Jump to content

Love_Sausage

Members
  • Posts

    243
  • Joined

  • Last visited

Everything posted by Love_Sausage

  1. Print the sheet out with an address and use a window envelope. We had an issue with the wrong sheet going in an addressed envelope, self reported to ICO and they were happy with this being a straightforward, sensible solution.
  2. A Handy guide on how to give the exam boards a little more work to do published by the ICO: https://ico.org.uk/your-data-matters/schools/exam-results/ Wise or not from the ICO?
  3. If you changed the term to "monitoring students?" then it becomes much more acceptable. Any form of monitoring becomes sinister when you call it spying.
  4. We spoke to AQA today - nice person there had never heard of GDPR but did suggest files on an encrypted USB stick was "a good idea".
  5. No thanks, the question was simply polling opinion on whether we resend them in May or find an alternative.
  6. @MYK-IT did you get a chance to ask?
  7. Last session at a Trust solicitor they used this as an example of legal basis for processing being contractual, the school needs to pass data on to that supplier to enable the school to offer meals and payments.
  8. Back onto this, our BM had a letter insisting anything paper based is not GDPR compliant. That, coupled with websites like this one: https://www.proxyclick.com/subscription-gdpr?ads_cmpid=1001805055&ads_adid=52351302474&ads_matchtype=b&ads_network=g&ads_creative=249318249784&utm_term=gdpr%20visitor%20book&ads_targetid=kwd-387622852020&utm_campaign=&utm_source=adwords&utm_medium=ppc&ttv=2&gclid=Cj0KCQjwtOLVBRCZARIsADPLtJ1UYLywVOcXqZS9VzHsymwSZ-5RTw9XLNpXAPImErpF5PBdlzbv0JMaAjapEALw_wcB meant she was keen to press the button on buying something in. Interestingly, this is how the letter sells the system: 4 Reasons why paper-based signing in systems could cost you under GDPR 1: Right to Erasure If an individual requests that you delete their personal information, and you have no legitimate reason to keep it, will you be able to find it? How long will it take to redact the individual entries? 2: Data Privacy Visitors signing in on your paper-based systems can see the personal details of other visitors who have already signed in. 3: Data Security Paper-based systems are not robust and can be easily lost, damaged or end up in the wrong hands. 4: Data Disposal Legislation states that personal data must be disposed of in an appropriate manner and not simply thrown in the recycling. What is the solution? Electronic staff and student management system costing £3k! ...or a 23 quid book from Viking and some organisation
  9. The same exam boards who only just moved away from Cassette tapes, colour me surprised.
  10. So this is something either everyone already knows or nobody knows..
  11. Any thoughts on whether we need to send out new Privacy notices in May or before, or can we wait until the new intake and do it in September?
  12. Let's be honest here, Capita haven't met any deadlines or have almost dropped development of "old" SIMS so are fudging the issue. We were one of the (many, I suspect) schools who didn't really pay a lot of attention to retention guidelines in SIMS, so I made sure we went through and deleted all the records we should no longer hold one-by-one late last year. It took a significant amount of time and I kept being reminded of the promised bulk deletion tool that would be available "soon". Shows how long I've been using SIMS that I didn't believe for a moment it would be here in time.
  13. Office manager yesterday asked me if I knew whether our perfectly capable cross cut office shredder had GDPR certification, because she was about to buy a similar one to replace with a certificate of GDPR compliance. The salesman who cold-called her convinced her this was mandatory for all shredders before May. Not a shredding service, just an bog-standard ordinary office shredder. I asked her not to but I suspect next week there'll be a new one sitting in the office, and the old one will be in the skip.
  14. Contacted our closest school in the MAT about teaming up to help each other - "What's GDPR?" was the answer from the BM.
  15. Uninstalled Wonde. Will deal with the aftermath next week. Zero transparency and also zero response to emails.
  16. Interested to know where you went in the end @sparkeh We transitioned from Behaviourwatch to ClassCharts, it's world's apart in reporting and capability.
  17. The clerk to the governors being part time...ok, that might work for someone who can hit the ground running on that - but the DPO role would be a serious stretch. Smacks of a combination of jobs nobody wanted to take responsibility for being lumped together. I've seen this before and nobody got appointed because nobody could cover all aspects.
  18. You're right - you know it's a bad week when you've lost track of what day it is, and it's only Monday. We have tests tomorrow AND Wednesday, I'll ring them tomorrow to confirm.
  19. I hope it isn't down on that day (tomorrow), we've tests scheduled and no word of that from them.. We had a yeargroup ready to do the NGRT today, with impeccable timing 15 minutes before the test was due to start our internet went out. Didn't come back until an hour later - longest outage for over a year. Test abandoned.
  20. Posted this on the other thread mentioning Wonde, we knew in advance they were being tested by our supplier but we had a torrid time getting them to say who they were and correctly identify the software from our supplier. Their first contact is a technical guy who doesnt know anything of your relationship with the supplier, just expects you give them instant full access to your data and server. Needless to say, that didn't happen.
  21. Another of our suppliers are testing out Wonde, we're piloting it for them - Wonde were really unclear who they were when they called for the setup process, to the point where I had to interrogate them until they gave me their name and the name of the product we use. They only had a list of all the products of that vendor, and at first said didn't say who they were, they were just calling on our supplier's behalf. I understand them providing a service that looks to the end user as if it's part of the product you're using, but if they speak to anyone who's clued up - and they should be speaking to someone who's clued up to provide the access they need - they need to be clearer. I fed this back to our supplier. They were also taken aback when I wouldn't let them install their software without going through Data protection and policy checks first.
  22. Just to add that this works and gave us a heads up - I noticed the logica ofsted visit at 3pm on a friday, and we got the call 9am the following Tuesday. SLT (well, the ones that read their emails after 3pm on a Friday) were grateful for the notice. The Head decided not to tell the teaching staff in case the call didn't come, so they were blissfully unaware. "ftip003239872 logica ofsted ngdc" was the service provider logged. As for how useful it was to provide the information and what they did with it, I'm not fussed - but going above and beyond on occasions like this can't do any harm.
  23. We're looking at CPOMS, we briefly flirted with CURA last year - absolute nightmare to get installed and working. Any contact with TASC's support team just resulted in an email to look at the CURA wiki, which had huge gaps in the instructions. We had to trial and error the solution to the many obstacles we came across and cancelled the contract after just six months. They didn't object.
  24. Registered an interest, especially with Impero being as problematic as it currently is.
×
×
  • Create New...