Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. That’s because the details should be in the Privacy Notice :-)
  2. The phrase would be better if it was something like ... Within Safeguarding, data protection has a vital place but not just to restrict unsafe practices that create safe guarding risks, but to make sure the people understand Safeguarding is a clear and valid purpose for sharing data, and that it is easy to find that “lawful basis” when you do need to share. We shouldn’t view data protection as a reason to stop sharing, only to be mindful of our reasons and the methods we use.
  3. Terribly worded and extremely dangerous. It gives a false impression of what and why things are done. If you can PM me the details of the provider please so I can point them to someone who *can* word it better (UKSIC, various AACOSS members, etc.)
  4. https://www.gdpr.school/free-resources may help.
  5. Hey @Dos_Box ... escape and evasion training!
  6. The fine on this *is* a bit strange and there is more on this than in the press release. The ICO are starting to show teeth though, and not scared of making use of available laws (including CMA) to get prosecutions through. The fact that they haven’t taken action on the schools is good, as it makes it clear that where schools *are* working hard then they are not being penalised for individual actions. There *is* more to this and it will be interesting to read once more info comes out.
  7. I think the recent thread about ICO fining a former Head for removing data should be enough to quell this. http://www.edugeek.net/forums/data-protection-information-handling/202021-head-teacher-fined-dp-breach.html
  8. I'm investigating this at the moment ... the press release was purely about the prosecution alone, and not about the schools or any other action that may be in the process of being taken against the individual involved.
  9. Considering I was dealing with the fall out all the way home on the Saturday, I would prefer to forget it!
  10. But can you remember why? It got to one point with one firm where pretty much all their staff had changed but I was always ignored on their stand ... and it took until the first year of teh EG stand for someone to talk to me ... and noone could remember why it happened. I could ... I heckled a particularly annoying sales drone during a presentation because they were selling by slating the competition. I pointed this out and only 2 people could remember that person and fully agreed that they were a !
  11. There could be (and should be) a thread specifically about where EG members have been banned from at BETT over the years!
  12. EduGeek like to partner with the best possible company ... so no doubt @Dos_Box will confirm who it is over the next few weeks.
  13. You may not need consent and https://community.jisc.ac.uk/blogs/regulatory-developments/article/gdpr-recording-phone-calls is a pretty good article to start with and ICO do have more direct advice.
  14. I’ll send that on to Iain (if he hasn’t already seen it).
  15. This is related to PECR rather than GDPR/DPA, but it does show that ICO are sharpening their claws and happy to use their teeth. They will also support other actions such as prosecutions against individuals, calling on CMA when needed ... so we can see where that affects GDPR/DPA.
  16. I've seen internal auditors who are not specifically just financial working within schools and trusts ... covering everything from ISO9001/IiP/finance/safeguarding/DP ... often with legal and operational support. I'll use those infamous words from the ICO helpine ... "It Depends!"
  17. @Ditto ... that training has not been uncommon and we are still getting questions seeing who can be DPO, x trumps y, that they can refuse any SAR ... some organisations have done a lot of harm.
  18. Really does depend on the catchment of the school and the risks involved ... the digital footprint is an important factor as the school needs to establish where the right to erasure comes into play ... can they balance LI against not being able to claw back images when the child is old enough to make that request themselves? Opt out is really not an option ... or if that is what they are relying on then they may have a lot of additional items in the contract with parents.
  19. Hmmm .... Legitimate Interests in Public Authorities cannot be used for Core Purposes. If they are publishing on websites and social media they will have 2 purposes ... informing parents of educational activities (Core Purpose) and marketing to encourage applications to the school, promoting to try to gain additional funds, etc. (LI). However, the risk that could exist to children when you take into account that the school is establishing a digital footprint on an opt out basis instead of using explicit consent would be high ... and they should be showing they have tried to do everything to reduce the risk ... and a perfect and well established way would be to use Consent, preferably at a granular level. If it has been done that way to reduce the administrative burden rather than uphold the right of the data subjects ... then it is a no no! Ask to see their DPIA on it ... if they can’t give you one (which they should under FOI) then that probably answers you question.
  20. An exemption doesn’t give you a free for all ... the five bullet points in “At a glance” really are key. The example I gave of the board that gets opened and closed each day is an option already discussed with ICO and at the DfE working group (the example was actually for key data held in classrooms but kept on the inside of a cupboard door that could be opened as required but the principles apply when we expanded it).
  21. A network manager *cannot* be a DPO in the same school. I missed that in the earlier posts. There is a massive conflict of interests and you really do need a level of senior position in the school where you can take it to the Governing Body ... as that is who the DPO reports to, not the Head individually.
  22. Well, it is obvious that pretty much nothing is going to be accepted as any other reason in spite of trying to explain the turmoil that is BETT and how frustrating it is trying to market to schools. BBC were pushed out by software vendors ... because of politics and the Curriculum Online money. DfE pulled as a policy decision and that forced pretty much all associated groups to pull ... There are times when 1 or 2 folk make a decision on high and everyone else in the company / organisation, no matter how they know it could look, has to just get on with it. As I’ve put already ... there are quite a few understandable reasons why it has been done and why it may not change. I don’t particularly know which one of the many options it could be, but the party line is they will see more people and get more done by doing things like the regional roadshows *driven by the DfE* ... which would sound like a pretty good option. Marketing budgets are not bottomless ... and my personal feeling on BETT over the years is fairly well known ... it is about making money for the owners and not about the impact on schools / children. If someone points out a better option do I think companies should grab it? Hell, yeah! Do I think they are sat on their laurels? No ... I think it was a brave move ... and time will tell whether it was the right one ... but never make the presumption that just because any company / organisation has always been at BETT(or any trade show) that they always will ...
  23. Ok, the questions go like this ... Have we done everything possible to reduce any risks associated with the use of this data? They answer “yes”. You ask “have you considered and taken action to reduce or remove the risk of unchecked individuals from seeing this data such as visitors (adult and children), people using the facilities when no children are around, etc. They answer “yes”. Note that if the answer is no then this is a data protection *and* a safeguarding fail. We go on to ask what action have you taken then? They answer “none”. So you have explored every option? Having the VC board with a lockable cover that the site manager opens each morning and closes each night, or the DSL closes when the risk is particularly high such as open evenings, shows and events? “Erm.... but that costs money or time or both.” So you are justifying a safeguarding decision on money? “No ... but what happens if a cleaner or visitor discovers a vulnerable child.” The board is open to the cleaners if you feel they must know. They must also be included in any training associated with this ... oh, and you do pay them whilst they are being trained off course... “But what about visitors?” You mean you have visitors wandering around unaccompanied in areas where there may be vulnerable children? Can you explain to me why? “Erm ... open evenings.” Well staffed and and carefully managed open evenings? “Of course” Where key staff sweep the building for offending graffiti, rubbish ... oh, and stray pupils? “Yes ... erm ...” “But what about an emergency issue?” You mean where you circulate an email to key staff so they can brief their departments, or gather everyone in to the staff room for a briefing? “But not everyone will see it because they are teaching and we can’t take them away from that!” And a Notice in the staff room would be seen by them when they are teaching? .... Like I said ... it *is* safeguarding ... in the same way H&S is ... and Online Safety is.
  24. @jmak pleeeeaasseeee don’t use the word “trump”. It doesn’t exist ... if anything, safeguarding is the *purpose* for processing data!
  25. Oh sweet $deity. Nothing *trumps* data protection ... there are exemptions, there are judgements and decisions made on risk assessments (DPIAs) and then there are people not wanting to look at other options or the impact this has. If they have done the DPIA then fine ... they’ve made a decision and when it gets challenged they have to justify it, including to ICO and in the courts. If they are happy with that then there is little they can do (and no lawyer will ever say x trumps y!!) In this case, like many I’ve seen, the risk of data being seen by people who have no right to see it, who could use this data for their own purpose or who increase the risk that the information will spread to those who have court orders preventing them from having contact is going to be high ... this *is* safeguarding ... so they are making a poor safeguarding decision at that point. I would challenge it and happy to speak to you and them if you want. If, as DPO, you have advised them and they have ignored your advice then make a particular note of it in your next report to the Governors... force the DSL to take advice from others and finally recommend they get a legal clarification on it. I am starting to see more DPOs and DP leads in schools having to cover themselves now ... not because of their own liability but making sure everyone knows where the buck stopped should something go wrong ... and more on a safeguarding point than data protection!
×
×
  • Create New...