Jump to content

minimoo

Members
  • Posts

    373
  • Joined

Everything posted by minimoo

  1. The concept behind the FOI act is great - it allows individuals to challenge things that they wouldn't otherwise be able to. However in a way unfortunately this also a flaw. I submitted a FOI request a few years ago - for a friend. At the time the purpose of the request was to make a point / get hold of data that might be useful. The outcome of that request was that the public body replied with personal data of individuals by accident (sure, it was only public the 4-5 hours before I saw the response and the then the 20 minutes after that it took for whatdotheyknow to pull the response). That public body told me they were going to investigate the personal data leak - whether they reported it to the ICO etc, I don't know. In that case, my '10 minutes of fun' led to the personal data of 1000 people being leaked onto the internet, and probably someone getting in some form of trouble. Whilst I understand that the case of this request is wider research, there is a 'cost' to the UK for these requests. As a scenario, I could be concerned that your research might not be portrayed accurately, as you might be biased. The easiest way for me to confirm whether this could be an issue would be to issue a FOI request to all the schools email addresses listed on edubase. From my end, that's 10 minutes work sending an email... Correct me if i'm wrong, there is nothing in the FOI act to stop me doing this - and nothing to stop any of the responders on this thread doing the same. The only thing that I believe is required is that the entities that receive the FOI requests need to respond - either to tell the requester to go away for one of the exemption criterion or to provide the data requested. Scale that up to a silly level - if the 65 million people that apparently live in the UK did the same as yourself and chose to make a single FOI request to all UK schools for something they care about (fsm/pp/funding/parents/etc/etc) - and a school could respond in 1 second to any given request - it would require a single person working at each school 24/7, 2 years to respond.
  2. Gonna need to jump in here - emails containing random excel/word templates as attachments as FOI are probably more of a risk than a web form. The "solution" here is probably to request that people fill in a text template that can be parsed electronically e..g tell me about X? ------------------ my answer about X is Y ============== I'm thinking ASCII doc / markdown type concept here. Something that could be parsed by a computer (e.g. email response) and store evidence/record for the user sending
  3. Hi Guys, I was wondering what responses I would get. The reason I posted my scenario was to get people thinking, and thinking about risk. The angle I was going was that the family member could access the data, and do something with it. So whilst there may not have been a breach in that scenario so far (or maybe it still is - hopefully one of the GDPRiS guys might jump in on that comment with a view), there's a risk that the child could access the data and share it. Some teachers have children who go to the same school - so their son/daugther might see data about another child in the school for instance if it's left lying around. If you look back to last month, the ICO posted https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2018/02/former-council-worker-fined-for-sharing-personal-information/ - an apprentice at a council who took a screenshot and shared it via snapchat. OK, a bit different but if the sibling can access the data from the headteacher, see's it is about someone in their school, would they be tempted to show a friend? I'm assuming the point of the training session is to get people thinking about data security and what could be a risk - and using your home pc probably wouldn't be something most staff would necessarily think about.
  4. You check your school emails in your home computer. You have a password to log on to the computer that you and your family share. The headteacher has sent an email to you with an excel attachment. You download the file to your documents. The file contains behaviour information on students, which you update an email back to the headteacher via the school's email system, which uses HTTPS so the data transferred over the internet is encrypted.
  5. @bmaloney - thanks for the reply. I will check that our trip/medical forms ask for agreement from someone with parental responsibility - or how we word it. As you say, the medical form should be someone with parental responsibility. Obivously doesn't deal with the case where two parents might disagree (but arguably that might be down to the NHS/equivalent abroad in the advent of a medical issue. In an emergency (A&E) situation, I understand the NHS will treat people without consent for obvious reasons
  6. I asked the above last night, so just to clarify, there's been no suggestions made today for anything that school could do now ( assuming they are following current guidance from the DfE, which I believe seemed to state that shools should get details of both parents, but that it's not neessary to check birth certificates). I can only assume then that any future improvement/changes here would need to go through a legal loop; something which I'm not familiar with.
  7. Those are available from FOI to the DfE - there's 23699 email addresses in the file at https://www.whatdotheyknow.com/request/list_of_all_public_email_address .
  8. @bmaloney whilst the discussion on FOI/ICO is interesting, and i've just spent 10 minutes reading all the responses today, and debate about the cost of FOI requests. I'd like to try and steer conversation briefly to what I thought (in my mind at least) i'd tried last night. I assume you are collecting this data as you think/want a change in what the DfE / SChool's / LA's do around parents. I know that the DfE have issued occasional guidance for schools ( January 2016 - understanding and dealing with issues relating to parental responsibility for instance), and i'm sure I remember another document. In terms of changes to law, those would obviously need to go through the appropriate process - however, are there things you would like to see schools doing 'now' that you believe schools could be doing now, without falling on the wrong side of existing advice/law. My reason for asking is with the GDPR and school's taking a look at their policies around data, it would be good to hear suggestions... At least, I'm assuming that there is a purpose for a change behind the data collection...
  9. @Cache - I think my point was more, IF it takes 5 minutes to trigger the update on 500 workstations, whether I'm at the front or the end of the queue doesn't matter; It can take a minute or two for the agent to detect the install has finished. I always make one of my first tasks after logging in to check that a teacher can still log in - there was one update once where capita either broke the 'take register' box on home page or changed the permissions; I could use sims fine, the 90 teachers couldn't in the morning - sims crashed on them. Since then, I always find a member of staff to make sure everything is happy. I guess it all depends on what is important to different people - but I waste a lot longer in a day on sims then I do with the actual bit you can prioritize on a workstation deployment.
  10. two further thoughts: a) I wonder if there is requirement for an organisation (for FOI/other purposes) to have an email address. i.e. could schools have a web form that all correspondence goes through and not have a public email address. That would protect from viruses etc b) Something that might help bmaloney's case - under the GDPR if Parent A completes an admission form and is asked to list personal data (i.e. name + address + contact number) of Parent B, does the school need consent from Parent B
  11. @bmaloney - "I am a tax payer and schools are funded by people like me." - I suspect you didn't mean to come across, but that came across as quite rude to me - please do remember the people employed by schools are also tax payers. In terms of the web form - I believe the law states "an address for correspondence"; whilst I think most people would be happy to consider 'an address' in the digital age with live in also to include an email address, I guess the question here is whether a web url is an address. After all, it is hard to have 2-way correspondence with a web form. Then again - I'm equally amazed that you've had schools phone you up demanding an address - I'm surprised they've got the time! You mentioned birth certificate - the DfE try to steer schools away from requesting to see birth certificates: https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/389818/Free_School_Admissions_Common_Issues.pdf Once parents have been offered a place for their child, you can also ask for proof of birth date, but you must not ask for a ‘long’ birth certificate or any other documents which would include information about the parents. https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/389388/School_Admissions_Code_2014_-_19_Dec.pdf Once a place has been offered, admission authorities may ask for proof of birth date, but must not ask for a ‘long’ birth certificate or other documents which would include information about the child’s parents. https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/271552/2014_Spring_and_Summer_School_Census_Guide_for_primary__Version_1.1.pdf Full legal surname as the school believes it to be (Schools are not necessarily expected to have verified this from a birth certificate or other legal document). And the 2016/217 census documentation (where the government attempted to start asking for country of birth /nationality ) states a similar line. I'd be interested to hear your ideas on whether schools should be going further to obtain details (I know in our case, we ask for parent details on admission forms / data collection sheets etc - but then it's down to the person completing the form to inform the school.) And the guidance on birth certificates looks quite consistent from the DfE above, and what method/approach you think they should use to do this given the above. @jenatddm - guess you've got a view on this too ?
  12. @Esteban_Child_of_the_Sun the priority feature is pointless (imo) for a single school. We deploy solus to 500 PC's (and having pre-staged) the update, it takes about 4 minutes for the log file to cycle through pushing the update out to the 500 pc's. Given that, you would spend longer trying to prioritize the PC's then you would save by the end of it! If the solus 3 console states that the update takes about an hour for us; 20-25 minutes is doing the DB updates, document server etc - a fair chunk of that time made up by '2 minute waits'. 5 minutes is spent deploying workstations, and 30 minutes is spent waiting for a timeout of failed workstations. In terms of 3.12.41 being the last major update, I'm definitely not surprised there. In terms of features that is. I do think capita needed (and still need) to spend some time on optimizing the process and fixing the flaws that stop people using solus effectively for a deployment.
  13. I've been to a few of the London macadmin group meetups recently ( London Apple Admins) - in terms of the parallels / sccm stuff, observation I've made from comments seem to be the universities have stayed away from that route. There was a whole talk on some of this, and using the best product for the best job i.e. don't put your windows stuff on jamf and don't put your mac's on sccm (whilst you can, they just aren't as good for the task apparently) at the last meetup they had a few weeks ago was quite good on this topic. I'll try and find out where videos from that event are. I know a reasonable about of linux, so went down the route of munki + and separate profiles/scripts for tasks I wanted to complete - has worked OK for us so far. Some of the guys behind https://datajar.co.uk/ seem to also attend the london meetups, and they offer a cloud based munki/jamf/mdm solution for management in several educational institutions
  14. do you have AV installed on the box ? I'd be inclined to see if you can disable that it sounds like its 'waiting' on something (a failing hdd would fall into the 'waiting' category) - however conflict with some out of date file system filter driver would also make some sense.
  15. Not an impero user here, and whilst i've not yet implemented anything - i'd been having a look at what windows does e.g. Group policy - Computer Configuration, Policies, Administrative Templates, Windows Components, BitLocker Drive Encryption, Removable Data Drives -> Deny write access to removable drives not protected by BitLocker. Sophos AV which we use also has options - but i'd probably trust Microsoft to implement the protections more reliably than sophos/impero personally.
  16. I don't know what other schools do, but if they are anything similar to us, I can see photos/videos of children coming up in the following ways: a) School MIS storing a photo for identification purposes b) Recording / Photo taken of something in a lesson c) Recording / Photo taken at a school trip / school event d) Group Photograph taken when students leave school (the sort that photography companies sell to parents) Equally, we've recently pulled some photos/documents out of an old school archive - e.g. photos from WW2 of students being evacuated, an old film of someone in royal family at the school, whilst the electronic sharing of information so readily these days is a problem - I do wonder if in 30-40 years time, we might also regret that some things haven't been kept. And just to clarify that statement - for A above, sims should really have a method to batch remove leavers photos ( the purpose was for identification, after the student has left you generally don't need to be able to identify them. Unless you argue they are part of education record - but then that's name+photo together nicely), for B - there's probably often not much value to keeping in general. I'd suspect that particular category is out of laziness. Where i'm thinking of crowd is for C/D: a) Students go on school trip with staff, as a group they share photos with each other on file server of the trip b) school has a event where photos/recording are going to be taken e.g. concert. Presumably in this case, signage/a line on ticket/invitation stating the event is being recorded would cover any photos of the audience, and having a consent form for students doing music/drama that by taking part they will be consenting to the recording covers that.
  17. mm, doesn't the context matter? I've previously seen/read somewhere that photographs of crowds are not classified as personal data, providing no one person is the focus of the photograph. If you cropped a group photograph to a single person, it would then become personal data and subject to the original DPA. [edit: although references I can find atm tend to take the view that school groups are personal data]
  18. I'd offer to test that scenario tomorrow as i've still got original case open with sophos but we use the script method to install the client. When it's in the 'install active' state, is the solus installer showing as running task manager? and do you have an agent installer log you could send me? I can probably try a agent push install as a test if needed.
  19. Where i've asked sophos to close my case (as it's fixed), i've just added a note to it with that response as it would seem they haven't quite identified all affected customers - so bouncing queries seems a bit silly. From what i've seen, i'd be pushing for the update even if I don't run sims - the Hitman pro update has fixed issues I had been seeing related to Microsoft Office, Netsupport, Sims, and Smart so far. In terms of Jan and upgrading sims - you could probably wait - at least Jan census isn't learning aims etc - and office staff might like a break over xmas !
  20. "We have now released a new build of HitmanPro.Alert (3.6.14.616) which will resolve the upgrade issues identified within CAPITA SIMS and/or NHS CRS. To confirm you are now running the correct version please check the details tab on the file C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe A special release process has been completed for this release. Only customers who we have deemed to be affected by these issues will have this update. This will continue roll-out in the new year and all customers will have this update on the 9th January 2018 (Subject to change) If you have noticed that you do not have this update please contact Sophos Technical Support for further assistance." Although reading that, whilst i'm a single school, If I was an LA, I'd probably be inclined to wait pushing lots of schools until the 9th January now - at least, I wonder how they've determined what customers will be affected; as not all schools run sims, and presumably not all sims schools have been in contact with them.
  21. The new version will >= 3.6.14.616
  22. I've asked today - "The version number will be 3.6.14.616, you will need to check the details for the hmpalert.exe found in C:\Program Files (x86)\HitmanPro.Alert to confirm this." Still planned to be coming out today but they will be updating when it's complete. And on that note: i'd wait a few days before doing anything with sims to allow enough time for the update to hit all the workstations.
  23. did you hear anything interesting?
  24. Whilst you say they only say "pupil records" - to be fair, they also list out other information under the "Pupil data (within MIS)" category: Pupil records Safeguarding / Child Protection data SEN EAL Exclusion, behaviour Reports Examination results / Statutory Assessments Attendance registers Student photos Hopefully one of the others who have been getting legal advice can speak up here - but i'd hope the purpose here is to identify the general theme of the data e.g. pupil records / SEN - as opposed to listing out thousands of individual fields. Whilst "pupil records" is particularly vague, I'd like to hope that "Pupil Records: Basic details of the pupil e.g. name, address and parental information". The sentence that I've written there is quite similar to what the DfE have put in their updated privacy notice at https://www.gov.uk/government/publications/data-protection-and-privacy-privacy-notices
  25. LGfL published their template @ https://www.lgfl.net/ct?name=Online%20Safety%20Resource&url=http://static.lgfl.net/LgflNet/downloads/online-safety/LGfL-GDPR-Data-Audit-Log-10-2017.xlsx&source=Online%20Safety%20Section They've also filled in some data that schools might store e.g. Staff personal file until Termination of employment + 6 years as an example. I know there lawyers + ICO office was having a dialogue, so whilst only examples, I'm equally assuming that either a lawyer or the ICO believe that might be good example data.
×
×
  • Create New...