Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. What I mean is that it shouldn’t become a massive chore within the school. It should be a little of everyone, just like Safeguarding is. Yes, you will have companies that have solutions that can help keep it that way.
  2. You aren't really logging every transaction, systems do that for you where needed. The DPO makes sure that you know what data you have, and how it being processed, why, and how etc. They have oversight of the DPIAs.. It is a significant and serious role, but shouldn't be an industry of itself.
  3. The Data Protection Bill that is progressing through Parliament at the moment is trying to Brexit proof things... and the sticking point is data transfer agreements between us and EU. Because the bill is effectively GDPR, the expectation is that the transfer will not be a problem.
  4. The Data Protection Bill puts accreditation of certifications in the hands of the ICO, so it is a two hander... the DfE needs to know what training will be needed and ICO needs to agree.
  5. Looks a possibility, but won’t be able to promise until the week before
  6. If you are not being paid to do it then it *should* operate like this ... Relevant person designated with 'owning' the policy goes to get there relevant information and where they don't know it that ask others. That will involve speaking to the various folk to find out a) what legislation / guidance / rules are out there that should be considered (this is something that the policy owner should do for themselves and the exercise with others is to see if anything has been missed ... it shouldn't have been, but you have to check anyway), b) how things are operationally running at the moment (there should be existing policies and procedures in place for most of these and the policy owner should know these extremely well, and should just be checking if they are being followed and whether they are still suitable ... and feedback from subject matter experts is vital here ... but it is feedback, not rewriting) and c) looking at opportunities to improve ... and this is where those not being paid to write policies fit in. As subject matter experts, you should have a point in the process where you can feedback about issues, needed improvements, etc. You are not rewriting policy, but mainly dealing with procedures linked to that policy. Unless there is a person or contracted service that is also writing your procedures for you (you check logs on AV on day x, you check for replacement toners on day y, etc.) then *that* is your day job and part of the lifecycle management is feeding back into the policy. Under managed services ... yes, you are effectively doing nothing of this. Under a normal school contract, then most JDs will put you in place to deal with procedures.
  7. As I said ... used and abused. Done right and it works. Done wrong and it just makes people think it is a tick box. Done wrong too many times and no matter how many times people then try to do it right, everyone is jaded and it becomes a self-fulfilling nightmare. I had too many LA consultations like that. But I’m ever the optimist ...
  8. Unfortunately, too many good staff have been used and abused over the years and their valid (and much needed) input is lost. You know I don’t blame you for your approach @bossman ... I fully understand it. However, in schools where thing can be salvaged, by hook or by crook, then it should be input based on school needs and the contributors should be a range of staff. There are so many template policies available nowadays, no one should be righting from scratch or the sole writer. They may be the policy owner (ie it is their job to make sure the relevant people have input ... and that the input is listened too) but not the sole writer. Where policies don’t exist at all, due to changes in regulations or practices, it becomes harder ... but it is a School Policy ... school. Including input from parents and learners where needed!
  9. Good to see you again. Don't be a stranger / don't get any stranger
  10. We are working with suppliers to do this on behalf of schools. Drop me or one of the team a line if you'd like more info.
  11. Actually, they don't *have* to be ... it is just logistically and operationally unlikely that you will find someone completely separated from owning operations and systems related to data and also with enough knowledge.
  12. Check in the contract for the clauses about complying with local laws. Also, it would be a brace EdTech supplier that doesn't sort themselves out ... remembering that if they don't they will not be able to sell their service into EU at all!
  13. To be honest ... as we said at the conference ... *NO* company is compliant right now. There are still some things to tease out, a specially on contracts, but the best thing you can do is ask if they are working on it.
  14. Looking good. Really appreciate you getting the ball rolling.
  15. A consultation has just started by the ICO about contracts and liabilities between data controllers (e.g. The school) and data processors (e.g. Microsoft). https://ico.org.uk/about-the-ico/consultations/consultation-on-gdpr-guidance-on-contracts-and-liabilities-between-controllers-and-processors Many suppliers are waiting for guidance around this to see what needs to be updated in contracts, etc. To some extent, the best you can do for some companies is ask "Are you doing something to ensure compliance with GDPR and if so, what?" If they fail to respond or say it isn't relevant then point out that it is relevant and give them one more chance ... most will respond ...
  16. Yep. Perfect answer. Contractor. Get everything you need in their contract. Or make them a fixed term employee?
  17. The email alert service from gov.uk is very handy. You can do it for most parts of the site, so you are aware of funding changes, Safeguarding updates, etc. Set it to daily digest though otherwise you get buried on certain days.
  18. Once shredded it becomes waste.
  19. As with all things, you can guarantee that when someone says to you, "I wonder if supplier x is doing anything on GDPR?" then someone, somewhere sets up a list. And this is no different. After having had a good chat with a few EdTech consultants, it is obvious that there are still a lot of suppliers / data processors out there that don't know that they are going to have some difficult conversations with schools when it comes to asking what are they doing with data you have passed to them to process. Mark Anderson ( ) has even looked at his Periodic Tables of Apps and started cross checking which are doing things in prep for GDPR, as one example. @jenatddm has already started the process of gathering a list of suppliers together and there are still lots of other things to be raised on there. We at GDPR in Schools want to keep that going and go further. But we are only touching the tip of the iceberg right now .. Below is a link to a Google spreadsheet that we are asking you to add additional details to. https://docs.google.com/spreadsheets/d/1w0ObwB5jdg2NVKnxvTEqXP4GwHk5qyBJqQFnuj4TGRo/edit?usp=sharing We are looking for a supplier name, URL, product name and we will fill in the rest from public information. We will then send our standard question to them of whether they will have a data map available (the response to the questions, "What are you processing on our behalf, what are the common legal reasons for processing it, how long will you keep it for and how will you get rid of it?" There are more things we can ask, but this is a start. The idea is to have pretty much every EdTech supplier that is handling data contacted and with a response by the end of December. And there are *a lot* of folk out there. Yes, we are already chatting with systems integrators. Yes, we are already chatting with RBCs. Yes, we are already chatting with DfE, stakeholder organisations, groups like BESA, and pretty much everyone is saying the only way we will capture it all is we have a strong grass-roots push too. We are grateful for the large number of EdTech firms who are already coming to us and working with us (we can't pre-fill their details in until we have been asked to "ask the question" … ) and also very grateful for those resellers who are also raising the profile of what must be done around GDPR. There are many suppliers and data processors out there that have been working on this for some time already, and anyone with ISO27001:2013 will already be doing a chunk of what is needed … but sometimes it take a bit of time to pull everything together. Some are holding back a little as there is still some advice and clarifications to come out, so we do need to be patient at times. Some already have their data maps out there, but they are only partial (i.e. they cover a lot of items under the DP act as it stands) and we are working with them to update them for GDPR.
  20. https://ico.org.uk/media/for-organisations/documents/1132/report_dp_guidance_for_schools.pdf is a few years old now, but looks at a lot of problems that schools still have. This is based on 1st and 7th principles of the DPA. https://ico.org.uk/for-organisations/guide-to-data-protection/principle-1-fair-and-lawful/ https://ico.org.uk/for-organisations/guide-to-data-protection/principle-7-security/ You have to decide if you still need the data (in that format) and if so then you secure it. If not you destroy it. The DPA doesn't specify standards and so on, but I can bet that the company will talk about BS EN 15713:2009 ... if they say BS 8470:2006 then walk away, that standard has been superseded by BS EN 15713:2009 The thing is ... the standard is more about staff vetting, site security, collection and transport, audit controls ... the actual destruction can be done by the school. One benefit from using a shredding company is they will often provide you with the secure bins to use, but these are readily available to by. Shredders are in DIN levels, and go from P1-6 (P3 deals with confidential), so you can go and find a good shredder yourself. You simply need to have a destruction procedure (which should be tied in with your data proctection and information handling policy) and have evidence that it is being followed. You only need to have certificates of evidence if you are using a shredding service. Many LAs and businesses have done a Risk Assessment and a Time and Motion study and found that it is more cost effective to take on such a service (reduction in staff time doing the shredding, no kit required, reduced risk of fines for data breaches, etc.) so you are going to find companies chasing business again with the new law coming in. Don't panic, have it in mind when your school is discussing next steps and check what is actually needed.
  21. You need to be clear as to why you are taking the photographs, who is going to access them and how. https://ico.org.uk/media/for-organisations/documents/1136/taking_photos.pdf gives guidance on when the DPA may apply. Is it being collected to allow you to comply with legislation? Identifying a pupil so that their safety can be protected is a valid reason. The school may already be collecting their image for this reason via CCTV. Deciding to use it for other reasons, such as press, promotional materials, etc. would be outside of this and refusal could be made on those grounds.
  22. Well, what can I say. Last week was been a busy week over at GDPR in Schools, so not had a chance to introduce everyone to the general membership. More information can be found at GDPR in Schools You already know me and Lynne (@maturelady), and some of you will have met Alex (@AxB) at the conference We also have … @Karen_GDPRiS and @Kerrie_GDPRiS will be looking after sales and demonstrations @Mel_GDPRiS will be sharing resources with you all @Kathryn_GDPRiS and @Pieter_GDPRiS will be at your beck and call for support and help new schools get onto the system. Over the coming weeks everyone will dip in and out to help answer questions, or point people to where information is already provided. With the news that the Data Protection Bill has started its Parliamentary process there will be a lot of discussions over the coming weeks. The ICO has also opened the Consultation on GDPR guidance on contracts and liabiities between controllers and processors, which will be interesting to see where it goes. So, pop over to the Data Protection and Information Handling forum to chat with us and our co-Sponsor, Groupcall.
      • 1
      • Thanks
  23. https://ico.org.uk/for-organisations/guide-to-data-protection/principle-5-retention/ It should be in a policy somewhere. It might simply be a reference to the IRMS suggested retention schedule.
×
×
  • Create New...