Jump to content

Recommended Posts

Posted
Currently if our staff share a file in OneDrive it's only amongst themselves. A teacher has asked if they can share a folder of resources with a teacher at another school. Should we allow this? Caveats? Should the teacher at the other school have to agree to anything? Not quite the same as emailing the resources, after all. Or is it?
Posted

Collaboration is great, but...

 

If this is opened up will it lead to unencrypted sharing of personal information?

 

While I can see nothing against it the theory, the precedent it sets and the GDPR risks associated must be thought through.

  • Thanks 1
Posted

I'd restrict it to particular folders - we have a "Curriculum" library/team/folder which doesn't (shouldn't) have any personal data on it. I would allow sharing from the, but not from the "Staff" area.

 

I'd say it's better than email, as you could restrict sharing in the future or set the links to expire.

  • Thanks 1
Posted
If its just resources there should be no personal data so it should be fine. GDPR shouldn't put barriers in the way of collaboration. With proper staff training it should be fine.
  • Thanks 1
Posted

Just exploring options at the moment; our DPO is involved!

 

Our AUP could cover not copying sensitive data into an externally-shared folder; the trouble is that it's so easy to do. Whereas we can and do enforce encryption on USBs, for example.

 

Any thoughts on the teacher at the other school? If they were given an actual logon to our network they'd need to sign our AUP. So what about if they are sent a link to a file in one of our staff OneDrive accounts?

Posted
Just exploring options at the moment; our DPO is involved!

 

Our AUP could cover not copying sensitive data into an externally-shared folder; the trouble is that it's so easy to do. Whereas we can and do enforce encryption on USBs, for example.

 

Any thoughts on the teacher at the other school? If they were given an actual logon to our network they'd need to sign our AUP. So what about if they are sent a link to a file in one of our staff OneDrive accounts?

 

It would be better if they had their own account and you share with that.

Posted (edited)
We can lock it down to various degrees - e.g. users we deliberately add to Azure AD, or more "self-service" but from a whitelist of domains e.g. feeder schools. Personally I feel a (brief) AUP for them would be a good idea. Obviously we don't do this for recipients of our emails (!) but this feels a bit different. Edited by Quatermass
Posted
I'd restrict it to particular folders - we have a "Curriculum" library/team/folder which doesn't (shouldn't) have any personal data on it. I would allow sharing from the, but not from the "Staff" area.

 

I'd say it's better than email, as you could restrict sharing in the future or set the links to expire.

 

This is what we do, if it needs sharing externally we normally recommend the user creates a folder in their OneDrive, shares it explicitly with the people they want to only, and then set a restriction on the time.

Posted
This is what we do, if it needs sharing externally we normally recommend the user creates a folder in their OneDrive, shares it explicitly with the people they want to only, and then set a restriction on the time.

 

Do you limit who they can share with?

Posted

Also make any links to share time restricted.

 

As long as personal data is not involved then you only have to consider copyright and ownership of resources and content.

Posted
If your no 100% sure no personal data may be shared the information protection can auto classify files containing personal data. It can then apply a policy. E. G only staff can open the files. Of course this involves azure information protection licences.
Posted
Teachers have 2 jobs, teaching and working with personal info, should those really be mixed in the same account with the same security? One's projected onto a screen, one's GDPR'd to hell and back.
Posted

I agree with all comments about the separation work and personal data.

A Data Protection Impact Assessment should be conducted as the school is considering implementing a new process. When the new process is documented and risks assessed it should be submitted to the DPO and if acceptable the Governors/ Trustees can sign off. The Transfer policy can then be added to you Email usage policy, which all members of staff should of course be notified of. The school is then fully accountable for its actions.

  • 2 weeks later...
Posted
I agree with all comments about the separation work and personal data.

A Data Protection Impact Assessment should be conducted as the school is considering implementing a new process. When the new process is documented and risks assessed it should be submitted to the DPO and if acceptable the Governors/ Trustees can sign off. The Transfer policy can then be added to you Email usage policy, which all members of staff should of course be notified of. The school is then fully accountable for its actions.

THIS. Ultimately, your DPO should be involved at the start of a project while it can still be influenced (go on, tell me you're the DPO lol).

 

Also, I believe Data Loss Prevention is available in Office365 which covers SharePoint, OneDrive (which is powered by SharePoint) and Teams. Well worth looking into.

Posted
I agree with all comments about the separation work and personal data.

A Data Protection Impact Assessment should be conducted as the school is considering implementing a new process. When the new process is documented and risks assessed it should be submitted to the DPO and if acceptable the Governors/ Trustees can sign off. The Transfer policy can then be added to you Email usage policy, which all members of staff should of course be notified of. The school is then fully accountable for its actions.

 

The OP was looking at sharing resources. I think we can safely say that PD and SCPD *should not be in there* anyway so DPIA is not needed. However, a statement / confirmation that this method of sharing resources *has* to sure that no PD/SCPD is involved.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...