MkII Posted March 27, 2018 Posted March 27, 2018 I'm looking for clarification/ official wording on remote access. Specifically SIMS Hosted at the moment. Our HT is worried that this is not covered by GDPR at all. My feeling is that it would be perfectly acceptable if the usual safeguards are in place.. protect the screen from being overlooked, lock the screen when away, dual factor authentication to sign in. Many thanks
GrumbleDook Posted March 27, 2018 Posted March 27, 2018 Are you talking about a SIMS system hosted by Capita or the LA and remotely accessed via VDI or similar?
rom1984 Posted March 27, 2018 Posted March 27, 2018 There is nothing specefic in the GDPR that says you shouldn’t use remote/hosted services as long as have the usual protection in place. Not sure exactly how hosted Sims works but some of the things you may need to think about to tick all the boxes is if the transport of data to the server is encrpyed (i.e via https which I’m almost certain it would be) and if any local data syncs to the device (which I don’t think it would). On the plus side, I’m pressuming they are in charge of backing up the data, physically protecting the server, keeping the servers patched so you may decide that hosted Sims is even more secure than hosting it yourself. Because the school is using a third party you’d want to get a controller/processor contract in place, but knowing Capita that might not be as easier as it sounds so it may be the case that you do the next best thing and just keep an eye on their privacy policy to ensure you are happy with it. 1
MkII Posted March 27, 2018 Author Posted March 27, 2018 Great. Many thanks rom. Yes they'd be patching/ updating/ physically protecting/ backing up. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now