ICT_Pro Posted December 7, 2018 Posted December 7, 2018 Don't forget the most important thing. You make sure that you are "Being seen to protect". Have your documents stating :- - Staff cannot and must not... - USB usage is limited to ... - personal information of pupils/parents/guardians/staff must not ... etc Have documents stating we have firewalls/content filters etc etc Then if people still circumvent this then they are in breach - you are not at fault as it has been done maliciously and on purpose and also gives you ground to increase security of your network/devices/encryption etc etc. I think this is right if the practice and staff awareness in place than it is staff responsibility to follow the policy. Can someone share draft do and don't list according to new legislations for staff please?
DGardiner Posted December 7, 2018 Posted December 7, 2018 There is with Office 365, depending how tightly you chose to configure security and compliance settings for your users. the google drive audit log tells you everything too
AndrewSharp Posted December 7, 2018 Posted December 7, 2018 (edited) A little O/T, but does anyone have a link to a teacher or school getting a kicking for loosing data via lost device or stick? There's the Rochester Grammar case which shows that data was lost and the school reported this to the ICO, but no record of regulatory action. https://www.bbc.co.uk/news/uk-england-kent-44371759 As for prosecutions in the schools sector, a former local education authority worker in an admissions team was prosecuted for misuse of data - https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2018/02/former-council-worker-fined-for-sharing-personal-information/ Edited December 7, 2018 by AndrewSharp
elsiegee40 Posted December 7, 2018 Posted December 7, 2018 There's the Rochester Grammar case which shows that data was lost and the school reported this to the ICO, but no record of regulatory action. https://www.bbc.co.uk/news/uk-england-kent-44371759 As for prosecutions in the schools sector, a former local education authority worker in an admissions team was prosecuted for misuse of data - https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2018/02/former-council-worker-fined-for-sharing-personal-information/The Rochester Grammar one was days after the introduction of GDPR. There may have been some leniency for prompt reporting and actions
Bigbird7 Posted December 7, 2018 Posted December 7, 2018 The Rochester Grammar one was days after the introduction of GDPR. There may have been some leniency for prompt reporting and actions Possibly, they may also not have finished their review yet! I know of two breaches reported to the ICO back in June and July and the schools have heard nothing back yet.
GrumbleDook Posted December 7, 2018 Posted December 7, 2018 I think this is right if the practice and staff awareness in place than it is staff responsibility to follow the policy. Can someone share draft do and don't list according to new legislations for staff please? https://www.gdpr.school/free-resources may help. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now