Jump to content

MrWrighty

Members
  • Posts

    70
  • Joined

  • Last visited

Everything posted by MrWrighty

  1. At the moment we have a 5 minute delay before email is sent. This generally works as most senders realise their mistake fairly quickly after hitting the send button. I also wrote a script that would check certain domains for a user and would prompt them if they were sending to a domain that was not on the whitelist, however Outlook had a tendency to break the script over time and fail to inform the user.
  2. Eset Endpoint Encryption does not require a TPM chip to function. Will Encrypt, files/folders/laptops/emails etc.
  3. Has anyone a policy that defines access to OneDrive data for teachers at home. Their accounts at school sync to O365. There is nothing stopping teachers accessing OneDrive data at home or indeed installing OneDrive and syncing all their files to the home PC. I'm assuming that a suitable policy outlining the risks or stating that they are only able to access files directly via OneDrive and not sync locally should be sufficient.
  4. I have just been given a sponsorship form to sponsor a child on behalf of Cancer Research. I am just wondering how these forms now fit in with the requirements of GDPR. The Form requires a Name, Postcode, Address, Amount of sponsorship and whether gift aid is appropriate. Given the level of information being collected and the fact that these are passed around many people. I'm assuming that sponsorship forms in general may be a problem especially if passed amongst parents in a school.
  5. Surely the parent can see the other children walking around the school or in the playground. What difference does it make if they see them on CCTV footage. As long as the parents/teachers/children are made aware of the fact they are being recorded via CCTV that should be sufficient.
  6. So the Ics announce that "Elizabeth Denham welcomes the new Data Protection Act 2018 alongside the GDPR.". Are they not one and the same thing. Why confuse the issue?, its the first I've heard of DPA 2018.
  7. Just been to the Plickers website, never heard of it before now. Had to laugh at the strap line:- [h=1] "Tailor instruction with instant feedback Use Plickers for quick checks for understanding to know whether your students are understanding big concepts and mastering key skills."[/h] Great grammar used there. [h=1] [/h]
  8. It is interesting that they have not acknowledged that GDPR will override their statement "As in previous years". Previous years where different although one could argue that even under DPA, exams information should have been sent in an protected format. I would have thought that GDPR will override any other excuses for receiving data in an unencrypted format and that encryption is a must in this situation. I really do not think they get it. How do you encrypt a CD label or USB tag with the candidates name and number on it which they are asking to be attached to an encrypted device.
  9. This just goes to show there are huge gaps in GDPR. Those that have to deal with personal data and those 3rd parties on the receiving end of the personal data. I would lay the problem squarely at their door and expect them to respond accordingly. If they cannot handle encrypted data then I would say the board have failed to meet their responsibilities under GDPR. As the data belongs to your school and you are responsible for the transmission by what-ever-means, then sending unencrypted data is not an option under GDPR. I would suggest that schools adopt best practice under GDPR and send encrypted data. The boards will soon realise they are missing the point and have to do something about it. Their response is laughable. They have taken the easy way out, or so they think.
  10. Agree, that would be a good solution. Be interesting to follow the developments of this.
  11. Is it though. The reasons for requesting a DBS check will still be under strict guidelines and not necessarily open to all.
  12. Just found this regarding DBS:- [h=1]Will employers be able to carry out criminal records checks under the General Data Protection Regulation (GDPR)?[/h]Under the General Data Protection Regulation (2016/679 EU) (GDPR), personal data relating to criminal convictions and offences can be processed only: under the control of official authority; or when it is authorised by law providing for appropriate safeguards for the rights and freedoms of data subjects. On the face of it, this means that it would not be lawful for employers to carry out criminal records checks as a matter of course, unless they are recruiting for a role for which checks are authorised by law, for example roles involving work with vulnerable adults or children where a Disclosure and Barring Service check is required. However, the Government intends to legislate to authorise the use of criminal records checks by organisations other than those vested with official authority (the GDPR includes a derogation to allow such legislation). The Government published the Data Protection Bill on 13 September 2017, which will supplement the GDPR. The Bill includes provision for authorising the processing of criminal convictions data where necessary for the purposes of performing or exercising employment law obligations or rights. To carry out such processing, an employer would have to have in place a policy that explains its procedures for securing compliance with the principles of the GDPR in relation to the processing of the criminal records data, and that explains its policies on erasure and retention of the data. The Bill also authorises processing criminal records data in other circumstances, including where the subject has given his or her consent. This would allow employers to request a criminal records check where the prospective employee agrees to this, provided that the consent meets the specific requirements under the GDPR. The GDPR will come into effect on 25 May 2018. It is not yet known when the Data Protection Bill will come into force.
  13. I would have thought that in this case it was in the public interest to keep the information available, however I also think it depends on the severity of the criminal conviction.
  14. Microsoft have just gone live with their Office 365 Compliance Manager for GDPR and ISO27001 amongst others. Haven’t looked at the detail yet or whether it will be a useful tool.
  15. Business to Business or Business to School I believe is exempt from GDPR rules regarding consent. My understanding is that businesses can continue to send marketing emails etc if previously you have given them consent otherwise businesses would suffer. If the business you are dealing with is a sole trader or proprietor that is a different issue as their email could potentially be their private email and subject to different rules regarding consent and marketing. I too have receive emails clarifying my marketing choices of the back of GDPR, I don't believe this is necessary but there are a couple of cases of the ICO fining companies who breach this. I believe in Honda's case they could not prove that all recipients agreed to receive electronic communications. But these would have been Business to consumer as I understand it. https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2017/03/ico-warns-uk-firms-to-respect-customers-data-wishes-as-it-fines-flybe-and-honda/
  16. If the school has a legal need to keep data for the purposes of accounting, exams, audit trails (Legal processes) etc then this must override the RTBF.
  17. Yes I should have qualified that, it is the schools problem, but surely everyone is involved in data protection irrespective of the responsibilities. You may not have a choice but to get involved if data protection is not being applied correctly or there is a risk of data being compromised.
  18. I get the impression that people are expecting a rush of requests under the right to be forgotten. I would have thought this request would be under exceptional circumstances and will be few and far between. The legal right to keep data trumps the RTBF rule anyway. Is every Ex pupil or staff member or employee going to request their data be removed.
  19. Until receipt of said USB sticks by the relevant board, you will remain responsible for their whereabouts. Removing the restriction to appease a body that hasn't prepared themselves for this is not your problem, data protection is. If they cannot decrypt the files you send them then that is their issue to resolve not yours.
  20. Does it apply to ex-students across the board, surely it only applies if that student has left the education system and has passed the DOB + 25 years retention requirement (Secondary Schools). Parents data is a different matter and subject to different retention policies.
  21. Surely the RTBF rule only applies to staff, it cannot apply to students as there is a legal requirement to keep this data and pass it on where relevant, and if a student does come and go there should be no issue. Does keeping a record of the data you need to delete come under the data retention policy and potentially contain information about those that want their information removed.
  22. My response was to @psydii who was suggesting mounting a Shadow Copy to delete data which would be a pointless exercise if you couldn't do the same with your main backups. We all use VSS as a quick fix, but could easily fall foul of the RTBF rule in GDPR if restoring a Shadow Copy returns previously deleted data to a live system. This aspect of GDPR is poorly thought through from an IT need to have robust and timely backups kept for varying lengths of time depending on legal requirements and industry requirements.
  23. Shadow copies are not an excuse for proper backups. If you are solely relying on VSS Shadow copies and feel that editing their content in the way you suggest, is acceptable, then you need to re-visit your backup strategy.
  24. Its worrying to think that those preaching to us about GDPR have little understanding about IT services and backup procedures and the reason for keeping backups for extended periods. This also highlights that regulation and practicality have little in common. Different professions will require different backup terms.
  25. I'm in the process of reviewing backup software and how it might handle the 'Right to be Forgotten" If you need to do a bulk restore because of a catastrophic failure, then data for an individual who has requested a right to be forgotten, will be restored to the system. If you keep records to remind you to then subsequently remove that data. Even at file level restores, say a spreadsheet or document, these could conceivably contain reference to this individual, how will that work. How will the user of such data remember that this individual needs to be forgotten and remove the records again. This is very much dependant of the backup strategy, but some backups are kept for much longer that GDPR gives to remove the data under the right to be forgotten.
×
×
  • Create New...