Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. What would folk say is a Windows equivalent to a MacBookPro nowadays? Having to swap over from Mac to Windows for some time and handing the Mac on ... so Boot Camp not a real option. Output to two other monitors (HDMI/DisplayPort/etc.) is a must. All comments appreciated.
  2. So the latest we have is still the details posted by @EdWhittaker then, it seems.
  3. I saw, but a quick scan didn't show me what was updated. Will review properly week after next.
  4. What do you call a nun with a washing machine on her head? Sister Matic
  5. Welcome Katrina. Always good to have more Data folk on board.
  6. So we are saying that it is down to duty of care and contractual obligations?
  7. Ed, to some extent, until that response is made in a public arena (or released via FoI) there will always be some who question it. Would you be able to respond back Gary and ask him if this can be published as an article or clarification somewhere? It would simplify matters for many out there. I know that they are working on things, but every little helps.
  8. I've asked the DfE that on a number of occasions ... for a list of all relevant acts/legislation that affect EdTech ... and asked Becta before that, but they had the closure notice before they could respond ... and so got passed to the DfE (bless Sir Humphrey!) Effectively it is going to mean that someone, somewhere, is going to have to pay people with slim watches to stitch it together. I know ASCL have a good list of things (no longer a member so can't get to it), but come September it is on my list of things to follow up on, and I know that @jenatddm is already pushing a so many worthy questions too.
  9. From a range of conversations with DP/IM folk, but I will add it to the list of specific legal questions on @jenatddm's collated questions when I get chance. Yes, Recital 18 is interesting (especially when you look at the exceptions) ... I once asked the question (at RBC level) about whether there was any difference between a school hosting their own services (e.g. running HAP+) and an LA/RBC running a hosted file sharing service ... as was told no. When Live@Edu came on the scene (and then O365) I asked again if an RBC delivering services using these, rather than their own hardware, made an difference and was told no. So what is the difference between a school running the service in house and using a contracted provider? What if the service is provided within the school, but is run by a Managed Service provider?
  10. That is, when the DfE even acknowledge that they *need* to update things!
  11. Been this way for some time, but it fails to show notifications, yet they appear fine on an iPhone. iPad Air, 10.3.2.
      • 1
      • Thanks
  12. General *opinion* from good handful of clerks ... Data Protection Manager (operationally) is a possibility ... at a MAT level it could combine to be a full job ... DPO ... not on your nelly!
  13. Link - Brian Aldiss, science-fiction writer, dies aged 92 The Helliconia trilogy is a classic and much loved from my early forays into SF.
  14. A quick response on this. The data subject is not signing up as an individual, the school is contracting a services and so it would not be deemed as using an Information Society Service. It falls under the Public Interest bracket and that is an area clarified with @jdoyle already. Saying that, the school *is* obliged to ensure that children's data is being processed fairly and lawfully. This is the point where the company needs to show compliance (processing as instructed, etc.) and give you the information to inform data subjects and parents.
  15. No, it is an educational tool that you are using to deliver a curriculum, so it comes under Public Interest. However, you do have to inform and you do have to do Due Diligence that the data is only being used for the purposes *you* want and can justify. I'm going to be off EG for a week or two whilst I get through a chunk of work, but first week in Sept I'll try to cover this in more detail.
  16. And, to some extent, this is were *education* delivery is coming in ... we can link it to Acts and Statutory Guidance, but allow the school to justify the specifics. It isn't nice or neat at times and there are plenty of hurdles we will have to jump across. From a supplier side, I'm just working hard on making sure that where we collect and process data, we can provide schools with justification. Location is going to be the interesting example. We need to show we record it (needed to allow configure to change based on location) but we don't have to allow the detail to be shown ... but this means a level of automation ... so yes, it is going to take time and *everyone* will be searching for answers. Don't panic though ... just get what you can and then give it to your DPO to handle
  17. Yes, certain Safeguarding aspects hit the criteria too, and areas that could affect H&S (including mental health) as well. All areas that are nearly, but not quite in the compliance with legal obligations due to lack of specifics, from what I have seen so far. As always, Still asking advice on these and if anything gets clearer I'll share the references.
  18. I have a similar issue with Vital Interests ... close enough to compliance with a legal obligation, but not close enough to be mentioned *as* an obligation in the relevant acts? With all the Statutory Guidance out there on the National Curriculum, it doesn't give lesson plans, tell teachers where to stand in the classroom, what tools and resources to use, yet schools are legally obliged to educate the children enrolled at that school. If I am to teach KS1 Science (gathering and recording data to help in answering questions), then I might say that I would use product x, which also means that I can provide parents with information about what data has been gathered and recorded. Is this me gathering PII from both pupils and parents as part of my legal obligation or as part of Vital Interest ... or is it in the Public Interest that I use the most appropriate tools and resources to deliver the best level of education for each child? Actions taken by staff, who deem themselves to be working in the public interest, still have to comply with laws and also documented and agreed working practices. If the laws and employer policies say that you should not do X and you do it, then it is subject to challenge (legally and contractually). Whistleblowing is a perfect example, where you should not breach laws and policies, yet there should be policies in place to handle this ... and it is subject to the public interest test too. Whilst it would be ideal that everything was covered by compliance with legal obligation, I doubt it will be ... as the acts do not have enough specifics in them and even the Statutory Guidance is frequently designed to give freedom and flexibility to the experts (teachers and SLT). Leaving the rest as consent would place unreasonable boundaries on schools about how they can teach and how they manage the school. To some extent most suppliers will (should) be looking at what data their software makes use of, know how it is used within schools and providing some guidance on it themselves (they will generally be talking to lawyers and IRM/DP specialists on this) so hopefully that will also help schools. The rest will be down to Guidance from Govt Depts, ICO, Best Practice and eventually case law.
  19. As always, IANAL, but taking from a number of legal articles and referring back to the GDPR itself ... from Article 6(1) and Rec. 40-50 I'll try and get these clarified next week (still quite ill at the moment) but effectively it seems that we have 3 areas; legal obligations - these need to be tied in which existing legal acts and it *should* be Govt departments giving advice to remind people what these are (DfE responses to me so far have reminded me that schools are their own Data Controller and it is their legal responsibility to make sure they act as such) as well as advising on how the new act will need to have conflicts clarified (if any exist), vital interests - which should be determined by the DPA of member states when they enact any law pertaining to GDPR (we'll have to see what happens in the Bill) but there are some examples in there, and public interests - which should be determined by the DPA of member states when they enact any law pertaining to GDPR (we'll have to see what happens in the Bill) but there are again some examples. The education of a child, and allowing for T&L to take place, could easily be equated to the example given of public health. To some extent, the ICO's explicit guidance will help when their materials for schools come out, as well as any updates from DfE (such as their updated guidance on Privacy Notices, which is due sometime this month). In the meanwhile, even if schools just do a data audit of what they have, how they got it, where they store it and why they are using it *at this time* it will make life easier to work through what they will or won't do with data later on.
  20. GDPR says access at 16, but U.K. govt has said they will (tbc) change that to 13. Any existing legislation to say parent can access will have to have clarifications as we progress with the new bill. Until then we have possible conflicts. The thread, to some extent, is to try to say that don't believe any scare mongering about everything needs to be about consent. And yes, Public Interest is going to be vague until best practice is established or until further guidance comes out ... but it effectively becomes the lowest common denominator until things are cleared up.
  21. There will be times when data could be processed due to a range of possible reasons. Until we see the final Bill, it is hard to say what order or precedence the reasons will out with. One thing we do know, is that Public Interest is a valid reason (I still see that to comply with Legal Obligation needs someone to set these out clearly including reference and guidance on appropriate existing laws ... i.e. DfE), but in the same manner, I can see why saying it 'will' be processed under Public Interest could better be rephrased as 'Is likely to at least be processed under Public Interest'.
  22. Until schools start to look at what data they've got ... no one will know the percentage. If only there was a Quasi-Autonomous Non-Governmental Organisation to help look at that sort of thing
  23. Items such as attendance, census, etc would fall under legal obligations, then you start with the areas required to allow you to fulfill safeguarding obligations (including H&S) ... but then you start getting areas that DfE need to clarify on ... whereas most grey areas, even without clarification, could come under public interest. Progress data sheets, timetable, behaviour ... And once you have looked all though there, you then start looking at which need consent. First thing though, is understanding what you have, where it is, why do you use it, how did you get it and when do you get rid of it. Think ROT. What data you have, is it redundant, is it obsolete or is it trivial? This is where you start clearing out things you don't need or shouldn't be processing.
  24. The other consideration is the this is for a Data Protection Manager ... not explicitly the DPO.
  25. Clerks are a difficult one. I can see both sides here and I suppose it will vary slightly depending on whether your Clerk disseminates data (shunts around stuff that has been prepared) or takes data and operationally works on it with their remit as Clerk (they may already not be allowed to take on the role because of a day job they have within the school) Off to ask NGA and some Clerks.
×
×
  • Create New...