Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. I missed this thread too. Best of luck with the new venture and don't be any stranger ... erm ... I mean don't be a stranger!
  2. We also need to recognise that there is a problem with consistency of how Supervisory Authorities (ICO, CNIL, etc.) are responding to this from the very strict in some areas of Germany through to ‘keep calm and carry on’ from ICO. In our case, it is made difficult due to trade discussions between UK-EU and UK-US. It is also worth saying that many of your suppliers will also be doing a lot more digging and seeing where to make changes (or if they even should)... so asking suppliers right now about any position they have taken will probably get back a response of “we are seeking further clarifications” ... and so waiting for guidance from ICO and comment from DfE is the most schools can do right now. If there are parental complaints, then a note to show you are atLeast looking at it and have internally acknowledged the ICO advice, and then noted it in your risk register, is the best you can probably do right now.
  3. Right now? We do not have a clear picture about it means for the UK. We need our Supervisory Authority (ICO) to provide more guidance on this. There are so many things to consider on this, not the least about what arrangement will be in place in the future between UK and US, and between UK and EU. Right now, the most you can all do is be mindful of where data is processed by US firms in the US, where data is processed by US firms with bases/DataCentres in the U.K./EU but are subject to inter-territorial law from the US, and where EU/UK processors are using US sub-processors. That is going to be an unbelievably long list so you have to just be mindful and wait.
  4. As mentioned before, if they are doing anything prior to their contractual start date, they are being a volunteer, and so would sign anything that a volunteer would sign.
  5. Although I won’t be doing this soon, I’m looking at options as well. I’ve been using Apple’s Airport for some time and it generally just works (apart from a bizarre situation with next door’s broken wireless printer) but to extend or replace anything we are now on eBay hunts. I’ll put a bit away each month to sort out a replacement setup (knowing I will recoup some when I flog my Apple kit on eBay) but I am still mindful that I’ve seen mixed messages about what works best. One thing I am certain of, I want it to be in house management and not linked to Google/Amazon. I’ll keep a track on this thread and always interested to see what folk suggest.
  6. Comprehensive response and review. I will answer these in line to make it easier to see. Reviewing the Ofqual guidance so far it has been clear that the exemption goes on results day and the backlog of requests will then start (it is interesting that the 40 days past results day limit is longer than the limit for a new SAR of 1 month) ... as the resit of exams in autumn will *not* take into account the CAGs and so they will no longer be considered scripts ... apart from Art and Technology courses. I'm still waiting for clarification about if Art and Technology courses still need the exemption applied. We will have to wait and see. See above. Yes, people need to be careful about this, but those making requests need to be aware that they may be asked for clarifications and if the organisation puts in structure to help with that clarification (in the interest of accuracy and efficiency) then it is a reasonable approach. Demanding the information from the person trying to hand out the grades whilst others are also waiting for their grades will be problematic and if the school has been clear that if they have any questions they can go and speak to a member of staff, then they are doing what they can to help the students. A simple form to collect the student's details and verify who they are is not a bad idea, and that can be managed about someone else. Not quite. when we think of "as quickly as possible", we have to consider the disruption to the normal business of a school. even if they have everything to hand, if releasing the CAG at that point could then need a lot of other discussions and so it is perfectly reasonable to take into account the needs of others, as long as you stay within the time frame. Not quite. Yes, they can collectively grant authority to someone to get the information on their behalf, but that does not mean that the school has to give the results to anyone and everyone. The right is for the data subject, or their authorised representative, to have access ... if the school is told to give access to everyone in the class, that is not to say everyone in the class *wants* access to the information, or there may be other factors that have to be considered that the student may not be aware of. That's not to say that they can't build it all themselves and work out the gaps. I'm waiting for a clarification on whether an exemption under section 36 might cover this (as you mention below), and I've already had one trust discuss whether they will wait to publish it at a later date once any appeals (Centre appeals) are dealt with ... so they are exempt under Section 22. Whilst it may have been laid out in the fairest possible way, that doesn't mean it won't be open to it being used as part of legal challenge against the school and against individual staff. To some extent, I would like to see how DfE and Ofqual cover this via a Public Interest Test.
  7. At this time of year and throughout summer ... IT Staff don't *work* in secondary schools. It is more a case of *living* there to get everything done!!! (one aspect I don't miss!)
  8. I would question having lists of passwords and access to mailboxes by default. The age groups involved would be a factor in that (i.e. within KS1, maybe KS2, but not higher) and definitely not for staff!
  9. If this is being done, then ensure there is a clear audit trail of when it is turned on, what was found and when it was turned off. Ensure that the decision is coming from a significantly senior member of staff who includes safeguarding within their responsibilities and if it doesn't then speak with the DSL too.
  10. It was good advice then and still good advice now. These conversations were blurred between safeguarding and data protection ... and intentionally so. The emphasis was not to think in a silo about either but to consider where each had impacts on each other. Under the old guidance on using ILs and how multiple items of data can increase the level when combined, that is no difference to the data minimisation principles within GDPR/UK DPA. I would always ask, "Is there another way of doing this?" and see if you get a different answer.
  11. Just to double check, for the sake of clarity, that these are both schools in the same Trust and all staff are employed by that trust too?
  12. At the risk of contradicting ASCL, unless the guidance comes from ICO, DfE and/or Ofqual you need to be careful. I’m still trying to unpick this as guidance on the exemption applies up until results day, but if you have had FOI requests about the process and have slapped a S36 exemption on it (Professional Opinion) then that would need to be reviewed for subsequent requests post results day, as some of the stuff covered by that FOI exemption would now be issued under the SAR. It is a vicious circle!!!
  13. No, you are not imagining this and there is some concern that schools will be inundated with both SARs from individuals and FOI requests to find out how the process was set up. Once there is clearer information from Ofqual around challenges, then your DPOs will be able to help you put together some support on this. Yes, it could mean more work but some simple steps should allow you to prepare for anything you have to do.
  14. Is this a risk assessment for physically being on-site, managing social distancing and dealing with objects that may transmit infection? I'd strongly recommend review of the HSE guidance. https://www.hse.gov.uk/coronavirus/index.htm#
  15. If a user decided to send, for personal reasons, an email to all other users and it was not related to college business, to the 'school' they are in at the university (e.g. Political sciences) or part of an agreed group (political societies) then it is personal and is more likely to be an abuse of access then anything else.
  16. This is an area that touches very close to home for me. The pressure on schools to allow all and sundry to take pictures at school events is a real struggle. I have had some other parents grumble about me being that parent that stops photos being taken at events, but more often than not I am faced with the battle of do we allow others to take pictures which include our children and put them up online or do I prevent our children taking part in certain activities. As Neil Brown has put, it is about ownership of our own data ... and the detractors of that ownership do tend to be those with an interest in being able to commoditise our personal data, whether via profiling, ads, manipulation of interest ... some companies just don't get the principles of Security by Design and Privacy by Design.
  17. From commentary I have been reading on it, the fact that the court did not establish this is down to the court only being able to establish past and present use, but being unable to establish future use and the impact that could have.
  18. Seeing as I wouldn’t expect anywhere near that high for when businesses are actually in the office, has home working suddenly made them better? I would love to see the stats on that research. Sample size, the questions ... *Shudder* I think we can safely say that most are doing their best in a difficult time and leave it that as a response to that ‘report’.
  19. Necro-posting .... 5 1/2 years!!!! Is that a record @Dos_Box?
  20. I never understood why that blog post references age and consent together. That isn’t relevant in schools.
  21. Most of the responses have this covered now .... but let's look at the flow of this @jrma91. The council (a data controller) shares information with you, the school (another data controller) about children and parents as part of their remit as part of the admissions process. This is to allow you, as a school, to fulfil your responsibilities. Once you have that data, you are using it for the purposes that you specify and under the appropriate lawful basis. You are transparent about your use of this data because it is in Privacy Notice, but you might have a concern that the parents have not seen it yet because they have yet to see a copy in your admissions pack. Simple solution ... when you send out the details for them to log into whatever system, you provide them with the details of the PN and explain things in clear language. The thing you have to remember is to ensure that you have a clear down process for all systems should any child not join you in September.
  22. Oh yes ... been doing this joke since '92 with Mrs Dook ... sometimes I get the question "can you turn the kettle on?" (approaches kettle) Hey, how you doin'? You have wonderful curves and I know I can get you hot and steamy! And yes, the rolling of eyes is audible.
  23. As others have said ... a new contact. You are holding their data in the particular of as a parent. Their role as a student is almost irrelevant and their data will slowly disappear as you apply your retention schedule.
×
×
  • Create New...