Jump to content

Recommended Posts

Posted

I'm helping to put together some staff training on GDPR and instead of talking to staff for an hour we wanted to give some scenarios of "Is this a data breach?" and "Is this processing data?".

 

To give an example I've got a slide saying - You lose your USB memory stick, It contains your lesson plans for the next term, It and the individual files on the USB are not password protected nor encrypted. I'm trying to trick them here (presuming lesson plans don't contain PII) to saying yes. All a bit of lighthearted fun before I tell them they won't be allowed to use USBs anymore because we've got Google Drive and USBs break and I spend far too much time trying to recover data from them as "it's my only copy" (and staff can't be trusted to not put PII on them and lose them).

 

Anyway I thought you lot could come up with some fun scenarios that we can use in staff training. The silliest, most outlandish wins a prize.

Posted
You check your school emails in your home computer. You have a password to log on to the computer that you and your family share. The headteacher has sent an email to you with an excel attachment. You download the file to your documents. The file contains behaviour information on students, which you update an email back to the headteacher via the school's email system, which uses HTTPS so the data transferred over the internet is encrypted.
  • Thanks 1
Posted
You check your school emails in your home computer. You have a password to log on to the computer that you and your family share. The headteacher has sent an email to you with an excel attachment. You download the file to your documents. The file contains behaviour information on students, which you update an email back to the headteacher via the school's email system, which uses HTTPS so the data transferred over the internet is encrypted.
I'd say that's not a data beach.... Yet. Unless the staff members' laptop is encrypted, the data is at risk. If you can't prove that all copies are deleted when the staff member leaves, you can't apply the rule to only keep the data while it's required.

 

So it's a no for me [emoji3]

Posted
I'd say that's not a data beach.... Yet. Unless the staff members' laptop is encrypted, the data is at risk. If you can't prove that all copies are deleted when the staff member leaves, you can't apply the rule to only keep the data while it's required.

 

So it's a no for me [emoji3]

I'd say "not yet" for that one but basically 100% chance that it will be when they leave.

 

The school's internet connection is down so the data team takes their laptops and goes to McDonalds to use their free public wifi to work on the cloud MIS. Is that a data breach?

 

The Performing Arts teacher records their students dance recital on her iPad and sends it to the website manager to stick on the schools website (with the permission of the students/their parents). The teacher then deletes the video from their iPad, is that a data breach?

  • Thanks 1
Posted
You have a password to log on to the computer that you and your family share.

 

It's probably a not yet for me too, but I would say this ^^ is the part that makes it closest to being a data breach now. I would say you've allowed access to the data to people that aren't required to have access. It's just waiting to be accessed by spouse/children in the my documents and then you've got a breach.

 

Thanks for the ideas so far.

Posted
You check your school emails in your home computer. You have a password to log on to the computer that you and your family share. The headteacher has sent an email to you with an excel attachment. You download the file to your documents. The file contains behaviour information on students, which you update an email back to the headteacher via the school's email system, which uses HTTPS so the data transferred over the internet is encrypted.

 

I disagree with @jmak , this IS a data breach because the document was downloaded onto a shared device. Even if the password is unique to the teacher, the disk isn't encrypted and can therefore be popped in a caddy and accessed - we drill teachers that passwords on home computers don't constitute adequate protection.

  • Thanks 1
Posted
Just had someone ask if I could help them get photos off their phone this afternoon after they take pictures of XYZ. That's going on the list...
Posted

Scenario 1: you share your home computer with your family, and have all your passwords saved so you don't have to type them in.

 

Scenario 2: you have your school email added to your personal phone. Your husband/wife/child knows your PIN code.

 

Scenario 3: you have a child in the school. Your child knows where you keep your planner and any books you're marking at home, and has access to them.

 

All breaches, all overlooked surprisingly often. Scenario 3 quite difficult to avoid, unfortunately.

 

To be honest, scenario 3 is a breach even if your child isn't in the school, but the impact is obviously a lot less.

Posted
Scenario 3: you have a child in the school. Your child knows where you keep your planner and any books you're marking at home, and has access to them.

 

All breaches, all overlooked surprisingly often. Scenario 3 quite difficult to avoid, unfortunately.

 

To be honest, scenario 3 is a breach even if your child isn't in the school, but the impact is obviously a lot less.

 

You'll have the business manager after my head when teachers start asking for the school to supply them with a home safe! :D

Posted
You'll have the business manager after my head when teachers start asking for the school to supply them with a home safe! :D

 

I suspect the BM's response would be "you choose to take the work home, therefore it is your responsibility to buy the safe". If your school expects/requires staff to work from home, you may need to rethink this.

 

Our advice up until now has been to leave the really sensitive stuff in school but taking marking home is fine. Planners may contain a mark that a child is SEN but won't include details.

Posted
I disagree with @jmak , this IS a data breach because the document was downloaded onto a shared device. Even if the password is unique to the teacher, the disk isn't encrypted and can therefore be popped in a caddy and accessed - we drill teachers that passwords on home computers don't constitute adequate protection.

 

Yeah you're right, I missed that it was a shared device!

Posted

How about teacher unmutes, unfreezes or otherwise turns on their IWB/projector with MIS, email, electronic register, etc still open and maximised during a lesson.

 

Or even just, Outlook popup notifications are enabled and Outlook is running during lesson time.

Posted
How about teacher unmutes, unfreezes or otherwise turns on their IWB/projector with MIS, email, electronic register, etc still open and maximised during a lesson.

 

Or even just, Outlook popup notifications are enabled and Outlook is running during lesson time.

 

This is why we have split screen in all classrooms. Also, staff are told to only use students' initials in the subject line of emails.

Posted
I'd say that's not a data beach.... Yet. Unless the staff members' laptop is encrypted, the data is at risk. If you can't prove that all copies are deleted when the staff member leaves, you can't apply the rule to only keep the data while it's required.

 

So it's a no for me [emoji3]

I disagree with @jmak , this IS a data breach because the document was downloaded onto a shared device. Even if the password is unique to the teacher, the disk isn't encrypted and can therefore be popped in a caddy and accessed - we drill teachers that passwords on home computers don't constitute adequate protection.
Just re-read my response and realised that it probably doesn't come across the way I intended it:

 

My "no from me" was supposed to be a "don't do it" instruction to staff in the training session.

 

I got the impression that the OP was looking for suggestions that appeared to be a bad idea, but weren't actually a breach and was trying to say that this wasn't suitable.

 

TLDR: I agree with @enjay

  • Thanks 1
Posted
I got the impression that the OP was looking for suggestions that appeared to be a bad idea, but weren't actually a breach and was trying to say that this wasn't suitable.

 

Looking for anything that makes them think about their current practice and engage with the training. Beit obvious, tricky or funny scenarios.

Posted
I got the impression that the OP was looking for suggestions that appeared to be a bad idea, but weren't actually a breach and was trying to say that this wasn't suitable.

 

Both are important. You don't want staff members reporting breaches all the time when they're not genuine or stopping working practices which are actually okay, but more importantly nor do you want them overlooking things they think are fine but are actually not.

Posted

Hi Guys, I was wondering what responses I would get.

 

The reason I posted my scenario was to get people thinking, and thinking about risk.

 

The angle I was going was that the family member could access the data, and do something with it. So whilst there may not have been a breach in that scenario so far (or maybe it still is - hopefully one of the GDPRiS guys might jump in on that comment with a view), there's a risk that the child could access the data and share it. Some teachers have children who go to the same school - so their son/daugther might see data about another child in the school for instance if it's left lying around.

 

If you look back to last month, the ICO posted https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2018/02/former-council-worker-fined-for-sharing-personal-information/ - an apprentice at a council who took a screenshot and shared it via snapchat. OK, a bit different but if the sibling can access the data from the headteacher, see's it is about someone in their school, would they be tempted to show a friend?

 

I'm assuming the point of the training session is to get people thinking about data security and what could be a risk - and using your home pc probably wouldn't be something most staff would necessarily think about.

Posted
Some teachers have children who go to the same school - so their son/daugther might see data about another child in the school for instance if it's left lying around.

 

I don't think that only applies to staff with children in the school. Even if their children are at another school, they may well know children in the teacher's school so there is still a risk.

 

Plus, a breach is still a breach even if the person who receives the information doesn't want it or know what to do with it. If I send an email to John Smith when I meant to send it to James Smith, that would still be a breach, even if John did nothing with the information I sent him.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...