Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. Hmmmm .... Should we dough? It gives me pains to say that these puns are half-baked and need to be stopped before someone fritters away any opportunity putok this discussion to bed.
  2. This is too easy. Favourite Doctor: The Doctor (is there any other answer?) Favourite Villain(s): The Doctor (well ... he can be his own worst enemy at times) Favourite Companion: The Doctor (Look, we have had multiple doctors together so many times, this is the only true answer ... not that any of them would admit to being the companion) Favourite Episode: Them all! :getmecoat:
  3. Personal recommendation - Education Data Hub ... They truly are the best in the education space right now.
  4. At one point I did build a fancy calculation that took into account the number of pupils in a school, the key stages they were in, and so on, all to generate what would reasonably needed by each school across an LA within an RBC. That then went into comparison against the technology which was in place, what was available for upgrade and what required significant investment. And then we had the cull of Becta and various chunks of funding. There is no simple way of calculating things really. It has to be curriculum driven, and factor in the school's long term strategic planning.
  5. Dave and Lee have both hit the nail on the head (not surprising, really), and there has always been this balance across school connectivity about planning for the future. As regional grids faltered, it was largely left to the market to plan how this capacity would be delivered; some have done it better than others. I would always recommend you speak with your existing (and other) providers to see how they will support your needs for connectivity over the next 5-10 years. Whilst your contract with them may be from year to year, I would always say to plan for at least 5 ... but you've heard me drone on about that before. The DfE requirements are where they are right now ... they will move and, as Dave's experience shows, they may not be as communicative about what those changes could be.
  6. Bill and Ted ... if you could be introduced to him in any way, that has to be the best.
  7. There are many ways to skin a cat, and if you have a search for 'strategic plan' or '5-year plan', you should find a range of threads on this. When asked for something like this, it can be hard to find what SLT and the Governing Body want. Do they want to know how much you are going to spend? Do they want to identify risks and put plans in place to manage them? Are they trying to assess whether school staff are in the right place to make the most of the teaching already there? I know ... more questions and not enough answers. Below are some ideas to help ask those questions and get some info. This is not a comprehensive answer for you, but hopefully it helps. Whatever you write, it must also align (support or improve) the school's strategic planning. Look at it, see who the target owners are, discuss their needs with them, and identify the purposes for using technology across the school for curriculum delivery and operational/strategic management. Once you have this, you can make a full assessment against what you already have in place, do your gap analysis, identify any immediate deficiencies, scope out future requirements to meet the targets on the school's plan, and identify how you expect it can be delivered on the present model of IT services it has. Then, you can look at improvements and efficiencies. Provide options that step up the IT Services and any associated changes to how the school works (communications, storage, access to data, security, etc) and outline changes/impacts. I would heartily recommend visits to other schools/MATs to discuss some of these points too. Discussions here are brilliant, getting to ANME meetings is brilliant, and the annual EDIT conference is brilliant ... This truly is just a short summary. Discussions on online courses/exams, use of AI for targeted/personalised learning, 1-to-1 schemes, data analysis tools ... so much more to look at. Best of luck with it all, and, like many others on here probably are, keen to hear of any insights you have along the way.
  8. Like many of us who have served ... the woods is a perfectly natural place to take a **** ... and no, we never worried about the bears; they were always very polite about asking for some bog paper when they ran out of squirrels,
  9. I’ll be heckling^Wwatching on the live stream today whilst some of my eager colleagues get to catch up with you all. Have fun.
  10. IIRC, you can set paid channels to restrict membership from particular account types. I've done similar in the past (to prevent schools signing up for something) but that was some time ago.
  11. Qustodio is not too bad as it goes, but you as a parent are making the decisions about risk and which apps are ok, not Qustodio or the school. If you child's device was to be used at school would you be happy for them to run their own tools on that device? When would you want them run and where? What apps/sites/activities would you expect to be restricted/allowed but monitored? What happens if you disagree with certain things (e.g. school automatically blocks anything nude, but that then hits many museums due to paintings and statues)?
  12. My thoughts exactly ... it would have to be a very bizarre set of circumstances for that even to be possible and it definitely sounds like the way things were caught (what apps were used, etc.) has not been explained correctly.
  13. The laws aren't that daft. A chunk of what we think of as data protection and safeguarding both come under human rights. As children grow, so does their need for independence and protection of their own rights ... there is no exact age but you would not be as invasive for a 12 year old as you would a 5 year old. As they get older, you may be more specific in the things you are looking at as a parent but there are far more places that you give them their independence. Prof. Sonia Livingstone's book on Parenting in a Digital Age is a really good place to start on this, and whilst I don't always agree with how she and the other researchers look at how it crosses into education, they do raise valid concerns. Within schools we *have* to have accountability. If nothing else, the IICSA has shown that. That means schools have to be able to justify when they are using invasive means of protecting children, and they have to be able to justify the where and when. As I have said, the question raised to the OP may have not been worded as effectively as it could have been around EdTech, but it is a valid one and one that should already be transparent to the parent.
  14. I came to this one a little late and it has been an interesting discussion. There are a lot of things that I could repeat based on some of the replies, but I hope people don't mind if I bring together a summary. Thank you @pete, for reminding people that Safeguarding does not trump GDPR, nor does GDPR trump Safeguarding. Whenever you do something with personal data you need a purpose (reason, requirement, etc.) and also a lawful basis (Legal Obligation, Consent, Public Task, Legitimate Interest, Contractual Obligation, Vital interest), and for Special Category PD you need an additional basis too. Safeguarding is the purpose you are processing/handling data, including sharing it with other agencies who need it for them to do their bit on safeguarding. Yes, you need a lawful basis and Legal Obligation or Public Task is the usual option here (the choice between the two is for a debate at another point). It is as simple as that. You need to share something with LADO? Fine. It says to be mindful of data protection principles. You need to give stuff to LADO ... don't just email super sensitive stuff without encrypting it ... don't leave it on the bus ... give it to the right person. There's nothing there about anything trumping anything else. Generally, it's just common sense. AUP - Yes, getting people to read through *and understand* periodically is a good thing. Yes, there have been cases where the lack of renewed engagement has gone with the employer and some with the employee. Context is king in all of these. In short, whilst there is an expectation of staff to keep up to date, they need to have the opportunity and the access. Access is not just whether they have permissions but whether it is accessible. A legalese doc does not help anyone. KCSIE needs the update each year because a) it changes and b) the DfE wants to make sure that there is a consistent(ish) level of understanding. They have gone for the lowest common denominator on that, which is fine. Getting the AUP agreed upon each year is also understandable. Even if KCSiE has not created a change, it is good to remind people of expectations. Is the AUP a contract? For your children and parents, generally no. It may be that there is a home-school contract which is in place that does have some standing and it refers to the AUP as part of a set of 'rules'. For staff, if it is written as such, it is part of the school policies and procedures, and tied in with their contract of employment. This is not always the case, so before anyone says x, y, or z, it is worth checking. Personal devices. Now this is a very difficult area. This is so reliant on having serious risk assessments run that it is scary to still see Heath-Robinson style approaches. Whilst the use of certificates on devices to ensure that MITM interception can take place on school owned and managed devices would readily fall under the lawful basis of Legal Obligation/Public Task, there will be concerns about whether this is intrusive. It is not that there is a balance between individual rights and the school's needs. The school's needs have to ensure they are using the least intrusive way. That does not mean that they don't do it if it is intrusive. It still remains as objectionably intrusive and has a high risk still, then the school needs to take the DPIA to the ICO. I have yet to hear of any school doing this, or schools being taken to task about their DPIAs specifically on this matter when the ICO did their review of MATs. School-owned devices that stay on-premise are generally seen as acceptable, but you have to be transparent about this. That cannot be stressed enough. By introducing this to 1-1 scheme devices, which are still owned/managed by the school, then additional factors have to be considered for use outside of school hours, off-premise and by family members. Generally, this is managed by selective use of the tools off-site/outside of school hours. I've written guidance about Privacy by Design which covers this for schools. Again, context is important here and it may be that the DPIA considers, in addition, at risk children being supported differently even though it could be more intrusive. But when it comes to personal devices ... it would not be practical for a school to rely on Legal Obligations or Public Tasks as the Lawful Basis as there is no requirement for children to use personal devices for their education. The school cannot use Legitimate Interest (not available for Public Authorities for their core purposes), Vital Interest is about saving people's lives ... so that leaves Contract and Consent. I mentioned contract earlier and the difficulties, so that leaves consent. At this point you start to wonder whether the tool being used is the problem rather than the purpose. If a tool was there to support learning, rather than be seen purely for filtering/monitoring, then you have a different position. And this is why a number of tools have keystroke logging in place rather than the interception. It is not that one is better than the other, they generally can be used alongside each other, but it is sometimes about what it the least intrusive. And this is where we talk about balance. We would like parents to agree to use tools, but also want them to know that schools are managing things effectively, respectfully, transparently and appropriately. Being clear that whoever you work with is under clear instructions via the Data Processing Agreement only to do what the school has agreed. That means any sub-processors used by that vendor are also restricted to those instructions (or more secure). Ensuring people know that you don't share with any 3rd parties (other Data Controllers who can use that data for whatever they want) but *the school* may in turn share that data with other agencies (LADO, NHS, etc.). The school making thoughtful decisions about where they want the tools to be running and when. If a parent is raising this, it is usually a sign the school needs to do more work on their stakeholder communication, or needs to rethink their DPIA and look at what less intrusive options there could by with personal devices. It may be that this is a parent who works in the privacy arena but does not know how it works across education (we all know that there are some marked special cases in education), so could be a good evangelist for you after some initial dialogue. I think I've summed up everything others have put, and put it into a general order.
  15. It was Claire Archibald, DPO and Service Manager, Education Data Hub, who chased this down and got the result. If anyone needs more info she is happy to have anyone contact her at [email protected]
  16. *Really* good points and are definitely things I would mention too. I can add a few more that may be helpful. All requests are logged (including the purpose for review), but where a significant privacy concern is raised consider if the authorisation for looking at footage needs to be different (and get this decision down in your DPIA and risk register) Consider any impact on the mental health of those being asked to review footage where there may be a privacy concern.
  17. Woohoo!!!! brilliant news ... good to see some wonderful people actively involved in supporting the Bosses. Just remember, try not to get into arguments with idiots. They will drag you down to their level and beat you with experience.
  18. Morning all. In conversation with Claire Archibald over at Education Data Hub, Derbyshire County Council, she has been pressing Wonde on this and has said I can share the following response from Wonde (please note, any Bold is from Claire to me as part of our discussion) The Wonde Platform, as previously in use at xxxxx Infant School, provides a range of tools in addition to securely sharing your MIS Data, such as; the App directory, Activity reports and App security information. These features are specifically designed to empower schools with the process of managing and controlling access to their school data, and have been developed from the feedback we have received from schools. In order to enable us to continue to deliver a high level of service with these tools and respond to further feedback to develop additional enhanced features, we have introduced a subscription for the Wonde Platform. Wonde is committed to helping all schools securely manage their data. If the additional tools within the Wonde Platform are not of benefit to your school, our new Wonde Basic solution can be used by your school and is free of charge (as chosen for use at xxxxx CofE Infant School). We are communicating the introduction of the subscription to schools via email (the email to xxxxxx CofE Infant School was sent on the 27th April 2023). Within that email the additional features (beyond the ability to securely share MIS data with your third party apps) are detailed, as well as the cost and timescale of receiving an invoice. The email also communicates the choice for a school to use the free Wonde Basic solution. Wonde takes its position in the education sector seriously regarding the role we play in helping to ensure the protection of school personal data. We have invested, and continue to invest, significant resources to allow us to ensure that we are acting as a facilitator of best practice in the data processing chain between schools and the apps that they use. We also aim to provide further assurance to our school and app partners around our secure and compliant information processing practices through our externally audited security accreditations ISO27001 and Cyber Essentials Plus certifications (copies of which can be provided upon request). We also take any queries around data protection very seriously. We treat it as a priority and engage appropriately qualified personnel (including specialist solicitors) to better understand any such query and resolve it in a timely and professional manner. Data protection is obviously a technical and complicated area of law which does require some level of interpretation. Hence why we always seek specific legal advice in respect of any issue that needs addressing. We are grateful for the feedback from you and your DPO as we believe that continually engaging with our school users (e.g. we take such feedback through Wonde’s MAT forums) assists us in maintaining the high standards that we hold ourselves to. In relation to the point raised by your DPO that as a data processor, Wonde is obligated to ‘carry out all instructions of the data controller (i.e the school)’ this goes to the heart of the obligations of the data processor. We have received specific legal advice in respect of our Wonde Platform and were advised that our approach to data protection was compliant. If a school considers that any additional functionality to the platform would assist them further in managing their personal data, the school would normally discuss this with us and (if applicable) the relevant app provider. We will then consider whether it is technically and commercially feasible to add such functionality. However, as detailed in the legal advice we have received, we are not required, by UK GDPR or otherwise, to add additional or change any existing functionality based on a school’s request. In line with that process, we thank you for your query regarding the Access Control tool. As you know, the Access control feature assists schools in managing how data is shared down to an individual or group user level and, as an enhanced feature, is included within the Wonde Platform at, what we believe to be, a justifiably fair and reasonable cost. Regarding your concern that making Access Control a paid for feature risks Wonde’s compliance with its role of a data processor as defined by UK GDPR, as stated above Wonde takes its responsibility in helping to ensure the protection of school personal information seriously. Whilst our legal advice has given us comfort that our approach remains compliant with our data protection obligations, we are also committed to an open dialogue with our school users. As such we will be reviewing your comments regarding the Access Control features inclusion within the Wonde platform. Whilst this review is being carried out, access to the Access Control feature will be available to all Wonde Platform users, whether they have chosen to use the Wonde or Wonde Basic platforms. We are grateful to yourself and your DPO for contacting us. We hope the above information answers your queries. We will ensure you are kept informed as this review is carried out. Please do not hesitate to contact us should you have any questions in the meantime. ------------------ Kudos to Claire for getting Wonde to rethink things and it shows you what a proactive DPO can do.
  19. That's no way to talk about @dcwhitworth ;-)
  20. This is a regular discussion on here, and is had every few years ... around this time. As already mentioned, their contract of employment has a start date and it is from that point all policies and stuff apply. This is also important from an SCR point of view too. However, that does not mean they can't do things beforehand. They can be considered a volunteer and given appropriate access *after* appropriate training. Some schools/MATs now include such language within the teacher/SLT contract. One school used to provide an account to new staff which was limited to a section of their Learning Portal and allowed for some online training to be completed. Once completed, more access was granted.
  21. There are 3 main problems involved in looking at this, and none of these are new. As much as I might grumble about BCS at times, their Learning and Development special interest group have a lot of experience around this and are well placed to share ideas/solutions ... The first problem that schools face is centred around how schools are generally structured. They are designed for end-of-course tests, with courses fixed within an academic calendar. In the same way that 'just in time' learning is still not really catered for, assessment needs to change to let them be taken when a student is ready to demonstrate their knowledge and understanding. This then goes back to focusing on 'learning to learn' approaches ... and the difficulty in changing the whole flipping system. Until schools can assess on an individual and personalised basis, electronic examinations are going to be a problem. Secondly, there are the logistics of taking the exams. We are not just talking about the number of devices or who owns the device, but the proctoring, the technical support, and the infrastructure ... and it is good to see that discussion going on ... notice that solving the first problem would significantly help with this problem? And finally, we have the type of assessment. This one still needs more research done and is an area I would always defer to others on. Formative? Summative? And what about the type of questions and style of answering? If diagrams are needed are we talking using a tablet and pen/pencil? Again, a change to the first problem could make a massive difference about how we address this one. For those interested in Learning Theory, I would suggest Donald Clark as good reading that could give insights into the amount of research that has already gone on and is still needed. If anyone is involved at looking at this, I would be interested in chatting with them.
  22. DPIAs are a risk assessment. Vendors won’t (can’t) know all your risks as they are relevant to your school, though they are likely to be aware of most possible risks … as it is (or should be) part of a suitable development programme (and yes, our Devs just love me ;-) ). However, we cannot guarantee the software will be used as designed. We just try to give as much info as we can. A good vendor will provide with a clear Data Processing Agreement (see https://classroom.cloud/data-processing-agreement/ as an example), with associated technical information (https://classroom.cloud/wp-content/uploads/2021/11/classroom.cloud-Security-Request-for-Information.pdf for our example) and further guidance to support how you make decisions on security and privacy (https://classroom.cloud/privacy-by-design/ for our example). The ICO has a general DPIA template (https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/guide-to-accountability-and-governance/accountability-and-governance/data-protection-impact-assessments/), but If your DPO does not have appropriate templates then working with people like the Education Data Hub at Derbyshire County Council, and compliance tools like GDPR in Schools, might be the best bet.
  23. If the software is being given away for free and registration is on the publisher's site, then you really need to check the terms and any agreements. You may find that they set themselves as the Data Controller and the school has a minimal role. It may also be that consent is the lawful basis ... and that should not be used in software that a student is *required* to use ... as it would not truly be consent! Speak with your DPO or DPOaaS provider.
  24. @Dos_Box ... remember http://www.edugeek.net/forums/general-chat/45189-going-meet-man-your-behalf.html ?
  25. This is a major issue for some schools who have never looked at it before, and it is something to take to your DPO. By using the school credentials to sign in to non-school related services, you are passing on school data to 3rd parties ... i.e. other data controllers. You might think that is ok for some sites, but what about all the chat sites that let you use Google accounts to sign in/create accounts? The only '3rd parties' who should be able to do this, are your Data Processors ... companies you have signed up with and have agreements in place where you are in control. Most GWfE are set up this way out of the box, but not all have been over the years. Google have provided guidance previously and there is a change coming up to force some of it too.
×
×
  • Create New...