-
Posts
12,876 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by GrumbleDook
-
GDPR - Teacher notebooks/planners/etc
GrumbleDook replied to FragglePete's topic in Data Protection & Information Handling
We need to think about the scope of GDPR. Teacher's notes, where structured and recorded to be part of, or feed into, the learner's educational records (which will include assessment, behaviour, etc.) would be covered under Public Interest as it is part of delivery of the curriculum. You cannot know whether delivery has been effective, needs to continue or needs to be changed without making notes. Where the notes are unstructured (comments in margins, post-it note records of actions, etc.) then this would fall out of the scope of the Regulation *but should not be ignored as there may be impact if lost, shared incorrectly or holds incorrect information*. -
Right to delete from backups
GrumbleDook replied to enjay's topic in Data Protection & Information Handling
This is a cracking start and I would heartily recommend others contribute their ideas based on operational possibilities ... talk about the limits of available products, possible compromises ... but keep in mind the retention schedule ... -
Right to delete from backups
GrumbleDook replied to enjay's topic in Data Protection & Information Handling
That'll be Andrea Jelinek, Data Protection Commissioner of Austria and newly elected Chair of the Article 29 Working Party, which will be replaced by the European Data Protection Board come 25th May. Folk are extremely vocal about the problem ... but to minimise it people are having to rethink what they store, how it is backed up and how it is retrieved. If you are restoring data bases or from databases, then knowing what you need to remove once the restore is complete is a start. Having other files in a structured format also helps to ensure that data is not restored, or is restored and then items removed. One of my questions would be if data could be held on a student until the expected leaving date, not the actual leaving date ... ICO response has been it is down to the school to justify their retention schedule. We've asked IRMS if they are updating their toolkit and they have said yes, but as a volunteer organisation it is down to those helping. If your school uses the toolkit, get someone to join IRMS and get involved. -
Edubytes South Central Meet - Christmas 2017
GrumbleDook replied to AJWhite1970's topic in Other Stuff
You could use an EduGeek group ... -
Can a finance manager be DPO?
GrumbleDook replied to MS2011's topic in Data Protection & Information Handling
And any idea where they got that advice from? -
Right to delete from backups
GrumbleDook replied to enjay's topic in Data Protection & Information Handling
Without saying “you must do it this way” (mainly because the same discussion is happening across all sectors and I’ve yet to see any complete answer), think about this from the other end of the problem. The school has a retention schedule. The school can dictate how and where things are stored ... Knowing that, can you design an information and file structure and storage that will allow you to backup and restore as per your retention schedule? Then think how you are going to get to that point from where you are. -
With cloud services we also have to remember that you need where providers are working under the EU Model Contract Clauses rather than Privacy Shield. Both Microsoft and Google can cover that, but as already mentioned the data residency can be sorted for you in O365. To be honest, the bigger risk is not where it is stored, but where it is accessed from ... staff mobile devices with no pin codes, laptops that have no timeout to screensaver and lockout ... you know the sort of thing.
-
Accelerated Reader - Data residency
GrumbleDook replied to ozydave's topic in Data Protection & Information Handling
It is a Risk-Management thing, to be honest. UK data controllers have Privacy Shield in place for US residency, but for some they want more ... which is why folk like Google and Microsoft use the EU Model Contract Clauses. If you email [email protected] and ask if they are considering using the EU Model Contract Clauses, and then ask for a copy of the Data Sharing Agreement they will respond in due course. -
Can a finance manager be DPO?
GrumbleDook replied to MS2011's topic in Data Protection & Information Handling
Have a look at the following guide as it may be beneficial to you. https://www.gdpr.school/wp-content/uploads/2017/08/Who-will-be-your-DPO.pdf -
Woooooohhooooooooo!!!!
- 28 replies
-
- 1
-
-
This would be the general option. The exception would be if the account generated was subsequently used for booking other events. At this point they are the Data Controller and deal directly with the data subject. Because of this, you might consider the option of being joint data controllers for the interaction for your events.
-
GDPR + Users signing up to services themselves
GrumbleDook replied to PyROm's topic in Data Protection & Information Handling
Yes, due to the position of authority that a teacher holds the suggestion or recommendation is enough to imply coercion. This is not a new concept as it applies to other areas as well. Another example of handling data protection being an extension of existing practice. -
It would be lovely to get more EG members who are NMs and techies along to TeachMeets. You learn so much about the brilliant ideas about what can work in the classroom ... and you’ll be surprised how many ideas you can contribute.
-
GDPR + Users signing up to services themselves
GrumbleDook replied to PyROm's topic in Data Protection & Information Handling
Consent is generally not the issue. If the service is required for delivery of the curriculum you might use the basis of public interest, as consent is only *1* legal reason for processing ... This would be picked up during a DPIA, or as part of you audit of data maps / data sharing agreement. If it is consent, then you cannot do it on bulk, as that is not giving the parent/child the chance to opt in to what they want ... you are coercing them to choose all or nothing, so the consent would *not* be valid. Consent has to be freely given each time it is asked about. -
Anyone recommend some GDPR training?
GrumbleDook replied to localzuk's topic in Data Protection & Information Handling
It all depends on what you need. Groupcall run a training programme and we also have a range of other contacts. In your area I would recommend Fusion Forensics as an option too but happy to pass on others to you. -
GDPR + Users signing up to services themselves
GrumbleDook replied to PyROm's topic in Data Protection & Information Handling
It wouldn’t be a valid consent if being instructed by a teacher ... it is forced and so dubious as to the validity. In short, this short not happen. No service should be signed up for until a DPIA is complete. Under COSHH, you wouldn’t just let anyone bring chemicals into school, especially in a random container and just leave it lying around. Same applies.
