-
Posts
12,876 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by GrumbleDook
-
USB Drives - Encryption or banned?
GrumbleDook replied to tj2419's topic in Data Protection & Information Handling
Can I just point out that this is not a GDPR thing, but is actually to do with DPA98? No? I’ll get my coat then. -
Encrypted share that only two members of staff can access? (and admin can't)
GrumbleDook replied to Cazale's topic in Windows
To be honest, it is not really about whether people can access ... it is about whether there is a log of who did access it, and if anyone can edit those logs to hide things. It is Risk Management ... and you have to take into account the likelihood (probability) of such action occurring, put in a mitigation plan and try to reduce the risk ... but at times you just have to accept it but put in place audits to spot check that people are following procedures. This is not new ... it applies to Food Hygeine, H&S, etc. -
Would they only have access to live feeds of the cameras in the leisure centre? Do the leisure centre still have the PIA they did for their own system, so that you could review and set up a data sharing agreement? Have you informed pupils and parents, and are both you and the leisure centre following the CCTV code of conduct? Just a few things to consider.
-
The problem is not that you are sharing a password ... it is the lack of risk analysis that is a problem. There may be times when it is acceptable.
-
GDPR - Articles 9 and 10
GrumbleDook replied to tommeiklejohn's topic in Data Protection & Information Handling
There are some discussions on it but clearer advice is needed in the education sector. When comparing against DPA the following article gives a good breakdown. https://www.twobirds.com/~/media/pdfs/gdpr-pdfs/25--guide-to-the-gdpr--sensitive-data-and-lawful-processing.pdf?la=en We are keeping an eye and will share advice we are given or find. -
Encrypted share that only two members of staff can access? (and admin can't)
GrumbleDook replied to Cazale's topic in Windows
Encryption solves everything though!!! I’ll get my coat -
We have had this query email to us from someone outside of EG recently, as well as in discussions via LinkedIn. The Pupil record (both paper and electronic) is meant to be handed over to a new school when the pupil transfers to that new school and the record is no longer needed, so a record needs to be deleted. However ... if we take attendance, then this is retained for three years after the data of the entry made or an IEP which is kept for data of birth of the pupil plus 25 years. Considerations also need to be taken into account where there may be litigation ... so records of injuries, bullying and other possible areas may need to be kept once the pupil has left. It is not black and white but it has been this way for years and the principle of having and adhering to a retention schedule is enshrined within the upcoming changes. I would strongly recommend that your school becomes IRMS membership, or is in contact with someone has is a member (within the LA, etc.)
-
Freedom of Information request
GrumbleDook replied to Jobos's topic in Data Protection & Information Handling
To be honest, FOI requests are better placed coming via sites like https://www.whatdotheyknow.com as data is then published and available for future queries. I always search on there first. It was interesting to see that the creator of the original tool that this is based on spoke at the International Conference of Information Commissioners the other months, and was warmly received. -
An example could be Microsoft. Whilst it is increasingly common to use their cloud services in one way or another, but some schools may still be standalone. The AD stores a lot of personal data, but because there is no connection to any cloud service, no connection to any other service within the school (which may transfer data without you knowing), no connection to feedback services (so no anonymised or pseudo-anonymised Data is transferredy), and the AD is not used for authentication for any other service. It is growing less but some assessment and curriculum tools still only used what is setup on a local server within the school. Any downloads from the provider are usually downloading content sets ... stuff that used be sent out via CDs.
-
He is even on a video of the takedown of the EG stand in the early days at Olympia. He was tired and not feeling brilliant but wanted to stop, see how it had gone for us.
-
I've not seen anything on here yet, so wanted to put up a short comments. Taken from Tim Rylands' Blog - to baldly go....... Using ICT to inspire Tim was often known as 'that Myst bloke' but he was a truly inspiring speaker. I can remember going to a regional ICT event with a colleague who was slightly jaded around the event and speakers. "Getting kids to write because of games? One trick pony, if you ask me!" Within 5 minutes they were on the edge of their seat, jotting down notes and quotes, eager to sift through every morsel that Tim could share. Afterwards I asked what they now thought. "Blood fantastic ... and it makes sense once it is explained to you." A one trick pony then? "Nah, more like Black Beauty ... pure thorough-bred!" I never got the chance to let tim know that I would often get the Black Beauty them tune running through my head when talking to him as a result. Here is a fantastic session he did at Learning Without Frontiers. His funeral is today and many of his friends and people inspired by him can't make it ... but in the words of Sir Terry Pratchett ...
-
What Policies do you have? | Is there a definitive list?
GrumbleDook replied to M.Byford-Rew's topic in School ICT Policies
Data Protection Policy. It should be about updating the one that is there ... because everyone already has one after all. (Looks around) -
Edubytes South Central Meet - Christmas 2017
GrumbleDook replied to AJWhite1970's topic in Other Stuff
I still can't confirm until the week before :-( -
Ok folks, a basic things for you. If you get software from company x, you install it on your servers, you configure it and run it ... you are the data processor as well as the data controller. Microsoft can't tell you the AD is GDPR compliant as it could or couldn't be depending on what you set up. If a supplier is not doing the work for you, then it is hard to say they are the data processor. They are facilitating you being the data processor in that role. If the data goes to their servers, or they remotely setup and manage the service, then start asking them about comliance and the data sharing agreement. As always, if you have a particular sticky company, drop me a PM. I am doing a number of direct phone calls with certain companies so happy to add a few more in. Those phone calls are showing some fantastic practice, by the way. As I've said ... some companies really do get it. - - - Updated - - - Purely a frame of reference and addition to your response.
-
Simple response. You can't be compliant unless you know what data you are collecting, why, etc. If a company will not tell you what is being processed by the software you buy from them, then how can you work out if you are meeting the rights of the data subject. I mention this to some companies and they get it ... they really do get it (NetSupport, Impero, Smoothwall, RM) but other take some more convincing. When you explain that some customers will walk away if they don't have this information ... they start to listen.
-
This is something we are helping a few companies clear up ... even things like where a data processor ends up putting in a direct relationship with the parent and even becoming a data controller for that parent (effectively sharing it with the school). An important thing to remember is where a company provides you a system to process data (you are both controller and processor) there is still an onus on the company to help you understand what is being processed. Some folk get it ... some folk take more time. Explain to them that you need to understand what their system does. Drop me a PM if you want to talk about it more.
-
GDPR in Schools Demo
GrumbleDook replied to Simcfc73's topic in Data Protection & Information Handling
No problem. I believe this answer was sent out to another school yesterday as well. User creation and getting school staff signed in comes into its own around March time, as shown in the timeline we did. We have a number of options available but we haven’t made it available or really talked about it because of where it fits in the timeline. I’ll get the team to whip up some blurb over the next week. -
GDPR in Schools Demo
GrumbleDook replied to Simcfc73's topic in Data Protection & Information Handling
Morning. We are always happy to get feedback and I’m sorry that the demo didn’t cover everything you wanted to see. I’m sure that we can go through it in more detail with you. If you can drop me or @Mel_GDPRiS a pm we would be happy to chat. The audit process also covers the process and questions you need to ask yourself as a school. We can do more to give you an overview of the audit and questions but we have to balance about sharing everything for free. As I said, we are happy to chat more.
