Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. It is one for the MAT. We have an article about it that I’ll link to in the morning.
  2. Something I've been meaning to raise for a while is whether folk have noticed that schools have had fines from ICO for non-payment of the Data Protection Fee? The volunteers at the DfE Data Protection Working Group have been discussing it recently and we would have loved to have seen DfE do another push, but as they are pretty much quiet at the moment due to the election, we thought we would raise it on here. A short poll to see what your school has been doing with registration. We've also been looking at the work ICO have been doing with MATs. Are you aware that over 10 MATs have had ICO audits, covering 364 schools? https://www.educationdatamatters.org.uk/?page_id=1709 covers the report produced and a lot of other helpful information. The group is eager to receive feedback so please drop us a line.
  3. I have a very special VM set up just for such occasions ... running Windows 98SE and full of fun things. It is amazing how many remote tools don't run on Windows 98SE ... or how the word document with all my passwords *might* have a virus or two on there. To be honest, I don't have the time to mess with folk anymore ... and only save it for very special occasions.
  4. Liability is determined by a range of things but the important thing to remember is that the Data Controller/Data Processor now share liability ... how much depends on the balance of actions leading to a breach. Where the Data Controller and Data Processor are the same organisation (the example of teacher leaving their mark book on the bus), then the liability is with the Organisation. For individuals, you need to also look at the criminal offences within the Data Protection Act 2018. This is before you get to organisations taking direct actions against individuals who breach their contracts. Criminal Offences are primarily in sections 170 - 173 of UK DPA 2018, but there are others dotted throughout the act (providing false statements to ICO during investigations, the confidentiality of current and former ICO staff, etc.) As Andy has said, the DPO role has some special rules though with regards to their responsibilities ... that is to protect DPOs from being blamed for the organisation not following their advice. It is the organisation's responsibility to make sure that they have the right DPO and that they are correctly resourced ... Happy to have a chat with anyone on this.
  5. I cringe when I take a peek at what you Mac Admins have to do now to make things work. I started on 7.5.5 back on '96 and made good use of MacAdministrator ... and then when it the wall around 10.2 days we fiddled with Server and Login hooks. Whilst at the LA I blogged about how Apple's work on management was woeful (getting blacklisted from some events as a result) and then working for an MDM provider showed that things had gone from bad to worse. The advice from @TomPearceGeek is probably the best but I think anyone who has spent time working on Macs will admit that there are times when something just does not work in your own set up ... that works perfectly for someone else ... and there is no clear reason why. Short of starting from scratch, it can be hard to pin down. Best of look with it.
  6. It depends. It all depends on what the purpose of needing the ID in the first place is? Is it to identify the individual as proof of their identity? Is it so that should a security or safeguarding issue occur you have more information to be able to hand to authorities? Is it so that should they be a regular visitor (e.g. a volunteer), then you have a consistent means of proof of identity so that they don't have to repeatedly bring phot ID every time? If you do decide you need it are you agreeing to a point when it gets securely deleted/shredded?
  7. The schedule of data is good, but the rest of the document is seriously lacking with respect to GDPR. Insist on a plain English version of the DPA. Email them.
  8. The issue is around when data is being sent back into the UK by your processor or the sub-processors. There are situations that could arise where Supervisory Authorities could restrict data being sent back. It is a bit of a ludicrous situation and I'm not going to even start talking about whether the probability can be calculated (you would have to assess each and every day from now until the moment any agreement between UK and EU/EEA is made) ... Standard Contract Clauses don't have a model to cover the EU-UK Processor to Controller but they can be adapted. Yes, for our customers we are asking ... and most guidance from ICO is fairly generic but repeated calls to the helpdesk has raised interesting options ... one has even gone as far as the data controller contacting each Supervisory Authority for each case! The best thing you can do is say not to panic, check that processors are doing what they can to ensure data continues to flow. The reason the DfE cannot do this risk assessment on mass as *it* doesn't know what you are using and each school / or trust (in the case of MATs) is the legal entity. It will be a fun few weeks. Let's just say that at least Education is getting some guidance ... there are folk out there completely in the dark.
  9. The discussion has been an interesting read ... a few points to consider and remember though. Firstly, in the UK we have the Protection of Freedoms Act which also governs the use of biometric data and ICO / DfE have advice on this already ... it has been discussed in previous discussions and also in one of the sticky threads too. Secondly, whilst the translation of the final decision I have is a tad shaky, there are a few easy things to pick out as key points. 1 - the processing was more intrusive compared to other options 2 - processing of personal data under consent was effectively forced on the students. This meant that the lawful basis under both article 6 and article would be invalid. 3 - they failed to recognise aspects of article 5 (purpose limitation and data minimisation) 4 - the Risk Assessment (DPIA) was deemed inadequate as it did not deal with certain areas including fails on identification due to headgear/scarves/shawls. Having also spoken with some of the same folk at BETT about their systems, some of them had a clear message that DPIAs had to be rigorous and deal with all aspects. Others had a more laissez-faire attitude ... One important purpose, identification in the event of an emergency (e.g. fire or significant threat) was an interesting approach, but falling back in purpose limitation, you couldn’t then use that to justify general attendance use. It is an interesting area to consider when you think about the recent news about use of facial recognition in the Kings Cross area of London. More guidance on Risk Assessments is obviously needed.
  10. Roughly translated ... Have a records management and retention policy, which makes sure you store information in the relevant system and it is then removed from the 'transitory / transport' mechanism (email, memo, hard copy of letter, etc.)
  11. I'd like to see whether a combination of moving to 0 level, and blocking of sending data tothe telemetry servers does the job.
  12. @petem46 Just to clarify things … GDPR does apply to all personal data sharing from schools to third parties, but there are exemptions and criteria for those exemptions … I know it sounds pretty much the same as "GDPR doesn't apply", but if people say it doesn't apply they forget to ensure they know why there is an exemption. Language helps to change the mindset.
  13. There are 3 issues that are within this ruling and why it has come up. Forget where it goes … that is only a small part of it. 1 - the issue within the telemetry data is collected based on what the company decides is needed, not the customer. 2 - if any of that data pertains to personal data (subject lines on emails, usernames, etc.) then the company is the data controller (*they* have made the decision) and so have a direct relationship with the data subject. 3 - As that is not the service delivered by the school, ISS rules come in so consent is needed … which cannot be given in most cases. An instruction from the institute to improve services by making use of selected data gets around this … but the institute needs to know and agree what that data will be. This is the stumbling block. The mitigation of this is ensuring that data is protected within law from anyone outside of the DP and DC accessing that data … and once it is on US servers then yes, the US Govt can seize it. There is still the challenge that the US Govt can seize when overseas as well, but the EU and EDPB constantly reviewing Privacy Shield is keeping some of that at bay … so the removal of the service in Germany has sparked off this review again … and rightly so. Turning telemetry off deals with that, but I have yet to see a seriously good guide about turning it all off … and does it turn *everything* off? We don't have definitive guidance in the UK, and NCSC offer guidance on dealing with cloud services … so it becomes a risk assessment in my opinion. I expect to see a number of DPIAs being done on this in the autumn term.
  14. This is going to be an interesting one ... There has long been an arguement that there should be a standard set of things a school turns off ... I've yet to see that though, and yet to see whether it is an issue with what is left. The other side of things is whether the school is instructing MS in activities to improve its service ...
  15. You only keep *information* as long as you need it ... the format is irrelevant. If the email has been dealt with and information recorded elsewhere, why keep the email? If you need to keep it then have an email retention policy set up so you simply label it not for deletion ... and it is not deleted. Apply that label to folders within your mailbox and put mail in the relevant folder (helping to make it easier to find at times too).
  16. “But what did I do wrong?” Do you shower? “Yes, most days” Do you wash you clothes? “Yes, when they need it” Do you tie your shoe laces? “Yes, but tend to just pull my trainers on and off” Do you put petrol in your car? “Yes, when close to empty” Do you check and top up the oil? “When the warning light comes on” Do you replace worn tyres? “When I get told to at the MOT” Do you check there is no glass in front of your tyres before driving off? “No one would be stupid enough to put glass there!” Do you check you car is locked? “I press the button” Do you leave your wallet on your car seat over night? “That would be stupid” Have you ever bragged that you have lots of cool gadgets at home? “Yeah ... you should see my 89” screen...” Do you ever wake up in a blind panic because you can’t remember if you closed the patio doors? “Sometimes, but I hardly ever forget to closed them” Lock them? “Erm ... most of the time” So, you basically say that you do the minimum, wait until you are told to do things and often forget to take basic approaches to security. Now, tell me, why do you want a job as our Head of IT?
  17. But there are times when do it really well ... that’s the thing that annoys me so much. As already shown though, there is a different story behind this and the experience schools are seeing. Hopefully, over the summer, we will be able to get the full picture and dive in a bit deeper to point out areas that schools can work on.
  18. The phrase “it depends” applies here ... there are a range of circumstances where they would require information and can reasonably request it. OP - If you are an overseas school dealing with military families, I would strongly suggest that legal services are employed to support this, especially if there is challenge against the request.
  19. It is a notice of intent ... there will be representation on this and the final judgement will be more telling ... how realistic it is that they could have handled differently
  20. I have a few issue with both the stats and the article. Once again, Schools Week take a swipe at DfE on data protection without taking into account the history of what has gone on, where volunteers are actively involved in doing things and where priorities have been. Anyone would think it is political opportunism to take a swipe. I would rather there are good news stories about guide practice, designed to raise people up rather than fear monger and slap people down. I’m not saying things are perfect, but maybe I’m a glass half full person. As for the stats, ICO have not provided this in their disclosure log so it is unclear where those stats are from. I have an updated FOI request in at the moment to see if we can get the same data set and do a bit more drilling into it. What we do know though is where no action is required is because the school may have already dealt with it, and ICO is taking no further action. That severely skews that stats when you take it into account.
  21. There are a range of tools out there ... SDS is the model upon which most are based, but chat to Alex at BFC Networks or Richard at SalamanderSoft for more info (sorry folks ... can't remember your EG handles)
  22. UCL are a major research centre for education and work on a range of projects around EdTech too. There are exemptions within GDPR around scientific research and the research should be compatible with the original purpose for collecting data. That would lead me to question LI (the data was collected under the lawful basis of Public Task) but if the data controller doing the work cannot use public task and there is another suitable lawful basis then that is workable ... but they have to be mindful of the other data protection principles too, e.g. transparency. I know BERA has been updating their guidance around transparency so I might go and dig again, but ... being honest ... what has been sent over so far looks fine. Use of UPN in research is compatible with the use of the NPD (at the moment), but I know there are concerns about NPD anyway ... I'm not going to go down that rabbit hole right now.
  23. Even with the push on GDPR and so on, many companies kept their existing list of contacts because they had quite good records of how they got the information, kept it as they felt using Legitimate Interest was the best lawful basis for the use, and so applied soft opt-in on PECR too. Some companies will make use of social media and so on to better identify contacts to ensure that they have relevant information .... Some still just go and buy the info in, as it doesn't take much to identify folk at times. Realistically, you can send in a SAR to a) see what information they have about you, b) try to identify the source and c) then go and tackle the source (if it is outside of that company). You can also request to be removed from their contacts and any other records they hold. I'd like to say you would be surprised the lengths that folk go to get infromation on potential clients ... but I don't think many of you will be. There is also the other side of things ... new staff come into the company, they are told the contacts list is up to date and verified, they build a campaign based on apologetic interuptions and think they are doing everything right, will be aghast that this isn't the case and rectify it straight away.Generally ... I tend to fall on the sympathetic side of things if it is a one off contact. Most places I contact to check things are apologetic and sort themselves out pretty quickly. Noone is perfect ...
×
×
  • Create New...