-
Posts
12,876 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by GrumbleDook
-
So you would say that the ability of a device being connected to your network (a personal device or a school owned device) that could run software that can scan and monitor IP traffic for IP cameras is not possible?
-
DSAR - Print Emails
GrumbleDook replied to DSapseid's topic in Data Protection & Information Handling
Data minimisation is one of the principles of data protection. If you can't establish a need (purpose and lawful basis) and establish how long you need it for, then you get rid of it. Email is not a long term storage solution for knowledge management. It is an information transfer mechanism ... and if you are going to use it for knowledge management ... then bloody well manage it! You say tagging is a waste of time ... I say that not tagging and not putting the information in the right place to start with is a waste of time. -
Mathschase - Is this a suspicious website?
GrumbleDook replied to ap_'s topic in Data Protection & Information Handling
I've requested more information with my DPO hat on. -
The article has some issues ... if nothing else they state that BA have been fined (they have had to notice of intent, so it has hoops to jump through and appeals and so on), and the headline is click bait. Biometrics can be used but it has to be proportionate and also done legally. In this case it was neither. That is a problem with the school, not the use of biometrics. I’ll be putting out a more detailed article tonight.
-
How protected is your LAN?
-
Where you are making use of a service for free... Please, please, please make sure you read the T&Cs, that the school is established as the data controller, that you have evaluated their privacy policy/DSA, that you are clear what happens with the data and that closing it all down is easy, including removing any and all data.
-
I'm presuming that transfer of data between all systems is encrypted?
-
GOOGLE PLANS TO MOVE USER INFO OUTSIDE EU
GrumbleDook replied to nettihen's topic in Data Protection & Information Handling
The school is Data Controller for G Suite for Education ... the question is about the additional services and the application of legislation there. To be fair, the education team at Google are switched on and sorting out who to speak with on this. I am sure we will see more information soon. Some schools *will* need to look at DPIAs, and also need to think about the additional service. -
External DPO Role provider recommendations
GrumbleDook replied to hudsen123's topic in Data Protection & Information Handling
There are a few good folk mentioned already, but Chorus are a really good bunch. Speak to @AndyCrow.- 11 replies
-
- data protection
- dpo
-
(and 1 more)
Tagged with:
-
External DPO Role provider recommendations
GrumbleDook replied to hudsen123's topic in Data Protection & Information Handling
It also depends on what you want the DPO to do, how hands on they are for all activities or whether you need them to support the building of the right culture in the school ... or both.- 11 replies
-
- data protection
- dpo
-
(and 1 more)
Tagged with:
-
Student Email Account & Parental Access
GrumbleDook replied to jaminben's topic in Data Protection & Information Handling
@enjay has it spot on. Why are you using Consent? It is not the most appropriate lawful basis. Also, the age is related to consent for ISS. If it comes via the school it is not ISS (Internet Society Service). -
Student Email Account & Parental Access
GrumbleDook replied to jaminben's topic in Data Protection & Information Handling
This is incorrect. The age of 13 is related to Internet Society Services, where the relationship is directly between the child and the service provider (e.g. Blizzard) and is related to where Consent is the lawful basis for processing. Whilst children have a right to control their data from any age, you have to be mindful of their competency. In Scotland that is deemed in law as over 12 (basically 12 years and 1 second counts), but in the rest of the UK there is no set age. To be honest, this is more of a safeguarding question than anything else. Why do the parents want or need access? Is this related to possible harm the child is getting into (county lines etc.)? Is there a risk that they will send emails from this account to other children, possibly pretending to be their child? Is this part of a greater issue? Until those questions have been answered then it is hard to pin down what to do. I would suggest a discussion between your line manager, the teach and the DSL in the first instance and then chat to the parents after that. -
Subject Access Request - Whats reasonable
GrumbleDook replied to titch's topic in Data Protection & Information Handling
As others have already said, the IRMS toolkit is your best place to look, and if you review the DfE Data Protection toolkit you will see an explanation around weeding some data out over time which matches the IRMS information. -
Subject Access Request - Whats reasonable
GrumbleDook replied to titch's topic in Data Protection & Information Handling
PII does not exist with GDPR, it is Personal Data... which covers a fair chunk more! -
GOOGLE PLANS TO MOVE USER INFO OUTSIDE EU
GrumbleDook replied to nettihen's topic in Data Protection & Information Handling
There are areas being contested about how Google use data and whether they are making decisions or not. The main things to remember are that they are still subject to UK law, schools need to be careful about the use of the additional services by school accounts and that the biggest areA to be mindful of is what users upload and share within G Suite ... sending access links to the wrong people is always going to be a problem! -
Email Retention Policy
GrumbleDook replied to Reboot_IT's topic in Data Protection & Information Handling
Your retention policy is based on need and is not specific to the technology. The technology should fit around this and this is what we consistently say to all our schools when they ask. We also recommend you look at the IRMS Records Management Toolkit for Schools as it goes into a lot of detail about retention. In short, email should not be a data storage system. Information from there should be put into the most relevant system and the email deleted if no longer needed. This is set out with law as it is part of the Data Minimisation principle. -
Apple TouchID and GDPR
GrumbleDook replied to howartp's topic in Data Protection & Information Handling
Can you give a definition, as set out in any legislation, agreed standard (not a patent) or any legal case for ‘Biometric Authenticator’ that shows it is not processing biometric information in a manner that can identify a person? -
Apple TouchID and GDPR
GrumbleDook replied to howartp's topic in Data Protection & Information Handling
And this is where I start to jump up and down and tell people not to focus on one bit ... the encryption/the string/the hardware used for scanning/whatever else is used to justify that it is not biometric data. Article 4(13) of GDPR has the following definition If the processing of data is taken from a physical or physiological characteristic (in this case, a fingerprint), then you are processing biometric data. Whether you can reverse the subsequent data string to form a functioning example of that biometric data or not is irrelevant. You are processing biometric data. You provide the kit, you control it, you are giving people the option to use it, then you either accept that you (as data controller) are making a decision on what is processed, or you have some way to show that the decision is down to the individual as part of their processing of their own data for personal use. I am very serious when I say that there are groups that are very concerned about the use of biometric data and the lack of concern schools show in using it. -
And that it causes cancer.
-
Apple TouchID and GDPR
GrumbleDook replied to howartp's topic in Data Protection & Information Handling
Biometric is biometric. Your risk assessment will take into account the technology and judge any risks appropriately. -
Apple TouchID and GDPR
GrumbleDook replied to howartp's topic in Data Protection & Information Handling
Subject rights are not absolute. a SAR for biometric data is often rejected as it is something already held by the person. Right to erasure is simple enough ... you remove the records from the device. If that means you have to physically do it on teh device or send an instruction to the end user how to do it ... it covers it. If the end user sets it up in the first place then that needs to be considered in the risk assessment. You might decide to prevent that facility completely. You might have a statement in the handover docs to say that the function is turned off by default but if they chose to enable it, then it is their choice and you accept no control, but reserve the right to remove the function at a later date (appropriate details in your data retentions schedule and any other docs to that affect too). Another approach could be to consider that if you as a data controller don't require it, then you could have in your risk assessment that it is personal use of data, and not under your remit ... Whichever way it goes, document the decision, be clear about it to end users and make sure you still have control over other aspects of the devices (which will be processing data on the school's behalf). -
Access to employees files.
GrumbleDook replied to JaffaC121's topic in Data Protection & Information Handling
As @rom1984 has said, no reason not to comply with this request but you also need to consider this within wider legislation and practices. Why are the files being accessed? To assess for reasons for stress? To allow someone else to carry on the work? To allow for the SBM to identify who to hand things over to (effectively being the gatekeeper ... which is actually a good thing as it shows that someone is taking ownership of this and not just giving carte Blanche to others to dig in there). There is nothing wrong in asking for the Head to sign off the request (it should be done by someone other than SBM to protect the SBM and the school) and ensuring that they have considered all applicable legislation, sought guidance from HR and checked school policies. -
Apple TouchID and GDPR
GrumbleDook replied to howartp's topic in Data Protection & Information Handling
1 - it is biometric Data and so covered by the Protection of Freedoms Act 2 - you require a clear purpose (ensuring devices remain secure and able to be used for delivery of curriculum and running of the school?) 3 - you require lawful basis under both Art. 6 and Art. 9 of GDPR. A DPIA could be done to cover the specific use of Biometric data in this instance or Biometric data in general. Your DPO should assist you in this. Check https://www.educationdatamatters.org.uk for example templates for DPIAs that could be used to kick start this. I’m interested to catch up with the Veritau team about the EDM site. Are you able to PM me with your contacts’ details? TIA.
