-
Posts
12,876 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by GrumbleDook
-
Data Protection Act Report stage 11/12/17
GrumbleDook replied to Ditto's topic in Data Protection & Information Handling
The work of Baroness Kidron will be an area to watch! -
Educational Websites
GrumbleDook replied to DSapseid's topic in Data Protection & Information Handling
One of the good things about the introduction of GDPR is that it takes a risk-based approach. The location is not as important as it used to be as we have things like the EU Model Contract Clauses, ISO27000 series certification, etc. The DfE have their self-certified list, but that will need a slight update (which is only likely to happen once the DP Bill is closer to Royal Assent). Don't rule any supplier out until they have been given a chance. -
A question I have open at the moment. As the MAT is the legal entity, there are scenarios where centralised decisions have been taken in such a way that the consultation on those decisions may affect what the school judges to be any conflict. The oficial ICO position is that it is down to each school or business to assess, but they need to make sure that they truly do assess it and not try to make a decision and backwardsly justify it. I have provided a few scenarios to be considered and a sticking point looks to be knowledge and understanding of the regulation / law.
-
Edubytes South Central Meet - Christmas 2017
GrumbleDook replied to AJWhite1970's topic in Other Stuff
On my plans ... if I do come I will be driving so that I can get to it. -
Data Processing Agreement - What Is Required?
GrumbleDook replied to DavR's topic in Data Protection & Information Handling
@tinkerbotsict drop me a line so we can have a chat. I’m interested in how you may fit in the DPO role. Also, DPIAs can start without a DPO, as it gives them something to work with when they arrive. -
Data Processing Agreement - What Is Required?
GrumbleDook replied to DavR's topic in Data Protection & Information Handling
The other aspect is that for some solutions, although they are hosted and run on your own servers, you might not understand what data is processed and how. You need assistance with understanding that side of things. -
There are a number of running jokes on GDPR ... one is that the InfoSec response is to encrypt everything!
-
Risk assessment. There is no legal requirement for encryption, but it is a good way of mitigating risk.
-
Data Processing Agreement - What Is Required?
GrumbleDook replied to DavR's topic in Data Protection & Information Handling
If they are generating any new data from it, they should be sharing it with you as that is likely to be one of the criteria for you using them in the firstplace ... It is if they set out what will be processed and how, and you don't have any choice ... then they can be considered to have some data controller responsibilities. These will be rare as, generally, you are choosing whether or not to use them at all as part of your procurement process. - - - Updated - - - Schools will *always* be the Data Controller for data they ask to be processed or asked to be generated. -
Data Processing Agreement - What Is Required?
GrumbleDook replied to DavR's topic in Data Protection & Information Handling
This is an interesting one. There are definitions about the Data Controller and the Data Processor, adn their responsibilities. From the ICO - At first sight, this would make it look like most EdTech suppliers would become data controllers, but it is not quite that simple. If we take where it could be considered to be shared ... the school will always be the Data Controller, but where the Data Processor is then using the service as part of their own service directly to a group of people, e.g. parents who may have children across multiple schools. But what about all the other times you get 'told' what needs to be processed? You, as a customer, have purchased the product / service and so have made the decision about whether or not you will allow it ... and *this* is why seeing the data sharing agreements is so important. -
Data Processing Agreement - What Is Required?
GrumbleDook replied to DavR's topic in Data Protection & Information Handling
Yes, and I’m trying to put together more advice on this before we all break up. -
Data Processing Agreement - What Is Required?
GrumbleDook replied to DavR's topic in Data Protection & Information Handling
Which is the message we are hearing from a number of schools. -
Data Processing Agreement - What Is Required?
GrumbleDook replied to DavR's topic in Data Protection & Information Handling
From the ICO “Personal data means data which relate to a living individual who can be identified – (a) from those data, or (b) from those data and other information which is in the possession of, or is likely to come into the possession of, the data controller, and includes any expression of opinion about the individual and any indication of the intentions of the data controller or any other person in respect of the individual.” The names are personal data. You will need a DPA. -
GDPR Responsibility in your school
GrumbleDook replied to prad-ucs's topic in Data Protection & Information Handling
Remembering that there are no accredited courses yet ... However there are some really good courses and schools, like the rest of the country, need to balance the need to have someone support them against waiting and waiting for courses. This is where DPO as a service comes in, as a good service can give you access to a range of folk who *really* know there stuff and have been doing it across a range of sectors ... folk who been doing information management, infosec, public sector governance, privacy, etc. for 10+ years each! I can share more that in the next week or so, if people are interested. -
GDPR Responsibility in your school
GrumbleDook replied to prad-ucs's topic in Data Protection & Information Handling
I would suggest you have a look at the sticky threads and have a read through some of the resources that have been linked to on there. I would also suggest that you put aside any idea of you being DPO, no matter what your experience. There will be a conflict. I have yet to see any scenario in a school where the IT Manager could be the DPO for that school without there being a conflict. It has been widely discussed in other threads too ... please, don’t go down that route. The school is the Data Controller. The Governor Body, as the strategic body of the school, has a responsibility but it is the school, as a legal entity, that is the Data Controller and holds the liabilities ... unless you are in a MAT, in which case (in general) the MAT is the legal entity and becomes the data Controller for all their schools (there are a few exceptions). The DPO is not going to do all the work. They are the oversight person ... The school should do the same as it does for H&S, teach people about risk assessment and then making decisions based on predefined boundaries, keeping the DPO in the loop. When looking at new software or systems there are common things you can ask ranging from “do you have a data sharing agreement?” to “do you conform to and are accredited for any recognised standards?” The DPO would review your assessment and make suggestions on risk mitigation, but they do not have to do every item of work! Also, if you are changing that much software each year then you *really* need to get the school to stop and think about what is going on with their choices. -
GDPR Responsibility in your school
GrumbleDook replied to prad-ucs's topic in Data Protection & Information Handling
There is a saying in the army... “I’m sorry Sir/Ma’am, you seem to be confusing *your* rank with *my* authority!” You don’t have to be SLT, but simply be senior enough to report into the Head and Governors. -
Data sharing with NHS
GrumbleDook replied to Jollity's topic in Data Protection & Information Handling
Following on from Jen's post ... the first thing to do would be to contact the DPO/SIRO of the trust and ask for confirmation that data is being requested from the Trust and ask for where there is any agreement that the data will be shared. -
Lol, no worries ... I am going throgh and chatting with some suppliers on this already, as well as raising it via BESA. I'd rather have positions from both sides before posting it, but yes ... schools need to ask, suppliers need to work on it but the exact time of delivery fro the supplier will vary depending on the complexity of what they are processing. Just think ... Scholarpack will differ to SamLearning, Show My Homework will differ to ParentPay.
-
Data Processing Agreement - What Is Required?
GrumbleDook replied to DavR's topic in Data Protection & Information Handling
Don't forget that some cloud service providers have already done a lot to provide guidance against DPA ... the DfE Cloud Service self-certification is a really good place to look. -
Data Processing Agreement - What Is Required?
GrumbleDook replied to DavR's topic in Data Protection & Information Handling
If you use a service that processes data you need a DPA. You cannot be compliant without it. -
GDPR Responsibility in your school
GrumbleDook replied to prad-ucs's topic in Data Protection & Information Handling
https://www.gdpr.school/wp-content/uploads/2017/08/Who-will-be-your-DPO.pdf might help. I’ve had some follow on chats with ICO around this and it is pretty clear that the school has to evaluate if there are possible conflicts of interests. If the school says that there are not then they have to justify it. From every example we have discussed on here, no NM can do the role for their own school. The guidance comes from ICO, not DfE. -
USB Drives - Encryption or banned?
GrumbleDook replied to tj2419's topic in Data Protection & Information Handling
And this is why Data Protection is an exercise in Risk Management ... and we shouldn't expect everything to be black and white.
