Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. 1 - the ID card is not compulsory to have outside of the school so if they took it outside and lost it, it would be the equivalent of losing a personal item which holds data - so not a breach (I’m dubious about this ... this sounds a bit too much like trying to shift all responsibility to the owner of the ID card ...) 2 - if the ID is that if a child then have you checked to see if they are competent enough to look after personal data in the first place. (Interesting one but, again ... is this trying to put the risk into the child by saying they are old enough to know better? If that is the case, then they could be old enough to make their own decisions on data and even try to over-rule parental responsibilities) 3 - it depends on what is on the ID card. Does it show data that could cause harm or damage their rights and freedoms? Does the card also contain other data (RFID, mag-strip) that holds data or provides access to other data? (This is more promising and it makes the school think about the purpose and data minimisation) 4 - use common sense. Is it any different to losing a school book that has a list of classmates in who are all in a project? (Common sense is not that common and not always right ... but it is a good starting point) The simple answer is ... it is what the school feels it is and they just need to be able to justify it. Either in the DPIA undertaken around ID cards or in the way they record any losses of cards.
  2. My EG search-fu is failing a bit but I am sure that this is a conversation that has been had before ... I've gone back to our data maps and looking at agreements, and this has been asked for before. I checked with the SMHW team (Hi Greg) and they confirmed it. All pretty good purposes, and hopefully you can see what functions are used as part of this.
  3. A school sports day is not a public event, unless it is advertised as a public event and the general public can freely attend. If it is a shared event, it is still reasonable to say it is not a public event, unless otherwise stated. Any organised event should have set out rules on safeguarding, including the use of data. Unless otherwise agreed, no single school should be using the data of others, unless agreed for the running of the event. PR afterwards for teh purpose of a single school still needs to have the relevant agreements in place. Parents taking photos will be for personal use, so data protection rules do not apply ... but this is only where permission is given to take photos ... and safeguarding of children, staff and attendees is very pertinent here. Attendees, children, parents and staff have to be given clear opportunities to "opt out" (it is actually the right to object to processing, not opting out of consent) and if the school has taken the view that a local photographer can take photos they have to be mindful of any prior objections, where consent has not been given for other circumstances of a similar nature and any other associated risks (see safeguarding comments). A Legitimate Interest Assessment may be in order as well, and data sharing agreements in place with the newspaper. In short Do not let papers dicate to you If there have been objections before, do not presume that it is ok now If parents / children have already refused consent for other PR / Media uses, then take this into account even though you are using LI this time Don't just think about data protection, also think of safeguarding and the rights of staff Be prepared to justify yourself. If you are not, then you should not be doing it ... transparency is important, but accountability is even more so!
  4. Or you risk OSS projects stalling as the main developer does something else, meaning no updates. If you VLAN off the devices and restrict access would that be reducing the risk enough? If you are paying a software and support contract on the devices then any bugs they have should be sorted asap.
  5. Additional funding is Personal Data, not Special Category Personal Data ... though it may be data the school chooses to treat sensitively (see the DfE Data Protection Toolkit). SEN is Special Category Personal Data (Medical). If you do not have a purpose for this to be used, then it is reasonable to untick them ... but check if this is used for accessibility of the app.
  6. It is mainly there as a comment for those looking to say "do x as it will prevent y", when doing x only makes y difficult, doesn't prevent it. If your justification for x is solely to prevent y then it is faulty.
  7. Sorry ... it's taken me a while to pin point too. https://webarchive.nationalarchives.gov.uk/20091002201703/http://becta.org.uk/fits/index.cfm is a good starting point ... as you move forward in the timeline of National Archive snapshots it does move about a bit, especially as it moves towards v2 and the FITS Foundation.
  8. Personal use ... not a data protection issue. A nightclub using them is a different matter.
  9. Screengabs will be taken, and even people taking photos of the screen. If folk want the data, they will get the data.
  10. It depends ... it can be both.
  11. The problem is that sometimes, as a Governor, having access to information quickly is key. I can fully understand his requirements on this ... However, there are things that need to be done to protect you systems. 1 - any data that is sent via email or is linked to within an email can still be downloaded. Don’t confuse protecting one method of access with protecting information. 2 - POP is a big no no, and IMAP is susceptible, but you are going to have to face that if he uses the web app he will need to get notifications ... how about explaining how he can do that. 3 - also face the fact that guidance needs to be given to Governors about securing data on home devices. Whilst Governors rarely have to deal with personal data, when they do it is important to keep it safe ... organisational measures should be there to support that (policies). 4 - Please remember that Governors are volunteers ... generally a dedicated bunch who are not there to be difficult, but to help the school. There are many governors on EG (including yours truly) so please be mindful of not casually dismissing their needs.
  12. Courses still run, and even if you go back and use the FITS 1.5 materials (available on the National Archives site under OGL) it is a good starting point.
  13. There was/is FITS ... still extremely relevant.
  14. If she cannot present evidence of this being an instruction or statutory guidance then you cannot follow it. It is hearsay and unbelievably damaging.
  15. Erm ... if there is a concern then perform a DPIA and then make a decision. I honestly cannot remember seeing anything that says you cannot use a particular cloud service ... only that you have to be mindful of how you set it up, how you provide access and so on.
  16. Mmmmmmmmmmmmmmmm... Tasty
  17. If there is concern about someone faking identity as part of a fraudulent claim or stating that they were not at the scene of an accident then I would also suggest contacting the police. Whilst the insurance company has a duty to prevent fraud, identity theft and fraud also fall within the remit of the police. An employer stating an employee was at work on a given date, at a given location and has been paid for that days work is a credible witness. I am sure that others from the school can also provide witness statements to say similar too.
  18. Share (risk management terms)
  19. dog (it is the name of a friend's dog)
×
×
  • Create New...