Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. Fire extinguisher
  2. Hermione (it is World Book Day!)
  3. Car (before anyone else says it then mentions me!)
  4. I asked the Vice-Chair last night about when it is due for release. It is presently going through proof reading and design. All going well it should be ready for the May launch.
  5. You use what the school has defined int eh purpose. You will often find student / staff cards have multiple purposes ... Identify individuals Access control solutions (including building access, access to software / systems ... whether it is library software or to log into the AD) Payment systems There are a few others you could put in but some of those bring up interesting privacy concerns (Discussion on use of RFID is a separate issue). Look to see if any of these need a DPIA. Assess the risks and make a decision that is clearly documented and justifiable. Then go with want you are left with. It will be slightly different for every school ... but there are some common questions you might ask yourself (Look at the ICO guidance on DPIAs for more advice). It can work where there is phot ID on the card and it is used for payments and access control. Is losing it a data breach? If an individual lost their own Photo ID ... it would be debatable (I've had 4 different opinions on this so far). If the school lost a load of cards? Yes, then that would be a breach.
  6. Don’t punish on SLAs. However do use KPIs to identify areas for change. KPIs can be quantitative or qualitative, and so look at both averages of times to respond / fix / etc. and look at how people feel about how it was handled. Failure to adapt and change by individuals is an issue to be addressed by training, mentoring, targets and, ultimately, action. This has to be achievable and reasonable. Anything else goes towards constructive dismissal.
  7. I can appreciate what you are saying but what if we all started from the basis that having an SLA is a target ... a bit like a mountain to climb. The purpose could be a range of things ... basically a vision statement. If climbing a mountain it could be to prove physical and mental strength, it could be to be the first at something... or simply because it is there. A vision for a support team could be to ensure a smooth running IT infrastructure and systems to allow teachers to teach, pupils to learn and the school to run. It could be more business orientated ... to deliver required services through efficiency and control (these are both paraphrased from real examples ... and get which one is BSF related). Either way, the SLA is an end goal at this point. So you can either look at the industry / sector examples and work out are they achievable for you ... do you need to tweak them or do you need to change how the team works to hit them. In reality, it is a hybrid ... Is there a collected set of SLAs which schools have? How did each school put them together? Are they based on fix / resolution times, on comms times or both? There have been some good discussions on this so far, but can members actually state what their SLAs are?
  8. Also, instead of just looking at the SLA/KPIs, look at particular functions within them ... if communication has been a problem then getting an acknowledgement and regular updates on progress is possibly one of the best targets for bridge building with staff. The SLA should have a first response time and then subsequent update times until fixed. I'm half tempted to say don't worry about the fix times at this point. Likewise, making sure that problem management is in place, not just incident management. Are you also workign with them to explain and expand on IT Service Management? The FITS Foundation is still about, but most of the earlier iteration of FITS is available on OGL via the National Archives dump of the Becta site. Just a few thoughts.
  9. It is not consent ... they are not allowing a 3rd party to act on their behalf to make a SAR. It may seem like a fine line, but it is an important one. There may be areas that need discussing under duty of care, progress within lessons, and so on ... all areas where the school has decided there is a lawful basis for sharing information with parents.
  10. Ok, a couple of interesting things to cover on this. 1 - There is a difference between an Educational Record and information on a pupil ... the applies to maintained schools though. Alsp pupil meeting notes are unlikely to be within here. 2 - Any information you have been provided is yours to use under your policies and procedures. The data shared to you from the previous school is based on a relationship that used to be termed Controllers in Common, i.e. you have a reason for sharing it to the other school (legal obligation / public task) but they are the controller once they have it. 3 - Having said that, common sense is needed too. IF you have data provided by the other school and you are concerned then call them. Tell them that they sent over X & Y and according to your policy you share that un-redacted ... if they shared in error, then that is their breach to worry about and you have a reason not to share yourself, but if they didn't then go ahead. 4 - Be mindful of issues that may be ongoing. At this point, go and chat to those wonderful, your legal services (remember ... IANAL!) 5 - The age thing is interesting. The best I can say here is to check https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-of-access/#13 for the latest guidance and remember it is a 2 stage process ... is the child mature/knowledgable enough to understand their rights ... and if they are, have you asked if the parents can make the request on their behalf. I have a particular position on the difficulties with the former, but it is down to a case-by-case process ... making sure you record results. IF the child refuses then the school should consider other means to get key information out.
  11. I'm trying to work out who is saying that the additional services require parental permission (i.e. consent).
×
×
  • Create New...