rom1984
Members-
Posts
236 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by rom1984
-
Forcing parents to share data with Controllers
rom1984 replied to enjay's topic in Data Protection & Information Handling
I'm not 100% sure about this one! The example I can think of is if your say to parents, to pay for schools dinners you must register with a third party payment service. Is this the kind of thing that you mean? The test to be a controller is if you determine the purposes for processing the data and the means of processing it then you are the controller. I see this as meaning the "why" you are processing it and the "how" you are processing it. So in my example of school dinner payments, the school is determining why the data needs to be processed. You are telling the parent, you must give this third party company your details so we can process school dinner payments. But... the third party is determining how they process the data. I'l use my example and apply it to some questions that you must ask yourself to help determine if you are the controller... Why are you collecting the personal data in the first place? (school decides it is being collected it to process school dinners) Which items of personal data is collected? (third party decides what they need, i.e name, address, debit card details etc but there is a little influence by the school. The school is saying you must register with the third party to pay for school dinners so clearly they are telling the parent they will need to provide some online payment method) The purpose for collecting the data? (joint responsible, school is giving the overall purpose but the third party decides the purpose for the individual data sets, i.e why do we need the debit card, why do we need the name etc) Which individual to collect data about (school decides, i.e. all students need to use it, or just year 1&2 students or all students apart from students on free school meals) How long to retain the data (both, the school tells them how long the student is there for, but the company will be responsible for deleting the data) Whether to disclose the data, and if so, to who, (the third party with a little bit of the school, for example the school may ask how much credit the person has on their payment account) The above questions can only be answered by the data controller so if you answer yes to them, I'd say you have controller responsibility. The data processer decides thing like what IT systems to use, how to store the data, the security of the data, the retention methods, backup strategies etc. If you are required by law to process the personal data, (I'm thinking legal obligations like recording child protection incidents or registers) then the school must retain their data controller responsibilities. From my example I think the decision will be either the school is a data controller and the third party is the processer OR joint controller. I'd be willing to edge towards both having controller responsibilities so I'd be asking the third party to provide details on what data they collect about our parents, how they collect it, how they store it, is it encrypted, is it within the EU, how long do they keep the data etc. This should all be document to protect the school in case of a breach by the third party. I can't think of an example where you are telling people they have to provide a company personal data, but then you have absolutely no controller responsibility. Hope this helps! -
Right to delete from backups
rom1984 replied to enjay's topic in Data Protection & Information Handling
Yeah I agree you shouldn't bundle legal and public interest together, the school needs to decide which one it is, it can not be both for the purpose of processing personal data. Do you know who advised you to use consent in the event you have no other grounds as I don't think that's right? You shouldn't really just put it into consent unless it legitimately is consent. Remember as well that for consent to apply, it needs to be freely given. So it can not be consent if you are going to do it anyway, or for example when the person is almost blackmailed in to it (i.e you need to consent to be recorded in the classroom otherwise you won't be allowed in) There is also an almost overriding principle within the GDPR that comes from Article 5 which is that data shall be processed lawfully, fairly and in an transparent manner. This principle will always be referred back to when dealing with the other Articles and is one that a school must always keep asking themselves - am I being fair, am I being transparent. So if you tell the person at the point of collection what your data backup strategy is, how long you keep it for, why you keep it, your strategy for dealing with data removals on the backup, what the procedure is to restore data, then you will be 99% there in dealing with rights to removal in fair and transparent way. This will be looked at a lot more favourably compared to an school that didn't tell the person anything about backed up data and didn't do anything with a right to erasure request. Finally, I can't remember what Article it is but the GDPR gives up to 2 months to deal with rights to erasure. So you could comply with a right to erasure and still have backups from up to 2 months ago with the data on. Again it will come back to fair and transparency, so did you tell the person that you still have a backup of them, did you tell them when the backup would be overwritten, did you tell them what will happen if you do a full data restore within the 2 months etc -
Right to delete from backups
rom1984 replied to enjay's topic in Data Protection & Information Handling
Just to expand on Enjays comment here, the recitals in Article 17 specifically go out of there way to say that any child who has given consent to process their data can at a later date request to have the data removed. This is why it is so important that schools determine on which basis they are processing data and not just to have a blanket policy of "we collect all our data on the bases of consent" Paragraph 3 of Article 17 says that the right to erasure need not apply if you have processed the data due to legal obligations, the performance of a task carried out in the public interest or for archiving purposes in the public interest. So if you have collected data about a student and told the student/parent that you were processing this data due to a legal obligation or in the publics interest, and they then request their right to erasure, you will be able to reject that request if you still need to keep the data due to your legal obligations. Where it is frowned upon, is if the school collects the data on the lawful bases of consent, and the person requests to have the data deleted, and the school then says well actually we don't need your consent because its our legal obligation. The GDPR has set out that this can't be done and you must commit to one basis. -
I wouldn't take it personally mate! I used to work in the same school as my missus and I trust her with my life, but I wouldn't give her my domain admin credentials. Not because I don't trust her or I think she will use them to go snooping, but if there is ever a data breach I want to be able to put my hands up and say I followed best practises so you can't blame me! I think this is what the deputy head is doing, although he's not articulated it very well lol
-
Right to delete from backups
rom1984 replied to enjay's topic in Data Protection & Information Handling
I think the person who told you this is getting confused with another paragraph within Article 17 which is the Article that deals with the right to erasure. If a data controller makes personal data public (for example by the consent of the data subject) and they then receive a request for erasure from that person, the data controller must attempt to delete the data in the public domain taking into account the cost of doing this, the technical measures available and the reasonable steps that can be taken. There is nothing else that I can see in the Article or the recitals that suggests the data controller can take into account things like cost etc when dealing with a right to erasure. -
GDPR - Teacher notebooks/planners/etc
rom1984 replied to FragglePete's topic in Data Protection & Information Handling
Do you currently have a procedure in place that deals with this under the current Data Protection Act? If so I don't think the GDPR will have too much of an impact on your current procedure, presuming there is one in place that is compatible with the current DPA. The only relevant thing that springs to mind is that under the DPA a Privacy Impact Assessment wasn't mandatory. Where as under the GDPR a PIA is mandatory when there is a high risk to the rights of the data subject so if you felt this was high risk, then you would be obliged to do a PIA covering it. -
The GDPR doesn't specifically set out if you can or can't use CCTV, but some of the principles and rights you will need to think of are; Lawful Processing - on what lawful bases are you going to process the data (i.e on what lawful bases are you going to record people). The GDPR sets out 6 reasons why you can process personal data. You data officer and SLT will need to decide which one is relevant for them. The most popular that most people think of is consent, but you probably wouldn't choose consent for CCTV recording. The bases for what you are lawfully processing data will need to be balanced against the rights of the individuals and you will need to justify how you balanced this. For example if you are recording to prevent people breaking equipment, but there are no records of broken equipment in the last 12 months, you may be asked to justify why then are you recording people then. A big one that is looked at is the quality of the CCTV, if you are using it to record potential crimes to convict people, but the quality of the CCTV is such that you could never make out the person, then you will be asked to justify why you are recording on that bases. The GDPR sets out 7 principles that your data protection officer will need to work through and decide how they will comply. For example the principle of fair processing (i.e transparency is the key - are you telling people in clear terms that they are being recorded and for what purposes). If there is a data breach relevant to CCTV you will be asked to show what other strategies could you have used that didn't collect personal data, for example would security lights / street lights have achieved the same result of crime prevention. You will then be asked to show how you justified CCTV over security lights etc. Storage Limitations - you will need to justify how long are you keeping the data and if the length of time is compatible with the reason you are collecting data. For example if you are recording for the reason of protecting the equipment, and at the end of the night there is no broken equipment, then you don't need to keep the recording anymore and it should be deleted that night. If its not, you need to justify why. Integrity and Confidentially - you will need to document who has access to the CCTV, why do they have access, how do they access it, how do you prevent unauthorised access These are just a few examples that your Data Protection Officer and Senior Leadership team will need to work through and decide.
-
What actually needs encrypting?
rom1984 replied to enjay's topic in Data Protection & Information Handling
Could you use BitLocker so the staff don't need to worry about buying an encrypted memory stick (see this link for details on how to do it ... http://www.edugeek.net/forums/data-protection-information-handling/192353-gdpr-compliant-i-think-not.html ) In terms of what data to encrypt and what not to encrypt on a memory stick, I think its a bit of a recipe for disaster (unless I've misunderstood what you mean!). It would put the burden on staff to determine what is personal data and what is not, then the burden of encrypting that specific data, then you'd always get someone who didn't encrypt it or would say they didn't know it was personal data. I'd say the starting point should be enforce encryption for pen drives, unless there is a valid reason not to. If there is a valid reason not to, then risk asses that and see if you can off an alternative solution. -
The deputy head might have done a Privacy Impact Assessment in light of the GDPR and found that having staff being able to view CCTV when ever they want as a risk. One of the things that the ICO will look at when evaluating CCTV usage is that is it being used in a proportionate response to a problem taking into balance the rights of privacy of the students. They may feel that having staff being able to just look at the CCTV when ever they want is not using the CCTV in a proportionate response to a problem and thus it should be placed in a lockable room/cupboard and used when required (i.e to view a potential safeguarding issue) Quick Edit- I work for the ICO but the advice given is my own and not made on behalf of the ICO! When dealing with CCTV some of the key question that I would expect a case officer to ask would be 1) Who has access to the CCTV records / who has access to view the CCTV recording 2) Justify why the person has access to the CCTV system. 3) What's the procedure to view CCTV recordings 4) How are the CCTV recordings protected (i.e encryption, physical access etc) If the ICT Team had near unlimited access to the system at any time without authorisation I would expect the school to be able to justify this taking into account the privacy rights of the students and staff
-
"Repeat...."A management issue!" not an IT one full stop!.....!" Are all issues not management issues ICT is there as a tool to help management achieve their goals and overcome issues
-
We used a 3rd party product called Boomerang (for Gmail though). It allowed staff to "pause" there own email so staff could opt in and out on their own accord. They'd leave in the evening and pause there email, then in the morning would unpause them. It got used for 2-3 weeks and then turned into a bit of a fad that no longer gets used. Staff that didn't want to read their emails out of business hours just didn't log into them. We didn't want to completely ban email in the evening as we promoted flexible working hours for staff.
-
1. Primary School (age 2-12) 2. 700 devices (Desktops, Laptops & iPads) 3. Part Time Technician (3 days a week term time only) across 3 separate sites.
-
http://www.teach-manchester.org/Vacancies/Details.aspx?vacancyID=20064 If any one wants any more details about this job just let me know as its my current position. The trust is a small MAT off three school based in Manchester. Across the trust there is approx 1,200 students and 200+ staff within a single domain. Cheers
-
Hi, Bit of a SCCM question that I'm not sure about... I've started pushing Windows update out via SCCM and wanted to check that I have understood it correctly. I've gone to All Software updates then filtered just the updates that I need (i.e Server 2016, no expired, required etc). I create a software update group which includes the filtered updates and call it "Server 2016 Updates October." I then deploy this update group by creating a deployment package called Server 2016 updates. My question, next month when I do the Server 2016 updates for November. Do I use the same deployment package? I.e do I create a new software update group called "Server 2016 Updates November" and then deploy it using the package called "Server 2016 updates" or do I need to create a new deployment package for it? Thanks
-
Windows 10 here. I originally built a Win 10 Enterprise image, sorted it all out, deployed it but when I came to put the key in realized that our Microsoft EES agreement didn't come with the Enterprise key - it said to ring them. I put the Education version key in and it accepted it and upgrade/downgraded/did something to it and it "became" the education version.
-
Yes thank you for the reply you are right! I took the wrong switch out of the cabinet was using the 2510 when I should have picked up the HP 2920 do'h! Thanks again
-
Hi, I have a HP ProCurve 2510 with PC-1 and PC-2. PC-1 has an ip address of 192.168.2.1 /23 PC-2 has an ip address of 192.168.4.1 /23 Does anyone know how to configure the switch so I can communicate between the two devices? I've created VLAN10 and VLAN20 and added the ip address in. I can ping from the switch to both devices but can not ping between PC-1 and PC-2 Any help would be appreciated! Thanks
-
Joe Rogan Experience Waking Up with Sam Harris The Co-Main Event Podcast
-
University of E. Anglia Data Breach
rom1984 replied to Dos_Box's topic in Data Protection & Information Handling
This worse thing they could have done was send another email out asking people not to read it! I'd defiantly read it if I was told not to -
Google Chrome 'Your connection is not private'
rom1984 replied to cdwyer's topic in Internet Related/Filtering/Firewall
I had a similar problem and Lightspeed needed to remote into the rocket to make the changes. They said it was a known problem but didn't actually provide the fix to me, they said they needed to actually remote in to resolve it. -
I'l put a tenner down that only one person notices
-
Hi, Our MAT does it via a change management process. So I present any significant change proposals to the SLT/Governors - I try to keep it short and sweet and do it like this... Section 1) Introduction (i.e we use Windows 7, we've used it for x number of years etc) Section 2) Business Options: I always include staying the same then two other options to show you have looked at different solutions. So like follows Business Options 1)Maintaing the status quo (i.e no change): advantages/disadvantages of this and cost 2) Upgrade to Win 8.1 (for example): advantages/disadvantages of this and cost 3) Upgrade to Win 10 (for example): advantages/disadvantages of this and cost Section 3) Recommendations: Your professional recommendation on what you think is best for the trust/school. Sections 4) Risk Management (i.e what are the risks of your recommendations - how do we manage them. For example, Risk = Capita Sims does not fully support Windows 10 (just as an example I don't know if that is true!) - risk mitigation = confirmed working in test lab, support company confirms they will still support Win 10) Section 5) Planning (how will I trial it, roll back plans in case it goes to pot, test periods etc) If it is a big project, I normally do section 4 and 5 as a second document called, for example "Solution Implementation: Migrate to Win 7 to Win 10."
