Jump to content

enjay

Members
  • Posts

    8,254
  • Joined

Everything posted by enjay

  1. So, back to the original question now I know what a VRM is! Is there any reason not to share this information? It's nothing you can't find out by looking in our car park anyway then searching the vehicles on DVLA's website. The document you linked is interesting, but I can see why DVLA refused to provide a private citizen with that information; in that scenario it is for the Police to request it. I've done a bit of Googling, and found the response from a Government agency who got word-for-word the same FOI request recently.
  2. Ah okay, the Estate Manager thought they were asking for something else.
  3. I know that, I'm now wondering if the requester meant to ask for the licence plate / reg number rather than the VRM. It seems odd they haven't asked for those!
  4. Don't give them the plates, or don't give them the VRMs? Actually, they don't ask for the reg numbers, only the VRMs. I wonder if they meant the plates and said VRM by mistake...
  5. An personal email address, but that doesn't mean much with FOIs as even the newspapers use GMail for FOI requests because of better handling of mass emails. The requester didn't identify themselves though.
  6. Has anyone else received this FOI request recently? Dear FOI Officer, Under the Freedom of Information Act 2000, please provide for each DVLA-registered road vehicle currently owned, leased or operated by (school name): make and model, colour, full DVLA first registration date, MOT issue/expiry date, and VRM. Spreadsheet/table format preferred. If (school name) does not currently own, lease or operate any such vehicles, please confirm this. Kind regards, Our Estate Manager has some reservations about providing the VRM as this could be used to forge V5 documents (and they can't immediately think why anyone would want to know it!).
  7. The longer you keep them on the phone, the more of your voice you give them so they can synthesise it and make deep fake calls and videos which sound convincingly like you - https://edition.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-kong-intl-hnk
  8. The teachers would have to manage that, and the students remember their pseudonymised login (which also gives them the opportunity to "forget" it for homework purposes!). I'd prefer to use the sign-in with Microsoft which also limits what information is available to just names and email addresses. The code.org registration process asks for their age (mandatory) and gender (optional) but it's still relatively low risk - especially since you can't contact our students anyway.
  9. All code.org would get is students' names and email addresses. For me, this looks like a prime example of risk assessments but our DPO is taking a slightly harder line of "pass/fail" with the DPIA.
  10. Code's own privacy policy says they don't have EU adequacy! "The United States has not sought nor received a finding of “adequacy” from the European Union under Article 45 of the GDPR"
  11. Our DPO did a DPIA on them a few years ago and "failed" them because of the data location. I've asked them to review this, given they say they may take direction from the school (although the policy only mentions doing that for US school authorities not UK ones), and the data held is minimal. Also, as you say, a DPIA isn't a pass/fail thing, it's something to risk assess.
  12. Our Computing teacher would like students to use code.org but when you sign up, you have to specifically acknowledge that data will be shared with a company in the US and subject to US data access laws. According to their privacy policy, they are typically the data controller although they might enter into a separate data sharing agreement by which they'd just be a processor. The data would still be subject to the US access laws. How do we feel about that?! Should I allow the data sharing as it is very limited personal information anyway, or push back against the teacher and get them to select a different platform?
  13. Can anyone recommend a company who can scan (and ideally subsequently shred) a load of paper records? The company we've used previously are no longer trading.
  14. Blocking text and blocking images are very different things. Also I think the complexity of live-sharing a document and the speed with which text can be typed and deleted adds a challenge which content filters didn't previously have to contend with.
  15. Not really, no. It might flag certain inappropriate words but you can do/say a lot without using those words, and it wouldn't block images which had been inserted into a Google Doc, for example.
  16. Thanks. We've also blocked things like DropBox for students for similar reasons. Google Drive continues to present a challenge, as I'm not sure of a way to stop students accessing personal Drives while still allowing access to the school one. Why students are still using Google when we moved to Microsoft 5+ years ago is another topic!
  17. I could do that but I am not sure if the M365 login process uses something at live.com, in the same way some logins to Google Drive go via a YouTube URL. I wonder if my filters can block the string https://onedrive.live.com/:w:/g/personal but not the overall domain...
  18. Our email said "mid-2026". We don't have any more parents evenings this academic year, so we're assuming it will have changed by the time we next need it in October.
  19. For safeguarding reasons, we'd like to prevent students from being able to access documents shared with them by people outside the organisation. I've done this with Google Workspace, but not been able to fully do it with M365. If you select to share the document with the student by name, it doesn't work but if you share a document "to anyone with the link", students can still access them. Does anyone know a way of stopping this, without impacting students' ability to access their school M365 account? I've noticed their school OneDrive address is https://schoolname-my.sharepoint.com/shared but a personal OneDrive begins https://onedrive.live.com/:w:/g/personal, so could I just block the onedrive.live.com domain, or would that prevent students logging in to their school account too?
  20. And that's becoming more common, as people ask ChatGPT to "write a letter of complaint to my school" rather than just write an email saying they're unhappy.
  21. You can request that, but not insist on it. SARs can come via any medium, including verbally.
  22. My numbers are roughly in line with those, in that case, allowing for us being a single academy not a MAT so possibly "escaping" some of the FOIAs. As for detection, I'm confident the ones which come in to office@ etc get to me, it's the requests (more likely SARs than FOIAs) which are going directly to year teams which might not. One example I can think of is a parent who wanted more detail on their child's behaviour points because the parent portal doesn't include everything - this made it to me because the admin who received it is relatively new and didn't know how to redact the document, but otherwise it might not have done.
  23. Only a small number (1-2 per month) of SARs and/or FOI requests make it onto my radar, but based on the number of emails I receive from companies/consultancies offering advice or assistance with SARs and FOI requests, I wonder if we're actually receiving more, and staff are handling them directly without notifying me. I don't want to make more work for myself for the sake of it, but I do want to ensure we're handling these appropriately so I'm wondering if some improved staff training is needed. This training would be in case we're missing the requests, having accidental data breaches by staff who don't understand it properly, or have staff wasting time by manually redacting documents not using the redaction software we have. So, how many requests are you receiving? To avoid this thread getting derailed, I know these aren't IT things however I am also the school's GDPR lead (DPO is external, of course).
  24. Wouldn't that involve them sharing their personal numbers with each other? I can imagine some people saying no to that. We've created limited M365 accounts for our invigilators, so they have a mailbox but no other access.
  25. I'm a sucker for long exposure when at a waterfall too. This is Aira Force in the Lake District.
×
×
  • Create New...