Popular Post rom1984 Posted December 5, 2018 Popular Post Posted December 5, 2018 For people that require some extra ammunition; https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2018/12/former-headteacher-prosecuted-for-unlawfully-obtaining-school-children-s-personal-information/ The Deputy Head had personal data of children on a USB drive. He then started at a new school and uploaded the data to their servers. The ICO fined him £700 under Section 55 of the DPA 98. 42
pete Posted December 5, 2018 Posted December 5, 2018 Yup, always nice to have some ammunition to shoot down the "but they won't prosecute schools" naivety. Have also just stuck it on the day board. 2
Sephiroth Posted December 5, 2018 Posted December 5, 2018 Just in time for our trainee teachers to read before they decide to take the entire contents of the shared drives to their next placement... 3
hardtailstar Posted December 5, 2018 Posted December 5, 2018 (edited) Nice, but this bodes the question, How can we stop teachers taking data with them to the new school? You can block USBs etc but Teachers will still find a way to copy all of the personal data and work they created to use in the next place. Edited December 5, 2018 by hardtailstar 2
elsiegee40 Posted December 5, 2018 Posted December 5, 2018 (edited) It raises all sorts of questions. The ICO appears to have punished neither the schools this teacher had left, nor the one he moved to. This, to me, suggests that somehow they had evidenced that they had attempted to stop this... perhaps with some kind of signed declaration. I feel that the school's practices surrounding leavers is isomething that should be as important as the induction/Safeguarding procedures for those joining. Edited December 5, 2018 by elsiegee40 2
mthomas08 Posted December 5, 2018 Posted December 5, 2018 Have used for good ammo. This isn't about stopping them from keeping learning materials, this is about personal data which they shouldn't have. How many of them have simply innocently copied GBs of data and kept it without even questioning what it is? This is why an audit is very important. 1
caffrey Posted December 5, 2018 Posted December 5, 2018 Not just USB, I suppose "insert cloud storage of choice here" is a problem too 1
hardtailstar Posted December 5, 2018 Posted December 5, 2018 (edited) Have used for good ammo. This isn't about stopping them from keeping learning materials, this is about personal data which they shouldn't have. How many of them have simply innocently copied GBs of data and kept it without even questioning what it is? This is why an audit is very important. Have edited my post for clarity. Edited December 5, 2018 by hardtailstar
Popular Post GrumbleDook Posted December 5, 2018 Popular Post Posted December 5, 2018 It raises all sorts of questions. The ICO appears to have punished neither the schools this teacher had left, nor the one he moved to. This, to me, suggests that somehow they had evidenced that they had attempted to stop this... perhaps with some kind of signed declaration. I feel that the school's practices surrounding leavers is isomething that should be as important as the induction/Safeguarding procedures for those joining. I'm investigating this at the moment ... the press release was purely about the prosecution alone, and not about the schools or any other action that may be in the process of being taken against the individual involved. 7
Sephiroth Posted December 5, 2018 Posted December 5, 2018 I don't see this as a technical issue; this is a user training issue that HR processes should iron out as part of the induction/leaving processes. 3
PD1279 Posted December 5, 2018 Posted December 5, 2018 Don't forget the most important thing. You make sure that you are "Being seen to protect". Have your documents stating :- - Staff cannot and must not... - USB usage is limited to ... - personal information of pupils/parents/guardians/staff must not ... etc Have documents stating we have firewalls/content filters etc etc Then if people still circumvent this then they are in breach - you are not at fault as it has been done maliciously and on purpose and also gives you ground to increase security of your network/devices/encryption etc etc.
AndrewSharp Posted December 5, 2018 Posted December 5, 2018 Don't forget the most important thing. You make sure that you are "Being seen to protect". Have your documents stating :- - Staff cannot and must not... - USB usage is limited to ... - personal information of pupils/parents/guardians/staff must not ... etc Have documents stating we have firewalls/content filters etc etc Then if people still circumvent this then they are in breach - you are not at fault as it has been done maliciously and on purpose and also gives you ground to increase security of your network/devices/encryption etc etc. Absolutely right, it's all about accountability and transparency under the new legislation. As with the recent prosecution of a medical practice receptionist, the individual has been prosecuted here and not the employer. Schools need to be sure that they have appropriate policies, have appropriate mechanisms to detect likely breaches and have evidence that they test and review policies and processes. Senior Leaders and governors should be monitoring this and leaving a suitable evidence trail as they would with safeguarding, health & safety inspections, etc etc.
Andrew_C Posted December 5, 2018 Posted December 5, 2018 A little O/T, but does anyone have a link to a teacher or school getting a kicking for loosing data via lost device or stick?
southhamster Posted December 5, 2018 Posted December 5, 2018 A little O/T, but does anyone have a link to a teacher or school getting a kicking for loosing data via lost device or stick?Here you go. A perfect example to get staff to take it seriously https://www.bbc.com/news/uk-england-kent-44371759
GrumbleDook Posted December 6, 2018 Posted December 6, 2018 A little O/T, but does anyone have a link to a teacher or school getting a kicking for loosing data via lost device or stick? The fine on this *is* a bit strange and there is more on this than in the press release. The ICO are starting to show teeth though, and not scared of making use of available laws (including CMA) to get prosecutions through. The fact that they haven’t taken action on the schools is good, as it makes it clear that where schools *are* working hard then they are not being penalised for individual actions. There *is* more to this and it will be interesting to read once more info comes out. 2
Davit2005 Posted December 6, 2018 Posted December 6, 2018 Nice, but this bodes the question, How can we stop teachers taking data with them to the new school? You can block USBs etc but Teachers will still find a way to copy all of the personal data and work they created to use in the next place. There are other ways to move data apart from USB. Email, online personal storage etc. Not impossible to block but will prove challenging and possibly costly. IMO, I feel there should be more onus on individuals to realise this is personal data the fine aimed at the employee is a good way to show this. As others have stated this is not so much of a technical issue but a behaviour issue.
enjay Posted December 6, 2018 Posted December 6, 2018 There are other ways to move data apart from USB. Email, online personal storage etc. Not impossible to block but will prove challenging and possibly costly. I think it IS impossible to block, actually. There's no way of knowing whether someone has accessed email, Office365/Google Drive from home and downloaded to the local PC. IMO, I feel there should be more onus on individuals to realise this is personal data the fine aimed at the employee is a good way to show this. Agreed. The fact the fine was to the individual not the school suggests there was policy in place which they didn't follow. As others have stated this is not so much of a technical issue but a behaviour issue. Agreed. 1
mb2k01 Posted December 6, 2018 Posted December 6, 2018 I think it IS impossible to block, actually. There's no way of knowing whether someone has accessed email, Office365/Google Drive from home and downloaded to the local PC. There is with Office 365, depending how tightly you chose to configure security and compliance settings for your users.
free780 Posted December 6, 2018 Posted December 6, 2018 You can actually force encryption of files and monitor if they appear in Dropbox etc. It all boils down too cost of fine + damage to reputation vs trusting staff to follow policy.
jmak Posted December 6, 2018 Posted December 6, 2018 The Office 365 solutions include options to either restrict download to specific devices (Conditional Access) or create encrypted containers on users' personal devices which can then be remotely wiped by the organisation without affecting the rest of the device (Windows Information Protection). It's quite clever and your opinion of how expensive it is will depend on how much you trust your staff/how likely you think you are to be fined.
free780 Posted December 6, 2018 Posted December 6, 2018 The WIP only works with 1:1 scenarios. It affects all users of a shared home device. Other than that it's rock solid. You can deploy.it using Configmgr I think.
jmak Posted December 6, 2018 Posted December 6, 2018 The WIP only works with 1:1 scenarios. It affects all users of a shared home device. Wasn't aware of that. Where I am, the price was considered too high [emoji849] Although I did get Conditional Access through [emoji846]
free780 Posted December 6, 2018 Posted December 6, 2018 You could force all users to go through a VPN/RDS and not allow any data on personal devices. I can't see not being able to use email on your phone unthinkable.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now