Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. Can I just point out that this is not a GDPR thing, but is actually to do with DPA98? No? I’ll get my coat then.
  2. The problem is the word ‘complete’. We’ll get there though ... it is slowly coming out.
  3. Off-topic but .... Yay! Someone is finally taking the fall for it! (Btw, Embc didn’t kick the bucket, the LA did not buy a contract on behalf of schools and instead helped schools make their own choices)
  4. The leisure centre can be said to have a duty of care under H&S during the daytime too, so may need live access all the time.
  5. To be honest, it is not really about whether people can access ... it is about whether there is a log of who did access it, and if anyone can edit those logs to hide things. It is Risk Management ... and you have to take into account the likelihood (probability) of such action occurring, put in a mitigation plan and try to reduce the risk ... but at times you just have to accept it but put in place audits to spot check that people are following procedures. This is not new ... it applies to Food Hygeine, H&S, etc.
  6. Erm ... that is something Virgin have tried with me over the last year ... they were interesting conversations, including them trying to get me to pay for a premium technical service because I like to run my SuperHub in Modem mode and run my own network ... apparently they don't support that.
  7. Would they only have access to live feeds of the cameras in the leisure centre? Do the leisure centre still have the PIA they did for their own system, so that you could review and set up a data sharing agreement? Have you informed pupils and parents, and are both you and the leisure centre following the CCTV code of conduct? Just a few things to consider.
  8. The problem is not that you are sharing a password ... it is the lack of risk analysis that is a problem. There may be times when it is acceptable.
  9. There are some discussions on it but clearer advice is needed in the education sector. When comparing against DPA the following article gives a good breakdown. https://www.twobirds.com/~/media/pdfs/gdpr-pdfs/25--guide-to-the-gdpr--sensitive-data-and-lawful-processing.pdf?la=en We are keeping an eye and will share advice we are given or find.
  10. Encryption solves everything though!!! I’ll get my coat
  11. We have had this query email to us from someone outside of EG recently, as well as in discussions via LinkedIn. The Pupil record (both paper and electronic) is meant to be handed over to a new school when the pupil transfers to that new school and the record is no longer needed, so a record needs to be deleted. However ... if we take attendance, then this is retained for three years after the data of the entry made or an IEP which is kept for data of birth of the pupil plus 25 years. Considerations also need to be taken into account where there may be litigation ... so records of injuries, bullying and other possible areas may need to be kept once the pupil has left. It is not black and white but it has been this way for years and the principle of having and adhering to a retention schedule is enshrined within the upcoming changes. I would strongly recommend that your school becomes IRMS membership, or is in contact with someone has is a member (within the LA, etc.)
  12. To be honest, FOI requests are better placed coming via sites like https://www.whatdotheyknow.com as data is then published and available for future queries. I always search on there first. It was interesting to see that the creator of the original tool that this is based on spoke at the International Conference of Information Commissioners the other months, and was warmly received.
  13. An example could be Microsoft. Whilst it is increasingly common to use their cloud services in one way or another, but some schools may still be standalone. The AD stores a lot of personal data, but because there is no connection to any cloud service, no connection to any other service within the school (which may transfer data without you knowing), no connection to feedback services (so no anonymised or pseudo-anonymised Data is transferredy), and the AD is not used for authentication for any other service. It is growing less but some assessment and curriculum tools still only used what is setup on a local server within the school. Any downloads from the provider are usually downloading content sets ... stuff that used be sent out via CDs.
  14. This is talking about where no data is transferred. There are a number of examples around.
  15. He is even on a video of the takedown of the EG stand in the early days at Olympia. He was tired and not feeling brilliant but wanted to stop, see how it had gone for us.
  16. I've not seen anything on here yet, so wanted to put up a short comments. Taken from Tim Rylands' Blog - to baldly go....... Using ICT to inspire Tim was often known as 'that Myst bloke' but he was a truly inspiring speaker. I can remember going to a regional ICT event with a colleague who was slightly jaded around the event and speakers. "Getting kids to write because of games? One trick pony, if you ask me!" Within 5 minutes they were on the edge of their seat, jotting down notes and quotes, eager to sift through every morsel that Tim could share. Afterwards I asked what they now thought. "Blood fantastic ... and it makes sense once it is explained to you." A one trick pony then? "Nah, more like Black Beauty ... pure thorough-bred!" I never got the chance to let tim know that I would often get the Black Beauty them tune running through my head when talking to him as a result. Here is a fantastic session he did at Learning Without Frontiers. His funeral is today and many of his friends and people inspired by him can't make it ... but in the words of Sir Terry Pratchett ...
  17. Data Protection Policy. It should be about updating the one that is there ... because everyone already has one after all. (Looks around)
  18. I still can't confirm until the week before :-(
  19. Ok folks, a basic things for you. If you get software from company x, you install it on your servers, you configure it and run it ... you are the data processor as well as the data controller. Microsoft can't tell you the AD is GDPR compliant as it could or couldn't be depending on what you set up. If a supplier is not doing the work for you, then it is hard to say they are the data processor. They are facilitating you being the data processor in that role. If the data goes to their servers, or they remotely setup and manage the service, then start asking them about comliance and the data sharing agreement. As always, if you have a particular sticky company, drop me a PM. I am doing a number of direct phone calls with certain companies so happy to add a few more in. Those phone calls are showing some fantastic practice, by the way. As I've said ... some companies really do get it. - - - Updated - - - Purely a frame of reference and addition to your response.
  20. Simple response. You can't be compliant unless you know what data you are collecting, why, etc. If a company will not tell you what is being processed by the software you buy from them, then how can you work out if you are meeting the rights of the data subject. I mention this to some companies and they get it ... they really do get it (NetSupport, Impero, Smoothwall, RM) but other take some more convincing. When you explain that some customers will walk away if they don't have this information ... they start to listen.
  21. This ... a common one in so many organisations, not just EdTech!
  22. This is something we are helping a few companies clear up ... even things like where a data processor ends up putting in a direct relationship with the parent and even becoming a data controller for that parent (effectively sharing it with the school). An important thing to remember is where a company provides you a system to process data (you are both controller and processor) there is still an onus on the company to help you understand what is being processed. Some folk get it ... some folk take more time. Explain to them that you need to understand what their system does. Drop me a PM if you want to talk about it more.
  23. No problem. I believe this answer was sent out to another school yesterday as well. User creation and getting school staff signed in comes into its own around March time, as shown in the timeline we did. We have a number of options available but we haven’t made it available or really talked about it because of where it fits in the timeline. I’ll get the team to whip up some blurb over the next week.
  24. Morning. We are always happy to get feedback and I’m sorry that the demo didn’t cover everything you wanted to see. I’m sure that we can go through it in more detail with you. If you can drop me or @Mel_GDPRiS a pm we would be happy to chat. The audit process also covers the process and questions you need to ask yourself as a school. We can do more to give you an overview of the audit and questions but we have to balance about sharing everything for free. As I said, we are happy to chat more.
×
×
  • Create New...