Jump to content

Recommended Posts

Posted

I'm delivering some data protection training soon which Ive done in the past but would would like to add some real-world tips and tricks and examples of simple things we should be mindful of and can go wrong.

 

Some things like:

 

BCCing when sending things outside your organistaion

 

Sending anything sensitive should be encrypted

 

Etc Etc

 

Cheers in advance

Posted (edited)

- - - Updated - - -

@gszech Thanks for this.

 

 

My sarcasm detector is ringing :). I do appreciate there are some generic bits out there but wondered if anyone had any specific EDU related ones of things that often go wrong in schools as they do differ from most other workplaces.

Edited by titch
Posted
From a teacher's perspective, I think the breadth of data that is considered personal is always an eye-opener. (Informal) assessments done in class with students' names on - personal data. Students' notes who left the school 2 years ago - personal data. Bottom line - shred everything if you can work out who it belongs to. Just my 2p.
  • Thanks 1
Posted
This sophisticated Google search result came up with some really good real-world suggestions like: lock your computer, use suitable passwords, report phishing emails, Etc Etc.

 

 

Thanks

Greg

Just did that and the near top result redirected me back to this thread. Bit of a loop with no results. Very sophisticated :)

 

It doesn't help that a lot of the advice like lock your computer after 5mins or less is completely unsuitable for classroom use.

  • Thanks 1
Posted (edited)
- - - Updated - - -

@gszech Thanks for this.

 

 

My sarcasm detector is ringing :). I do appreciate there are some generic bits out there but wondered if anyone had any specific EDU related ones of things that often go wrong in schools as they do differ from most other workplaces.

We have a spreadsheet full of all the different types of photo/video consent for social media, photos on displays per group/class with a final page which lists only all people who have withdrawn constant. This allows staff at least in theory to check the groups they are in and figure out what they can and cannot do. If its helpful I could put some fake names in and share the spreadsheet. Our spreadsheet has 9 categories of media/photo constant with an additional Notes section along with ticks for parent consent and student consent as students can override parents at a certain age.

 

EDIT: The other small tip I recommend is most Councils have a data retention policy like https://www.nottinghamshire.gov.uk/media/5082814/records-retention-schedule-v19.pdf which will have a section in for education and extra requirements for SEN and other types of students. Its worth checking your local Council policy.

Edited by Pottsey
  • Thanks 1
  • 2 weeks later...
Posted
The extremely vast majority of our GDPR breaches have been misdirected emails, often a) someone reading an address in SIMS/ClassCharts then mistyping it in email, rather than copy-pasting it, or b) someone selecting a similar but different name from the auto-complete in Outlook.
  • Thanks 1
Posted
I always recommend staff turn off reply to all as the default. Most of the miss sent emails I have seen are replies to a parent sent email that should only be a discussion between staff.

 

Good point, or over-sharing in response to All Staff emails, e.g. an email from Cover Manager saying "here's the updated cover rota" and a teacher replies with details of why someone is absent. It doesn't help that the default reply option in the Outlook app is Reply All.

 

We've had a few incidents of students being included in emails about them, because the staff member had added them so they could check the spelling of their name then forgotten to remove them. That's usually easily solved though, as we can get in to the kids' mailboxes but obviously it does require the staff member to know they've done it.

Posted
Oh, and data being shown on a classroom projector by mistake, either because the teacher forgot they were projecting/duplicating, or by closing one tab and something being visible in another tab or e-PostIt notes. Less common now we're not doing live lessons via Teams, but it still happens.
Posted
Oh, and data being shown on a classroom projector by mistake, either because the teacher forgot they were projecting/duplicating, or by closing one tab and something being visible in another tab or e-PostIt notes. Less common now we're not doing live lessons via Teams, but it still happens.

 

It is definitely still happening, I've come across 2 examples very recently. It's well worth reading about the expectations of the ICO around what schools should be doing to prevent this (particularly policies and staff training) in the reprimand they gave a primary school last year: https://ico.org.uk/action-weve-taken/enforcement/parkside-community-primary-school/

  • Thanks 2
Posted
Always use the MIS (or an MIS-linked system) to fetch or use parent contact details. Staff members digging up an address from an earlier email thread (or having it saved in their email contacts list), obviously won't account for subsequent changes to contact details held by the MIS.
  • Thanks 1
Posted
It is definitely still happening, I've come across 2 examples very recently. It's well worth reading about the expectations of the ICO around what schools should be doing to prevent this (particularly policies and staff training) in the reprimand they gave a primary school last year: https://ico.org.uk/action-weve-taken/enforcement/parkside-community-primary-school/
This answer is why it's worth posting questions on a specialist forum. A response from the experts on how to avoid making mistakes based on a real world example. It didn't come up near the top of a sensible Google search.
This sophisticated Google search result came up with some really good real-world suggestions like: lock your computer, use suitable passwords, report phishing emails, Etc Etc.

 

 

Thanks

Greg

Posted
I always recommend staff turn off reply to all as the default. Most of the miss sent emails I have seen are replies to a parent sent email that should only be a discussion between staff.

 

You can do this for them with powershell.

Posted
Always use the MIS (or an MIS-linked system) to fetch or use parent contact details. Staff members digging up an address from an earlier email thread (or having it saved in their email contacts list), obviously won't account for subsequent changes to contact details held by the MIS.

 

I'm less concerned about picking up changes, as email addresses don't get recycled to other people so worst case there is the parent doesn't get the email. The problem is when someone looks up [email protected] in MIS then opens Outlook and sends an email to [email protected] instead.

  • Thanks 1
Posted
It is definitely still happening, I've come across 2 examples very recently. It's well worth reading about the expectations of the ICO around what schools should be doing to prevent this (particularly policies and staff training) in the reprimand they gave a primary school last year: https://ico.org.uk/action-weve-taken/enforcement/parkside-community-primary-school/

 

That's an eye-opening read. I wonder how many other schools aren't doing half the things listed in that reprimand...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...