-
Posts
12,876 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by GrumbleDook
-
Email retention policy
GrumbleDook replied to Simcfc73's topic in Data Protection & Information Handling
You have a range of options, and retention does not have to be on the email platform itself. You can save the message as a pdf or .msg file if you feel it may be needed. It may be attached to a personal record of a student or member of staff. -
There are times when a password is changed each time you log in (certain social care or financial solutions) but that is reducing now that multi-factor authentication has grown. In those situations where it has to be written down the keep it secret and secure. Also consider the domain admin account ... we have often discussed on the forums about this, where Heads or line managers have demanded a copy of passwords being available. The general response has been to write them down, stick into an envelope and sign across the seal, then laminate. An example of having to write it down and keeping secure.
-
GDPR - DPO and External IT Provider
GrumbleDook replied to IT4Edu's topic in Data Protection & Information Handling
Very true, but we are also facing that fact that the existing DPA is fairly untested for schools and some of the existing guidance needs a good overhaul (it is underway). It is going to be an ongoing journey ... and even if everyone is 100% compliant come 25th May, we still have various items to be worked on over the next few years ... codes of practice for age-appropriate website design, age-verification systems, certification and accreditation schemes for DPOs and other services ... it is going to be an evolving beast. -
I've had a few LinkedIn messages like that ... including one that wanted to sell us a portal (aimed at SMEs and marketing firms) to help schools with GDPR compliance as it recorded consent for everything from the kids ... as consent is the main thing schools need to worry about. They then couldn't explain the difference between a public authority and a Supervisory Authority.
-
Article: GDPR in Schools - EduGeek Members Offer
GrumbleDook replied to Dos_Box's topic in Legacy CMS Comments
Will PM you shortly -
Lists of pupil names on the wall
GrumbleDook replied to Jamman960's topic in Data Protection & Information Handling
Yes, the guidance appears to say that you do not need consent to publish. I've asked ICO and so far they can't explain the lawful basis for processing that would cover the advice in the existing guidance. "we are planning to develop more detailed guidance on this topic". Consent, at the moment, is the fall back, but will keep asking. -
Lists of pupil names on the wall
GrumbleDook replied to Jamman960's topic in Data Protection & Information Handling
Just in case anyone asks ... this is because the personal data you now hold is for compliance with legal obligations ... so you are processing it under a different lawful basis. You should inform people that you will be retaining that personal data as a result ... it makes for some interesting circular arguments ... -
Lists of pupil names on the wall
GrumbleDook replied to Jamman960's topic in Data Protection & Information Handling
Am I the only one who has considered changing the name of their child to a bit of VBA so when it gets typed up it does something amusing? -
Lists of pupil names on the wall
GrumbleDook replied to Jamman960's topic in Data Protection & Information Handling
Some good responses so far ... We have use for internal reward / motivation, internal publicity, external publicity, identification, medical support, safeguarding. We know that some of these will refer to name, age, medical need, educational needs, educational specialisms, personal interests. We've had some risks covered so far, but based on the above put together some scenarios and try to explain the risks involved. -
Forcing parents to share data with Controllers
GrumbleDook replied to enjay's topic in Data Protection & Information Handling
One of the things we have to remember here is that the data processor is forging a direct relationship with the parent at times ... so the relationship is one of data subject and data controller. So it is quite feasible for youto have joint data controllers with data elements relating to you, the parent and the processor ... and then additionally they may be a data controller on their own, or have joint data controller activities with other schools (think about services that give parents access to things across multiple schools). So, simple answer, yes, you may have suppliers that are joint data controllers, but you should also put things in place it people do not want to use those services. -
Pupils names in email addresses
GrumbleDook replied to MkII's topic in Data Protection & Information Handling
Had a catch up with ICO on a few things today ... they cannot comment on safeguarding practices but remind you that you need to take that into account. As for the personal data itself? It's a risk management exercise. Make sure you have a lawful basis for processing any personal data, regularly review your DPIA on it and justify your choice.- 16 replies
-
- 1
-
-
PM sent :-)
-
Lists of pupil names on the wall
GrumbleDook replied to Jamman960's topic in Data Protection & Information Handling
Ok, let’s get some more examples in before we start looking at them. -
Pupils names in email addresses
GrumbleDook replied to MkII's topic in Data Protection & Information Handling
The advice from Becta (paraphrasing) was make it age appropriate, use it in stages to educate about the real world and remember to identify risks on a school, class/group and individual level. The last bit is most relevant ... The problem is that most would look at this solely from an online safety point of view rather than from an all round position... There is nothing to say that you can’t do it ... as long as you have reviewed why you are doing it and can justify the decision.- 16 replies
-
Lists of pupil names on the wall
GrumbleDook replied to Jamman960's topic in Data Protection & Information Handling
Think about why you are publishing them and who they are used by ... then think about what impact there is of others seeing it. Let’s all do it as a general exercise and then round up at the end of the day. -
Pupils names in email addresses
GrumbleDook replied to MkII's topic in Data Protection & Information Handling
Numbers can work fine ... the panic about dehumanising is over used at times ... learning an important number and making use of it is a key concept children have to pick up. NI number, payroll number, phone number, army number, driving licence number ... It should also be explained clearly to learners that it is a protective barrier ... helping to add a bit more of a shield to them. As the children grow older then yes ... add their name as an alias ... it is part of growth. One thing I would say is to avoid identifiers in the number such as year of entry ... this gives an approx age ... As for it being too much? Heck, they learn whatever strange variant they are given when signing up for social media sites or gaming sites ... they will adapt.- 16 replies
-
GDPR - DPO and External IT Provider
GrumbleDook replied to IT4Edu's topic in Data Protection & Information Handling
Yes, it does depend on the size of the company. In the same way it depends on the size of a school as to whether there are enough staff / resource so an in-house DPO doesn’t have a conflict of interests. There does need to be clear segregation between any ‘operational’ activities by contractors / service providers and any “audit / governance”, and that is a risk management activity when you purchase services. -
Can I check with everyone who does retrieval of data from CCTV, do you make sure you have a log of who is authorised to make the request, the request itself (including justification), and who any data is subsequently shared with *as a minimum*?
-
GDPR - DPO and External IT Provider
GrumbleDook replied to IT4Edu's topic in Data Protection & Information Handling
I think mention of finance has been taken out of context slightly ... I mentioned the finance department to show it is a designated team with the LA that is likely to have nothing to do with the IT team installing and running networks. This is a governance issue, and yes ... you do need to be 100% sure that it can work, but how about thinking about it in an environment dealing compartmentalised information where only those who need to know, actually go know. Safeguarding is an example ... and whilst there is the possibility of people talking ... job descriptions, contracts, etc. rule this out (or should do) ... and the same applies to audit and compliance services. Of course, this would have to be included in any contract and carefully reviewed and checked on a regular basis. -
GDPR Guidance - Backup Question and Answers
GrumbleDook replied to rom1984's topic in Data Protection & Information Handling
Brilliant news @rom1984. I’ll drop you an email as soon as I can.- 1 reply
-
- 1
-
-
GDPR - DPO and External IT Provider
GrumbleDook replied to IT4Edu's topic in Data Protection & Information Handling
If the networks team was running your network would you allow the legal team be DPO? What would the conflict of interests be? -
GDPR - DPO and External IT Provider
GrumbleDook replied to IT4Edu's topic in Data Protection & Information Handling
If the networks team at your LA put in your network, would you stop the legal team being DPO? The same rules on assessing conflicts of interests apply. -
GDPR - DPO and External IT Provider
GrumbleDook replied to IT4Edu's topic in Data Protection & Information Handling
I will disagree with @elsiegee40 and say yes ... in the same way a school can employ someone to be a DPO. In large managed companies there are demarcations between departments (services, legal, finance, etc.) so you need to consider the risk of whether someone in this external company doing an audit of someone else on the same company is a risk to you ... for both conflicts of interest and for management of the contract with the external provider. Those taking DPO as a service from LAs have this to consider and, all being good, this has generally been seen as low risk ... but it is up to the school to decide. -
A quick note for those who say that they have a thumbnail of every image as a way of checking all the cameras are working ... In your CCTV policy you should have a maintenance log. This will be a record of when you check every device that it is viewing what it is meant to be viewing, that it operates as specified in the policy .... Some places will do this check on a weekly basis, some daily ... in shopping centres it will be at least once a shift, and is combined with a rolling (and usually automated) check on each camera. What you do is based on your school's need. If there is a high risk of intruders, a risk to damage to the cameras to prevent things being recorded ... then you will have a different operating procedure to other lower risk establishments.
