Jump to content

Recommended Posts

Posted

Hi,

 

Staff use laptops which not on the domain (some windows 10 machines are azure, but windows 7 are non domain) and these are taken home -

 

Does anyone know what the GDPR says about lock screens eg:- if Mrs Smith takes laptop home and accesses sims via remoteapp and then gets up to make a cuppa, Mr Smith comes along and has a nosey through sims.

 

Our staff would be lost without access from home, but im also very aware of the potential risk to data breaches ??

 

Cheers,

 

Matt.

Posted
It won't say anything specific about lock screens but if a breach occurs because the laptop was left unlocked without proper safeguards being put in place then the school will be found at fault. Now, there may be some debate about if telling staff that they must lock their devices when leaving them is enough, but I would say that as implementing a screensaver is relatively trivial then it should be implemented.
Posted
there may be some debate about if telling staff that they must lock their devices when leaving them is enough

 

I don't know if telling them is enough either, but surely if there's a policy which sets out that this is something they SHOULD do, are they then in breach of it by not doing so? And therefore the school not at fault?

Posted
I don't know if telling them is enough either, but surely if there's a policy which sets out that this is something they SHOULD do, are they then in breach of it by not doing so? And therefore the school not at fault?

 

This is where the debate would come from. Yes I should have said, with policy backing it up, but would that be considered as the company doing all it can to keep data safe? If enabling a screensaver had a large cost or lots of technical work associated with it then I think it could be had as a good compromise. As neither of those are involved then personally I think it should be done.

 

I suppose the other way to look at it is what is the worse that could happen. Teacher takes laptop to Costa (other coffee houses are available) to get some work done. Gets a table and sets up, goes off to order here macha-wacka-cuppachino. Opportunistic thief grabs the laptop and runs. Depending on what other safeguards you have, he now has access to your system as a member of teaching staff for as long as the battery lasts, or until you can do something about it. All accessible shares, all parent data, all pupil data. Now, if you heard of this tale about a company or another school, what would your first response be?

Posted

If you've got a reasonable lock period in place, it’s in a policy that you should lock the screen when leaving it and the person is given regular data protection training (i.e yearly like with child protection review training) then there is nothing more the school can really do. The school have put reasonable measures in place measure to mitigate the risks as per their requirements under the GDPR.

 

The person that is snooping could be committing a DP section 55 criminal offence and it is this that has undermined the measures that the school put in place.

Posted

That's the nightmare scenario for all of us surely?

 

Encrypting the drive, having 2FA and any other technical fix will all be void if the device is left unlocked in a public environment.

Posted
This is where the debate would come from. Yes I should have said, with policy backing it up, but would that be considered as the company doing all it can to keep data safe? If enabling a screensaver had a large cost or lots of technical work associated with it then I think it could be had as a good compromise. As neither of those are involved then personally I think it should be done.

 

I suppose the other way to look at it is what is the worse that could happen. Teacher takes laptop to Costa (other coffee houses are available) to get some work done. Gets a table and sets up, goes off to order here macha-wacka-cuppachino. Opportunistic thief grabs the laptop and runs. Depending on what other safeguards you have, he now has access to your system as a member of teaching staff for as long as the battery lasts, or until you can do something about it. All accessible shares, all parent data, all pupil data. Now, if you heard of this tale about a company or another school, what would your first response be?

 

I agree that if you can implement safeguards to mittigate the impact of a breach of policy then that should be done.

 

Though in the scenario OP suggested, I'm assuimg the screensaver delay would be longer than

?!
Posted
I've just come back from walking round the school putting one of these on every monitor!

[ATTACH=CONFIG]48895[/ATTACH]

 

Did you make those yourself or buy them? If bought, from where?

Posted
I've just come back from walking round the school putting one of these on every monitor!

[ATTACH=CONFIG]48895[/ATTACH]

 

We've done very similar - a graphic on every users desktop...

WindowsLDesktop.png

and stickers of shame if we find their machine unlocked...

WindowsLSticker.jpg

 

But going back to the original question, as others have said GDPR doesn't state any specific measures just reasonable technical measures. What is reasonable is for you to decide and document (and possible argue in court).

  • Thanks 3

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...