Jump to content

Recommended Posts

Posted

I notice we can't even rely on them to spell correctly LOL

 

[h=2] "SECRUITY: How does the system ensure the security of the personal data held? What recognised standards are in place?"[/h]

Posted
I notice we can't even rely on them to spell correctly LOL

 

[h=2] "SECRUITY: How does the system ensure the security of the personal data held? What recognised standards are in place?"[/h]

 

Y'see I deliberately ignored that to see how long it'd take for them to realise.

Posted
I notice we can't even rely on them to spell correctly LOL

 

[h=2] "SECRUITY: How does the system ensure the security of the personal data held? What recognised standards are in place?"[/h]

 

Never encouraging, but I do like the irony of them mis-spelling that particular word!

Posted
people store servers in locked rooms with antivirus and malware protection. Fails to address lack of audit trail.

 

That's quite a big assumption to make... When I took over my school, neither server (curriculum or admin) was in a locked room. In fact, the room was a server room, photocopy room and staff locker room!

 

Yes, the onus is on the school to ensure their data is safe and secure, but it seems like a cop out from Capita to say, it's secure because that what we think our users do!

Posted
First line:

The DfE have suggested six questions schools should ask of their MIS Suppliers, this is Capita SIMS responce

KPMG are auditing their spelling and grammar.

  • Thanks 2
Posted
Requires a MyAccount login.

 

https://myaccount.capita-cs.co.uk/Notifications/GDPR-Questions-Answered-from-the-DfE-of-MIS-Suppliers/

 

Short-sh version:

  • Granular deletion of pupil data = Summer 2018
  • Granular deletion of staff data = Autumn 2018

  • Maintains SIMS is secure because they have permission groups and people store servers in locked rooms with antivirus and malware protection. Fails to address lack of audit trail.

 

Shoddy date delivery given they will make your controler function unable to comply with legal obligations from May, and the GDPR has been in place for two years.

 

Since Capita SIMS so far refuses to engage with us - despite various email and phone attempts in last 12 months, not a good look tbh - perhaps those who have them as suppliers can ask them how they plan to enable you as controllers to fulfil GDPR SAR obligations, right to rectification, and retention managment without audit functions? And make clear on asking, that you will publish the reply.

 

If they refuse to reply, let us know.

 

Individuals have the right to access their personal data and supplementary information. The right of access allows individuals to be aware of and verify the lawfulness of the processing. Schools may be controllers but Capita has new obligations as a processor too.

 

Under the GDPR, individuals will have the right to obtain:

  • confirmation that their data is being processed;

  • access to their personal data; and
  • other supplementary information – this largely corresponds to the information that should be provided in a privacy notice (see Article 15 - ref p43 http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679&from=EN). including the recipients or categories of recipient to whom the personal data have been or will be disclosed, rights to correction, and to obtain the source of where data came from that was not provided by the data subject (ie. ascribed by school or other third parties in SIMS)

  • The GDPR also includes a best practice recommendation that, where possible, organisations should be able to provide remote access to a secure self-service system which would provide the individual with direct access to his or her information (Recital 63).

We’d also like to discuss their data plans for health data in SIMs via the parent lite app.

Posted
That's quite a big assumption to make... When I took over my school, neither server (curriculum or admin) was in a locked room. In fact, the room was a server room, photocopy room and staff locker room!

 

Yes, the onus is on the school to ensure their data is safe and secure, but it seems like a cop out from Capita to say, it's secure because that what we think our users do!

 

It is a cop-out, hence "maintains" in my summary, but if a school is storing data about people unencrypted on a device that anyone can touch, they're breaking the law.

 

We can't keep kicking Capita about their lax attitude and not also kick bob@randomschool if they don't do something about the SIMS server in the copier room.

 

Shoddy date delivery given they will make your controler function unable to comply with legal obligations from May, and the GDPR has been in place for two years.

 

We know, my original post wasn't celebratory. It was more "Oh FFS".

Posted

 

they will make your controller function unable to comply with legal obligations from May

 

Until they update the tooling the data can still be removed 'by hand' row by row.

 

If the issues are flagged in your initial audit and you have policy and a plan in place to bring into alignment, I understand that the view is nobody is going to throw a school under the GDPR bus in 2018.

  • Thanks 1
Posted

 

Granular deletion of pupil data = Summer 2018

Granular deletion of staff data = Autumn 2018

Maintains SIMS is secure because they have permission groups and people store servers in locked rooms with antivirus and malware protection. Fails to address lack of audit trail.

 

Shoddy date delivery given they will make your controler function unable to comply with legal obligations from May, and the GDPR has been in place for two years.

 

I'm not sure that's entirely true, is it, that we won't be compliant in May without this? The right to erasure is "trumped" if we can justify continuing to process the data. For example, a student can't ask to be forgotten while they're still in the school because we still need to process their data as part of our legal obligation to provide an education. Similarly, we can't delete a Year 11 leaver in May/June because we need them in SIMS until August for results day, and probably longer for other retention period obligations (SEN until they're 25 or whatever it is) (staff we'd need to keep for at least 7 years for financial auditing), so by the time we're actually in a position to grant someone's right to erasure, we'll have a SIMS database which supports this.

Posted
I'm not sure that's entirely true, is it, that we won't be compliant in May without this? The right to erasure is "trumped" if we can justify continuing to process the data. For example, a student can't ask to be forgotten while they're still in the school because we still need to process their data as part of our legal obligation to provide an education. Similarly, we can't delete a Year 11 leaver in May/June because we need them in SIMS until August for results day, and probably longer for other retention period obligations (SEN until they're 25 or whatever it is) (staff we'd need to keep for at least 7 years for financial auditing), so by the time we're actually in a position to grant someone's right to erasure, we'll have a SIMS database which supports this.

 

You're probably correct in the examples given but what about the staff and student records your still holding in SIMS that are already outside of these timeframes already?

 

Many schools have had SIMS so long they have 15/20 years of records that it would be very hard to justify still holding.

 

Capita need to provide better tools, at a quicker pace, than they are.

Posted
Many schools have had SIMS so long they have 15/20 years of records that it would be very hard to justify still holding.

 

If SIMS doesn't permit their deletion, that sounds like a reasonable justification for why we've still got them...

Posted
If SIMS doesn't permit their deletion, that sounds like a reasonable justification for why we've still got them...

 

Maybe as a stop gap until we get the tools, but could you imagine the same scenario for papr records? "sorry, we kept them as we don't have a shredder".I know that's taking it to the extreme.

 

Audit and delete facilities in SIMS have been requested for so long that its hard to believe that Capita still havent done anything significant about it. The SAR requests side is starting to look better but still not complete. like a lot of things from them is the slow rate of change and poor communication that's hard to take.

Posted
If SIMS doesn't permit their deletion, that sounds like a reasonable justification for why we've still got them...

 

no. You shouldn't use technology that isn't compliant by design and default (article 25) "by default, only personal data which are necessary for each specific purpose of the processing are processed."

 

but it sounds as though you ahve a way to delete, just it is slow, not bulk. You need to look at retention periods and if you meet them, then no you don't need it yet anyway. And if you can do ad hoc as needed, then presumably it works for now.

 

For example - if someone asks you to delete ethnicity or nationality it should be replaced and overwritten with refused. So the field still has data, but historical content removed.

Posted
I'm not sure that's entirely true, is it, that we won't be compliant in May without this? The right to erasure is "trumped" if we can justify continuing to process the data. For example, a student can't ask to be forgotten while they're still in the school because we still need to process their data as part of our legal obligation to provide an education. Similarly, we can't delete a Year 11 leaver in May/June because we need them in SIMS until August for results day, and probably longer for other retention period obligations (SEN until they're 25 or whatever it is) (staff we'd need to keep for at least 7 years for financial auditing), so by the time we're actually in a position to grant someone's right to erasure, we'll have a SIMS database which supports this.

 

What I'd (possibly mis)understood from "Granular deletion of pupil data = Summer 2018" (let me know if so) is that there was no way at all to delete data for individuals. But if it's only that there's no 'bulk' way, then you're fine to carry on as you do so far. Of course you are. No one is suggesting you need "delete a Year 11 leaver in May/June" - carry on with today's lawful retention periods.

 

The thinking shouldn't be what do we need to delete - it's what do we need to hold? The principle is data minimisation. It's just like today - if you need the personal data and the reason for holding, has a fair and lawful basis, and respects the essence of the fundamental rights and freedoms, is necessary and proportionate you hold it securely etc etc - then you're right, why would you want to delete it? There is no absolute right to erasure broadly speaking. It's based on an evaluation of all the above, but this is not legal advice, and each will vary and be different in diff schools.

 

If a school holds onto data you don't need and has no basis for holding now, then that shouldn't be held under the DPA 1998 either, not new to GDPR or the DPA 2018 as will be. So that needs work now, not connecetd to GDPR delivery dates.

 

Presumably you/schools have some consistent reference point for retention periods now (is it online and might you share it if so? Could be useful for others too), or is it only scattered in various legislation and guidlines? If so, we should see if we could get that sorted out. Presumably you have deleted data in the past that you no longer need and have no gounds for processing. Carry on as is until you have a better tool. But the tool cannot justify unlawful processing just because it's not well designed.

Posted (edited)
What I'd (possibly mis)understood from "Granular deletion of pupil data = Summer 2018" (let me know if so) is that there was no way at all to delete data for individuals. But if it's only that there's no 'bulk' way, then you're fine to carry on as you do so far. Of course you are. No one is suggesting you need "delete a Year 11 leaver in May/June" - carry on with today's lawful retention periods.

 

Currently in SIMS you can:

 

  1. Delete everything about a person (whole record)
  2. Delete nothing about a person

 

...and you have to do that one at a time.

 

You can't (for example) say "OK, for this year's leavers delete the data fields X,Y and Z but leave everything else".

 

From the Summer 2018 release (assuming they don't delay the feature), you'll be able to delete parts of the student records (ethnicity, attendance, etc) in bulk if they're no longer necessary. You will also be able to delete whole student records in bulk.

 

Presumably you/schools have some consistent reference point for retention periods now (is it online and might you share it if so? Could be useful for others too), or is it only scattered in various legislation and guidlines?

 

The IRMS Toolkit is a good start (with reference to legislation), but it doesn't cover everything. IRMS Schools Toolkit - Information and Records Management Society (PDF at bottom of page)

Edited by pete
typo
Posted
Currently in SIMS you can:

 

  1. Delete everything about a person (whole record)
  2. Delete nothing about a person

 

...and you have to do that one at a time.

 

You can't (for example) say "OK, for this year's leavers delete the data fields X,Y and Z but leave everything else".

 

Thanks. So if you change ethnicity field to refused today, for child that's been in sims for 2 years, does it not permit you to keep history today?

Posted
Thanks. So if you change ethnicity field to refused today, for child that's been in sims for 2 years, does it not permit you to keep history today?

 

There are exceptions, but most fields changed in that way, would delete the history (except from backup, of course - different topic for a different day!). Finding everywhere outside SIMS which also references their ethnicity would be a challenge though, plus the data would have been included in previous censuses (censi?) so the DfE would need informing too.

Posted (edited)
Perhaps they need to think about making case sensitive passwords also for SIMS.

 

That's just crazy talk. Next you'll be expecting them not to show SQL passwords in the process list when you launch Exams Organiser.

 

 

--

 

In case anyone's still not aware, if you're using SIMS SQL auth, the user (and anyone with admin rights to the workstation running the SIMS client), can see SIMS passwords in the clear when things like Options, Exams Organiser and T6 are launched.

 

TLDR: don't use SQL auth. It completely breaks accountability.

Edited by pete
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...