Jump to content

Recommended Posts

Posted

I'm looking for clarification/ official wording on remote access.

 

Specifically SIMS Hosted at the moment. Our HT is worried that this is not covered by GDPR at all. My feeling is that it would be perfectly acceptable if the usual safeguards are in place.. protect the screen from being overlooked, lock the screen when away, dual factor authentication to sign in.

 

Many thanks

Posted

There is nothing specefic in the GDPR that says you shouldn’t use remote/hosted services as long as have the usual protection in place. Not sure exactly how hosted Sims works but some of the things you may need to think about to tick all the boxes is if the transport of data to the server is encrpyed (i.e via https which I’m almost certain it would be) and if any local data syncs to the device (which I don’t think it would).

 

On the plus side, I’m pressuming they are in charge of backing up the data, physically protecting the server, keeping the servers patched so you may decide that hosted Sims is even more secure than hosting it yourself.

 

Because the school is using a third party you’d want to get a controller/processor contract in place, but knowing Capita that might not be as easier as it sounds so it may be the case that you do the next best thing and just keep an eye on their privacy policy to ensure you are happy with it.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...