Jump to content

mjk

Members
  • Posts

    938
  • Joined

  • Last visited

Everything posted by mjk

  1. here is a free encryption addon for google, useful for key staff - senco etc https://flowcrypt.com/
  2. I wouldn't mind betting there are some GDPR 'consultants' out there trying to ban Royal Mail as we speak.
  3. Ever get the feeling we might be over thinking this?: we don't encrypt paper copies and seem happy enough using the same postal system that we do for the USB/CD's. As the AQA said - it's not a requirement and there is no more risk of anything getting into the wrong hands being on USB/CD.
  4. For those that don't want to faff around with educational licensing with winzip, or cannot use Bitlocker (macs, older windows): I can confirm that 7zip is a good opensource alternative that will create files that can be opened in winzip. Just choose zip and AES-256 as the encryption method.
  5. 0 */1 * * * will run every one hour. If you put the script in: /etc/cron.hourly/ it will do the same thing and you won't need the cron config. Remember to make the script executable chmod u+x /etc/cron.hourly/script.sh
  6. Run it in a container and nobody cares what the OS is, with the added advantage of being able to fail over to cloud systems. - - - Updated - - - here you go: https://hub.docker.com/r/farfui/3cx/
  7. please could anybody help with these questions: 1) If a school has a contract with a company who shares data with a third party, does the school need to report that they share data to the third party ? An example would be that the school contracts it's MIS data to Capita, and that Capita store their data on Microsoft and Amazon's servers and then subcontract the support to another company. When we report to students and parents, do we say that we share data with all of the companies - or just Capita. (this is a hypothetical scenario - I've no idea where Capita host their data). 2) If a school subcontracts to a third party who does not hold data, do we need to report to students and parents that we share data with them. An example might be an engineer who would remote in and have access to data but would not store or copy the data.
  8. That's very interesting because the DfE document seems to be quite clear that only a small amount of information should be retained for 25 years. I'm genuinely interested because it would save us a lot of time if we are able to keep all information this long. Do you have any legal advice from you MAT's lawyers that you could share with the forum - it will certainly help others out!
  9. I'm sure a lot of Chromebook schools have been waiting for passthrough wifi authentication. https://chromereleases.googleblog.com/
  10. That's not entirely accurate, it depends upon the type of data. See the document that I linked to in my post above.
  11. See the annex of this document: https://www.gov.uk/government/publications/data-protection-toolkit-for-schools There isn't much on holding behavior records past a year, but you can certainly hold safeguarding info for 25+yrs. I'm not sure if restraint would come under safeguarding?
  12. We've had no problems with reliability.
  13. Sort of, it replaces the network drive with a "G" drive using file stream.
  14. ssh into it and 'show running-config' sorry I don't think I read your question properly before replying
  15. I don't think it is a reasonable request because it would become impractical: If I have 3000 parents and some don't like Google, some don't like paper, some don't like open source and some won't use propriety I cannot be expected to create an ad hoc system for each parent: thus (as @Edutech98 pointed out) the data would best be processed under a legitimate interest.
  16. OK - I understand what you are saying now: that the OP shouldn't ask for consent because they already have a legal basis for collecting the data and the parent can go whistle.
  17. None of these points are talking about the system in which the data is held so they are irrelevant, rather they are talking abut consent around how the data is used (who it is shared with). You are misinterpreting the law if you think that you can dictate to institutions the systems that they use, that's not what the GDPR is designed for, nor how it can be used. I absolutely can guarantee you that (as a parent) I cannot make any institution hold data about me only on paper or system Y and it's ridiculous to suggest otherwise. You might be getting muddled up with offering alternatives about storing biometric data - where you would offer an alternative because the student refuses to give the data - but it's not about the system.
  18. No they don't. I'm not sure where you got this idea from. I want a driving license but I'm not going to let the government store the data in the DVLA system - fine, don't have a driving license.
  19. For Desktop virtualisation we now use RHEV. It's been pretty good so far. There are free versions but we went with fully supported: https://www.redhat.com/en/technologies/virtualization/enterprise-virtualization
  20. we had to ditch Citrix as their new pricing model would have cost us £20,000 per year. Shame as we've been a loyal customer for over ten years.
  21. Problem is that you'll likely have to collate the paper information into a different system, like a google sheet ! Where does it end though? You might get another parent who has an aversion to mysql databases, or msofficephobia !
  22. If the parent refuses to let you store the data, don't sell them a ticket. Put it in the T+C's of your paper and google forms.
  23. I think that would be a problem with the security settings on the legacy system. If any user can get any sensitive information out of the legacy system they's just email it out. Need to tighten up how the users get the sensitive info into the system in the first place. I've heard teachers claim this, but when management actually did an investigation they found it to be a non issue from some whiners. Our department ( ITSupport ) had to convert a handful of files and the problem went away. That's not a surprise for microsoft to remove a nice migration path
  24. Agreed. I'd be inclined to install powerpoint viewer on the school machines to help get across the point that these documents are legacy and staff shouldn't be creating new ones.
  25. I've not found it to be quite that bad but I think you should check my earlier comment: 1) chose an online suite such as google/office etc 2) prevent documents being downloaded What you've done is: 1) chose an online suite such as google/office etc 1a) continue to use the old system 1b) have a mismatched system 2) get complaints because you have mismatched systems 2b) not get the benefits of either system I'm not saying it's your fault as it sounds suspiciously like management had their hand in this one; but at the end of the day if you're using Gsuite then you really need to start enforcing staff to create documents in it and treat Powerpoint as legacy.
×
×
  • Create New...