Jump to content

Recommended Posts

Posted
Don't forget the most important thing.

 

You make sure that you are "Being seen to protect".

 

Have your documents stating :-

- Staff cannot and must not...

- USB usage is limited to ...

- personal information of pupils/parents/guardians/staff must not ...

etc

Have documents stating we have firewalls/content filters etc etc

 

Then if people still circumvent this then they are in breach - you are not at fault as it has been done maliciously and on purpose and also gives you ground to increase security of your network/devices/encryption etc etc.

 

I think this is right if the practice and staff awareness in place than it is staff responsibility to follow the policy.

 

Can someone share draft do and don't list according to new legislations for staff please?

Posted
There is with Office 365, depending how tightly you chose to configure security and compliance settings for your users.

 

the google drive audit log tells you everything too

Posted (edited)
A little O/T, but does anyone have a link to a teacher or school getting a kicking for loosing data via lost device or stick?

There's the Rochester Grammar case which shows that data was lost and the school reported this to the ICO, but no record of regulatory action. https://www.bbc.co.uk/news/uk-england-kent-44371759

 

As for prosecutions in the schools sector, a former local education authority worker in an admissions team was prosecuted for misuse of data - https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2018/02/former-council-worker-fined-for-sharing-personal-information/

Edited by AndrewSharp
Posted
There's the Rochester Grammar case which shows that data was lost and the school reported this to the ICO, but no record of regulatory action. https://www.bbc.co.uk/news/uk-england-kent-44371759

 

As for prosecutions in the schools sector, a former local education authority worker in an admissions team was prosecuted for misuse of data - https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2018/02/former-council-worker-fined-for-sharing-personal-information/

The Rochester Grammar one was days after the introduction of GDPR. There may have been some leniency for prompt reporting and actions
Posted
The Rochester Grammar one was days after the introduction of GDPR. There may have been some leniency for prompt reporting and actions

 

Possibly, they may also not have finished their review yet! I know of two breaches reported to the ICO back in June and July and the schools have heard nothing back yet.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...