Jump to content

jmak

Members
  • Posts

    5,571
  • Joined

  • Last visited

Everything posted by jmak

  1. I'd still look at setting up AD Connect to synchronise - you then only have one place to manage user accounts. Also, you're likely to use Google accounts more and more; I got into a battle with Microsoft and Google as (predictably) neither would accept responsibility for why the new accounts which were auto provisioned into Google from AD worked perfectly, but the pre-existing accounts logged in but didn't have access to the data they had before they were synchronised. I'm sure you can guess who had to deal with the mess...
  2. From my reading of the privacy notice: You scan QR code of venue which is stored on your phone. QR code of venue is held centrally (it's not personal data). All venues identified as possible sources are marked and their identifier is shared with all phones with the app installed and your phone checks the list of places with the records on your phone of where you've been. And for the other way around: You register a positive test result in your app. The app then sends all of the data from all of the venues you've visited (and the other phones detected) and uploads it to the central database. You're not identified because the identifier is anonymised by the use of the daily code. The only bit that I can see that's being missed is that the venue had no way to prove that they've collected the data from everyone who visited. Also, if the proximity party of the app hadn't picked up that you were close to the person who treated positive, how much risk are you actually at? I know I don't need a test unless I have symptoms, but is checking in to a venue at some point during the same day as someone who tested positive enough of a reason for me to self isolate?
  3. Have you sorted out synchronising user accounts with your Active Directory? Not sure if it's mentioned in the guide you linked, but there's an option to pre-populate your domain for user sign in. If you set that, the login will be the same on Chromebooks as on Windows devices.
  4. Congratulations. It's entirely reasonably to feel slightly apprehensive, but don't start questioning whether you're good enough. Checking that they've got a working backup probably is a job for the first day. After that I'd prioritise the people and relationships side of things. It's unlikely that there'll be a long term impact of delaying technical things by a couple of weeks, but if you don't get off to a good start with the staff, you might never recover. You might have bridges to build with the technicians - it's not unlikely that at least one of them applied for the job you got. Even if they didn't, it'd be surprising if they weren't at least slightly defensive about the fact that someone has been brought in after two years - there's a potential perceived criticism of what they've been doing. Get on good terms with the site team. The bursar is important, if you think you might ever want to buy something. You'll find out what's going on around school much quicker if you make friends with the receptionist and head's PA. Find out from your technicians which classroom staff are always the most vocal critics of IT - if you can fix one of their gripes (even if it's just helping them to do something that the technicians have told them a hundred times) you might cultivate a vocal supporter. Also find it who the "sensible" users are, so that you know if they come to you with an issue, it's something that needs your attention. After that, if there's an issue log or help desk, go through it and identify some quick wins and major issues. If there isn't a help desk in place, get one set up quickly. Good luck!
  5. Just a brief one to highlight something in my previous post: Your DPO should know all this and be supporting whoever is making this decision. It's great that you're there and asking sensible questions, but it's the law that the school employs someone qualified to deal with this kind of scenario. That person must not be in the IT support team.
  6. You certainly don't need to remove the child from all your systems. Check here: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/ The only issue would be if you asked for consent to prices their data. Hopefully your DPO would have told you not to do that. For MIS, it is clearly essential for your organisation to operate. The purpose of your organisation is to educate. If using O365 or other cloud platforms is a key part of how you provide that service, then you don't need consent unless you can reasonably deliver it without holding that data. Realistically, even if the teachers printed out everything for that one child (and I think you would have a strong case that that's an unreasonable requirement) you would still need to hold the child data on the system so that you can manage the work that they are set.
  7. For the test and trace records I'd be inclined to generate a QR code and use the government app. Anyone who doesn't want to use the app, use a piece of paper per day in an A4 binder. Once you get to 14 pieces of paper, remove and destroy the one on the bottom every time you add a new one to the top.
  8. I remember in January one of my first reactions to hearing about lockdown in China due to Covid-19 was "Can you imagine if that came here and they asked European people to lockdown? The Chinese government is lucky it's a totalitarian state and people are used to complying." By the beginning of March I was writing to my MP and telling anyone who'd listen that we needed to lockdown immediately - I'd read a lot about how the disease was getting out of control in other countries and thought a full lockdown early on would have the least long-term impact. I don't think there's an alternative to trying to track who has been in contact with who in order to limit spread of the virus. I think using the app (even though it's government controlled) is probably one of the least intrusive ways to achieve it. But I hope that we can get to a point where it's not necessary and at that point the public isn't so accustomed to bring tracked that they forget to object. Ironically, before Covid, there was lots of covert tracking using facial recognition CCTV. Mask wearing has blown that out of the water...
  9. For eating out, it's not legally required, but the establishment you visit is required to keep details for track and trace. Most of them will have an alternative, as they've had to do that since they re-opened. My take on the official app is that they're more likely to have decent privacy controls than random paper systems in restaurants and the other apps I've used might have decent controls, but I definitely don't have time to check when I arrive at the restaurant. My posts on here will show I'm quite privacy conscious and sceptical of giving away more data than necessary, but I think the situation has changed. My hope is that once this crisis is over, the genie can be put back in the bottle...
  10. You could make an argument that all equipment should be issued to staff and not shared (not one that convinces me) but even if you were, this is completely undermined by the fact they're sharing keyboards and mice. So no, it's not you, it's them [emoji854]
  11. It may be safe, but every time you share pupils' data with that an external organisation (which you will need to do if you're providing individual logins), your organisation needs to carry out a risk assessment and Data Protection Impact Assessment, which includes understanding how they will process and safeguard your data. This would need to be approved by the DPO. Assuming you already use O365 or G Suite and the DPIA had been carried out, no personal data would need to be shared with the new organisation of you could sign in with an organisational Google or Microsoft account. I think the point being made here is that if $staff-member wants to choose a new supplier, they should be the ones carrying out that task, not the IT support team. It doesn't seem an unreasonable approach to me, but I've certainly worked in places where I'd end up in trouble for doing it. Make sure you know what the consequences would be for you before you make too much fuss...
  12. Might be worth looking at https://wiki.lineageos.org/devices/#samsung Not for the Covid-19 app, just because you're not getting security updates anymore (for me, the equivalent of running Windows XP) on a device you have personal data on.
  13. In another thread I saw a suggestion to use screen sharing in Teams. I know it wouldn't work for every scenario, but it was a face palm from me for not thinking of something so easy (assuming you're using Teams already).
  14. You'd hope it would take into account when the test date was - although judging it by edge cases that only exist for a few days after launch would seem harsh, especially when what is on the app isn't legally enforceable. Might be worth deleting all the data before you go back to work as nothing is picked up will be relevant any more. Presumably it's most relevant for people who are exposing themselves to lots of different contacts and you'd expect them to be more likely to have newer phones. No criticism of you running an old phone (mine is over 5 years old and still going), but it doesn't seem unreasonable to insist that the phone is still getting security updates when you're designing an app that gathers personal data.
  15. I'd assume it will, although there is an assurance that they will never use the app as a way of checking that you do obey the instruction to stay at home. You can also tell it to delete any of the data it holds.
  16. I think (being positive) it remains to be seen how effective the Bluetooth proximity detection is. However the built in track and trace seems to add quite a lot of value. The current track and trace organisation is performing very poorly (that's not political - why it's the case is up for debate, but not here). If enough people use the app, contacting people who have been at a particular location will be automated and instant. It's also more anonymous than leaving your details at every place you visit and relying on the staff there to look after and dispose of your data. Hopefully they'll also be able to adjust the algorithm for the Bluetooth proximity measure by linking test results to notifications.
  17. Well, I've just tried to install it, which worked, but when I run it, I get the message "Currently only for NHS Volunteer responders, Isle of Wight and Lewisham" and won't let me continue without an invitation code. Guardian reports that lots of people are making the mistake of downloading the trial version. Well I used a link from the NHS app support website which has a banner saying "Now available in England and Wales" and it takes me to the app I've got installed. Brilliant Edit: I followed a link from The Guardian, which appeared to take me to the same app (it gave me the option to update, not install) and despite the fact I installed it this afternoon and the app information says it was last updated yesterday, it did install an update and it now works [emoji2369]
  18. So... The NHS Covid-19 app is now live. They've now moved to the decentralised/anonymised data-storage model. With the original app's design, I was a definite no. I think this has addressed most of my concerns. What's the opinion of the collective? https://www.gov.uk/government/publications/nhs-covid-19-app-privacy-information/nhs-test-and-trace-app-early-adopter-trial-august-2020-privacy-notice (Updated today, despite link text)
  19. I'd want the bursar and finance team working away from each too. If they all go off sick, no one will get paid!
  20. Business continuity requirements would suggest that you only have one person on site from each time at a time and then only where essential. If you have the option to keep teams isolated from each other, it seems like bad management not to. Have you asked how they are responding to the updated government guidance that everyone who can work from home should work from home? I can see that having someone on site is potentially useful, but it seems unnecessarily risky to have the whole team in a room together.
  21. The key thing is that this is the wrong time to switch. In your position, I'd make a strong case around that. As a starting point, I'd mention: 1) All your existing files are in Google Drive. Staff would need to use those even if they create new lessons/homework tasks in Teams, so you'd quickly end up with confusion about where stuff is stirred and which is the correct version. 2) Your distribution lists/contacts are all in Gmail, so you'd have to recreate all of that 3) You'd need to create Office 365 accounts for everyone and set up SSO 4) You'd need to install additional software on all client machines which should be tested before it's released 5) You don't know how to support Teams (obviously make it clear that you'd be happy to learn, but there's a big learning curve) 6) You'd need to provide training for all staff If all of the other schools in the MAT are O365, you'll probably end up going that way and it's quite usable nowadays. When I was planning a transition to cloud, I recommended G Suite, as I'd tested both and found it easier to implement, manage and use, but I was honest and said that other schools locally were using O365. On that basis we went O365. I managed fine and I think it's better now - although as ever MS seem to make the simplest things painful, including the normal nightmare that is licensing. I'd still go back to the fact that it's not a simple switch. For it to succeed, it's needs a strategy, a proper plan, investment of time for you to support it, for staff to be trained and an understanding that any change like that costs time and energy and during the migration process, the organisation will be less efficient and there will be teething problems. It would need full backing from SLT. Now is not the time.
  22. You #shouldn't# need 3rd party tools to create a "mapped drive view" any more; it's now possible using group policy: https://docs.microsoft.com/en-us/onedrive/use-group-policy#configure-team-site-libraries-to-sync-automatically When we did it a couple of years ago, there was some grumbling because people didn't understand what they were getting and it wasn't possible to configure through GPO, so people had to set up the sync themselves. Once people realised how easy it was to set libraries to sync for themselves, most people were happy. When the word got it that all the files were available anywhere, people were generally happy with any downsides compared to the benefits. Obviously downloading and uploading large files is slower than with a local file server - but that only impacts the first time you access the file: after that it's quicker because it's local so you're not even dependent on the LAN. You're also dependent on O365 working properly and your internet connection. The internet connection for individual users is easily overcome by using a hotspot from your phone (also means you're not dependent on any of your local infrastructure). I would say that you should do it as a project with sponsors in SLT and it should be part of adopting O365. I also used Conditional Access so that the files are only accessible from domain joined machines - you need Azure AD P1 for that - but that's a risk decision for data security that your management would need to take. On backups, I reckon the Microsoft are more capable of keeping data safe than I am, but there are various commercial products or you could sync all libraries locally and then back that up (not an official approach...)
  23. I was taught that I should deal with an email as soon as I open it, i.e. don't open it until you have time to deal with it and if you don't need to do anything, either delete it or file it appropriately. Obviously this lesson was given by someone who only had to teach other people about time management and didn't have to do any actual work... On a more serious note, why not set a flag, possibly with a complete by time? It doesn't take any longer than marking something as unread and it's clear to you which ones are actually new. I'd be interested to see what can be done from exchange side; I always set my email clients to deny requests to send a read receipt. If people aren't reading emails from the Head, they're sending too much dross. Even with piles of emails, if one comes from the head of the organisation, I'd always expect to read it pretty quickly - although I might let someone else deliver that message...
  24. I can only find information about trials of that technology. The price mentioned is "similar to a paperback book", so about £5? Who's paying for your tests? Sounds expensive... I know Exeter university is paying for weekly tests and Addenbrookes hospital in Cambridge is trialling it for inpatients alongside swab tests. Government are running trials starting soon in Salford and Heathrow have got their own thing going on. Have you managed to get involved in a trial? NB: in no way getting at you, just interested in a) how the school's got involved and b) how the powers that be decided it's good value. I'd love to have a 20 minute saliva test widely available.
  25. Guidance from an authoritative figure in a BBC radio interview this morning (trying to keep this apolitical): 1) If you are a family of four going for a walk and you see another family going for a walk, you mustn't stop to talk. 2) If you suspect that a friend or neighbour has allowed a seventh person onto their property, you should call the police non-emergency number. Like most people, I am very keen that the disease is kept under control, but I do think that aim could be better served by trying to keep people on side than threatening them.
×
×
  • Create New...