quite an assumption and there's no need for this to be installed on the server - it could be on a workstation in which case, how secure would it be then. I'm not aware of any specific warning messages or documentation where it informs users of this which is even more worrying. I'm tempted to disable these tasks. I've just discovered that the MyConcern Groupcall does the same thing but only pulls changed data. @RLR - do you know if the MLS export only pulls changed data or does it pull the whole data set every time? - - - Updated - - - It does seem to be a lot of information for no real reason. I don't know for certain but I would guess all data as the reports are ran every time the MLS job is ran. Greed might have some more information but not sure how to tag them?
InspireICT Posted February 6, 2018 Author Posted February 6, 2018 (edited) What I'm really struggling with is that this seems like a really easy problem to fix. The current process is; 1: Pull data from MIS 2: Create local file with data from MIS 3: Push data to MLS (or other) All they would need to do is to add a 4th step; 4: Delete local file with data from MIS This seems like a no brainer, at least until they work out how to encrypt the data. We had a case recently where a school secretary installed an exporter (not for MLS) on her office computer which would be storing exactly the same data on the C: drive of an unrestricted computer. i.e. any other member of staff could have browsed to "C:\Program Files (x86)\Groupcall\Xporter\(online software manufacturer)" and gained a copy of all pupil data without entering so much as a password. Edited February 6, 2018 by InspireICT
hiphopamus Posted February 6, 2018 Posted February 6, 2018 We have noticed a lot of 3rd party software in our schools are extracting more information than required, schools will have to query this with the companies involved to establish what is being extracted and for what reason. This is also an issue with the permissions granted to 3rd party user accounts created in SIMS, I have raised the issue with schools numerous times where they are asked to give personnel officer access to software that doesn't need contract information. With GDPR looming schools really need to get an understanding about who has what access to their data through user accounts and extracted data.
Oaktech Posted February 6, 2018 Posted February 6, 2018 Jeez - how much work would it really be to script an encrypted zip of the information that gets sent with a hashed password? Certainly going to raise this with our Trust IT as they are doing our GDPR compliance.
Banjo Posted February 6, 2018 Posted February 6, 2018 We had a case recently where a school secretary installed an exporter (not for MLS) on her office computer which would be storing exactly the same data on the C: drive of an unrestricted computer. i.e. any other member of staff could have browsed to "C:\Program Files (x86)\Groupcall\Xporter\(online software manufacturer)" and gained a copy of all pupil data without entering so much as a password. Or the PC gets stolen or recycled as a classroom/library PC without realising it holds the entire pupil database tucked away in a folder on the C drive.
pete Posted February 6, 2018 Posted February 6, 2018 Groupcall exports the information that the customer (Microlibrarian Systems in this case) asks them to export. MLS need to ask Groupcall to amend the config. As far as I'm aware (I contacted them because I couldn't find anything on their Support site or KB), MLS have yet to publish anything about what they're doing for GDPR (their response was "sign up for the whiny hellhole* that is edoocoo.com and join our circle") and haven't updated the Groupcall report definitions that pull information they don't need. *not their exact words, but it is a whiny hellhole.
GREED Posted February 6, 2018 Posted February 6, 2018 To all Allow me to explain on behalf of Groupcall some things: Yes, some of our older extracts from Xporter, with some of our long standing partners, particularly those that have not changed their extracts for a long time, do in certain scenarios result in plain text files being placed onto the local server storage. Back in the day, it was assumed that the servers that these extracts occurred on were given appropriate physical and network security and safeguards. Clearly, things have moved on since those days but the extracts for these older ones have not. In addition, many extracts do self-clean to remove these files securely and permanently – again some older ones do not. So what are we doing about this: We are currently piloting an updated Xporter client where all output files are encrypted on disk (transfers externally are already always performed over https). This is with a number of local authorities currently and will be soon rolled out across the country and Xporter estate. As part of this compliance programme, we are auditing and updating existing bespoke extracts for all partners to identify where self-cleaning and removal of local working files is not taking place automatically (typically the longer standing partners mentioned that have not had recent updates). This is a piece of work that is already in progress. We are also encouraging our partners where sensible (though not with this as a reason) to move to using Xporter-on-Demand which is a secure API layer the partner interacts with, removing the need for locally created and forwarded files. This, as some have mentioned, then allows you much greater tools to authorise specific data areas for a partner, determine the mode by which you want to share data (send all by default or send only specific people by default), as well as using the new School Portal to discover who has your data, where, and tools to control this. As a reminder as this is also inferred, Xporter only extracts the data that was asked for by each partner individually, if there are concerns over the fields being used by a partner, this is one to speak to the third party about. Hope this helps, happy to answer any other questions on or around this, with these ongoing plans in mind.
RLR Posted February 6, 2018 Posted February 6, 2018 To all Allow me to explain on behalf of Groupcall some things: Yes, some of our older extracts from Xporter, with some of our long standing partners, particularly those that have not changed their extracts for a long time, do in certain scenarios result in plain text files being placed onto the local server storage. Back in the day, it was assumed that the servers that these extracts occurred on were given appropriate physical and network security and safeguards. Clearly, things have moved on since those days but the extracts for these older ones have not. In addition, many extracts do self-clean to remove these files securely and permanently – again some older ones do not. So what are we doing about this: We are currently piloting an updated Xporter client where all output files are encrypted on disk (transfers externally are already always performed over https). This is with a number of local authorities currently and will be soon rolled out across the country and Xporter estate. As part of this compliance programme, we are auditing and updating existing bespoke extracts for all partners to identify where self-cleaning and removal of local working files is not taking place automatically (typically the longer standing partners mentioned that have not had recent updates). This is a piece of work that is already in progress. We are also encouraging our partners where sensible (though not with this as a reason) to move to using Xporter-on-Demand which is a secure API layer the partner interacts with, removing the need for locally created and forwarded files. This, as some have mentioned, then allows you much greater tools to authorise specific data areas for a partner, determine the mode by which you want to share data (send all by default or send only specific people by default), as well as using the new School Portal to discover who has your data, where, and tools to control this. As a reminder as this is also inferred, Xporter only extracts the data that was asked for by each partner individually, if there are concerns over the fields being used by a partner, this is one to speak to the third party about. Hope this helps, happy to answer any other questions on or around this, with these ongoing plans in mind. Do you know when this new tool will be ready?
GREED Posted February 6, 2018 Posted February 6, 2018 Do you know when this new tool will be ready? School Portal? We are piloting now, we expect it to be generally available in March, watch out for marketing bumf on it
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now