Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. NAACE (I know ... there as so many I could think of but that is the first one that always comes up when people say the word ... can't think why!)
  2. Since when has facts made any relevance to click bait articles?
  3. Although, as a company, we marked ‘the one year on’, as an individual I’m tending to benchmark against where we are compared to when Becta releases their guidance over 10 years ago. A lot of the advice out there still applies. It needs tweaks and some of the questions schools ask themselves need another shake, but that will come with time. There is still lip service in some places, but it will improve.
  4. There is this idea that a DPO does all the work ... *all* the work. The regulation says that the DPO should be given adequate resources and that truly does mean access to people to do things they know about. There is not that much difference than under DPA98 really ... but the better structure and oversight has helped schools on this. This will be part of my session next week at the conference.
  5. Benadryl Cabbagepatch (my favourite variation on the Benedict Cumberbatch name generator)
  6. You mean an external DPO? They cannot be data controller ... only the school / trust can be data controller (including where they are joint data controller).
  7. As a member (and a volunteer who contributed to the toolkit) I really do think that membership is a good thing to have full access to it all.
  8. I’ve asked the question but you can also ask directly via [email protected]
  9. Yeh beat me to it. It went online this morning for members but they have been tweaking the page for public access.
  10. I started to watch It Ain’t ‘Alf Hot Mum ... and whilst there are so many funny bits, it just leaves me feeling uncomfortable.
  11. Hold on ... when I hosted the first conferences I was excluded from taking part in prize draws ... I demand your entries as well as my own!
  12. SAR, requesting the source of information. Just imagine how busy they will be if *everyone* submitted a SAR.
  13. You may not have MFA on your SSO ... Actually, some of the organisational barriers to MFA on MIS also apply to SSO to, to be honest ... however, I think this is going off-topic for this thread ... @matt40k if you fancy starting a thread on it, it could be worth folk talking about the technical and organisational issues they have had to deal with in implementing MFA. Staff not wanting an app on their personal phone is one that comes up.
  14. It is worth saying that some schools can not afford MFA and not all SSO/federation can be set up to allow it. So corners get cut ... We know corners get cut.
  15. “However, if an attacker compromises a user's account or password, that attacker could have easy access to far more content than they might have in a traditional system. For this reason, we recommend that SSO be implemented to require MFA.” https://www.ncsc.gov.uk/collection/passwords/updating-your-approach It is a risk assessment and introducing SSO to connect to your MIS significantly increases the risk to Personal Data and Special Category Personal Data ... and considering that there is evidence of this resulting in data breaches (including sanctions against a school) then you *have* to treat it with caution. The use of MFA is a good countermeasure but you have to also look at how good it is at treating the risk. Good if app-based on a phone that also has access control on it but not as good if a code generating token that is in the same bag as the notebook where a user has written down their passwords!
  16. SSO / federated Access is not always a good thing. If the main account username / password is compromised then access to the MIS is then open too. There have been incidents of this in schools previously, including one school having to sign an Undertaking with ICO as a result.
  17. It should not be a day off ... it is valuable CPD (and free to get in too!)
  18. Happy to chat about this. We work with a number of LAs, DPOaaS providers and also do it ourselves.
  19. This should be based on 3 things. 1 - a marketing / comms programme by the school and the social housing ... raising awareness of what is going on. This could be targetted to groups of parents if the school knows who is 'likely' to be involved. 2 - The school and the social housing group both having mechanisms for parents / residents to grant permission for data to be shared (you have a purpose ... the lawful basis could be Consent, but could even be public task ... but getting the information first is an important factor) 3 - this data is shared (securely) on a regular basis so that they have a matching list that is updated and accuracy maintained. Privacy Notices for both of them should be updated and a Data Sharing Agreement should be in place (School and Social Housing Group are likely to be Joint DCs)
  20. Article 30 compliance is a Record of Processing Activities and you need your Information Asset Register to go along with that. It will something that you will build over time or find tools to help (usual declaration of interest here as we do stuff in this area). As a Data Controller you will get contracts / T&Cs / DPAs from suppliers (where they are your data processor) and you work out what data they need to use to deliver youthe service ... but you are making the choice on that. Ulitmately, the choice is to use a different supplier / tool! Groupcall, etc. generally have that available for you. Where there is shared decisions on the data use then you are joint DCs ... and so on. Your auditor will be interested if you have worked all of this out. Did they mention anything on risk assessments? DPIAs? The rest of it ... sounds like you are making some good progress.
  21. Serious harm is a difficult one to use at times, partly because it has very specific use within cases and partly because it is very accusational against others involved with that child. If that is going to be used, you shuold really be in contact with social services anyway, and a multi-agency decision might be needed.
×
×
  • Create New...