Jump to content

GREED

Members
  • Posts

    4,102
  • Joined

Everything posted by GREED

  1. Emerge Desktop has class layouts now.
  2. This is correct. We (Groupcall) are contracted to supply software for others, your processors. We are a duly appointed sub processor, and do not have a direct contract with you, but do with your processor(s). If you also have one of our products (Messenger etc) then we are a direct processor and you would have contract with us.
  3. Do what we can
  4. I've done what what on the what now? Oh Emerge Desktop...
  5. OK no idea then. I know there have been changes to the RM data integration due to RMs switch to their new API... But off topic!
  6. Out of interest, are you an RM Integris school by any chance?
  7. The URL you want is https://manage.groupcall.com If you have XOD with any partner you should have a login, if not then yes just give our helpdesk a ring and they can sort you out.
  8. Apologies late to respond. Yes absolutely, in Xporter's School Portal, you not only authorise data scopes but can then see who has what data, where it is located, and with tools to revoke some or all access if you want. This is for ALL vendors who are connected to your data using Xporter or Xporter on Demand - which currently is over 100 suppliers (so a good change most if not all your vendors will be in there).
  9. Easy is great. Xporter (Xporter on Demand) has just as simple an authorisation/consent process. However easy over authorisation, for an authorisation-related process, I would not assume is the way you would want it
  10. Just wait, I'll send you some emails
  11. It is good that you and so many are asking these questions
  12. Please check with the vendor (i.e. Softlink in this case) that they have authorised Wonde to act on behalf of them, and to contact you. Also worth checking that the vendor has exclusivity with Wonde, or they give you the option to use either Wonde or keep Xporter. Obviously treat anything I say as sceptical, working for Groupcall and all, but this is just helpful advice. We have had reports from both schools and vendors where 'enforcing' an installation and removal of Xporter was more optional than mandatory.
  13. As I understand it, if you can prove you have followed pre-issue and post-issue procedures, then you are fine. Remember GDPR is as much about prevention as it is handling when there is a problem.
  14. Them would be the ones
  15. There will be the tin-foil-hat brigade that will. However you are right the legal requirement to keep the information particularly as a public organisation overrules RTBF. So if people look carefully, once past this legal requirement, retention rules should kick in and the information removed anyway... So really RTBF should have virtually no impact if we are all doing the job right. That said, it is a kick up the back side to actually enforce and enact those retention policies...
  16. Have you discussed this with the wife yet?
  17. Nice find. One of the changes with GDPR is active consent with personal data - and so with this being for the old DPA my interpretation is this is no longer true with GDPR. Sounds like one for Mr @GrumbleDook to take to DfE or the ICO
  18. We are all over this currently! Was discussing in the office today. You need to keep a record of Subject Access Requests and RTBFs, and the details of when/who requested. This is a requirement that sits above the subjects rights, and so you can legitimately keep a record of that because contractually you have to. I would guess though that this would a) fall into data retention territory (how long do you keep that for - and longer than original data retention requires on the original data you have deleted?) and b) not be required when you delete data due to retention rules - as opposed to RTBF.
  19. Fun conversation. So what would happen when parent doesn't want this, their kid scores the winning goal, what do you put on the score sheet like you publish for all the other events/sports teams/games etc? Smith (4 mins) Jones (51 mins) Redacted (90 mins)
  20. Indeed - and is worth following this though as a conversation. My definition of public in this case is someone who you are not in direct control of knows the information and could mention or make it more publicly available - as opposed to you know and professionally need to keep it confidential...
  21. Well, I guess if there was a child protection issue surrounding the kid who scored the winning goal (say dad is not to know where the kids are), then no. That is not a GDPR thing, this is a lot older than this. However that aside, the GCSE results are personal data items, whereas the sports results (one could argue) is public information? Give it is being played in public?
  22. Oh I know it is, I remember when I got my GCSEs they were posted in the local newspaper (not just mine, I am not that self-centred!). My question is, assuming there is no active consent - should they be? On the wall, on the website, anywhere?
  23. Saw a school recently I visited where they had students names, photos and their GCSE results (a promotional type thing it was) - thoughts?
  24. Yep, absolutely - and that is down to all the customers using XVault (and it is XVault, because Xporter is in most schools around the country in one form or another) to decide to get involved. As a vendor, they are our customers whether public or private sector, and is not for me to publicly reveal this information about them. Otherwise why wouldn't we just make public our entire customer book for all products sold to anyone in the education sector?
  25. Should probably take this offline as is commercially sensitive. Will PM
×
×
  • Create New...