-
Posts
12,876 -
Joined
Reputation
31,493 ExcellentAbout GrumbleDook

Personal Information
-
Occupation
Privacy Professional and Educational Technologist
-
Interests
Computers ... Duh! ... and fencing ... and chocolate.
-
Location
Gosport, Hampshire
- X
-
Homepage
http://www.grumbledook.org
Employer (optional)
-
Company Represented
Independent Consultant
Recent Profile Visitors
The recent visitors block is disabled and is not being shown to other users.
-
It has been a while since I popped in a went through my reading list and TBR .... so here is a lengthy one. I've been going through quite a few things ... some series are finished and some have more sets to go. I've been rereading my collection of CJ Archer stuff, followed by Ryan Kirk (absolutely fantastic person ... gifted me some of his audiobooks!), Sarah K L Wilson's Dragon School series (Just finished book 15?), reread Ben Aaronovitch's Rivers of London series so I then dive into Stone and Sky, Jon Cronshaw's The Ravenglass Chronicles (up to book 9), Graeme Parker's Bruised Sole: The unfiltered Story of The Hoof GP (still ongoing, CN Crawford's Dark Fae series (book 7, I think), a bunch of Brandon Sanderson, Jill Bearup's Just Stab Now (finished) and now reading Andy Peloquin's Darkblade series alongside Elisabeth Wheatley's Daindreth series. I've probably missed off a few others in there, some audiobooks and stuff. The other thing I have really enjoyed is this year's Big Read from The Tolkien Society. A wonderful book club reading of The Hobbit and now onto LotR, followed by hour long lectures once a month from noted scholars and Tolkien lovers, and then 1/2 hour discussion between small groups of different members. I know the recordings will be online at some point, and if you are a fan then it is worth watching some of the older recordings on The Tolkien Society's YouTube page. Looking forward to the final Thursday next book coming out from Jasper Fforde, and until then it will be finishing off some more series, and diving into my heavily reduced TBR pile (I culled it before moving house in Jan).
-
I've been through quite a few books and audiobooks over the last few months and whilst some of it has an element of comfort reading, some has been to pick something new. I really enjoyed getting into Marcus Lee's The Chosen series (5 books) and have a few other books on my TBR pile now too. Ryan Kirk's Nightblade books/novella are really enjoyable third of fourth time. Then some comfort reading with Raymond E Feist's Fireman Saga, though I am still not 100% sure I like the ending. Dipping back into some romance/romantasy with a smattering of different books from various series ... a bit of C J Archer (Cleopatra Fox), JS Kennedy (Mackenzie Green) and C N Crawford (Shadow Fae). I've also been reading/listening to Jon Cronshaw's The Ravenglass Chronicles (nearly at the point of book 10 ... will then take a break for a bit) And over the weekend I picked up the latest Ryan Kirk - These Fallen Swords - as an audiobook. He had a prize draw and I got one of the promo codes :-) So that will be my next one. In between these I have been picking at Bruised Sole, and autobiography of Graeme Parker (The Hoof GP). A very emotional and poignant read so far. My TBR has only increased by a few though ... moving house has meant I have had to curtail a fair chunk of buying extra books. I did pick up the complete bundle of Elisabeth Wheatley in the Black Friday sale, so I have 35-40 books to get through there!
-
When I saw the bit about routers ... I had horrid flashbacks of having to collect a few hundred of them from schools, and then flash them all before they could be disposed of.
-
Coronavirus: General discussion (see opening post for rules)
GrumbleDook replied to Dos_Box's topic in General Chat
I get a free flu jab now, as have had Covid 4 times and it has affected me and it puts me at risk. I won't get a free Covid jab though ... I am not a high enough risk to others. -
The ICO has a history of engaging and working with public sector organisations rather than fining. However, the PR aspect of it is likely to be quite a problem, as well as open the school up to complaints. Even if the school ask for consent, it is unlikely to be considered as 'freely given', as without access to the additional services then the children whose parents refuse to give consent may be affected adversely, not having the same level of education as the others. This means the school is effectively forcing parents to give consent. There is no clear answer on how it can all be made to work, but the larger priority for schools look to be around managing their supply chain, incident management and transparency.
-
Just to clarify on this, the reason you need consent on this is due to Google's terms and conditions for the additional services. For the additional services Google is a separate Data Controller. They will used the personal data for purposes *they* decide on. This has been discussed with various folk at Google for some time and for the bulk of schools they will need consent for the additional services. The post from Hwb was talking about the Hwb additional services, which included Google G Suite for Education ... *not* the Google Additional services. The previous advice from Hwb, IIRC, was that use of any additional integration with Hwb (M365, Google, etc.) may result in needing Consent ... and that was partly due to the additional services. When looking at any SaaS, not just Google/Microsoft, if they say they will use any personal data for their own purposes, then they are becoming a Data Controller in their own right. That is what the law says. Moreover, they now also have to comply with the Age Appropriate Design Code ( aka The Children's Code) as the relationship is directly between the child and the provider of the additional services requiring consent. This has been discussed with the ICO policy teams, with DfE and with numerous children's rights stakeholders. The DPO is right in this case, and if anyone wants the warts and all for the above discussions I'm happy to talk to school DPOs and others about it.
-
DfE - Protect and Prepare - SCORM
GrumbleDook replied to Alastairb25's topic in Virtual Learning Platforms
There are LMS tools that can hook into M365 that play SCORM content. IIRC Learn365 is one, but there are others ... the problem might be cost though. -
Declaration of Interest - I have done some work reviewing SLT AI works and discussing it with the founder. I like SLT AI. They have taken the time to look at the quick info and other tools SLT needs, and work out the best way of using AI to siphon through it without it causing problems. Yes, you can do this yourself with enough time and tools, but you can say that about almost everything. As with other tools over the years, to some extent you are paying for the fact that someone has had the expertise to put together a solution. If it saves you time and lets you get on with other things ...
-
The Data Use and Access Act 2025 (DUAA)
GrumbleDook replied to Alis_Klar's topic in Data Protection & Information Handling
Public Task, as a lawful basis, includes tasks completed in the public interest or undertaken through the organisation's official authority. The official authority is set out in education legislation and SoS instructions (including things like KCSIE), or other legislation which affects children within a school environment or school activities. Within England, the requirements for schools as set out by Ofsted also come into play (similar is in effect for Wales and Scotland, and NI is a bit more complicated). One area that could change is around research and direct marketing, but that will come under secondary legislation really. -
The Data Use and Access Act 2025 (DUAA)
GrumbleDook replied to Alis_Klar's topic in Data Protection & Information Handling
There are a few changes that will benefit schools. There are a few folk discussing it, but https://www.brownejacobson.com/insights/data-use-and-access-act-2025-what-you-need-to-know is probably the simplest one to share with you senior leadership/DPO. From a vendor point of view (as a data processor for the school) it increases the need for transparency, and there are a few items needing secondary legislation to enact, but some of those are a separate discussion. The important bit from a relationship position as you do due diligence on your supply chain (CE+ requirement) is that your data processors only process what is in your agreement with them. Nothing has really changed there. -
Children's Code/COPPA Parental Consent
GrumbleDook replied to gpjt's topic in Data Protection & Information Handling
Am I right in thinking that some of this is US based, not UK? I'll try to cover both. In the UK, when EdTech solutions are used for the education, pastoral care or running of the school, then those vendors are being used as data processors and through an intermediary (i.e. through the school who is the data controller). This means they do no count as Information Society Services and so are not covered by the Children's Code (Age-Appropriate Design Code) in the UK. Where the school is the Data Controller and processing the data under their official authority or in the public interest, then the lawful basis is likely to fall under public task (under art. 6 of GDPR ... I'll leave art. 9 for the moment to keep it simpler). In the US, at the moment the efforts to introduce variations of the Children's Code have been centred on commercial/consumer rights and not where it is applied to schools/direct education. The US also doesn't have the range of lawful bases that we get under GDPR, and so you have the need to get Parental Consent for children under the age of 13 if the school wants to use edtech. As far as the vendor is concerned, they don't need to see it for each student, and as far as the school is concerned they can list everything they want to use and just ask once to cover them all. There are some issues with this last one as the lack of granular records can be problematic but I've seen it done in a variety of ways. For COPPA, the FTC do make amendments and the most recent ones do clarify about de-identified data, reuse by vendors and a few other bits ... and COPPA 2.0 is still not close to being passed ... so you get the MIS being used to record that a form has been sent in, a Google/MS form being used, of a few apps that do send a request to the parents on behalf of the school and so on. The simplest way is a form, providing the purposes for using data, what data it actually is and who will be doing it for you. Ask for agreement, keep the record and on you go. Some schools record each year, some do it only once. The risk cannot be passed onto the EdTech vendor, it is down to the school (or District) to make sure it is being recorded correctly. This is a vast simplification and there are some variation out there, so I tend to say to UK folk to speak to your DPO and to US folk to speak to your District. -
Holiday Time Safeguarding Monitoring
GrumbleDook replied to mitchell1981's topic in Internet Related/Filtering/Firewall
I presume this was said tongue in cheek, but just to repeat things for all to be aware ... teachers work on directed time. Teachers’ working time | National Education Union provides a good breakdown of what it covers. However, it is not uncommon to hear of teachers working 50+ hours a week, and from recent surveys 1/5 work 60+hours. The holidays will often also involve work, whether marking and planning, or being back in school running extra sessions, sorting out displays and more. So yes, teachers are only meant to work the Directed Time, but often they work a lot more. Senior Leaders in school are meant to work more, and both the Head and Dep Head don't have restrictions on how much they work or when, but that doesn't mean they will be free to deal with issues at any time, night or day. -
Holiday Time Safeguarding Monitoring
GrumbleDook replied to mitchell1981's topic in Internet Related/Filtering/Firewall
Was a DPIA done to assess the risks on this? This is one of those discussions where some folk will talk about the liabilities of providing devices and something going wrong, and those saying that it is an invasion of privacy. I have been asking the question for nearly 20 years which you need to take as the priority and the consistent message is "It depends!" ... and this is why your risk assessment is so important. For classroom.cloud, we talk about how you make choices based on the needs of the school (in their duties and activities for the learners), but also about being transparent with parents and children. These discussions have to be led by the DSL, but with input from all stakeholders. The ICO's DPIA template gives you space to discuss what impact stakeholder engagement has had on your approach. When it comes to alerts and notifications, that is also an area that needs careful consideration, and has to be part of the risk assessment too. Basically, there is no single answer to it all, and there is no shortcut to the efforts on risk assessment. -
GDPR or Data Protection Act?
GrumbleDook replied to Gongalong's topic in Data Protection & Information Handling
Yes, there are differences in them. DPA2018 also covers law enforcement as well, and does not cover some of the detail that GDPR does. We also need to remember that GDPR is written to be both stand alone, and to fit around other EU Regulations and Directives. And now we have to go through it all again and see what the new Act will do.
