-
Posts
12,876 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by GrumbleDook
-
Related to online harms? Still won’t make any difference to schools.
-
It has been so interesting reading all the different news articles, political commentaries, analysis by privacy professionals and rants by a few individuals. I’ve tried to keep a balanced approach to this (yay for fence sitting!) and usually just try to clarify how schools work, why this could have such a positive impact for the school and individuals, and to point people to the relevant legislation, especially about consent and competence. Most of this thread has shown so much good discussion, done in an open and friendly manner. One of the reasons why this is still a favourite place for me. I only have a few bits to add to this discussion. Most have been said in similar discussions about biometrics in the past, or have been directly mentioned. We know the Protection of Freedoms Act is a principle piece of legislation for biometrics in schools, and we know the emphasis on communication about the use of FR has to also explain the alternatives that can be used. It is really hard to use consent/explicit consent and the art. 6 and art. 9 lawful bases due to the imbalance of power that the school has, but this is the only option. This is why the use of biometrics is tricky. But this discussion has been had so many times. The main change is the intrusiveness. There are other changes but that one is the first. Is a check against somebody’s face for their ID intrusive? In itself, no. We do it on a regular basis, many schools have ID card that can be checked and we know how this is used to ensure the right children be access to their money to pay for food, whether that money comes in as payment from family or as part of FSM. We know cashless catering is used to reduce bullying, remove stigma against FSM and to try to help make sure disadvantaged children get a solid meal, possibly the only one they might have that day. But this is not asking a human to check a card against a person. This is a computer checking a face against an image in the database. The DPIA for this is available from the relevant Scottish council, and it is clear that these areas have been considered but the benefits to the individuals are significant enough (at the point the DPIA was done) that it could go ahead, but whether the work on communication with the families was enough is one of the areas being questioned. The other thing to discuss has to be normalisation to intrusive use of personal data. That has to be a discussion point at the very beginning of looking at this. I’m not going to say it is or isn’t. I will say that consideration for your community is a must as it does affect groups differently. I would also recommend looking at the work of the Digital Futures Commission and the Children’s Rights Impact Assessment. But most of all, it makes me so happy to see a strong and open discussion on EG about all this. Well done to you all.
-
Rather than just pulling out a form, do a risk assessment. You also need to consider the IP of any materials created, who retains the images, any considerations for reuse including future commercial use. That means you also need to check all the criteria set by the exam board as well.
- 1 reply
-
- 1
-
-
A significant amount of data, including performance data, is held under contract with the clubs themselves, as well as through the relevant associations. A significant amount is also subsequently licensed. There is a lot more to this than just GDPR and clawing back personal data, and has bugger all to do with Consent.
-
Outsourcing Contract
GrumbleDook replied to sarahstacey's topic in Data Protection & Information Handling
You do, but there is a clear purpose and lawful basis, and should you be concerned about the protection of the data you need to raise it with the person managing the TUPE process (after a check with your DPO, of course). You may be told it is an accepted risk. Get that in writing. -
What a day! Van broke down this morning, so I looked under the bonnet and saw a bat sitting on the engine. Amazingly he said, “Hello, madam. You are a beautiful lady and very nicely dressed, too." I realised the problem straight away. Bat flattery.
-
Will you be buying the iPhone 13?
GrumbleDook replied to Sonic007's topic in Mobile Devices & Tablets
If the right deal comes along, but I'm in no hurry. I'm happy with my XR, have an SE for my other bits and pieces, and the rest of the family are on SEs too. -
So we have the name of a child and DoB, their parents(s), their address, other contact details and the reasons for leaving (which can vary a *lot*). And this is on an online form, that anyone with the link to it can access, that anyone with that link has full edit rights to all the data. And these could be children who have left due to a lot of difficulties or sensitive circumstances? OK, look at it this way. You are being asked to shared data with another organisation. You have a responsibility to make sure that suitable controls are in place for the security of that data. Do you have an agreement in place with the Council? Has there been any risk assessment on this? Are there any children at your school who could be at risk if their data was not kept secure? If so, then you can raise a concern to your DPO about this as a data breach for the school. Just because it is the council, it does not mean it is automatically ok. It also does not mean that a risk assessment done 18 months ago will have covered something like this.
-
Did your school put any data up there? If so, it is also your breach as you were sharing data with the LA as another controller (I don't know the purpose of the form but so far it sounds like a data gathering exercise by the LA for something ... don't really need to know what, only whether it was for their benefit or not). Did you do any checks to see if it was a secure area? Was it checked against any DSA you may have in place, or legislation/regulation/instruction meaning you have to share the data? See .... lots of reasons why you can kick up a fuss. It might not be reportable, depending on the personal data involved and the risks (if any) to the individuals. I don't think the LA can acertain this fully and so they should be discussing it with schools to see what the impact is ... and quickly.
-
Please report to the council immediately. Feel free to PM me with the details as well. Without knowing more details I wouldn’t want to make a longer comment other than it is a real concern.
-
Except staff want to use something was to work with … the fact that it makes SARs difficult is unimportant to what they do.
-
That could be construed as being deliberately obstructive. If you go from tens of thousands of emails to five, then it will be obvious the school are taking the mickey. If the family are already disgruntled, then this has the hallmarks of a significant complaint being built!
-
No, you use initials so that it reduces the chances of some random person at the school being able to work out who you are talking about, or it is an agreed reference (like the teacher identifier when timetabling). As it is commonly used and can be used with additional information to identify individuals, then it is personal data and covered by the SAR. As the search will include where staff are discussing the individual it will be extremely hard to build a regex to remove random emails. However, it does make it more complex to look through things and so it may be reasonable to say it would take longer than the 1 calendar month to complete. Advice on that side will need to be taken from your DPO.
-
Just to back up the idea that it is worth doing, it really is. It also gives you opportunities to make sure that people see updated information and have easy access to it. It is *always* worth giving information in multiple places. One thing I would suggest though is that you should use a tool that tracks who has or hasn't agreed to it. Yes, NetSupport DNA is one of a number of tools that make use of this, so if you have DNA already I would suggest people look at this function. It can be really helpful.
-
As much as I love gaming, I don't think I have a bucket list anymore. I've dabbled too much in lots of things to have any real dedication to anything now. I don't even go into WoW anymore. I'll happily update copies of Football Manager, dip into Diablo III for a bit of random slaughter, boot up the Wii for a bit of fun (I do like the Wii version of MoH:H2 ... strange as it is), or play random word stuff on phone/tablet. Occasionally the PS1 or 2 get broken out for a bit of FF7 or 8, Tony Hawk or crazy things like Crash Bandicoot. I've given up having the latest/greatest machines to play games on, preferring to nip onto GOG.com and grab some old games to go through. They might not have the best graphics, but the gameplay/story is sometimes way better. Most of all ... I miss having time to go onto a decent MUD.
-
Data Sharing with a Virtual School
GrumbleDook replied to garbage46's topic in Data Protection & Information Handling
If the child is looked after and is supported by the Virtual School, then contact the Corporate Guardian to see what information has already been shared. Going via their social worker is usually the quickest route, but the Virtual school may very well need the results. Check with the social worker first.- 1 reply
-
- 3
-
-
Mine are here too. Thank you!!!!!
-
The EdTech Demonstrator programme is something that has growing for some time. The drive from the EdTech Leadership Group to have a funded programme of good practice around EdTech for Learning and Teaching kickstarted this, but there have been moves to this for a long time, through groups such as the EdTech Leadership Group's predecessor, ETAG, and the FE equivalent, FELTAG. It is not that is it new. https://www.ednfoundation.org/2020/02/18/edtech-demonstrator-national-project/ gives you some idea of the work already done, and there was a lot of politics involved at the start of lock down to continue to get advice out to schools on implementation (the programme from The Key used DfE funds to support rollouts), and then the renewed contract went to United Learning (and there are many members on here who work for them) who are doing a very large promotional drive. This also fits around things such as BESA's LearnEd and LendEd programmes, work from SWGfL and LGfL, constant drives from Microsoft, Google and Adobe ... There is *always* something going on. One problem is that there is not always a conversation with the IT staff who work within schools, those who have to do due diligence or those who have to need to make it sustainable. Knowing the way some of the folk at United Learning work ... I wouldn't be surprised to see more advice coming from them around that.
-
Impero Education Pro premise V cloud version
GrumbleDook replied to Face-Man's topic in Network and Classroom Management
The cloud is definitely an option (which is why we are adding more and more stuff to classroom.cloud) but we are also still updating our on-premise tools (DNA is still growing). It's one of those things were some still need to have complete control, whilst others have options for cloud and remote services. Happy to chat to you about both options from NetSupport if you are looking at updating what you use. -
Governors are not likely to be accessing personal data of pupils or staff, and if they are then it would be for particular reasons such as appeals or similar. The sending of emails from M365 and Google Workspace for Education is done over TLS and kept secure, IIRC for encryption in transit might not be a worry. The main issue is that if the school has the policy to work in a given way for particular reasons, until that policy is updated or scrapped, someone, somewhere, needs to document who made the decision for it to be ok to work in this new way. Don't forget that the risk assessment should be driven by your DPO. Go and see what they say.
-
It has been an interesting year or so, watching the Children's Code (aka Age Appropriate Design Code or AADC) go through consultation, effectively missing out on what is needed for schools to be part of it, or how it could affect them. The released version that was laid in front of Parliament and adopted then had a year for companies and organisations to get to grips with and this finishes on September 21. There have been lots of conversations and work going on in the background, from the odd voice challenging the ICO around it, group sessions with DPOs to take on board how schools truly work, discussions with EdTech vendors (extremely grateful to many providers and especially to both NetSupport and 2Simple) and a fantastic report from the Digital Futures Commission (a collaboration supported by 5Rights). I would strongly recommend that you read the blog post and watch the report launch too (if you can). The report is a fantastic paper that helps to clearly show how EdTech and the use of data relates to schools, and is also supported by the commentary on it by the AADC team at ICO. There are three important things that need raising for schools and three for EdTech providers. Schools Schools need to be clear where they are the sole data controller and where any other company or organisation may also be a controller. Schools need to understand that where they are the sole controller, the code does not apply to them and what they do, but GDPR still applies and the code has chunks of good practice to follow. The importance of risk assessments cannot be stated enough. If you haven't done them for the systems you are already running (including in-house stuff) then treat it as a gap analysis ... but just get it done. EdTech Vendors Make sure you are clear and transparent about where you are a controller for your business stuff (sales, etc.) and where you are a processor on behalf of the school (i.e. the actual service you run) Be transparent in your documentation and agreements about what you do and who you work with. Make sure any other partner is only doing what you instruct and based on your agreement with the school. If you are also dealing directly with families for a consumer offering, make sure you are using the code for that part of the service, and make sure you know what doesn't need to be in place for the school-delivered side. There is so much more I could add, and more guidance will come over time. The ten steps the report puts to the Government are clear, well-targeted and will make a significant difference for schools in England. We can also hope that it helps to set things out for NI, Scotland and Wales too. I'm just glad that the Digital Futures Commission are leading on this, as they are approachable and want to take in the wide range of experience and expertise that is available within schools, MATs and LAs. The targets are below: I would suggest schools share this report with their DPOs and SBMs, and I am happy to discuss this further with any EdTech providers out there or introduce you to people who can help. --edit-- For whatever reason, the link to the blog on the report got stripped out. I've put it back in now but here it is again - https://digitalfuturescommission.org.uk/blog/the-education-data-governance-vacuum-why-it-matters-and-what-to-do-about-it/
-
- 2
-
-
The IRMS Schools Toolkit is also available to provide guidance for schools (and is presently under review for the next version as well) - https://irms.org.uk/page/SchoolsToolkit The Academies version is also available at - https://irms.org.uk/page/AcademiesToolkit
- 1 reply
-
- 1
-
