Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. We need to think about the scope of GDPR. Teacher's notes, where structured and recorded to be part of, or feed into, the learner's educational records (which will include assessment, behaviour, etc.) would be covered under Public Interest as it is part of delivery of the curriculum. You cannot know whether delivery has been effective, needs to continue or needs to be changed without making notes. Where the notes are unstructured (comments in margins, post-it note records of actions, etc.) then this would fall out of the scope of the Regulation *but should not be ignored as there may be impact if lost, shared incorrectly or holds incorrect information*.
  2. This is a cracking start and I would heartily recommend others contribute their ideas based on operational possibilities ... talk about the limits of available products, possible compromises ... but keep in mind the retention schedule ...
  3. That'll be Andrea Jelinek, Data Protection Commissioner of Austria and newly elected Chair of the Article 29 Working Party, which will be replaced by the European Data Protection Board come 25th May. Folk are extremely vocal about the problem ... but to minimise it people are having to rethink what they store, how it is backed up and how it is retrieved. If you are restoring data bases or from databases, then knowing what you need to remove once the restore is complete is a start. Having other files in a structured format also helps to ensure that data is not restored, or is restored and then items removed. One of my questions would be if data could be held on a student until the expected leaving date, not the actual leaving date ... ICO response has been it is down to the school to justify their retention schedule. We've asked IRMS if they are updating their toolkit and they have said yes, but as a volunteer organisation it is down to those helping. If your school uses the toolkit, get someone to join IRMS and get involved.
  4. You could use an EduGeek group ...
  5. And any idea where they got that advice from?
  6. Without saying “you must do it this way” (mainly because the same discussion is happening across all sectors and I’ve yet to see any complete answer), think about this from the other end of the problem. The school has a retention schedule. The school can dictate how and where things are stored ... Knowing that, can you design an information and file structure and storage that will allow you to backup and restore as per your retention schedule? Then think how you are going to get to that point from where you are.
  7. With cloud services we also have to remember that you need where providers are working under the EU Model Contract Clauses rather than Privacy Shield. Both Microsoft and Google can cover that, but as already mentioned the data residency can be sorted for you in O365. To be honest, the bigger risk is not where it is stored, but where it is accessed from ... staff mobile devices with no pin codes, laptops that have no timeout to screensaver and lockout ... you know the sort of thing.
  8. It is a Risk-Management thing, to be honest. UK data controllers have Privacy Shield in place for US residency, but for some they want more ... which is why folk like Google and Microsoft use the EU Model Contract Clauses. If you email [email protected] and ask if they are considering using the EU Model Contract Clauses, and then ask for a copy of the Data Sharing Agreement they will respond in due course.
  9. Have a look at the following guide as it may be beneficial to you. https://www.gdpr.school/wp-content/uploads/2017/08/Who-will-be-your-DPO.pdf
  10. The only time we stopped schools doing completely their own thing was when they wanted to do something seriously stupid ... other LAs on EMBC operated differently, but Northants worked damn hard to be flexible.
  11. It is the case that schools *do* need a DPO, and there has yet to be an amendment carried through that changes this.
  12. Woooooohhooooooooo!!!!
  13. The standards and ideals behind it are from the existing DPA... not GDPR.
  14. This would be the general option. The exception would be if the account generated was subsequently used for booking other events. At this point they are the Data Controller and deal directly with the data subject. Because of this, you might consider the option of being joint data controllers for the interaction for your events.
  15. My apologies on that ... We are waiting for updates and have more follow ups from BETT.
  16. When I say ‘school’ you are correct when you say Leadership. It is someone with authority to make, or help others make decisions. That could be SLT, HoD, line manager, mentor (thinking about ITT/NQT). Staff simply sharing ideas would not really count.
  17. If the site is paid for by the school, the staff are either instructed or suggested they should use it, or they need to use it to do part of their job (e.g. exam boards to get resources, specification and so on) then it is not a choice.
  18. Yes, due to the position of authority that a teacher holds the suggestion or recommendation is enough to imply coercion. This is not a new concept as it applies to other areas as well. Another example of handling data protection being an extension of existing practice.
  19. It would be lovely to get more EG members who are NMs and techies along to TeachMeets. You learn so much about the brilliant ideas about what can work in the classroom ... and you’ll be surprised how many ideas you can contribute.
  20. Consent is generally not the issue. If the service is required for delivery of the curriculum you might use the basis of public interest, as consent is only *1* legal reason for processing ... This would be picked up during a DPIA, or as part of you audit of data maps / data sharing agreement. If it is consent, then you cannot do it on bulk, as that is not giving the parent/child the chance to opt in to what they want ... you are coercing them to choose all or nothing, so the consent would *not* be valid. Consent has to be freely given each time it is asked about.
  21. Was that on a call out via the chat? If via the chat I would love a copy of the transcript because it conflicts with the answer I get on the same question I ask on a nearly fortnightly basis.
  22. It all depends on what you need. Groupcall run a training programme and we also have a range of other contacts. In your area I would recommend Fusion Forensics as an option too but happy to pass on others to you.
  23. It wouldn’t be a valid consent if being instructed by a teacher ... it is forced and so dubious as to the validity. In short, this short not happen. No service should be signed up for until a DPIA is complete. Under COSHH, you wouldn’t just let anyone bring chemicals into school, especially in a random container and just leave it lying around. Same applies.
×
×
  • Create New...