Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. I think this is still the most relevant page covering what is restricted on MDMs. https://support.apple.com/en-gb/guide/mdm/mdm0f7dd3d8/web
  2. We really appreciate that feedback and we can look at those areas. It sounds like the error message is not right, so we can get that looked into in the first instance. Is it ok to drop you a line again?
  3. If you want to run through anything again, happy to do that with you and see how you can get a good balance.
  4. I know 'kill my self' should have been picked up (sensitivity of matching for variations of words may have been set too low) and I know that 'gun' and 'knife' are regular terms that may have needed additional terms, but I'm sure the team can check on that. And yes, the NetSupport phrase list is the result of working with many resources including the IWF. To say whack-a-mole-y is really putting it politely. Going back 20 years, Symantec bought out URLabs (the creators of iGear and MailGear) just so that they could get the scoring engine and rights to it. I watch conversations in Roblox and it truly scares me how quickly people adapt language now to bypass any filters of moderation!
  5. This comes down to the risk assessment and establishing the need for the software. Children can reasonably expect a level of privacy in their life, and monitoring tools have to take that into account (Disclaimer - as well as being a Privacy Professional, I am also working for NetSupport right now) and so you need to think about how invasive this is. It should not be that you monitor everywhere by default, just in case ... you should monitor based on risk. Privacy by Design and by Default is an important approach here. That's not to say that monitoring cannot be done, it just has to be for an agreed purpose, against a very strict scope, assessed against the risk and also proportionate. Some monitoring, for example ... device management and performance (e.g. what software has been installed, patches applied, local accounts created) could easily be acceptable due to the minimal amount of personal data involved. I would strongly recommend watching the following discussion between myself, Rowenna Fielding, Mark Anderson and Bukky Yusuf - As for liability to the school if something is done ... this goes back to discussions that Dr Brian Bandey was having over 10 years ago ... and there is case law that could be looked at, but there is also law around privacy and data protection. This is why you do a risk assessment and take into account other linked legislation. There could also be liabilities if you are too invasive. Until there is more joined-up advice on this, it is hard to say exactly what works best. Would people be interested in a short session looking at issues like this? Get a safeguarding expert, an NM and a Privacy Professional together to chat about it?
  6. It depends on who manages your DNS. Don't be scared to ask them about it. The Early Warning system is also very handy, if folk have not seen that.
  7. Welcome on board. I'd be interested in any guidance you help schools with around managing retention schedules within backups.
  8. A chunk of the information you are after will not be publicly shared due to IP and security considerations, and many of the cashless catering providers don’t just work in schools by across other sectors too. The range of due diligence taken when looking at systems vary, and to some extent, the reliance on procurement frameworks is part of this ... it you’ll know where I am coming from with that as it affects so many other aspects of InfoSec/Data Protection/Privacy. You are right about attacks too. As the systems are usually hosted on-site within schools, with no direct access externally, the main issue raised is usually about money transfer. As the other part of this, loading money on, is either within school or through online payment systems ... and they get checked over as part of PCI-DSS. I can’t talk about particular solutions but I would always say that should concerns be in place that any pseudonymised data is too easily converted back to its original form and re-used for other purposes, you must look at what measures can limit this. I’ll never say something is impossible ... very hard and improbable, but never impossible.
  9. To some extent, it was slightly easier in the days of numerical Information Labels (IL0, IL1, etc.) as you could explain that multiple data items of IL2 could generate data items that became IL3 or more. People could understand that cumulative nature. They may not have been able to work out what level something was at originally, but they could understand the additive nature.
  10. @AndyCrow has hit the nail on the head for this. FOI does not mean you have to release personal data. There are reasons why information is treated in confidence and we should educate families better about this.
  11. When you are collecting data in the first place you need to think about what it needs to be used for. UPN is not a general ID that can be thrown around. For ID between systems, yes ... you can justify it but you should be looking for an alternative (that discussion has been going on for 15+ years ... don't go there!) but for on a lanyard? That is going to be hard to justify. Admission number is for use internally, or for between systems. The risk of duplication is small but possible ... Exam Number? Unless you are using it for ID during exam season ... nope. Your best bet is to use something new that can then be tied in with other bits of personal data. To some extent, we can't really say much more unless we know what you are using the ID on the lanyard for.
  12. RFC1925 - The Twelves Truths of Networking.
  13. I’ll be honest, this is going to create a problem. If it is used for curriculum delivery, consent is inappropriate. However, as Google have identified consent as *their* lawful basis for processing then *they* have to collect it as they are DC for the additional services. The school could still use public task for their side of things (it would be hard though), unless there is a Joint Controller agreement in there (which there does not appear to be). I think I might drop Dean a line and sort out a group chat with some DPOs (if he is not already following this).
  14. The CS First request for consent is based on COPPA requirements so please be mindful of that. It is a curriculum package and I would need to get a better picture of a) how any personal data is used by Google for Google b) whether any of that data is also shared with third parties and c) how any rights of individuals are dealt with. @Zoom7000 can you ask the team about any of this? Has this come up in any discussions in the GEGs?
  15. If there is any help you need in getting the implementation running in the school then that can be arranged too. It is more about changing culture and identifying roles than anything else. Once you have that, the rest is a lot easier. Not easy, but easier.
  16. If you look at the exemplar DPIA that Derbyshire CC did on Zoom/Teams, you will see there is a set of screening questions. I would also look at compliance systems have these templates too. This is an easy way of checking through a lot of software and systems to see where personal data might be used, directly or indirectly (viewing and monitoring of screens is going to show some personal data!).
  17. @elsiegee40 has pretty much covered it. They are different roles and cannot be covered by a single person. In most schools, you won't find a single person as the SIRO, as it gets spread out (if done at all) and could be done better. Often the SIRO can be the DP Lead within the school, doing the operational tasks that the DPO has highlighted ... or at least coordinating the tasks to make sure that they are done. There are a lot of similarities in the roles, and if you don't have a SIRO you will still need to explain how your Information Governance structure is made workable.
  18. Also remember that there is a difference between ‘sharing’ and ‘processing’. The agencies mentioned in the DfE model policy are other Data Controllers who will be using the data for their own purposes. Google, etc. are your Data Processors and are operating under your instructions. As Andy says, chat to your DPO about it.
  19. There have been successive clarifications on how the requirements around cookies should be fulfilled. Companies that make it difficult get called out more frequently now. Cookie management tools are getting better (you will see a lot from TrustArc and OneTrust) and that has helped. Being completely blunt ... even when they are better than they used to be, they are using so many other tools now to track you it is frustrating trying to stop it all.
  20. PM me your contact there ... I'm open to work and so will approach them. Even if I can't help, I know a lot of others who can!
  21. The problem with some US-based companies is that unless there is a significant foothold in the UK and EU, they won't bother with the relevant information unless pushed and pushed. If you look at the Student data section they talk about sharing with third parties ... and that is because this is the term used by FTC and contract laws ... but if you read some statements such as They are basically saying that they use sub-processors. You can email them as ask them to clarify if the use of the term 'third parties' in this section is the equivalent of saying 'sub-processor' within GDPR. Explain that GDPR has a very specific definition of what a 'third party' is, so you just want to clarify that these are really just sub-processors. Ask them to complete the security RFI that is on the Education Data Matters website. Don't just look at the docs alone, if you have a concern. Talk to them ... most are happy to change and update things if it make them more friendly to more customers in the UK.
  22. For those of you who have been using ClassDojo and have been looking at what on earth has been going on, the DPO teams at Derbyshire CC and Coventry CC have been chasing for some changes, as well as some prodding from GDPRiS and also from me. As a result, ClassDojo now has an Addendum including SCCs that schools can sign to deal with the loss of Privacy Shield/transfer of Personal Data to the US. Please contact their support team for a copy of these, review them with your DPO, update any DPIA you may have done, and return back to ClassDojo. This has been a long job to deal with and hopefully it benefits all UK schools, but *please* get a copy of the Addendum and chat to your DPO asap.
  23. https://www.montagu.com/news/montagu-to-acquire-capita-s-ess-business-and-invest-in-parentpay-group/ And we have the result. So, Sims and ParentPay in the same family now!!! The market is shaping up to be quite Interesting.
  24. Just remember that the advice to ban is part of risk treatment. It is not to be taken out of context and there can be other treatments that you can do to get a similar result. You’ve already been told some of the alternatives. Propose them and see what you get back.
×
×
  • Create New...