Jump to content

enjay

Members
  • Posts

    8,254
  • Joined

Reputation

6,221 Excellent

5 Followers

About enjay

Personal Information

  • Occupation
    IT Strategy Manager
  • Location
    Berkshire, UK

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

  1. So, back to the original question now I know what a VRM is! Is there any reason not to share this information? It's nothing you can't find out by looking in our car park anyway then searching the vehicles on DVLA's website. The document you linked is interesting, but I can see why DVLA refused to provide a private citizen with that information; in that scenario it is for the Police to request it. I've done a bit of Googling, and found the response from a Government agency who got word-for-word the same FOI request recently.
  2. Ah okay, the Estate Manager thought they were asking for something else.
  3. I know that, I'm now wondering if the requester meant to ask for the licence plate / reg number rather than the VRM. It seems odd they haven't asked for those!
  4. Don't give them the plates, or don't give them the VRMs? Actually, they don't ask for the reg numbers, only the VRMs. I wonder if they meant the plates and said VRM by mistake...
  5. An personal email address, but that doesn't mean much with FOIs as even the newspapers use GMail for FOI requests because of better handling of mass emails. The requester didn't identify themselves though.
  6. Has anyone else received this FOI request recently? Dear FOI Officer, Under the Freedom of Information Act 2000, please provide for each DVLA-registered road vehicle currently owned, leased or operated by (school name): make and model, colour, full DVLA first registration date, MOT issue/expiry date, and VRM. Spreadsheet/table format preferred. If (school name) does not currently own, lease or operate any such vehicles, please confirm this. Kind regards, Our Estate Manager has some reservations about providing the VRM as this could be used to forge V5 documents (and they can't immediately think why anyone would want to know it!).
  7. The longer you keep them on the phone, the more of your voice you give them so they can synthesise it and make deep fake calls and videos which sound convincingly like you - https://edition.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-kong-intl-hnk
  8. The teachers would have to manage that, and the students remember their pseudonymised login (which also gives them the opportunity to "forget" it for homework purposes!). I'd prefer to use the sign-in with Microsoft which also limits what information is available to just names and email addresses. The code.org registration process asks for their age (mandatory) and gender (optional) but it's still relatively low risk - especially since you can't contact our students anyway.
  9. All code.org would get is students' names and email addresses. For me, this looks like a prime example of risk assessments but our DPO is taking a slightly harder line of "pass/fail" with the DPIA.
  10. Code's own privacy policy says they don't have EU adequacy! "The United States has not sought nor received a finding of “adequacy” from the European Union under Article 45 of the GDPR"
  11. Our DPO did a DPIA on them a few years ago and "failed" them because of the data location. I've asked them to review this, given they say they may take direction from the school (although the policy only mentions doing that for US school authorities not UK ones), and the data held is minimal. Also, as you say, a DPIA isn't a pass/fail thing, it's something to risk assess.
  12. Our Computing teacher would like students to use code.org but when you sign up, you have to specifically acknowledge that data will be shared with a company in the US and subject to US data access laws. According to their privacy policy, they are typically the data controller although they might enter into a separate data sharing agreement by which they'd just be a processor. The data would still be subject to the US access laws. How do we feel about that?! Should I allow the data sharing as it is very limited personal information anyway, or push back against the teacher and get them to select a different platform?
  13. Can anyone recommend a company who can scan (and ideally subsequently shred) a load of paper records? The company we've used previously are no longer trading.
  14. Blocking text and blocking images are very different things. Also I think the complexity of live-sharing a document and the speed with which text can be typed and deleted adds a challenge which content filters didn't previously have to contend with.
  15. Not really, no. It might flag certain inappropriate words but you can do/say a lot without using those words, and it wouldn't block images which had been inserted into a Google Doc, for example.
×
×
  • Create New...