-
Posts
12,876 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by GrumbleDook
-
Risk assessment it, then put in technical and organisational measures to reduce any risks. It is not a yes/no thing. It is about changing culture including home use. The suggestion of a separate user account on the home device (PC/Laptop) is a common technical way of reducing the risk as you know that other house members are not likely to be accessing that account, so as a risk treatment your governor is right. He might also suggest device encryption, that no other account has admin rights on there and so on. Operationally, you might get the same risk reduction by implementing a home-use policy with guidance for when working from home (a useful guide in present circumstances) including guidance on patching anti-virus/anti-malware products and so on. It is worth saying that NCSC has good guidance to review to help with all this. Instead of slapping the governor down, be glad that they are switched on to this. They are someone to work *with*, not against. As always, if there is something specific you can PM.
-
Yes and no. Where a recording is done as part of a broadcast, rather than CCTV, it has a different purpose. It will need a DPIA. That will include an understanding of what the expectation of staff and students would be, being clear about what is being processed and so on ... This is essential to ensure that people don't change their minds about what it is going to be used for without thinking of the impact. A common area where people change their minds about what is done will be recording. The idea that you can record a particularly good assembly to reshare is very popular. Then you have what will happen during lockdown or self-isolating learners? At that point we are looking at broadcast over the internet and that needs to be secured, both for transport and access. You also have to remember that although Consent may not be the lawful basis, you still have to be transparent and give the opportunity for parents to object. They may have very valid reasons (children who are vulnerable off-line have a tendency to be vulnerable and risk taking online, and normalisation of being on video could be a problem).
- 17 replies
-
- 3
-
-
- audio and visual
- cameras
-
(and 1 more)
Tagged with:
-
Move the users into an Alumni setup, getting their agreement (for both GDPR and PECR) when they get their results. This also gives the school a way of tying in the students for other things in the future ... they just need to be up front about it.
-
@Ditto You've pretty much covered it. It is core, it is covered under Public Task (or even Legal Obligation after later in the week) and is 'almost' a Substitution of what already goes on (see the SAMR model for more on this). - - - Updated - - - @Ditto You've pretty much covered it. It is core, it is covered under Public Task (or even Legal Obligation after later in the week) and is 'almost' a Substitution of what already goes on (see the SAMR model for more on this).
-
As already mentioned by @BinoX , the additional services are the problem. Core services are where the data is only processed as set out for the purposes of the Data Controller, in this case the school. The purpose is likely to be the delivery of an education curriculum, the pastoral support and well-being of individuals, and the management and running of the school. All these quite easily fit under public task. Some types of processing that you may do in there, where quizzes end up profiling and so on, need to be considered in this though. You will have some who question this and this is part of a long, ongoing debate on who sets out the purpose and what data is being used. Additional services are where both the school and Google are data controllers in their own right. Consent is needed as a result. By default, Additional Services are turned off for users when a new G Suite instance is setup. Historically, this may not have been the case. If you have enabled YouTube for your users, then Google are tracking the data for their own purposes and are a controller in their own right. Consent is needed for Google's purposes. I'm eager to see what comes out of this, as we have never had any proposals or standards around learning platforms and tools before ... ... ... ... ... ... Well, apart from Becta, the report from ETAG, the continued work of thousands of schools ... but I am sure that it will work out ok.
-
DPIA documents
GrumbleDook replied to chekmate1984's topic in Data Protection & Information Handling
Yes and no .... There are large parts of a DPIA that might not be understood by the 'project' owner (We'll call them that, rather than the data owner ... or more correctly, the Information Asset Owner) but they will be key for establishing the purpose for processing, what data needs to be processed (not what they 'want' but what is needed) and how long they need to keep it for (again, need not want). Evaluation on the security of the data during transfer, within the tools that are being used, any safeguarding and privacy concerns ... it is a group effort. Doing a bit yourself and passing to the next person can be done, but it really is not the best way of doing it. Of course, your methods may vary, depending on the templates you use (declaration of interest again ... I work at a company supporting schools with this) but there are a number of good ones out there that are available as templates (Including some of ours). Where possible, work as a group, not in multiple silos. -
'Disappointed' bidder sues MAT after MIS Tender failure
GrumbleDook replied to vikpaw's topic in MIS Systems
Not uncommon for that offer to be made. However, if you do then you cannot say you have used the framework to complete a mini-competition. -
And how many of us went to look at our own collection to compare?
-
Belated Hippy Bathday. Didn't spot this originally either.
-
I'm already chatting with Zoom about updating the DPIA that we worked on that the team in Derbyshire published https://schoolsnet.derbyshire.gov.uk/site-elements/documents/administration/dpia-covid-19-zoom-and-microsoft-teams.docx I've also dropped @PaulZoom a line to connect too. @Dos_Box can we have a chat tomorrow? - - - Updated - - - I'm already chatting with Zoom about updating the DPIA that we worked on that the team in Derbyshire published https://schoolsnet.derbyshire.gov.uk/site-elements/documents/administration/dpia-covid-19-zoom-and-microsoft-teams.docx I've also dropped @PaulZoom a line to connect too. @Dos_Box can we have a chat tomorrow?
-
'Disappointed' bidder sues MAT after MIS Tender failure
GrumbleDook replied to vikpaw's topic in MIS Systems
Having done tenders and procurement at a pretty large LA, the hoops to jump through are amazing and I was lucky enough to work with a fantastic colleague who really pushed our legal and procurement teams to get everything right. The right to challenge is an important aspect of the process and it is not for us to debate on this forum about who was right or wrong ... there are legal experts who will work on this from both sides. It may not feel right that there is a challenge, but companies do have to take action where they see that due process has not been followed. If they don't then it becomes a free-for-all and there will be some trusts that abuse the system. Large trusts are increasingly becoming adept at running tenders, and the UL team have been doing them for years. I can remember chatting through some of them over 10 years ago with some of the team that are still there. In the interest of fairness, Bromcom have but their bit up and I would guess that UL will not as that could be create difficulties further down the road in this case. (Edited to be fairer) I do have a personal opinion on this case as many others do, but we have to play fair. And it is a case ... and as such I would suggest to Bromcom that you don't respond further, suggest to fellow members to be mindful of what you are saying and suggest the mods lock this one so that it doesn't create more mess further down the line. -
Student Name and GDPR
GrumbleDook replied to CommodoreS's topic in Data Protection & Information Handling
Website and social media is different to a school display. I get what you are saying, it is just the blanket "it is a disclosure to do it" that I have an issue with ICO saying. -
Student Name and GDPR
GrumbleDook replied to CommodoreS's topic in Data Protection & Information Handling
And how do you know it is not part of a public service? Have you discussed with teachers why they display work that children have completed? About why they are displaying that particular child's piece of work? Is it linked with work that is going on to provide confidence to particular children? Is it in an area that may inherently have a low likelihood of those from outside of school seeing it? Yes, consent could be a lawful basis ... but that doesn't mean it is the only one. And yes, even if a different lawful basis is used, there is still the right to object. -
Student Name and GDPR
GrumbleDook replied to CommodoreS's topic in Data Protection & Information Handling
Which shows ICO still have limited understanding of schools. This will be a Sir Humphrey job. It depends on how you ask the question. Ask it one way and they will say that it is a disclosure and you are the spawn of Satan for suggesting it ... ask another way and they will say that you have identified the purpose, the lawful basis, measured the risks and taken appropriate action where needed. Context is everything with this, and that is why you may need to do a risk assessment. -
Remove pupil details from all systems???
GrumbleDook replied to InspireICT's topic in Data Protection & Information Handling
1 - It is not a 3rd party website ... it is a data processor. A 3rd party is something different and if you see it in an agreement you should challenge it. 2 - Having accurate data that is usable is important. Pseudononymisation is put in place because there is a need to add in protections, not because it seems like a good idea. 3 - If you need XXXXXXX to do something (maybe welcome a child to their learning tools) then why make it YYYYYY? -
Remove pupil details from all systems???
GrumbleDook replied to InspireICT's topic in Data Protection & Information Handling
Re: pseudonymisation ... Why? Is it a security measure? Why is it needed? Does it impact on the usefulness of the personal data? -
InVentry / vistor sign in retention period
GrumbleDook replied to klee's topic in Data Protection & Information Handling
On the example retention schedule, it shows some of the applicable legislation that requires that data ... To some extent you have to consider the liabilities to the school and the length of time from something occurring and the chance the school will be taken to court over it. -
DPIA documents
GrumbleDook replied to chekmate1984's topic in Data Protection & Information Handling
Does your DPO not have templates or tools for this? (Declaration of interest ... this is my day job) -
Remove pupil details from all systems???
GrumbleDook replied to InspireICT's topic in Data Protection & Information Handling
In your Record of Processing Activity you will have listed out the purposes and lawful bases for the processing of the personal data you hold. Where consent is the lawful basis, then consent can be withdrawn and the personal data has to be removed. For other lawful bases, then the parent is using the right to object to the processing of personal data. That is a different beast. It is not an explicit right, and has to be looked at proportionally to the purpose and lawful basis. The use of those products will be for the running of the school, delivery of education, the protection/safeguarding of children and the pastoral support provided by the school. Lawful basis of Public Task or Legal Obligation (depending on which bit you are looking at). This is for where the school is the Data Controller and the supplier is Data Processor. The moment the Supplier is using the data for their own purposes then they are a Data Controller in their own right as well. This is where the arguments exist. You then have the added bonus that these suppliers are US based, or use companies that have HQs in the US, and are affected by the Schrems II judgement (quashing Privacy Shield). Guidance is still ... well ... sketchy at best on what the impact for schools are. In reality ... If you need the data, then you need it. You just have to make sure that you have it documented, that you have risks logged and monitored and where anything can be done to gain more information (such as pressing ClassDojo on SCCs and UK based hosting) then you have done what you can. Probably the most important thing in all the above? Make sure that you are the data controller. If the supplier is using the personal data for their own purposes, then stop it. G Suite for Education has a core package that leaves them as the Data Processor. If you enable the children's accounts to access YouTube, then Google are using that data for their own purposes. I am not saying block YouTube ... just don't have students logged in when accessing it and turn that additional service (and any others) off. -
First things first, ask for the DPIA to be completed. It will have on there the purpose, the lawful basis, consideration for things like would they expect for their data to be used in this way (and saying "our contracts and policies say it is ok!" is not the right answer). It needs to cover retention, security of the data, etc. If it has not been done before, it is a new type of processing ... so *has* to have a DPIA completed. That needs to be agreed by the DPO (and if any disagrees with what the DPO recommends then that gets logged). Whilst the DPO does not need to be approaved by the Board/GB, for something as significant as this, it should be raised that one is being completed ... and I would expect that the relevant link Trustee/Governor has many questions to ask on it. Let's just say that most DPOs would have a lot to say on this!
-
DPIA documents
GrumbleDook replied to chekmate1984's topic in Data Protection & Information Handling
Have a look at https://www.educationdatamatters.org.uk for examples of DPIAs. -
No, the advice was that the sending/receiving of emails outside of the school should be used appropriately and based on the competency and safety of the children involved. Generally, KS1 - No, KS2 - unlikely, KS3 - possibly, KS4, only if a risk, KS5 - you want to stop it? Why? Guidance on this has had updates from UKCIS (Formerly UKCCIS) and is available via the Education for a Connected World resource. I did a presentation for the #UKEdChat conference earlier in the year on access to materials to help decide when a child can use digital tools and understand about privacy/data protection.
