Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. I would be hesitant of any plan to introduce facial recognition with CCTV in schools, never mind adding in any form of AI with it. If someone has done a risk assessment I would be very interested to see the results.
  2. Consent would be illegal in this case, as there is no way to avoid being in the system.
  3. Data Registration, as in you pay the ICO Registration fee? Handy to be transparent I suppose, but it doesn't need to be up on a wall anywhere. Stick with the regulated/legally required/those earned as achievements
  4. It should be that the WhatsApp business account(s) are owned by the school and WhatsApp are a data processor. The interesting bit comes when a member of staff messages on WhatsApp using a personal account from their own phone. For many, it would be that this is a personal account it comes from so it is a bad thing ... in reality, though, it is no different from someone using their personal email address to email something into work. Should it be used as a primary means of communication between staff? If they are all on WhatsApp for business, then the school is in control. If there is a mixture, then this is not a good thing and should be looked at in comparison to other communication methods. After all, you are unlikely to be emailing a personal email of a teacher to say that student X is needed out of lesson for a medical appointment ... so why would you do it with messages in any format or any provider. That is the first sticking point, no matter where the data is stored/processed.
  5. I love Rob Words ... so many wonderful videos on etymology. I think the suggestions about letters to add back into the alphabet is my favourite.
  6. Now, do I want a Dell Pro Plus Max, or a Dell Max Pro Premium Plus? Dellplus Promax Premium? Sounds more like an antacid!
  7. Like a number of things written in the past, you do need to take it into account that people often thought differently about things, and expressed them in the ways that they had available to them. Having read his biography, as well as materials from other Goons, writers and performers, it is pretty clear to see that Spike was pushing against what was typical for people of the era, and the memoirs really do give you an insight into how people survived ... or didn't, as the case can be. Does it excuse his brown-face, stereotypes and racial slurs? Nope, but there was also a lot of poking at the stereotyping that was going on too. There is a lot of reading between the lines that is needed ... and if you can do that sort of thing, I would also recommend the Kenneth Williams diaries.
  8. You are the Data Controller, as are they. You need to decide whether you are Joint Controllers (working on the data for the same purpose and only for that) or independent controllers who are sharing data for possibly common purposes but with each having different decisions to make. At this point, a data sharing agreement should be around. If they have chosen SAM as the system to use, then ask them for a copy of their DPIA. This should shortcut your work on it.
  9. Some good responses so far and the only comments I would add are around adequacy and risk assessments, and these are general comments, rather than specific to the OP. The DPF is a handy mechanism to allow data transfer to the US. It makes the hoop jumping around SCCs and such a lot simpler and lets you get straight to the bone of the issue. The CLOUD Act is what most people worry about and that can affect you no matter where you are. https://iapp.org/news/a/questions-to-ask-for-compliance-with-the-eu-gdpr-and-the-u-s-cloud-act/ gives a good coverage of what it means, but we have to remember that law enforcement agencies regularly make requests to each other about data, and some have been known to intercept traffic anyway. There are ways to mitigate this. If the vendor ensures that the data is encrypted at rest and also in transit, then it is down to who holds the keys. If the sub-processor does (eg AWS) then the risk is AWS are asked for the data. If it is the Data Processor, then you need to look at whether the DPF helps to cover any requests or if they are even affected by the CLOUd act. If you hold the keys (rare but it does sometimes happen) then the CLOUD act would not apply, but you are still subject to law enforcement requests. They would just come via the UK authorities on behalf of the US. Then you need to consider the likelihood of a request being made. Do you have data of US citizens? Overseas visitors? Data which could be relevant to the UK’s PREVENT agenda? General fishing for data by authorities is not likely to happen (safeguards in place should help in this), but what would the impact be if it was, and the data was held by US agencies? It is not going into some adtech data lake or being sold off. Used for future profiling? A possibility but are you holding any data likely to be used for that purpose? When people talk about the US with EdTech vendors, they are usually more worried about the data being shared with third parties (I.e. other data controllers such as AdTech profiling firms, looking to pool data to target individuals) rather than data being processed by processors and sub-processors. This is increasingly important as new data sources are also sought for AI training. Check to see if the vendor refers to deidentified data rather than anonymised. Look to see if they will use data for R&D or live data for testing. Most of these areas are relevant no matter the location, but may be particularly in need of review when considering US hosting. I could never say US = good/bad as the risks need to be relevant to your own institutions or organisations, but I hope this helps.
  10. Nah ... don't bother with cream or jam. Some lovely, rich Irish butter is all that you need.
  11. "Wow, there are only crumbs left on the plate. Whatever they were, they must have been tasty. Are your sure there are no more, and what are they called?" "It's gone ..." "Sgone? oh Scone ... I must write that down somewhere."
  12. I'm not a big fan of bacon or gammon. Smoked ham is nice, especially with some cheese or pickle, but I just don't like salty meats. That's just how my taste buds work. I would give these a go, but I can't see them replacing the proper beans and sausages.
  13. A few things to note. Your staff should only use systems with due diligence completed and subsequently allowed. It should be clear what the relationship between you and the system provider is (Data Controller-Data Processor, Data Controller-Data Controller, Joint Controllers?). Any use of personal data on personal devices would come under BYOD policies ... check them and get them updated. Unless the school is using WhatsApp for Business then they truly have little ownership on what is going on. This is what Teams/Google Chat and others are there for. I have repeatedly said that WhatsApp is usable for personal use, and even possible to have limited use at work for non-essential and non-sensitive things. The core though is performing a risk assessment. If there is still a high risk and someone is willing to accept it (and have the subsequent discussion with the ICO about a Public Body doing High Risk processing) then that is the organisation's decision and folk have to live with it. I don't envy your DPO's work.
  14. Just to circle back to this one, if you do not specifically say that they can only use checked and agreed systems, then they may end up using all sorts of things, but whatever they use falls within scope. If they are using a system that has not been checked and agreed upon, and you say that can only use the official/agreed systems, then they are in breach of your policies and whilst they can argue it is not in scope, you then have the issue of a possible breach and a Governor who is also breaching policies. I like the idea of a workflow that sends a notification to a given address if new emails arrive in the school-owned mailbox.
  15. Yep, some of them out there really do grab a lot more data than is needed. The other really important fact is that unless you have a formal relationship with them (Data Processing Agreement or Data Sharing Agreement) it is likely to be an illegal transfer. If your staff will get the student signed up anyway then that is a serious issue on data protection, privacy and safeguarding grounds. This should involve your DPO and your senior leadership team. In the interest of protecting yourself, if you are told to allow it, document it. Cover your behind. The school would not accept getting science supplies without thinking about COSHH, or ask random builder to sort out a new block for them. I’ll dig out a few old posts that give examples of the problems involved and how close to home it can get.
  16. If they use their school email address and decide on their own username/password then the school really has no involvement. The relationship is between the site (Data Controller) and the student/teacher (Data Subject) If SSO is involved, then the site is using personal data that the school owns and controls. There *is* a direct relationship and you are making a decision about what data can be transferred to another Data Controller. And this is probably being done with a data sharing agreement. Basically? The illegal transfer of data to an unverified Data Controller. Can it be made legal? Yes, of a fashion. We are now talking about consent to share data with 3rd parties (I.e. separate Data Controllers and *not* Data Processors) and managing everything that goes along with it. It is untested in court or ICO investigations as to whether the school has to do Due Diligence to ensure any Data Controller they share data with is up to spec with respect to The Children’s Code, but I am sure interested parties would insist on it. As a vendor, we are clear we are a Data Processor. We have to be and that means having the relevant agreement in place. As a consultant within the EdTech provider community, I am always clear about the limitations and implications of becoming a Data Controller. Only those who sell on a direct to family basis tend to opt for this, and try to keep their school version separate.
  17. I think you have hit on the most relevant term… 3rd Party! You have two types of site you are being asked to link to. The one you want is where you have a relationship with them, are clearly the data controller and they are the data processor, and you have completed any checks and risk assessment (including data requested with permissions during setup of SSO). The one you don’t want are the consumer / extra bits that you don’t control but are requested by all sorts of sites. These are their own data controller and could range from really good educational tools to dating websites! These would have a direct relationship with the end user and would count as Information Society Services, would come under the Children’s Code and likely require Consent. So yeah … you are right to avoid this, no matter what you are using … Google, MS, Apple …
  18. I've recently finished Emma by Jane Austen, as it was the last one I hadn't read. I suggested it for our book club at work ... and some of it has been heavy going, but other bits have been really good. I also recently re-read the Spike Milligan memoirs. I've also been rattling through a fair chunk of YA on Kindle Unlimited. It is comfort reading more than anything spectacular ... but still good fun.
  19. Evening all. Wasn’t sure if this one had been shared around but for those of us who are Kevins/Pratchett fans, have you considered supporting any of the custom builds on Lego Ideas? https://ideas.lego.com/s/p:b023eb6a83fc48dcb1255f2a6b7167a1 remains my favourite atm and the goal is to get it to 10k.
      • 1
      • Thanks
  20. It has been good practice to have areas of encryption or total encryption on hard drives that hold or process personal data. This goes back to guidance from Becta in 2009/10. Are there ways other than BitLocker? Yes. Are they worth the hassle? Probably not. The same applies to FileVault and Macs. Any exceptions? Devices that will bring to a halt? Risk assessment and put risks into risk register including plans to replace. So, yeah … pretty much what others have said.
  21. Some good suggestions in there. I know there are some things that have been looked at, but drop me a DM, and I'll see what's up.
  22. I'll share that feedback (if you haven't already) and see what the team says.
  23. Facial recognition has 3 problems and the last report from DefendDigitalMe pretty much nails most of the concerns about approaches. The original push on this was very clear that this was a new tool and clever SLTs should get on board asap. In reality, only the benefits were looked at and for some schools the view was, "well, we already use their finger prints, so we know biometrics can be ok". Normalising security measures through the public sector Removing perception of risk Putting the school before the individuals. These are things to look at and deal with, though. If you have a clear purpose for why you are using facial recognition, it is also clearly of benefit to the individuals, you are taking measures to reduce risks/possible harms, you are transparent with all involved ... then it can be made to work. However, no matter what you do when you put it in, you need to have non-intrusive alternatives and also be clear about why those are not suitable for what you are trying to do, but they are an available compromise. Remember, the general rule is that if you can be less intrusive for the same thing, then you *should be* less intrusive. So, what does it look like in reality? A school is desperate to make sure that all students get lunch. It is autumn/winter, and more and more students want hot food. The queues are increasing, and it is almost impossible to get them all through, never mind having enough time to eat properly. Even if it shaves off 2 seconds per student, then 15 students equal half a minute. A class is a full minute, an 8-form entry secondary school (where half are on hot lunches), that could save 4 minutes per year, which suddenly becomes 20 minutes across the school. Students have enough time to eat, have a bit of R&R, and maybe even do an extra-curricular activity. These are for the benefit of the students. Without the checks and balances about the usage, security, respect for privacy ... then the other part of the implementation is lost. Instilling respect for privacy (the school models and the children follow), clear communications ... I hope this breakdown is found to be helpful.
  24. It is worth mentioning that NetSupport Notify will integrate with TeamSOS too.
  25. 10 years is fine. The way some folk talk about it, you write the plan and stick to it. In reality, you are reviewing it constantly. Whether you are just doing it annually as part of the updates to the School Development Plan, or you do it as specific projects or workstreams are completed. There are times you need a 10-year plan. If the school/trust is in areas where there is a predicted growth or decline in the population of children they may need changes to building and facilities. When working at the LA one of the School Admissions staff was a marvel at this sort of modelling and it makes a world of difference in planning. Yes, technology may change and the tools used by teachers and children too, but that is why you keep on track in where changes may be needed.
×
×
  • Create New...