Jump to content

Recommended Posts

Posted

Possibly some crossover here as this is also about software installed on our server...

 

After some scrutiny, we have identified software on our server that collects data from our MIS and transmits it to a third-party.

 

Although I believe legitimate, we have very little documentation (OK, none) about what data is being collected and who it is sending to which is unacceptable.

 

All this was set-up before I started, but it's ringing alarm bells.

 

So far the software identified is:

 

Groupcall (Emerge\Xporter).

Wonde.

USO autoupdate.

Pebble

 

There are also various scheduled tasks which run both within the software and in the server to run these programs.

 

Groupcall - no idea, although I think there may be B2B (which apparently 'might' be a job from the LEA?) and Meritec jobs associated with it.

 

Wonde - possibly something to do with a Learning Platform\Service, maybe Purple Mash.

 

Pebble MISapp - I think this is a finance package... (waiting to hear from the Business Manager)?

 

USO - This I have found out is for LGfL accounts (but we don't use any of LGfL's USO services that I'm aware of, so I'm going to stop/uninstall this anyway).

Posted (edited)

Group Xporter on Demand (XoD) has a web dashboard (https://manage.groupcall.com/SchoolPortal) that'll tell you exactly what information is shared and with whom. Your username is "ESTAB-DFENumber (So ESTAB-7891234). Either nudge your SLT for credentials or trigger a password reset and look for an email mentioning "groupcall" in the inbound mail log to see who has the passwords.

 

Wonde has a similar dashboard (https://edu.wonde.com/login) with a list of applications/organisations and the permissions involved. All you need to get in is add an email alias for anyone who historically had admin access.

Edited by pete
  • Thanks 2
Posted

What Pete said!

 

Wonde are really helpful to talk to as you’re the end-user.

 

Groupcall will be contracted by the company’s that you’re sending data to so not so easy.

  • Thanks 1
Posted

Pebble MISApp is for Tali, cashless catering system I think.

 

All of these things should be documented in your GDPR data asset register, and potentially you should have DPIAs completed for them (depending on what data is sent to where).

 

Who is your DPO? You should speak to them about your data flows.

  • Thanks 1
Posted
Group Xporter on Demand (XoD) has a web dashboard (https://manage.groupcall.com/SchoolPortal) that'll tell you exactly what information is shared and with whom. Your username is "ESTAB-DFENumber (So ESTAB-7891234). Either nudge your SLT for credentials or trigger a password reset and look for an email mentioning "groupcall" in the inbound mail log to see who has the passwords.

 

Wonde has a similar dashboard (https://edu.wonde.com/login) with a list of applications/organisations and the permissions involved. All you need to get in is add an email alias for anyone who historically had admin access.

 

Great info, thanks!

Posted

Wonde and Groupcall are middle men which extract data from your MIS and then share it - with your approval - with various online ed tech products. The idea is each of them do a single extract from SIMS, selected data from which is then shared with the likes of your learning platform, e-book platforms, seating planner, parents evening management, home-school comms, etc. Historically, each of these products either relied on manual CSV imports or they each had their own bespoke exporter installed on your SIMS server meaning you had 10+ exports a night, and each supplier would need to modify this exporter each time SIMS changed and broke something.

 

As others have said, they both have portals through which you can see who is getting data and exactly which fields they're getting.

  • Thanks 1
Posted

This is great stuff... I have already found that due to a crossover in communication, we are apparently sending '2Simple software' data for 'Purple Mash' both via 'Groupcall' and 'Wonde'!

 

The Headteacher and Business Manager have the Dashboard for Wonde (as was mentioned it is end-user driven - and why I don't know what is going on) and have apparently agreed to the data sharing, without checking if the data is being transmitted already (which it appears it is - through Groupcall Xporter)... :doh:

Posted

You also need to think about which are Data Processors and which are Independent Data Controllers.

Where data is extracted to be used to manage other systems, then thayt are a data processor and you would have a data processing agreement in place.

If the data is share to an independent data controller, e.g. the DfE, then this is data sharing and there is a data sharing agreement/instruction in place.

Try not to use the term Third Party as it has a specific definition in GDPR and too often you hear it to mean both of the above, when really it just means the independent data contoller.

  • Thanks 1
Posted
You also need to think about which are Data Processors and which are Independent Data Controllers.

Where data is extracted to be used to manage other systems, then thayt are a data processor and you would have a data processing agreement in place.

If the data is share to an independent data controller, e.g. the DfE, then this is data sharing and there is a data sharing agreement/instruction in place.

Try not to use the term Third Party as it has a specific definition in GDPR and too often you hear it to mean both of the above, when really it just means the independent data contoller.

 

I usually think of the 2 as being processor - doing something FOR you. Controller - doing something for themselves.

 

Also, a firm can be both. Eg. School photographers. On one hand, they take the photos and send them to you to add to your MIS. But, they also sell photos to the parents, via their own systems (ie. the school isn't the one selling photos), so they are both a processor for the first part, and a data controller for the second part.

Posted
I think Meritec is reading cloud (junior Librarian)

 

We do have Junior Librarian, but last I knew the librarian was doing a manual upload from a SIMS output file, so I don't think we've linked that.

 

Isn't meritec CPOMS?

 

We do have CPOMS and Groupcall have got back to me saying that is one of the data feeds they have from the school.

Posted
I usually think of the 2 as being processor - doing something FOR you. Controller - doing something for themselves.

 

Also, a firm can be both. Eg. School photographers. On one hand, they take the photos and send them to you to add to your MIS. But, they also sell photos to the parents, via their own systems (ie. the school isn't the one selling photos), so they are both a processor for the first part, and a data controller for the second part.

 

For the processor, they are doing something on behalf of/instructed to. A controller makes the decision about the purpose and method of processing ... so yes, there are many occasions where schools are controller and processor, as most controllers will be in that situation.

 

For the photographer, yes, that is generally correct. Many photographers now have a direct to parent offering, but not all schools do it that way. For some, they will still do it via the school, but be instructed to manage the engagement with parents. Some will even be Joint Controllers with the school due to the way commision is paid to the school. It is all in the agreements that are made.

  • 1 month later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...