Jump to content

Recommended Posts

Posted
Let's be honest here, Capita haven't met any deadlines or have almost dropped development of "old" SIMS so are fudging the issue. We were one of the (many, I suspect) schools who didn't really pay a lot of attention to retention guidelines in SIMS, so I made sure we went through and deleted all the records we should no longer hold one-by-one late last year. It took a significant amount of time and I kept being reminded of the promised bulk deletion tool that would be available "soon". Shows how long I've been using SIMS that I didn't believe for a moment it would be here in time.
  • Thanks 1
Posted

Advanced have started running Progresso up for GDPR. Update this Friday gives us:

 

An 'anonymise' button to bin all the identifiers off a staff/student record

Pages to record consent

Pages to record SARS and right to be forgotten requests

More granular control of the API so you can restrict a particular company's access to only those records where the "This student consents to share their data with 3rd parties" is ticked

 

No granular deletion yet, but I think that's a quite nice start.

Posted
I get the impression that people are expecting a rush of requests under the right to be forgotten. I would have thought this request would be under exceptional circumstances and will be few and far between. The legal right to keep data trumps the RTBF rule anyway. Is every Ex pupil or staff member or employee going to request their data be removed.
Posted
The legal right to keep data trumps the RTBF rule anyway.

 

Not sure that is a correct analysis...

 

We've been told that too - if you have legal grounds for processing the data, you can refuse a RTBF request. Otherwise students would ask to be forgotten just after being given a detention!

 

So, RTBF requests will only need enacting if the student is over 25 (and not SEN, not involved in safeguarding concerns, etc.) as per the minimum retention requirements.

Posted
I get the impression that people are expecting a rush of requests under the right to be forgotten ... Is every Ex pupil or staff member or employee going to request their data be removed.

 

RTBF, unlikely (in my view) but I am expecting a few SARs when people realise they can ask for one. Parents wanting to make trouble for the school will submit the SAR on the first day of the summer holidays.

 

In both cases, I suspect the request will come from a recent leaver who had an issue with the school (the RTBF can therefore be declined, of course - see above post)

Posted
We've been told that too - if you have legal grounds for processing the data, you can refuse a RTBF request. Otherwise students would ask to be forgotten just after being given a detention!

So, RTBF requests will only need enacting if the student is over 25 (and not SEN, not involved in safeguarding concerns, etc.) as per the minimum retention requirements.

Ah, there's a key difference in your version - legal grounds for processing.

Posted
That's just crazy talk. Next you'll be expecting them not to show SQL passwords in the process list when you launch Exams Organiser.

 

 

--

 

In case anyone's still not aware, if you're using SIMS SQL auth, the user (and anyone with admin rights to the workstation running the SIMS client), can see SIMS passwords in the clear when things like Options, Exams Organiser and T6 are launched.

 

TLDR: don't use SQL auth. It completely breaks accountability.

 

Ah, I discovered this too and went and told the Capita folk directly a couple of BETTs ago. Demonstrated the issue and everything, using both Impero logs and "wmic process get caption,commandline /value"... don't seem to have done anything about it... :/

  • Thanks 1
Posted
Advanced have started running Progresso up for GDPR. Update this Friday gives us:

 

An 'anonymise' button to bin all the identifiers off a staff/student record

Pages to record consent

Pages to record SARS and right to be forgotten requests

More granular control of the API so you can restrict a particular company's access to only those records where the "This student consents to share their data with 3rd parties" is ticked

 

No granular deletion yet, but I think that's a quite nice start.

 

Curious what SIMS (and other MIS) offer today by way of SAR capability and what it will look like in future. They're not replying to my requests so if anyone wants to send me data-free screen shots I'd be *really* appreciative. Can you view what data items have been sent out of the system and where it went? Or get a bulk report of whose data was sent to a single provider, and which children were left out? (if you start using a new cashless payment system for example).

Posted
I get the impression that people are expecting a rush of requests under the right to be forgotten. I would have thought this request would be under exceptional circumstances and will be few and far between. The legal right to keep data trumps the RTBF rule anyway. Is every Ex pupil or staff member or employee going to request their data be removed.
There will be the tin-foil-hat brigade that will. However you are right the legal requirement to keep the information particularly as a public organisation overrules RTBF. So if people look carefully, once past this legal requirement, retention rules should kick in and the information removed anyway... So really RTBF should have virtually no impact if we are all doing the job right.

 

That said, it is a kick up the back side to actually enforce and enact those retention policies...

Posted
Curious what SIMS (and other MIS) offer today by way of SAR capability and what it will look like in future. They're not replying to my requests so if anyone wants to send me data-free screen shots I'd be *really* appreciative.

 

SIMS has a new data export, where you select the name and it pulls (nearly) everything in SIMS out into a single document. We have run a few of this to see what they're like, and they seem to contain everything except linked documents (they refer to the document, but don't extract it). They're pretty big, as they contain every achievement point, behaviour point and entry in the communication log - the ones we ran were over 200 pages long!

 

Can you view what data items have been sent out of the system and where it went? Or get a bulk report of whose data was sent to a single provider, and which children were left out? (if you start using a new cashless payment system for example).

 

No, but in fairness there's no way the database could know that. I think you can interrogate Groupcall to see what data it is sending where, and for things which run outside of Groupcall by extracting and exporting data themselves (SAM Learning, for example), you can manually run that report so you can see what is being extracted. Of course, anyone could run a report from SIMS, save a spreadsheet and send it somewhere so there is still that "risk".

  • Thanks 2
Posted
SIMS has a new data export, where you select the name and it pulls (nearly) everything in SIMS out into a single document. We have run a few of this to see what they're like, and they seem to contain everything except linked documents (they refer to the document, but don't extract it). They're pretty big, as they contain every achievement point, behaviour point and entry in the communication log - the ones we ran were over 200 pages long!

 

Where is this feature please?

Posted
Where is this feature please?

 

Give yourself (or whoever needs access) the Data Protection Officer role in SIMS, close and relaunch SIMS and then it'll appear under Routines > Data Out > Person Data Output.

 

Be aware that if staff misuse InTouch, the PDO report can contain personal data about other people, because it treats them as party to the communications. I'll quote from our Capita ticket.

 

In regards to the Communication Log for the student, there are a lot of Student General Messages appearing that were sent to different recipients. A Student General Message is a message sent from a student record, so these will typically be used if you want to alert a students parent or carer about something. By default, the recipients of a Student General Message will be the applicable students Linked Adults (parents, registration tutor, class teachers, etc). It is possible to send the message to any other recipient in SIMS but a message does warn the user of doing so. If the Student General Message is going to contain private or sensitive information then it is not something you would want to send to someone who isnt linked to the student in any way.

 

What I believe has happened is that a user was in the students record and clicked Send Message to produce a new Student General Message. Instead of treating this as a message specific to that student, it is likely the user decided to send the message to parents of specific students with the message body containing general information. While this is not specifically an issue, this is something that probably should have been sent as a General Message through Focus | InTouch | Send Message to avoid unlinked adults receiving any type of sensitive information regarding a student.

 

TLDR: If you do a general InTouch message from within a student record, don't add extra recipients or the PDO will contain personal data about other people.

  • Thanks 2
Posted
If you do a general InTouch message from within a student record, don't add extra recipients or the PDO will contain personal data about other people.

 

The output report would need checking and redacting, not just because of messages but also there will likely be other students named in behaviour incidents. This is one of the reasons we don't publish behaviour comments on our parent portal.

Posted
There will be the tin-foil-hat brigade that will. However you are right the legal requirement to keep the information particularly as a public organisation overrules RTBF. So if people look carefully, once past this legal requirement, retention rules should kick in and the information removed anyway... So really RTBF should have virtually no impact if we are all doing the job right.

 

That said, it is a kick up the back side to actually enforce and enact those retention policies...

 

>> tbh doubt you'll get many as ppl 'a rush of requests under the right to be forgotten' because few know that so much data is held and exported -- what they don't know they can't ask. Regardless, right to erasure can't see applying in school at all. Almost all data schools hold is statutory. Retain as long as statutory need. Then delete (including ensuring where there has been onward distribution) or anonymise (by which I mean by UKAN standards, not 'take off the name' or pseudo).

 

What might change in future is the indefinite retenton for re-use current practices -- the forever retention by DfE and onward sharing of data like reasons-for-exclusion (theft, violence) to third parties like press and businesses who don't have a clear 'necessity' for processing (as opposed to they'd *like* the info) given the possible interference with a child's confidentiality. But won't affect school holding it for the necessary purposes. How long they can be reained for today seems to vary though.

 

RTBF -- delisting from search won't matter much in schools.

Posted
>> tbh doubt you'll get many as ppl 'a rush of requests under the right to be forgotten' because few know that so much data is held and exported -- what they don't know they can't ask. Regardless, right to erasure can't see applying in school at all. Almost all data schools hold is statutory. Retain as long as statutory need. Then delete (including ensuring where there has been onward distribution) or anonymise (by which I mean by UKAN standards, not 'take off the name' or pseudo).

 

You are of course assuming schools have deleted students out of MIS after the statutory retention period. At present within SIMS, this is very time-consuming - you can delete a student entirely (but one at a time, no bulk option) in a few seconds, but if you wish to retain any information - even just their name and dates of attendance - you would have to manually go through deleting data entry-by-entry (which would take days!).

 

In reality, I think you'll find schools have all sorts of information in MIS which is beyond statutory retention, and likely beyond justifiable retention too (unless you count historical record as justifiable reason to keep information).

  • Thanks 1
  • 10 months later...
Posted
From the Summer 2018 release (assuming they don't delay the feature), you'll be able to delete parts of the student records (ethnicity, attendance, etc) in bulk if they're no longer necessary. You will also be able to delete whole student records in bulk.

Resurrecting this, has the bulk delete feature been added yet? If so, how is it used? Thanks.

Posted

There is a bulk deletion feature now available - it appeared in the Summer release and has some additional functionality in the Autumn release. I can't find any specific manuals for it in the SIMS Documentation though, although it is documented in the context sensitive help.

 

Its accessed from Routines>Student>Bulk Delete Student Data

 

Apparently they are working on a similar set of routines for bulk staff deletion as well.

  • Thanks 1
Posted
Has anyone been brave enough to try it yet?

 

Yup, we use it in line with our retention policies to have a clearout.

 

It's not feature-complete and some things you'd expect to be cleared out (student photos, for example), aren't.

 

As Capita add new things it can handle/delete you have to go back in to look at 25yrs+ people who now have data showing (in Bulk Delete Student Data) that wasn't visible previously.

 

I think staff/contact deletion has been pushed back to the Spring release (last time I checked).

Posted
Has anyone been brave enough to try it yet?

 

Yes, I used it to remove all our non-SEN 25yr old+ pupils during the Autumn term, as a sort of a test and as a way of making a start.

It doesn't remove everything, and I will need to track back through, but it does work and at least makes it possible to start on getting compliant.

Previously it was just such a huge job it was beyond what most schools had the time to do.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...