Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

mthomas08

Members
  • Posts

    3,240
  • Joined

  • Last visited

Everything posted by mthomas08

  1. What is troubling,.. some schools/staff will believe this rubbish and sign up. Just like quite a bit of 'extra' services that have popped up recently. Just stick GDPR compliant or 'must have'.... you've got a sale... And people will buy it...
  2. No. Simple really. If you have taken precautions in training staff on password/security. You do not *need* encrypted emails. Nothing stops you from using it, it's extra security but at the end of the day.. you don't *need* it.
  3. Our data protection officer sent this to all staff first thing this morning. Great example and let's face it.. there will be more. This is a fantastic (sorry I hate to use the word) example on why being relaxed on GDPR is WRONG. "We take data protection serious" then please explain why this USB was not encrypted? please explain why this USB contained all that sensitive data? please explain why this staff member had and lost it? did they have a data mapping setup? do all staff know about GDPR? We all know school politics and I see failings/ignorance of data protection because it won't happen to us. I wonder if they have a trail to prove they are 'serious'.. I hate to say this but I hope they get a fine to be made as an example. Still "no reason to believe the information has been shared"......maybe they have that Mission Impossible software that tells the user "data copied"... because we've all got that..
  4. For those who want to consider not encrypting USBs: https://www.bbc.co.uk/news/uk-england-kent-44371759 We encrypt all our staff laptops and USBs, without encryption staff can't write to them on site. We also do quite a few emails, weekly news and reminders in briefings to staff by SLT. It's important not just for encryption but to be aware of what data they have and where. It will be interesting to see if this school is fined. Although they have no reason to believe the data has been copied or accessed.. there's still that possibility though. I see a lot more cases like this appearing because we can no longer sweep it under the carpet. At the end of the day it's your schools decision to be safe or not.
  5. We was told to put them in our policies because they are external/cloud based of data handling.
  6. All our students know that their activity is monitored and logged (it's in our school policies - especially the AUP). Not everyone has access to the software, each person knows what it's for etc. We've even got the AB Tutor compliance.
  7. Not sure if I want to laugh or not. You'll find there will be parents/students who takes it serious and know what their rights are. We've had biometrics for a number of years and I can tell you... those parents exist and will push their legal rights with threats. I can imagine what would have happened if we didn't follow compliance and asked for consent before we switched to bio. Still if you don't care and willing to carry on.. fingers crossed your school doesn't get fined.. costing some ones job.. Exactly. And the more parents/students start to understand their rights....
  8. 0 here as far as I know. Considering 100% of all data requests I've seen are from companies that wanted our business (by chucking the freedom of info act in our faces like cheeky beeps)... I foresee us getting 0 for a while because we wouldn't have agreed to OPT in their emails to begin with. LOVE IT.
  9. Exactly. That word will be used a lot.. just because some one thinks they must have it.. doesn't always mean they need it. And what legal reason do they need it? to confirm their child has done wrong.. that's not a legal reason at all.
  10. First you'd do an investigation to work out exactly what data was lost, how it got lost and people responsible. Then if it contained say... a full name, DOB and addresses.. that's quite serious.. and I'd class that as a serious breach - considering police interview recordings have been reported lost and fines involved.. (not all are video based). If you lose simple work which doesn't contain personal data.... well.. that's nothing to do with GDPR because you can't ID anyone.. that wouldbe down to the school and (I believe) educational authority..
  11. - GDPR isn't just about electronical data, he/she will still need to understand what other jobs involve. This includes personnel, finance, attendance, SEN and data managers. - GDPR is about understanding all data and IT knowledge is a bonus not the priority. - Does the technician have administrator access? As a DPO & techie he/she would have keys to everything electronically which is questionable and could seriously be a conflict of interest. Main reason why we can't be the DPO is because of all the 'god' access we have. If your techie has the same level.............. he is no different to an NM..... the conflict of interest isn't about 'budget planning' or that you build/install a server.... it's about the data related issues.... it's about data security.. access to the logs.. the backups.. the data areas.. we really do hold all the keys (so do all my technicians). - Discuss with a union because the technician would have a altered job description/contract change? So technician could refuse - causing a restructure of the IT techie job by the HT. - That Technician will have the authority to investigate every member of staff and have the final say on what's considered to be breaches etc. This means he/she can over rule the HT on DPO matters. - Also the authority to risk assess and tell people to be safe etc - Able to raise matters with the Governors. It's possible but JD/Contracts need to be resolved between employer/employee along with the conflict of interest roles. Remove administrator access, remove the techie ability to have data access - effectively just another member of staff... P.s. Ask your self this.. would he/she have to investigate their own position... I'm assisiting our DPO but I can't be it.. I can help make sure my guys are following simple staff procedures but also.. we take extra care because we are 'gods' of data.. likewise for the Data Managers etc. There are currently about 15 staff here that can't be the DPO and my team are 3 of them.
  12. I don't think it's old fashioned at all, I think it's cost effectiveness and at a time when Schools are having budgets squeezed... are laptops the right place for teachers... but it's all down to preference and if that school can afford it. We used to have laptops here and it was scrapped to save money. -Windows Surface devices I think are fine and apparently there is a cheaper model coming out soon? With office 365 you've got a great office package which is quite simple to use etc. And if you're still a M$ Vanilla network, the backbone etc is there already. We rolled out android tablets to staff a little while ago to assist with student devices.. didn't quite pan out well when staff wanted to treat them like M$ machines with all the software. Our investigations found that 90% of what we currently had didn't exist in an App form, online based or the cost of buying new software was too high (plus training). So we didn't continue.
  13. Good question.. I guess you couldn't edit the video in such a way to blue out the other faces? That parent won't know the other students names so that's something. I believe our policy will cover this but not too sure... The parent is being shown the footage due to behaviour (and it's their child), as long as the parent isn't recording it and your school CCTV policy is covered by it.. should be fine but in all honesty it might be good to blur it out if possible? **update** According to our DPO who did the GDPR training - the question came up. Apparently we shouldn't be showing it to the parent with other students fin clear view. So now... I have to look at blurring if it's needed.
  14. DDOS attack? Some angry small business owner is .... doing something because they had to close? Some one pressed the wrong button? OR is it.... everyone has hit panic stations and decided now is a good time to sort out GDPR compliance?
  15. I like you. You are a dreamer No seriously though if only! For the OP: good question. If steps are taken to be secure e.g. staff only area. You've already done one major step to be compliant. We have two sets of pigeon holes, an area for SLT with staff who deal with sensitive data and another area for departments in general. The sensitive pigeon holes are in the main office which is locked when empty. The main pigeon holes are in the staff room. Our auditor didn't pay much attention to it though if any.
  16. I think it's time to start giving them examples of the type of fines occurring. I'd also do my own risk assessments that if a potential breach occurs you will have no choice to report it. I was able to do a list and present it to the DPO.. it was long.. Although I doubt the fines will be huge for education, it will occur and it'll be in the sum of £100K+. And even worse if it hits the press/social media. On the GDPR training there is a big bullet point on "Need support from SLT". I could send you a copy of our data mapping spreadsheet. I've worded it in a way that makes sense to me and the DPO while still understandable by a GDPR auditor. PM me if interested. I'd look at getting an auditor - don't know what any tools are like, we didn't use them but the audit was incredibly useful. We got a report simply stating we are on course very well to be GDPR compliant. The things we are finalising should cover us being compliant. We just have to continue to prove we are covering future angles, new staff training and refreshers, while also doing site walks to double check people are listening and understanding. Edit: I'm surprised the LEA DPO don't seem to be that bothered? you are paying for a service? yet not getting one? 48 hours to respond when there is a 72 hour time limit for reporting breaches? giving them 24 hours to do something about it? Maybe shop around and see if you can get something better... the DPO in my view should be there telling the school to get their act together. And you'd think they would listen more to an LEA DPO if they refuse to listen to you.. you've got a challenge though..
  17. I heard something like this a little while ago - one of those things that never got confirmed or denied... No matter what - have a lead on data, DPO or something similar. This covers you. Our SBM is still the DPO and we've still NOT got a definite answer he can/can't be it (even though he's line manager to multiple data crucial staff/areas). The one thing that popped up was to separate him self when needed. I think the best thing to do is have a leader as a DPO or similar. Show you are moving forward and working towards GDPR compliance.
  18. I think they need to calm down a bit. Basic personal data is okay, classrooms and marking books to take home are fine. What you need to be doing though is training staff to lock classrooms and be vigilant when taking bits home. Course work will have full names but nothing more and they will be in classrooms which should be locked when not in use anyway. They can take folders home and the majority of it again will be full names only. Be safe, be secure and show you are educating staff. The sensitive data is when you start some tougher stances on security. Do they leave them laying around for all to see? Do they have endless paper copies that they don't need? (insert the legit reasons). It's not about stopping them from doing their job but it's about safety/security and awareness. The teacher won't get strung up for leaving a classroom unlocked and a visitor stole the course work... and the risk/breach factor is very minimal.. but they should get a little talking to about locking the classroom.
  19. Not sure what we pay but it does cost us. Wouldn't surprise me if they increase costs if they are taking more collections.. which for us.. certainly is the case.
  20. Don't necessarily need a product like this. If IT have taken steps to secure their systems or collected GDPR policies from external email providers, add some staff training on being cautious/secure. It's all fine. Our auditor asked some basic questions regarding email and our system updates. He seemed happy. We even do the occasional email to all staff as reminders or with the internal weekly news bulletin.
  21. Good questions: For all sensitive personal data (photos being a prime one). The DPO could do a risk assessment, get consent and add it to the school policy. Is the company GDPR compliant? they should be able to send you their GDPR policy. Once you have consent and both sides have a policy. I'd say that's all good to go. If the company doesn't have GDPR compliance??? Can you imagine if they lost printing for your school that contained name of the child with a photo, name of parents and addresses? The school will have to report it to HT/Governors and the ICO. Questions will be asked of the company and the school. One could be "did you check that the company is GDPR compliant".. now that's where the school could be in a little spot of bother.. you would have two choices... admit that you was aware they didn't have GDPR compliance and continued to do business with them or didn't ask. It's one of the many reasons we are getting emails asking us to OPT in and that companies are informing us on their updated policies for GDPR compliance. Cover your bottoms, cover your bottoms and cover your bottoms If they are printing basic stuff with no personal details, I'd still get a copy of their GDPR policy (as part of our supplier company list that have staff contact details) and voila done. **Update** Just read through a bit more. Photographs can be owned by the company (usually a small business owner) until you purchase them, get GDPR complaince policy and the school policy should already cover image rights etc. You may need to tweak it. A useful common sense practice on events or photography classes is to ask students if they wish to opt out of the photos they can. Making sure no one else is clearly visible without consent. Consent, policies and compliance We have probably been a bit over cautious here but in fairness we've managed to get about 90% compliance because of it.
  22. Exactly. This is why data mapping is very important. You need to know from every staff member where personal data is located and especially sensitive information. Got to ask the questions: Who needs it, who has access, is it secure, have you got consent etc. I hate to say this but we need more examples popping up. It is the only way education will learn because there are schools that are STILL ignoring GDPR or others not taking it serious. The real silly part is... we are doing what should have been done under the Data Protection Act which is what 20 years old now.. Data is treated without care and using a basic scare monger tactic (I know it's not the best) seems to be working for us. We have leadership on board and presenting power points to staff by the HT with basic bits really helped. You know it's working when staff are sick and tired of the term GDPR and our paper shredding has gone through the roof!
  23. Basic practice needs to be considered: if a data breach has occurred, surely some one will be investigating it? Unless the school is completely closed and no one is reachable.. well technically no one will know about the breach anyway? Whats the procedure for a fire or a break in etc? This is a question we have not been given a direct answer on either but the ICO seems willing to be flexible according to their videos (not answered this particular question though). Not sure how many schools do a complete shutdown throughout the holiday but in my experience there is usually an SLT member on site enough to follow procedure?
  24. If it's covered by the school policies and/or consent e.g. School website/learning platforms. You 'should' be fine. One thing the audit didn't bother with was the names on our school website but we are about to ask the question. The generic response we tend to get is "why we do it". If it's not a viable reason and we don't have consent.. I WILL CHASE THIS ONE!
  25. Curious to know, how much each iPad cost? and what age range and type of behaviour are the students? Assuming all the staff also have an ability to link up to their projectors? Was there also the 'infrastructure' cost?
×
×
  • Create New...