Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. You mean this one? http://webarchive.nationalarchives.gov.uk/20081202172126/http://schools.becta.org.uk/index.php?section=lv&catcode=ss_lv_saf_dp_03&rid=14734
  2. No, previously the data controller was liable, now it is both. The thing that sometimes confuses folk is that when it comes to person / home use firms like Microsoft are the data controller as you, the Data Subject, give them you data to let them provide you a service. They are also the data processor as they are doing the grunt work, or they may sub-contract work out to another data processor ... but the original firm has the responsibility and liability. In a school, the data subjects (children, parents, staff) give the data to the school (the data controller) who will either process it themselves (the are the data processor) or will pass it onto someone else to process on their behalf (also a data processor), based on instructions the data controller gives. In reality, schools are just interested in the outputs of the services and the inputs (what the data processor needs to deliver the service) tend to be decided on by the data processor. Under the new arrangement liability will be jointly held, which is why Data Processors are having to look carefully at what they are asking for and the reasons behind it. This brings up an interesting query ... would a glossary of terms be helpful, with some examples?
  3. Most of the clever ones are getting advice and marking where there is not enough info (or info published by the people they need it published by) so that it can sorted at a later date. It is the ones that are doing nowt or who say it doesn’t apply to them (even though you know that staff have to login to access stuff)... those are the challenging ones.
  4. The draft consultation by the ICO on this has only just closed so you won’t get a definitive answer yet, but you can review the draft guidance. https://ico.org.uk/about-the-ico/ico-and-stakeholder-consultations/consultation-on-gdpr-guidance-on-contracts-and-liabilities-between-controllers-and-processors/
  5. Have you asked the MAT directly?
  6. Remember that is about appropriate technical and organisational measures ... Modern cameras do need to be looked at too as some may link to the interwebz for things like location ... and if that is tagged on a photo it adds extra info. It needs to be part of the trip risk assessment ... as does what you do with the class list that a teacher takes with them for emergency contacts, etc.
  7. Have a look at the sticky threads at the top of this sub-forum. A lot of helpful information in there including https://www.gdpr.school/free-resources/ We will be producing more resources shortly so hopefully they will help too.
  8. Sorry, but consent is only one legal reason for processing. If you have another reason to process and can justify it, then it is not risky. Yes, we are asking for clarification on how far this goes, but consent is not going to be the default position. Opt out being used instead of explicit opt in, where consent is needed, is a big no-no ... and it is shameful to see some schools still doing it that way. The rhetoric on fines has now been brought into line as part of the ICO myth busting blogs, as has reporting everything ... But all of the above has to go hand in hand with DPIAs, good audits and good record keeping. It is also hard to say that we have had a 2 year run up ... we haven’t. But schools *should* have been working with good DP principles already anyway.
  9. Providing a service outside of school has been a significant discussion point for about 5-6 years in one particular LinkedIn group, run by Dr Brian Bandey. His approach has been to look at the H&S risks associated with this as this is an area that cover mental health and well-being. From his conjecture we can see that a service provided by the school, to be used outside of school as well as in school, has an onus on the school to ensure the safety of the learners. If you approach it from that position when you talk to Legal then they may agree that you have the right approach and so you are complying with a legal obligation. Speak to your MDM provider on this to get their position ... as they are more likely to have access to legal folk to discuss.
  10. The problem is the leadership on this comes from ICO and DCMS. They have to work out what needs to be done, get relevant Acts of Law in place and existing ones updated. The relevant departments will work with DCMS to ensure that secondary legislation is updated and relevant guidance is put out *when they know what guidance to give*. There is enough guidance out now to make a start. Whilst I know many want to wait and be told what they need to do, that is not a helpful approach, for yourself or your school. We’ll be putting together a timeline shortly with things you can crack on with whilst we all wait for other things. Most of this *will* be things you should be doing already as a school and as IT Managers. Think back to the earlier Becta materials and look at what you are doing for security, managing your infrastructure, auditing what data you have already ... We all know that you will be asked about this by a DPO when they are appointed so don’t wait ... crack on with it. Remember that the DPO is not going to do all the work, the system owners will do the bulk of it so that means you, the MIS manager, the SENCO, the DSL, the finance manager, the HR manager, etc. Unions are starting to give more guidance to Leadership in schools, GroupCall and others are running awareness and training sessions. Yes, there are still questions to be answered, but there are still lots to be getting on with.
  11. I’ve just been sent this over as well and it is interesting to see the work they have been doing. I’m looking forward to their update of the DfE cloud services document as a result. There are still some elements on the data mapping to iron out but there is time for us all on that.
  12. Out of interest ... has anyone used the old Becta materials on Data Protection? Either historically, or possibly still using them?
  13. Ok, so we are looking at where an existing IT team / person providing services in a school is replaced in entirety by a contracted, external service to do this? The person involved could be TUPEd or redeployed in a different role? Is that what you are looking at?
  14. Schools are excellent at compliance ... finance, safe guarding, recruitment, QA, governance ... it is just that they are also poor at compliance ... when it is something that schools think is not so important.
  15. I’m waiting for my school to ask me to take it on ... I have a business conflict for some reason though ... can’t think what.
  16. You are going to be considered a 'systems owner' for want of a better phrase ... it means that you have a range of systems / solutions / products that are under your general control. You are going to be asked what data you collect, process, etc. You will be asked where do you get it from, where do you store it, for how long. You will even be asked why you have the data and what is is it used for. As @synaesthesia says, use the time now to start thinking about these questions.
  17. If they process personal data, or they provide you a solution that allows you to process data (think about in-house filters and tools).
  18. To some extent, this is what we are trying to do via this thread and related spreadsheet. http:// /showthread.php?t=188142/showthread.php?t=188142 The sooner we can get more on the list the sooner I can start getting responses on and you can see who is being proactive.
  19. And the operational side is the other question I’ve raised with Governance groups.
  20. Yep, and this is why we are asking about liabilities as the DPO is not liable, that is shared between the data controller and data processor.
  21. In the army we had a saying ... “I’m sorry sir/ma’am, you seem to be confusing your tank with my authority!” Sadly, we know that this approach would be a struggle in schools so it does need to have a certain amount of ‘weight’ to them. This is why we are looking at Governors or even doing a school swap between linked schools. We are investing questions around Operation v strategy as well as liabilities for Governors, and also querying how a DH in school A can be DPO for school B and vice versa ... without them thinking too operationally.
  22. There is an old policy on the wiki (remember that everyone) but it does need some TLC to take into account recent advice from ICO (already linked above)
  23. ‘Expert’ knowledge is an interesting term, aimed at companies with over 250 staff (so probably handling a sizeable number of customers). Education establishments seem to have been forgotten about. We are asking on this, but schools often rotate duties ... so senior staff may have expertise that is not presently being used. Also, when bringing new SLT in, Data experience is keenly sought anyway, so there should be some options.
  24. Part of the problem is that DfE is a large organisation so those doing stakeholder work with schools might not be asking the right questions of the right people. Schools could start by going to the old Becta materials and asking themselves are they even at *that* point ... and if not what do they need to do to get there, then look at the ICO site and ask the same. Yes, we know that this would have been a task for Becta in the old days, but I think even they would be on the back foot with this due the getting the DP Bill through, Still awaiting guidance from ICO, etc.
  25. With GDPR in Schools now (sig updated ... apologies). Drop a line to [email protected] and have a chat with the team. I think we've got what you need covered.
×
×
  • Create New...