-
Posts
12,876 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by GrumbleDook
-
It has been a while since I popped in a went through my reading list and TBR .... so here is a lengthy one. I've been going through quite a few things ... some series are finished and some have more sets to go. I've been rereading my collection of CJ Archer stuff, followed by Ryan Kirk (absolutely fantastic person ... gifted me some of his audiobooks!), Sarah K L Wilson's Dragon School series (Just finished book 15?), reread Ben Aaronovitch's Rivers of London series so I then dive into Stone and Sky, Jon Cronshaw's The Ravenglass Chronicles (up to book 9), Graeme Parker's Bruised Sole: The unfiltered Story of The Hoof GP (still ongoing, CN Crawford's Dark Fae series (book 7, I think), a bunch of Brandon Sanderson, Jill Bearup's Just Stab Now (finished) and now reading Andy Peloquin's Darkblade series alongside Elisabeth Wheatley's Daindreth series. I've probably missed off a few others in there, some audiobooks and stuff. The other thing I have really enjoyed is this year's Big Read from The Tolkien Society. A wonderful book club reading of The Hobbit and now onto LotR, followed by hour long lectures once a month from noted scholars and Tolkien lovers, and then 1/2 hour discussion between small groups of different members. I know the recordings will be online at some point, and if you are a fan then it is worth watching some of the older recordings on The Tolkien Society's YouTube page. Looking forward to the final Thursday next book coming out from Jasper Fforde, and until then it will be finishing off some more series, and diving into my heavily reduced TBR pile (I culled it before moving house in Jan).
-
I've been through quite a few books and audiobooks over the last few months and whilst some of it has an element of comfort reading, some has been to pick something new. I really enjoyed getting into Marcus Lee's The Chosen series (5 books) and have a few other books on my TBR pile now too. Ryan Kirk's Nightblade books/novella are really enjoyable third of fourth time. Then some comfort reading with Raymond E Feist's Fireman Saga, though I am still not 100% sure I like the ending. Dipping back into some romance/romantasy with a smattering of different books from various series ... a bit of C J Archer (Cleopatra Fox), JS Kennedy (Mackenzie Green) and C N Crawford (Shadow Fae). I've also been reading/listening to Jon Cronshaw's The Ravenglass Chronicles (nearly at the point of book 10 ... will then take a break for a bit) And over the weekend I picked up the latest Ryan Kirk - These Fallen Swords - as an audiobook. He had a prize draw and I got one of the promo codes :-) So that will be my next one. In between these I have been picking at Bruised Sole, and autobiography of Graeme Parker (The Hoof GP). A very emotional and poignant read so far. My TBR has only increased by a few though ... moving house has meant I have had to curtail a fair chunk of buying extra books. I did pick up the complete bundle of Elisabeth Wheatley in the Black Friday sale, so I have 35-40 books to get through there!
-
When I saw the bit about routers ... I had horrid flashbacks of having to collect a few hundred of them from schools, and then flash them all before they could be disposed of.
-
Coronavirus: General discussion (see opening post for rules)
GrumbleDook replied to Dos_Box's topic in General Chat
I get a free flu jab now, as have had Covid 4 times and it has affected me and it puts me at risk. I won't get a free Covid jab though ... I am not a high enough risk to others. -
The ICO has a history of engaging and working with public sector organisations rather than fining. However, the PR aspect of it is likely to be quite a problem, as well as open the school up to complaints. Even if the school ask for consent, it is unlikely to be considered as 'freely given', as without access to the additional services then the children whose parents refuse to give consent may be affected adversely, not having the same level of education as the others. This means the school is effectively forcing parents to give consent. There is no clear answer on how it can all be made to work, but the larger priority for schools look to be around managing their supply chain, incident management and transparency.
-
Just to clarify on this, the reason you need consent on this is due to Google's terms and conditions for the additional services. For the additional services Google is a separate Data Controller. They will used the personal data for purposes *they* decide on. This has been discussed with various folk at Google for some time and for the bulk of schools they will need consent for the additional services. The post from Hwb was talking about the Hwb additional services, which included Google G Suite for Education ... *not* the Google Additional services. The previous advice from Hwb, IIRC, was that use of any additional integration with Hwb (M365, Google, etc.) may result in needing Consent ... and that was partly due to the additional services. When looking at any SaaS, not just Google/Microsoft, if they say they will use any personal data for their own purposes, then they are becoming a Data Controller in their own right. That is what the law says. Moreover, they now also have to comply with the Age Appropriate Design Code ( aka The Children's Code) as the relationship is directly between the child and the provider of the additional services requiring consent. This has been discussed with the ICO policy teams, with DfE and with numerous children's rights stakeholders. The DPO is right in this case, and if anyone wants the warts and all for the above discussions I'm happy to talk to school DPOs and others about it.
-
DfE - Protect and Prepare - SCORM
GrumbleDook replied to Alastairb25's topic in Virtual Learning Platforms
There are LMS tools that can hook into M365 that play SCORM content. IIRC Learn365 is one, but there are others ... the problem might be cost though. -
Declaration of Interest - I have done some work reviewing SLT AI works and discussing it with the founder. I like SLT AI. They have taken the time to look at the quick info and other tools SLT needs, and work out the best way of using AI to siphon through it without it causing problems. Yes, you can do this yourself with enough time and tools, but you can say that about almost everything. As with other tools over the years, to some extent you are paying for the fact that someone has had the expertise to put together a solution. If it saves you time and lets you get on with other things ...
-
The Data Use and Access Act 2025 (DUAA)
GrumbleDook replied to Alis_Klar's topic in Data Protection & Information Handling
Public Task, as a lawful basis, includes tasks completed in the public interest or undertaken through the organisation's official authority. The official authority is set out in education legislation and SoS instructions (including things like KCSIE), or other legislation which affects children within a school environment or school activities. Within England, the requirements for schools as set out by Ofsted also come into play (similar is in effect for Wales and Scotland, and NI is a bit more complicated). One area that could change is around research and direct marketing, but that will come under secondary legislation really. -
The Data Use and Access Act 2025 (DUAA)
GrumbleDook replied to Alis_Klar's topic in Data Protection & Information Handling
There are a few changes that will benefit schools. There are a few folk discussing it, but https://www.brownejacobson.com/insights/data-use-and-access-act-2025-what-you-need-to-know is probably the simplest one to share with you senior leadership/DPO. From a vendor point of view (as a data processor for the school) it increases the need for transparency, and there are a few items needing secondary legislation to enact, but some of those are a separate discussion. The important bit from a relationship position as you do due diligence on your supply chain (CE+ requirement) is that your data processors only process what is in your agreement with them. Nothing has really changed there. -
Children's Code/COPPA Parental Consent
GrumbleDook replied to gpjt's topic in Data Protection & Information Handling
Am I right in thinking that some of this is US based, not UK? I'll try to cover both. In the UK, when EdTech solutions are used for the education, pastoral care or running of the school, then those vendors are being used as data processors and through an intermediary (i.e. through the school who is the data controller). This means they do no count as Information Society Services and so are not covered by the Children's Code (Age-Appropriate Design Code) in the UK. Where the school is the Data Controller and processing the data under their official authority or in the public interest, then the lawful basis is likely to fall under public task (under art. 6 of GDPR ... I'll leave art. 9 for the moment to keep it simpler). In the US, at the moment the efforts to introduce variations of the Children's Code have been centred on commercial/consumer rights and not where it is applied to schools/direct education. The US also doesn't have the range of lawful bases that we get under GDPR, and so you have the need to get Parental Consent for children under the age of 13 if the school wants to use edtech. As far as the vendor is concerned, they don't need to see it for each student, and as far as the school is concerned they can list everything they want to use and just ask once to cover them all. There are some issues with this last one as the lack of granular records can be problematic but I've seen it done in a variety of ways. For COPPA, the FTC do make amendments and the most recent ones do clarify about de-identified data, reuse by vendors and a few other bits ... and COPPA 2.0 is still not close to being passed ... so you get the MIS being used to record that a form has been sent in, a Google/MS form being used, of a few apps that do send a request to the parents on behalf of the school and so on. The simplest way is a form, providing the purposes for using data, what data it actually is and who will be doing it for you. Ask for agreement, keep the record and on you go. Some schools record each year, some do it only once. The risk cannot be passed onto the EdTech vendor, it is down to the school (or District) to make sure it is being recorded correctly. This is a vast simplification and there are some variation out there, so I tend to say to UK folk to speak to your DPO and to US folk to speak to your District. -
Holiday Time Safeguarding Monitoring
GrumbleDook replied to mitchell1981's topic in Internet Related/Filtering/Firewall
I presume this was said tongue in cheek, but just to repeat things for all to be aware ... teachers work on directed time. Teachers’ working time | National Education Union provides a good breakdown of what it covers. However, it is not uncommon to hear of teachers working 50+ hours a week, and from recent surveys 1/5 work 60+hours. The holidays will often also involve work, whether marking and planning, or being back in school running extra sessions, sorting out displays and more. So yes, teachers are only meant to work the Directed Time, but often they work a lot more. Senior Leaders in school are meant to work more, and both the Head and Dep Head don't have restrictions on how much they work or when, but that doesn't mean they will be free to deal with issues at any time, night or day. -
Holiday Time Safeguarding Monitoring
GrumbleDook replied to mitchell1981's topic in Internet Related/Filtering/Firewall
Was a DPIA done to assess the risks on this? This is one of those discussions where some folk will talk about the liabilities of providing devices and something going wrong, and those saying that it is an invasion of privacy. I have been asking the question for nearly 20 years which you need to take as the priority and the consistent message is "It depends!" ... and this is why your risk assessment is so important. For classroom.cloud, we talk about how you make choices based on the needs of the school (in their duties and activities for the learners), but also about being transparent with parents and children. These discussions have to be led by the DSL, but with input from all stakeholders. The ICO's DPIA template gives you space to discuss what impact stakeholder engagement has had on your approach. When it comes to alerts and notifications, that is also an area that needs careful consideration, and has to be part of the risk assessment too. Basically, there is no single answer to it all, and there is no shortcut to the efforts on risk assessment. -
GDPR or Data Protection Act?
GrumbleDook replied to Gongalong's topic in Data Protection & Information Handling
Yes, there are differences in them. DPA2018 also covers law enforcement as well, and does not cover some of the detail that GDPR does. We also need to remember that GDPR is written to be both stand alone, and to fit around other EU Regulations and Directives. And now we have to go through it all again and see what the new Act will do. -
GDPR or Data Protection Act?
GrumbleDook replied to Gongalong's topic in Data Protection & Information Handling
GDPR is the regulation, the DPA is how that regulation is enacted within law, including where it needs to make specific references to other legislation on the books or relies on other regulatory guidance or instructions, including instructions from the relevant Secretary of State and/or supervisory authority (I.e. the ICO). -
MIS Data Retention
GrumbleDook replied to Gongalong's topic in Data Protection & Information Handling
IIRC some of the guidance they used was taken from the IRMS toolkit, which was written for members. -
I always loved the fact that you could effectively give back to others by showing how much you respected what they said, what they did and for the knowledge they had. I know it got inflated by certain things but it was, in general, a darned good way of doing things. It was an interesting plugin and one that I had seen/used in a different forum when it came in. The use of dislike (or whatever it was) was always going to be problematic and who remembers when we had a few members with scores reaching -100!!!!
-
I love doing security wandering but rarely get the chance now. Our Internal Systems team are wonderful for spotting things (which, happily, is quite rare) and having a quick word. I do still do random checks when in the office but short of forced, physical entry there is little to check nowadays. School visits are another matter though. A small credit card-sized pocket tool usually gives me enough to point out external hinges which can be dismantled to get into a server room, an old loyalty card to beat spring-latched locks which have not been deadbolted (meant to be done each night to lock up but folk forget) ... and with the help of a year 9 student, showing how staggered A/C units could be used as steps to get to an external open window (I didn't ask him to do it, he had left stuff behind and needed to get it ... I spotted him and thought it best to let site staff know). Checking on clear desks .... no name and shame but work out there are, for example, 10 desks in a department across different offices and classroom ... and 2 have stuff on their desk which should not be there. 80% pass ... another department had 32 desks ... and 16 had stuff there ... so a 50% rate ... a clear fail. This way you are not targeting individuals and it helps to spot departments/groups who have little interest in following the clear desk policy ... so what else are they ignoring?
-
In a gruesome accident at a nuclear reactor due to an infestation of insects, an engineer lost parts of a leg which were grafted onto one of the nest's workers. It developed sentience and provided an inside understanding of insect life. Zoologists fought against just giving it a number and wanted a name. The insect laughed and said it was obvious. ... ... ... Ant Toe Knee.
-
Nope, the location of processing is a small part of a much bigger issue. The fact that you are making a choice to do the processing it is the problem. A key factor is the question, “can you do it in a less intrusive way?” When you also consider that this is special category personal data … under GDPR line you need to have a good reason for that and this exemptions are clearly outlined. Block processing when looking for an individual is excessive. That has been established by the courts already.
-
But use in a school in the UK is covered by GDPR and so any use of personal data needs to comply. Also, is there a less intrusive way of monitoring? Yes, motion sensors can be calibrated against speed (and have been in many circumstances over the years), and so you can have a buffer on the camera that only writes back to storage if the speed of a passing object is below a certain speed.
-
(Please note … this is a personal opinion) Having been involved in both sides of extremely large tendering processes, it is a minefield. Even with frameworks to use, it is a horrible process. Yes, incorrect practices should be challenged and action taken, but I favour that this is done via the oversight of the frameworks involved, not direct litigation, but that is a personal preference. The DfE do a lot of work to help schools and trusts manage procurement to try and avoid situations like this, as every pound spent dealing with legal matters is a pound taken away from schools. For a vendor to challenge another vendor is interesting, especially considering the recent issues between ESS and SCOMIS. I do think that this one is extremely misplaced though and hope some mediation is put in place.
-
We are talking about facial recognition, which is using biometric data. Regular CCTV does not do that, it is just an image recording system and any recognition of individuals is done by human eye, nothing else. The use of biometrics in public areas has been successfully challenged in the past, and the use of facial recognition in schools has also been successfully challenged.
