Jump to content

maturelady

AFK GNU
  • Posts

    91
  • Joined

Everything posted by maturelady

  1. Just something light hearted and an attempt to humanise data protection! Make sure you get to the 12th Day of Christmas Please share https://vimeo.com/487153501 MERRY CHRISTMAS
  2. You are right tj2419 to be looking for different data protection training for your staff. Your kitchen staff may handle biometric data, dietary needs and medical allergies, whilst teachers in the classroom might only manage curriculum data, names and classes. The important thing is to train each group using scenarios which mean something to them. How often do we experience 'generic' training which becomes totally irrelevant and boring? ICO is clear about training https://ico.org.uk/media/about-the-ico/disclosure-log/2018/2259541/irq0742288-disclosure-8.pdf I'm sure you all know about it but just in case - the 2nd generation of the DfE group which wrote the GDPR Toolkit for Schools has a website which has loads of free resources and more added daily. There's some good stuff here. Education Data Matters Doesn't answer your question but I hope something helps.
  3. @Nausing well done Make sure you get sight of the report when it arrives. Be aware that first glance will shock you by the number of their suggestions. However, nearly all will be happening or high on your list and it really will help you focus.
  4. @Nausing - let us know how you got on today with the visit
  5. Stop panicking - they are not random visits. I have spoken to ICO and the schools that have had visits and all had contact with the ICO - asking them questions or for advice. ICO does suggest they might visit but the school can say No. Someone has said Yes in your case @Nausing I have been in contact with 1 school through the whole process from notification, completing the pre-visit questionnaire through to the final report. I am currently putting together a document to show the experience of this school. The visit focuses on best practice. ICO will probably find things wrong but you can learn from it. I'll share what I have learned as soon as its finished
  6. Rockstars Ts&Cs are very good indeed. Their SCHEDULE TO GENERAL CONDITIONS, DATA PROTECTION WITH SCHOOLS is very clear and easy to understand. The only issue is that which you have identified, in section 2.6. In this they are telling you, the data controller, which legal basis for processing you must use. This is wrong. As data controller it is your responsibility to ascertain which legal basis for processing you are relying on. That section should be asking you to warrant that you have identified a legal basis for processing. I will personally contact this company and share my thoughts with them. I can't see enough about Educator to comment but it looks similar. My belief is that these companies have correctly taken legal advice. However, as soon as these legal advisors see the word 'child' they presume consent is the only route. Lawyers such as Michelmores, who specialise in education law would not have given this advice. They understand how schools work and how the law applies in this sector. I am now starting to see a lot of confusion with suppliers. Many simply do not recognise that they are data processors. As we said sometime ago this is a long journey we must take together, my company GDPRiS will help wherever we can but we're not magicians!
  7. Well your system suppliers are wrong! I was part of the team that helped write the DfE ToolKit. I hope we made it very clear throughout to avoid consent whenever possible as it can be withdrawn at anytime. Use another legal basis for processing and in most cases this can be Public task/interest. I am happy to take this up with any supplier. Point them to our website https://www.gdpr.school or ask them to drop us an email [email protected]. We have produced free resources for suppliers to help them help you.
  8. Sorry meant to say systems which include special category data need clearer justification than 'we use this to improve the way we run our school', ie finger prints - Biometric data - can the system run without using this? Yes - thus consent required allergies - Medical data - can a kitchen feed this child without knowing this data? No - public task Again you have considered the processing and have recorded your decisions and justifications
  9. It's about asking yourself: "By processing this data am I carrying out the task set to me by the 'public' to educate kids in the best way we know how?" If you say 'Yes' to this question, and your school has decided that by using Show my homework or any other system allows you to run your school in the best way you can, you may use public interest. Students are allowed to object, but you can give a reasonable and clear answer as to why you cannot meet their request of not sharing the data. Schools must be united on this otherwise we'll get swathes of kids and parents objecting because they can see it happening in other schools. The most important thing is you have considered the data processing, you are satisfied that it is being used for a public task, and YOU HAVE A RECORD OF THE CONSIDERATION
  10. Yes I think @Gongalong is right. There's been quite a few knuckles wrapped in education but this is the first fine that I can recall. I hope it brings home what constitutes a data breach. This is not about data collected today, this data was collected many years ago and just forgotten, left 'somewhere' online. How many teachers or even ex and retired teachers have very sensitive data still sitting on their laptops, data sticks, DVDs, or even floppies? You can argue that you can't be responsible but you are - the school is the data controller. This university was fined under the CURRENT DPA introduced in 1998 not GDPR. If you, as standard practice, ask staff to clear out information they don't need or not entitled to, as part of your current DP process you are in a better position. We are a profession and expect employees to carryout instructions. This is a very good example to use as part of your whole school GDPR training.
  11. Yes, we all know that it would have been better if it had come sooner, but I'm sure most of you that are already complying to the DPA will be reassured that you have been doing the right thing. The document has been passed by lawyers and ICO so it's a very good foundation now. The message is clear - May 25th is the start, not the conclusion. Compliance is subjective and by demonstrating that you are doing something is a huge step towards this. Feedback is invited. I hope you will help. Sorry - I posted too I've remove mine
  12. We have in excess of 100 data maps for major suppliers ready for uploading. We've held back uploading them until we have had details about the structure DfE expects from suppliers' maps. I have that now and our files are good to go. That's our job over the Easter holidays and we will publish the list at the beginning of the new term to our users. In addition to that we have a full mapping structure for EVERY supplier type, eg payment, cashless, curriculum, trips, etc We are not too worried about MIS suppliers; all major suppliers including SIMS have published their GDPR preparation plans. The maps will be very large, these suppliers need to decide how best to present them. Reports are now available on the platform and will be evolving as you tell us what you need. You can report on all your maps for things such as - where is sensitive data, who uses it, and why.
  13. Yes I think you are right It should read as you suggest or: "particularly as legislation is now passing through the parliamentary process." I'm sure its just a typo
  14. As promised here is the DfE open letter addressed to school suppliers outlining GDPR expectations. PLEASE DIRECT AS MANY OF YOUR SUPPLIERS THAT PROCESS PERSONAL DATA TO IT https://www.gov.uk/government/publications/data-protection-changes-letter-to-the-supplier-community GDPRiS is offering a free service to suppliers to map their data whether their schools use our system or not. Ask them to contact [email protected] for further details.
  15. No it has to be signed off by the DfE I assure you Edugeek will be first place we'll put it - I'm hoping sometime this week
  16. Thanks, my company GDPR in Schools, will continue to freely give resources to help. Please tell me what else you need. There's some really good stuff coming from the DfE too - a GDPR Toolkit. Suppliers are being targeted too - there's an open letter to suppliers advising them what schools will be expecting as many don't have a clue! I know its taking time but I cannot stress enough to schools to stop panicking. The education sector is in a very good position today compared to their counterparts in businesses. We have always practised strict data protection rules as part of safeguard and internet safety. However, the new regulation is making people stop, think and reflect about what they are doing. That's got to be a good thing as long as you don't let it take over.
  17. Took a bit longer than I had hoped but here’s the first of a set of free resources. These are videos and Mind-map sheets. The staff training one which you can use as part of your whole school awareness training is nearly ready and I will post later in the week. I really would value feedback, both positive and negative. For DP leads Mind-map sheet Information to share with parents Mind-map sheet
  18. Please could anyone who is in direct contact with their suppliers that process personal data for your school pass on our offer of help with their GDPR preparations. GDPR in Schools is offering a FREE data mapping service to all suppliers that process less than 30 personal data fields or data elements. (Name and Address count as 1 each even if they are split into multiple fields.) We are working with MIS suppliers, and very large system suppliers which will have many more than 30 fields in a different way. Our data mapping process follows the GDPR guidelines and recognises for each field or element, purpose, legal basis for processing, how the rights of the individual are met, data sharing and other key properties. The suppliers with whom we are working have told us of their genuine reluctance to engage with us as they couldn’t believe what we were offering was free. There must be a catch! Well there is a catch, but a good one! Suppliers must agree to share their data maps with GDPRiS schools. So instead of providing data maps to all these schools individually, they work with us to get it right and we share it. However, once we have completed the mapping, we will return the map to the supplier to use with schools that do not use GDPR in Schools. If they change or update their systems they send us the changes and we will action and inform our schools. They will of course need to contact all other schools by other means. We’re giving suppliers a massive push up the ladder to compliance. Sadly, we can’t write their data sharing agreements, privacy policies and the other mandatory documentation they need to give to you to demonstrate their compliance. We would if we could! We can however give them pointers to templates for such documents. Please tell your suppliers to send their data field headings in an Excel spreadsheet to [email protected]. We’ll acknowledge and do the rest. We'll need a contact to put questions to if needed. Thank you
  19. @Jamman960 Confused by what you are saying! There is a whole section of GDPR in Schools for individual school staff. It gives every member of staff their own account which records their responses to a number of questions which you will be including as part of your annual audit. It hold full accountability for EVERY member of staff. Here’s just a couple of questions straight from the Staff User section of GDPRiS: 1. Do you keep your passwords secure, change them regularly and never share them? You need to ensure that your password is never shared with anyone else. Ideally you should never write your password down anywhere, but if you do, this should be stored away securely. It is also a good idea to change your password regularly. YES ☐ NO ☐ 2. Do you lock / log off computers when away from your desk? It is important to ensure that your computer is not logged in when you are away from your desk so that others cannot gain access or view your screen. Ensure you always log off or lock your computer when you are away from your desk. YES ☐ NO ☐ Every member of staff, and I mean all, that comes onto the school site and handles personal data can be held to account. Very soon to be released will be a free automated staff import from MIS and you can still add people that come into your school but are not in your MIS. We have taken into account those staff that won’t use an online system and have produced resources to collect their evidence but still keep it in one place. There is an area where individuals confirm with systems they use which contain personal data and an area to report a breach or message a DPO. There are training videos and many other resources aimed specifically at governors, teachers, kitchen staff, etc GDPRiS has a lot in it. DM me or @GrumbleDook and we’ll show you.
  20. @jenatddm we're taking this thread off-piste. It's supposed to be feedback and new ideas relating to the current and future GDPR videos from the DfE. @GrumbleDook and I would be delighted to discuss the progression of the DP bill in Parliment and our related concerns in a different place.
  21. I've been told that a realistic timescale for the next video is mid March. This one will be a joint production with ICO I believe. Retention and explaining the legal basis for processing will be included. Training every member of staff to bring home the message that DP is everyone's responsibility is a key part of a school's GDPR preparations. I've asked the DfE to produce a video for this purpose, every school needs it. They made no promises but did warm to the idea. If I hear its a 'goer' I'll report back.
  22. No one, including the DfE, wants schools to be forced to appoint a DPO. At the moment EU law dictates it and when the Data Protection Bill is passed, the UK government will enforce it. I have lobbied my MP to ask for the new data protection law to take into consideration the plight of schools. He has said he would do what he could but I'm not sure how empty those words are. When the bill was in the House of Lords there was an amendment suggesting the removal of the mandatory need for a DPO in schools. Due to lack of time it wasnt debated. The bill has now passed to the Commons. This is the last opportunity to get the ruling changed. I'm not holding my breathe but I'm going to lobby again, I'm a born optimist. Perhaps Edugeek members can do the same? The DfE can't do anything about the law - only make suggestions on how schools can address it. In the case of schools having to get a DPO there aren't many avenues to explore given the existing rules. ...and as for funding - you know the answer to that!
  23. Oh I forgot! The next video does cover: Conditions for processing and when consent is needed. Getting old! Thus @maturelady!
  24. The DfE has published the first of a series of videos. I think its very good. Look forward to the next which covers SARs and retention.
  25. Back at the beginning of October I asked Edugeek members to make suggestions on how the DfE could help. I hope you all saw their first blog https://teaching.blog.gov.uk/2017/10/24/general-data-protection-regulation-evolution-or-revolution-for-schools/ The concept of building an Ecosystem of data is of course central to preparing for the GDPR. As their next piece to support GDPR guidance in schools, the DfE is in production of a short video which expands the concept of an Ecosystem and how it should be mapped and managed. In addition, the role of the DPO is discussed and explained. I have seen the script and I know all schools will find it very useful. Even better the script has been run past ICO and they are “happy/supportive of the content”. That’s better than any of us can achieve! I’ve been asked not to give a deadline on when the video will be available, but I’m sure it won’t be too long. I'll keep you posted. A third piece is already being considered. The current thinking is: conditions for processing communicating to parents – SARs increasing staff awareness data retention periods If there is anything else where you think we can help please let me know, I'll pass it on. To complement the DfE blog and video, I have produced a document with a purpose that you can send this to every member of staff to ensure you capture all systems used in school that process personal data. You can find this at: www.gdpr.school/Docs/BUILDING%20A%20SCHOOL%20DATA%20ECO%20SYSTEM.pdf For further information on GDPRiS visit www.gdpr.school
×
×
  • Create New...