Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. The advice and that extract is a little out of context as the wider piece ISBA have advised on is around correct practices, as I understand it. They are correct that the formal DPO role is not stipulated as applicable to them as they are not public authorities and they advise against appointing one (once appointed then the DPO role has to adhere to the roles and responsibilities as aligned to the GDPR guidance from folk like the WP29 group and as set out by ICO as a result). By having a ‘lead’ they get around some of the restrictions including being more relaxed on restrictions due to conflicts of interest. It will be an interesting world for independent schools ... and until issues arise some will take a more *relaxed* approach as a result ...
  2. An absolutely fantastic resource has been produced on this ... https://missinfogeek.net/whos-in-control/
  3. Actually, they are happy for me to share their details with others, as it is both part of sharing who work have worked with when demonstrating our steps towards compliance and they are interested in more business, so there is legitimate interest here. ... There... fixed it for you. I’ll get my coat.
  4. The folk at Team Satchel are aware of the discussion and reviewing.
  5. Hmmm ... trip to the premiere?
  6. I don’t want them ... I’m suggesting people collect them so that they can check with DfE if they are legitimate calls ... and information would be processed as a public interest task to ensure that people are not falsely calling to gain information from schools. Let’s see if anyone is given the info.
  7. Ask them for their contact details.
  8. The above is in relation to PECR, and the lawful basis is Legitimate Interest. ePR, when it comes in, is changing this but the draft has just been updated and it may not be as severe as some people worried it might be. In schools, this is mainly going to affect promotion of the school, marketing to parents and running the facilities for external hire.
  9. If they already have your details and are pretty happy with the level of consent previously granted, then this is a) letting you know that they have your details and why, and b) giving you a chance to remove yourself. Depending on the quality of consent before, this is acceptable for both PECR and GDPR... but it really does rely on consent having originally been unabiguous, freely given, etc.
  10. Three things to consider. 1 - if the teacher wants to continue to have the record, that is between Bluesky and that teacher. This would need consent from the teacher or a contract to be in place. Legitimate Interests would still require the teachers need to be informed and that is the responsible of Bluesky, not the school dropping the contract. 2 - if the school instructs the deletion at the end of the contract then it happens, unless the above criteria are sorted 3 - erasure has no chargeable element. Data minimisation means it should go!
  11. An insight into the DfE and IRMS sides of things. The IRMS schools toolkit is fantastic and I would recommend your school’s cough up for membership (it truly is a small amount) to help contribute to the group of volunteers working on it. It really does look into where legislation affects data retention and GDPR is not going to make changes to that side of things (other than changing the name of the Act once it is finally signed off. The DfE advice also covers a lot more ‘operational’ areas in consideration though ... and helps set a culture of only retaining what is needed. As the DfE toolkit says, there is no single guide that covers everything right now, but it will kept evolving with advice.
  12. Just spotted this ... sorry for the delay in responding. You do t have to be a public authority to do a task in the public interest... but in this case, consent is going to be the most likely lawful basis as contractual obligations is hard to deal with in this case. The school has a choice of not getting involved or working with the PFTA to be a joint Data Controller perhaps ... something they may need to consider anyway.
  13. Pencilled the date in ... as usual, will confirm closer to the day but I will try ... honest!
  14. The law gives a description of special category personal data, but information can have ‘handling notes’ ... reminding you to take care of it. In the same way that commercial data in a company would be ‘sensitive’ in how it needs to be handled ... think about it in a simulate fashion.
  15. It is risk management. The ICO doesn’t have a book saying parents of X (easily known because of surname) are in to see a certain member of staff (known to be SENCO). They don’t have a book showing the the PCSO and a parent are both visiting the Head at the same time. Whilst some firms may use it as a sales tactic, there are concerns on existing sign-in books for valid reasons. In some places I will not use a sign-in book if it is completely open.
  16. Are you talking about a SIMS system hosted by Capita or the LA and remotely accessed via VDI or similar?
  17. Consent advice is a tricky one to manage in schools ... which is why some firms spend a lot of time trying to explain it ... unfortunately, as @jenatddm says, this can end up as advising on using consent as the de facto lawful basis. If you do go to a presentation and have consent pushed to you then push back and ask where safeguarding requirements fit, processing of the educational record and even about educational school trips. Emphasis should be on transparency and informing, not consent as a catch all.
  18. The school is always the Data Controller up until the point the data is shared to another agreed party as a permanent transference (e.g. the DfE). In other circumstances, the school is the Data Controller and the company processing it on behalf of the school is the data processor. The data processor will, as @rom1984 points out, will update their contract or update a schedule in it or add an addendum, to provide the data sharing agreement. If *you* set out what is being processed then they may ask you to input that before it is updated. An example would be ZenDesk (who use the Model Contract Clauses) will ask you to describe what you are asking them to process as you jointly put together the DSA. There are some scenarios where you could end up with being a joint Data Controller ... and that could be where the data subject has a direct relationship with both you and the supplier ... By rights, you are deciding what is being processed and when a processor dictates that you agree to their terms then the initial instinct is that you have no choice ... making them a joint Data Controller. However, you do have a choice ... you have a market choice and can go elsewhere. Once you understand that, you realise that yes ... a data processor can say they need to work with x, y and z data ... as it is to deliver a service that requires it. If you don’t want to ... then other suppliers are available. So. A summary. Where you are making the choice about what is being processed a good data processor will ask you what *you* are putting in and giving you a chance to put it within the contract or DSA. Where a data processor needs set data for their service to work they will be transparent about it in their DSA and/or contracts/T&Cs. Where they use a sub-processor they will be clear (including where sub-processors may use contractors and the like ... ) and make sure any sub-processors go through them and not directly to you (unless instructed).
  19. You don’t have to take technical measures ... you can have organisational measures instead. Ensure you policies stare the need for complex passcodes (alphanumeric) rather than 4 or 6 digit / pattern swipes. You can make a decision on fingerprint or facial recognition for access (I had agreed to it previously when implementing ISO27001) ... but it is really just down to your school and what level of risk the school is willing to accept.
  20. At the risk of angering the mods by talking stats ... For things like this you cannot sample without having bias, or at least the appearance of bias. You can run targeted surveys because you want a response from a particular demographic or grouping ... but that is different to sampling. When you have an insecure data set to get a full response from you put measures in to at least report failed attempts and failed responses (there is a difference). There is a difference between delivery receipts, read receipts and use of other tools to see if the email has been opened and read. You can, if careful, get a broad idea of whether you are hitting a live mailbox or not, and if you are being ignored.
  21. (As a voice over on a video with relevant play-based graphics) “Schools can be fun but they have lots of things to remember and help you understand. You see lots of signs up in the school and lots of rules, and teachers and your parents try to help you understand what they mean. There is one called Privacy Notice, which is all about how things stay private on computers. It is how the school helps you understand what the school knows about you, why it needs to know it, who it will get to help with it and how they also talk to your parents about what it knows.” And you then go one from there?
  22. The right to be informed should not be confused with the lawful basis for processing. They should be informed no matter what lawful basis you use. The language should be age appropriate.
  23. And until a ruling has been given, the ICO’s advice stands.
  24. Based on the above, the school have no responsibility in this other than confirming the mail domain used, which is freely available information and could even be considered an FoI request if it comes in. The relationship is between the students (data subjects) and Unidays (data controller). However, it would be worth making sure that students are aware of the Privacy Notice and what it means.
×
×
  • Create New...