Jump to content

Recommended Posts

Posted (edited)

Has anybody looked at the GDPR management platform provided by Wonde? It can be found here https://gdpr.co.uk

 

It looks to have some interesting features but I can’t see if it has the 3rd party information promised elsewhere

Edited by Bigbird7
Posted

Have you contacted them?

 

Wonde seem to have come out of nowhere from my point of view with their data extraction tools. Two of our suppliers have moved across to them from groupcall exporter in the last couple of months. I had to contact wonde to find how I got access to their promised 'list of extracted data' but now I do have access it does exactly what it says on the tin.

 

Wonde seem to have quite a lot of good paperwork behind them to ensure compliance, it's the companies they are sending the data off to which I'm struggling to case for documentation.

Posted

I've had a demo of GDPR.co.uk and GDPR.School, I'm leaning towards GDPR.school as it holds the data in directly readable form whereas GDPR.co.uk provides a lot of templates that you then fill in and re-upload making it harder to use the data

 

I did like the fact that it includes a staff training module which GDPR.School doesn't

  • Thanks 2
Posted

@Jamman960

 

Confused by what you are saying!

 

There is a whole section of GDPR in Schools for individual school staff. It gives every member of staff their own account which records their responses to a number of questions which you will be including as part of your annual audit. It hold full accountability for EVERY member of staff.

 

Here’s just a couple of questions straight from the Staff User section of GDPRiS:

 

1. Do you keep your passwords secure, change them regularly and never share them?

You need to ensure that your password is never shared with anyone else. Ideally you should never write your password down anywhere, but if you do, this should be stored away securely. It is also a good idea to change your password regularly.

YES ☐ NO ☐

 

2. Do you lock / log off computers when away from your desk?

It is important to ensure that your computer is not logged in when you are away from your desk so that others cannot gain access or view your screen. Ensure you always log off or lock your computer when you are away from your desk.

YES ☐ NO ☐

 

Every member of staff, and I mean all, that comes onto the school site and handles personal data can be held to account. Very soon to be released will be a free automated staff import from MIS and you can still add people that come into your school but are not in your MIS.

 

We have taken into account those staff that won’t use an online system and have produced resources to collect their evidence but still keep it in one place.

There is an area where individuals confirm with systems they use which contain personal data and an area to report a breach or message a DPO. There are training videos and many other resources aimed specifically at governors, teachers, kitchen staff, etc

 

GDPRiS has a lot in it.

 

DM me or @GrumbleDook and we’ll show you.

  • Thanks 1
Posted
This is the same Wonde that were all shouting about not a few months back because of their dubious data retention/protection policies?
Them would be the ones ;)
Posted
@Jamman960

 

Confused by what you are saying!

 

There is a whole section of GDPR in Schools for individual school staff. It gives every member of staff their own account which records their responses to a number of questions which you will be including as part of your annual audit. It hold full accountability for EVERY member of staff.

 

Here’s just a couple of questions straight from the Staff User section of GDPRiS:

 

1. Do you keep your passwords secure, change them regularly and never share them?

You need to ensure that your password is never shared with anyone else. Ideally you should never write your password down anywhere, but if you do, this should be stored away securely. It is also a good idea to change your password regularly.

YES ☐ NO ☐

 

2. Do you lock / log off computers when away from your desk?

It is important to ensure that your computer is not logged in when you are away from your desk so that others cannot gain access or view your screen. Ensure you always log off or lock your computer when you are away from your desk.

YES ☐ NO ☐

 

Every member of staff, and I mean all, that comes onto the school site and handles personal data can be held to account. Very soon to be released will be a free automated staff import from MIS and you can still add people that come into your school but are not in your MIS.

 

We have taken into account those staff that won’t use an online system and have produced resources to collect their evidence but still keep it in one place.

There is an area where individuals confirm with systems they use which contain personal data and an area to report a breach or message a DPO. There are training videos and many other resources aimed specifically at governors, teachers, kitchen staff, etc

 

GDPRiS has a lot in it.

 

DM me or @GrumbleDook and we’ll show you.

 

Is all this 'coming soon' cos mine doesn't have a staff user section where I can add questions.

Posted
The advice questions above about changing password on regular basis is old hat, it should be when you suspect or know it’s been compromised. It also says never write passwords down but them if you do... seems a bit mixed message to me.
Posted
The advice questions above about changing password on regular basis is old hat, it should be when you suspect or know it’s been compromised. It also says never write passwords down but them if you do... seems a bit mixed message to me.

 

There are times when a password is changed each time you log in (certain social care or financial solutions) but that is reducing now that multi-factor authentication has grown.

 

In those situations where it has to be written down the keep it secret and secure.

 

Also consider the domain admin account ... we have often discussed on the forums about this, where Heads or line managers have demanded a copy of passwords being available.

 

The general response has been to write them down, stick into an envelope and sign across the seal, then laminate.

 

An example of having to write it down and keeping secure.

Posted
If you can't reset a domain admin account without knowing the password, should you really be employed as the head of IT Support?

 

True, but the point has always been that some schools have wanted to make sure that if something happens to you, then your replacement can get into the system to sort things out.

 

No one wants passwords floating around so a common suggestion in many threads has always been write it down, seal the envelope, sign it and laminate it, then stick it in the safe.

 

So when we say that if you *have* to write a password down then you must keep it secure, then this is the sort of example we would be talking about.

Posted

First thing to do when you start a new job is to hack into the system, as no one can find the password. Second job is to make your replacement's job at hacking into the system harder than it was for you.

 

We should make a GDPR service comparison chart, what should the rows be?

Posted
First thing to do when you start a new job is to hack into the system, as no one can find the password. Second job is to make your replacement's job at hacking into the system harder than it was for you.

 

An interesting take ... I’ve heard this argument before, usually based on the idea that you should do it prior to reading and handover notes / documentation ... the problem is that the school would probably prefer you focus on the priority of ensuring you are supporting the school with a working system rather than trying to break it.

 

Happy to take to another thread to discuss what are the priorities when moving into a new job (I’m sure this was talked about about 6-7 years ago but can’t find a thread on it ... about time to revive perhaps).

Posted
Them would be the ones ;)

Can you point me in the direction of those threads. Wonde has out of the blue hit my inbox as a result of Maths department signing up to a project with EEF who use Wonde. Apparently they are 'a trusted MIS integration specialist now used by many of the leading EdTech applications, requires less than 13 minutes to get your school set-up". Given we are on progresso we shall see.... And I'll decided if they are trusted once I have the input of my fellow edugeekers! Oh, and can anyone tell me how on earth you get staff (aka as teachers) to bl**dy well speak to us before they sign up to the latest whizzy idea! :mad: And breathe.....

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...