Jump to content

maturelady

AFK GNU
  • Posts

    91
  • Joined

Everything posted by maturelady

  1. ICO carried out a consultation relating to consent in March. I replied giving my views from the perspective of what I believed would be best in schools. Until the actions relating to this are published no one can give you a definitive answer. However throughout the consent directives in the original GDPR documents reference to mandatory need to tick a box as opposed to unticking is one of the major changes. From this you can assume electronic consent is becoming the norm. Again 'however' the consent we collect is a lot more important to a child than agreeing to receive emails or marketing calls. Identity management is the key here. We're going to have to wait until we get clear guidance on this one. I'll ask ICO when can we expect publication of the consent consultation and let you know.
  2. As promised here's a Word version of my GDPR Readiness Tracker. A PDF version is on the website http://www.gdpr.school/wp-content/uploads/2017/06/GDPR-readiness-tracker.pdf Hope it helps GDPR readiness tracker.docx
  3. As promised at the conference, you asked me to ask Capita SIMS on Monday what they were doing to make their software GDPR compliant. They told me that it was definitely a priority on next year's roadmap and more details would be revealed at their annual conference later this month. Perhaps PhilNeal can tell you more. However, I am aware that many other 3rd party suppliers which process personal data for schools have not started their preparation to become GDPR compliant. Try to wake up these companies and tell them that they need to do something asap. Come 25th May 2018 it will be illegal for you to use anyone that is not compliant. You will have to change suppliers. That should wake them up! You can refer any to me - we are preparing a pack for suppliers, FOC, outlining what schools must have from them and how to approach the process of becoming compliant I'm here to help with any questions about GDPR
  4. A meeting with 2 hansom young gentlemen – how can a girl resist that! I live less than an hour away. DM where you are staying Tony and sort out the time between you guys.
  5. Sorry meant to say Yes you must have a legally binding contract with all your 3rd party data processors and they must be GDPR compliant too. If they are not its your problem as well as theirs now. https://ico.org.uk/for-organisations/data-protection-reform/overview-of-the-gdpr/transfer-of-data/
  6. The key words in this is that data must be ‘Lawfully processed'. All data you hold or send to a data processor must qualify as being lawfully processed. This means that you have gained consent to use the data or that you are processing the data under a different umbrella as defined here https://ico.org.uk/for-organisations/data-protection-reform/overview-of-the-gdpr/key-areas-to-consider/ In schools, we will be processing much of our data under the public authorities’ umbrella: 6(1)(e) – Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller An example of this is a student's name which may be shared with a 3rd party provided you are able to justify this party is processing that data as being necessary for your processes. Thus, it will fall under the 6(1)(e) umbrella as being lawfully processed. You will not be required to seek consent although you must let the subject know with whom the data has been shared. The subject may ask for the data to be removed but you will be justified in refusing citing 6(1)(e) However, a parent's email address which you will have collected by your own means will fall under a different category. At the point of collection of the email address you will have needed to make it clear the legal basis for collecting this data and you must make it clear that you will be sharing the data with a named 3rd party. If you did not you must go back and gain permission either through consent or telling the subject that the data will be used lawfully under the 6(1)(e) umbrella. More tham happy to help where I can
  7. Groupcall's Emerge/Xpressions ticks all the boxes for the features you want and a lot more. Well respected company - take a look.
  8. WordPress is so, so easy to use. I'm a 65 year old non techi lady who's still involved in schools and I'm 100% self taught. I've built a couple of website in no time. Didn't cost anything only hosting charges. I'll DM a url in case I'm breaking forum rules by posting it. I love working with WordPress its so flexible. Chose a good theme, definitely go for a responsive one. I used Square but there's lots of other good free ones. Experiment with Plugins, you'll be amazed what they can do, eg bring in your Twitter feed, have a count down to an event, link to Amazon to make you some money! Google analyticals can be added too and SEO is very powerful. It tells you when you need to update anything so be sure to always do it. Shout if I can help
  9. Data protection is about all personal data that is stored and shared in schools. I agree with pcstru that schools’ physical servers and access should meet the requirement and if they don’t someone is not doing their job. However, it’s all the stuff taken out on paper, sent to 3rd parties and extracted for everyday use is where breaches will occur. Do you know if the school canteen prints off any names from the cashless system or the PE staff emails the mini bus driver with kids names to pick up? ...and what do they do with them when they finish with the information? That’s the scary bit.
  10. Back to the original question. I think we all should understand that ICO is never going to say to us – “Yes, you need to encrypt teachers’ laptops, No, you don’t have to encrypt data sticks.” Or anything similar. What they will say is that it is a school’s responsibility to take all steps necessary to keep personal data safe. It will be up to individuals to define what keeping data safe entails. If nothing goes wrong you will never know if you have got it right. Sadly, it will be the first school to be fined for a data breach under GDPR that will give us many of the answers we want. I believe you must apply common sense and logic and of great importance, maintain a full log of the steps you have taken. Thus in my opinion if any device which stores any personal data that allows an individual to be identified must be protected. If it is paper it must be secured and if it is electronic it must be encrypted, password protected or locked away in a big vault! If you can demonstrate that you have taken every appropriate step to protect your data then I believe any breach will be investigated with sensitivity. It’s going to be a learning curve for all and that’s why it’s vital that we continue to share experiences and good practices.
  11. Leeoakley I'm interested in your meeting with a 'GDPR consultant'. Are they education specialist? I'd be keen to know if they have knowledge of what data schools have and how its shared, eg SIMS data goes to a payment provider who then shares it with a cashless provider (or the other way around depending on the system you use) I'm always concerned that external 'experts' dont know how you work in schools and you'll be left doing the donkey work. Please post the outcome of your meeting.
  12. I agree with GrumbleDook - where the DPO has their office is a bit irrelevant. The school is the data controller and thus is absolutely responsible to ensure compliance. The DPO's job is to advise and make it happen. If anything goes wrong it will be the school that is fined, not the DPO or the Head.
  13. I just asked ICO - reading their reply I think the answer is Yes schools can share a DPO Here's their reply: We have recently published further guidance regarding DPO's under GDPR, and if you haven't already done so, you may wish to look at the guidance we have published on our GDPR microsite https://ico.org.uk/for-organisations/data-protection-reform/overview-of-the-gdpr/accountability-and-governance/#dpos It is possible for a single DPO to act for a group of companies or public authorities, taking into account their structure and size. More recently, the Article 29 Working Party issued further guidance regarding DPO's and published a useful list of FAQ's you may wish to look at http://ec.europa.eu/newsroom/document.cfm?doc_id=43823 and http://ec.europa.eu/information_society/newsroom/image/document/2016-51/wp243_annex_en_40856.pdf respectively Hope it helps
  14. You can't get the staff! Try this https://ico.org.uk/about-the-ico/news-and-events/events-and-webinars/data-protection-for-the-education-sector-webinar/
  15. Sorry I'm repeating the same thing as I did in the post: GDPR Data Protection and Memory Sticks. but GDPR is important. It is going to have a major impact in schools as we hold and share so much data. Whether we stay or leave the EU is immaterial - ICO has clearly said that the initiative will go ahead. A lot of questions regarding the new GDPR initiative is in the Webinar ICO produced and is worth listening to if you have an hour to spare! If not there's a PowerPoint that summarises it all and will be useful to use to get the message across that DP is about to change big time. https://ico.org.uk/about-the-ico/new...ector-webinar/ You may find this useful.
  16. I missed this first time around but it answers a lot of questions regarding the new GDPR initiative. Its an area in which I have a particular interest. The Webinar is worth listening to if you have an hour to spare! If not there's a PowerPoint that summarises it all and will be useful to use to get the message across that DP is about to change big time. https://ico.org.uk/about-the-ico/news-and-events/events-and-webinars/data-protection-for-the-education-sector-webinar/ Hope its useful.
  17. No certain data will be protected. Individuals can request removal of data but the controller has the right to refuse in certain instances. The regulations state: "When can I refuse to comply with a request for erasure? You can refuse to comply with a request for erasure where the personal data is processed for the following reasons: 1 to exercise the right of freedom of expression and information; 2 to comply with a legal obligation for the performance of a public interest task or exercise of official authority. 3 for public health purposes in the public interest; 4 archiving purposes in the public interest, scientific research historical research or statistical purposes; or 5 the exercise or defense of legal claims." The scenario you suggest would apply to at least 2 of these categories as will data in statutory returns that schools have to do.
  18. You are absolutely right pcstru. It's a problem that's alway been there and largely ignored. The cashless systems are secured but many head teachers and data managers are unaware of the sensitivity of the data they hold. Of course knowing who's on FSM, if there are dietary needs through health or religion is essential for a school meals service. However in many schools there are outside caterers who are not employed by the school and I'm sure the dinner/kitchen personnel are not part of any data protection training. Just raising yet another issue that schools may not be aware of.
  19. One area where schools could really get themselves in trouble is with school meals. You can lock up your MIS data as secure as you want but the cashless system, controlled by the catering staff, is in a kitchen store room It holds FSM data, allergy and dietary needs and religious food requirements. Yes they are secured but look for the username and password its usually on a PostIt note on the wall!
  20. Yes – absolutely you can, and should, become cashless. That was the vision I had 15 years ago and there are many schools now that have achieved this. It won’t be easy to begin with but once you are there you’ll never regret it. I was there at the very beginning - in 2002 I originated and founded ParentPay. It was the first online payment system in UK schools. I developed and fashioned the software around my experience as a teacher of 18 years who ran loads of trips and a busy Mum. I wanted a system that kept children safe, reduced workload for staff, and saved money. Being 100% cashless achieves all 3. In the early days, I dragged around schools showing version 1 of ParentPay and was laughed at by many bursars and heads. I hope none of you were one of those. However as always in education the visionaries shone through. I retired from ParentPay 3 ½ years ago and am no longer part of the organisation. Yet I still follow with great interest the online payments world which has grown so much. I’m happy to share my expertise freely with any school but please don’t ask me to say which is best.
  21. I hear GroupCall has a new payment system they are showing at BETT. Worth a look.
  22. My husband’s health will prevent me from attending this year but I will be following with great interest online, through social media and on Edugeek. One thing that really bugs me is that in previous years I visit a stand and see something really exciting only to learn that the concept is ‘in development’ – vapourware. There are some very reputable companies that do this every year. I’m particularly interested in apps for parent engagement, communication, attainment tracking and reporting. Could any of my BETT visitor colleagues name any products broadcasted in company literature as new and innovative that they think is just vapourware? Have a great BETT and take care of those feet.
  23. I very much agree with vikpaw’s comments – reports should be unique to each student. However there are many dangers if you start cutting and pasting from last year’s reports. It’s so easy to miss a ‘his’ when it should be ‘her’. It would be very disappointing if any teacher used any supplied set of comments ‘as is’ and did no editing but sadly some will do this. To write reports using well-structured and grammatically correct phrases and sentences, and to be sure that the name is correct with all the he/shes, his/hers, him/hers being right has to be a much better starting point for any teacher. The alternative is a blank sheet of paper or an empty Word document. Most reporting software allows full editing function and/or sends the reports to Word once the bulk of the text is written. This is certainly the case in SIMS. Another huge benefit of using such report writing tools is consistency. Heads can be sure that every teacher meets reporting requirements and of course the reports are stored centrally. The SIMS Teacher Comments are for use in SIMS Profiles – a module every school has if they have the SIMS Assessment Suite.
×
×
  • Create New...