Jump to content

GREED

Members
  • Posts

    4,102
  • Joined

Everything posted by GREED

  1. SchoolPod have a lot of special school customers, worth a review.
  2. I think the question is how did you obtain the data - was it given to you by the parent/student, or even created by yourselves (school nurses etc) - or is it NHS data that you simply access?
  3. If only paying the bills were the problem! Allow me to confirm that this is a issue related to our web-hosting partner HubSpot (who have had some issues today with a large number of their customers). THEY may have forgotten to pay some bills, I don't know... Anywho, I believe it is back up now. Our phone and email support lines are unaffected if you need to get hold of us. Regards Graham
  4. I don't know if the medical records have different stature or not so won't comment on that. However, GDPR is law and is unrelated to you being a private or state school, and unrelated to whether they pay you or not, data law overrides all of this. That bit I do know!
  5. We've had a good private chat, and have taken on board that we could perhaps be offering 'advanced' advice/instructions around this to schools where they want to not use Groupcall's security controls, and use the MIS security controls instead/as first line - which is totally acceptable. I'll share this with the rest of out senior leadership team and look to appropriately implement in future installations/onboarding. We stand by our approach given that you (the royal you) have data sharing agreements with every third party just as you do with your MIS provider that they and we are all bound by, and that approach we feel gives the right balance between convenience and access control. However we happily take onboard feedback as we have here to see how we might better cater for these requests on a platform and requirements set that are continually shifting. Very pleased to have explored this with you too @djrscally
  6. Groupcall Xpressions
  7. Understood. Just for clarity, we don’t load the entire MIS dataset into XoD. While some services might do that, XoD is dynamic in what it retrieves in respect to Personally Identifiable Information from SIMS and that’s based on the net total of data areas have been authorised across the partners you use XoD with. I think you have to think about it from the technical and practical point of view - we have a single integration with the MIS and so to service everything your schools needs from all the different third party applications; to keep this straightforward for the majority of school customers we have a recommended set of permissions that give potential to access the wider scope of data that XoD could be authorised by you to provide to third party applications. This is access too though - it DOES NOT mean that by default we read it all. What we actually do is process the data areas that are within the collective data areas that your school has authorised for all of the third parties you permit to access your data via XoD. Here is the key though - for each third party, we only process those data areas based on. So - yes there is an element of trust you have to have in Groupcall and the XOD management platform, there is no practical way around this (having an integration, and a SIMS permissions account, for each third party is not practical for you or us - we have look at this previously). However, this platform is your tool to control the data, think of it as a parent of the security layer you control in SIMS. It is absolutely not in our interest to take anything more for each partner than needed, and ultimately you control this - even if it makes the third party not work properly or fully, you are still in complete control of that. Want to revoke it completely - done. And when that is the case, data items only concerned with that party are no longer taken. You could reduce the permissions on the SIMS user account down to what you believe is represented by your current authorisations, but if you then authorised a new third party at XoD that introduced a new scope of data that wasn’t permitted by the SIMS user permissions then you’d have to adjust those and resync the relevant data with XoD before that third party was able to work fully. Summary - you can grant access to just the things you want taken out in SIMS if you want to, using SIMS permissions as long as what you reduce it to still covers the areas you have authorised for third parties. Each time you add a third party you may then need to change these permisisons. The 'better' and most flexible way is to have a SIMS account that allow all the data needed by all third parties, and then let XOD divi up the data using the authorisations you have set in XOD, which is absolutely abided by - no partner will get any data you have not authorised them to have. period. It’s worth adding too that the reason the partner is in the mix at all is because your school has purchased their software and signed a data sharing agreement with them, the XoD authorisation and even the SIMS permissions themselves, are technical controls on the implementation of that data sharing agreement and we believe that the authorisation model in XoD is robust in that respect. In fact XoD goes beyond what you can achieve in SIMS permissions because we also fully support inclusion/exclusion of individual data subjects in the feed to a third party service (where such services aren’t marked as Safeguarding products) Perhaps the instructions our team give are a little general - in that we ask for a user account with the permissions to everything that any of our partners might require - so without knowing exactly what partners you have not and might have in the future, and means you don't have to adjust the permissions in the future. Again, you can do if you want, but is easier to allow XOD to manage this as this is what it is built for. If you want a further discussion on this then we’re happy to arrange a call, PM me and we can get something set up. For further reading, check out our GDPR compliance resource centre https://www.groupcall.com/our-gdpr-compliance
  8. Because if you want to keep all those services in sync when details change, you would need to import to every 3rd party service every time there was a change. Automation saves your staff a heck of a lot of time
  9. Sorry, what have we (Groupcall) done to offend you?
  10. What have Littlewoods got to do with it?
  11. Questionable source of information in there "According to a user on an education technology forum" - very questionable source is said forum :D
  12. As you have mentioned Groupcall: Yes, all of these can be done within Messenger - can be emailed, or emailed with SMS notification, successfully for years. Also includes Exam Timetables. Over the summer we are enhancing the Xpressions parent app to ALSO be able to get at the reports archive, so parents have the choice and the repository
  13. Just to clear up a point on this: We released version 2 of Xpressions around March this year, the previous version did have it's issues due to how the data was being got at, stemming from the reliability and robustness of internet connections at peak times in schools (where the SIMS DB is held often). Not going to deny this caused some bad feelings around the end of 2017/start of 2018 which is why we rebuilt it. While there are a number of bad reviews since then, this is a LOT less than we got previously... You might be surprised for the vendor to admit this, but not going to hide this and it is rapidly improving. Further, 95% of cases where they have not been able to log in we investigate and find that details such as email address or mobile number (which are used as part of the login process) have either not been told to the school, or the school have not updated their MIS/have a typo/etc. What I would also say, is that given these sorts of apps are not optional by parents (as in, they have the one from x supplier or nothing, there is no choice), I do not see them going out of their way to give good reviews because it is a tool they are given not one they wanted to go find and enjoy. I expect this to now get refuted and lambasted but I would suggest is most of my fellow competitors apps are similar then there is some truth to this...
  14. Just remember to do as I heard recently - put a password on the spreadsheet - which as we all know ISN'T A THING! For clarity, this was nothing to do with my place of employment (for those of you that know me)!
  15. Have you logged into Xporter on Demand recently? It shows all of this there...
  16. MS have been working on this for ages.
  17. +1 Yes it is a little suggestive it needs to be an electronic system, but as above, paper is still fine. Though, i'm not sure how this is to do with GDPR, other than ensuring you keep the information inside secure...
  18. No? Can't make this a sticky as a sponsoring partner?
  19. Of course they are - lets all jump on the GDPR bandwagon *cue western banjo music* I would counter this with 'what new things are you going to be doing to protect the data in transit/destruction they you were not doing under the old DPA - and then why were you not doing them under DPA...
  20. They do a great deal of work in the Middle East and other places.
  21. Dear @MkII Thank you for your comments on the XoD data authorisation process. Allow me to answer some of your points: Groupcall work collaboratively with all data partners including GCSEPod (as they have mentioned in this thread) to ensure GDPR compliance in the processing and sharing of schools’ data. The process that is in place now between GCSEPod and Groupcall (and all partners using XOD) is GDPR compliant, both between the two data companies and on behalf of schools using these services (specifically, the data authorisation and sharing of data). The use of scoped data areas/information domains that partners request schools provide authorisation for is very similar to the methodology adopted by most of the main UK MIS providers when providing access to any API integration services such as individual products or services like Xporter on Demand. Combining the authorisation of the data scope areas and partners use of our functionality to only request specific fields from those scopes, places control over what data is being processed firmly with the school as it should be. In that regard GCSEPod is an example of a good implementation, with suppliers working together to ensure the best available data protection coverage. It’s also worth adding that some of our data scopes are for sensitive single fields only, like UPN, religion and ethnicity so that you have full granular control over them. The ability for XoD to control access to individual specific fields for a given partner is functionality that is being given careful and ongoing consideration by our team and has been for the past 12 months or so – we (Groupcall) need to ensure that any implementation of this strikes a practical and technical balance between providing appropriate and straightforward controls to schools as Data Controllers without being so complex as to increase the chances of configuration accidents or impact on education delivery. As mentioned above, the combination of the balanced access to carefully constructed information domains, along with the ability for partners to select only the fields they need from those information domains, already provides a flexible and working solution to ensure technical implementation of the written Data Sharing Agreement between the Data Controller (school) and the Data Processor (partner) is accurate and correct. The key thing is that GDPR does not end on May 25th, it merely starts! Past this date we will of course continue to make our services better and provide more compliance tools based on partner and school requirements and based on how case law and the ICO clarify GDPR implementations over the next few months. With regards the transparency you mention, we’ve tried to be as clear and transparent as possible during the authorisation process and our platform details what you are doing, agreeing to and authorising. To support that transparency we’ve also developed our free School Portal that details not only Xporter on Demand but also Xporter usage in your school, and a further update to that portal is due this week which includes visibility of data fields that are available to be processed per partner ( @enjay I think this is what you’re waiting for). Feedback is of course always welcome and is part of the continual improvement processes that make up all data protection compliance not just GDPR specifically. Hope that helps. Graham Head of Products, Groupcall
  22. Could a helpful mod or admin please make this sticky (and remove then remove this!)
  23. https://www.groupcall.com/gdpr-videos-registration Groupcall have so far trained over 7000 school leaders at 100s of events across the country. So we thought we'd share the key elements from that training in the form of short videos - available in the link above. Ahead of the big day next week (25th May), you get any final tips and advice here (because hopefully you have done something about those 4 letters already!). It's completely FREE! Enjoy
×
×
  • Create New...