-
Posts
12,876 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by GrumbleDook
-
One of the problems is so many schools still do opt-out for consent, rather than explicit consent. I've already come across a few schools who have said it is too late to change this year so they will do it from next year, also giving time to chat to parents. There are quite a number of schools that really do ignore the existing law, as well as a lot of data protection good practice.
-
Let's look at article 6(1) So the scenario is that the 13 year old does not give consent ... so any other lawful reasons apply? This is likely to be relevant in HE/FE where payment is made as part of a contract between student and institute. Schools are legally obliged to educate the learners. You may get parents that argue about the tools ... but that is the choice of the school. As long as the tools used do not breach compliance with the new Act, then we are down to a school being sued by parents / learners for the choice of tools used to deliver the curriculum ... at this point, speak to a lawyer. Other things like registration ... the school has to do it. Simples! Again, you could argue that it is in their interest to educate as well as use services that protect them (walled garden of a VLE instead of social media as prep for being a member of an online society?) Public interest ... probably going to be the most used reason. And this last bit seems to say (and I need clarification on this) that (f) is not going to apply in schools should other legal reasons for processing apply. (Making a note to ask another question of DfE and ICO)
-
Are these companies data processors?
GrumbleDook replied to enjay's topic in Data Protection & Information Handling
Contractor / sub-contractor. They are providing tools that allow you to process data, and have access to logins to allow this to happen. A) make sure you can audit when they have used those accounts, b) you know what those accounts provide access to and c) have a sufficently robust contract with them to ensure that follow *your* data handling policies. This is where your data audit comes in . The online heldpesk will have the information of *your staff* possibly including contact information (email address, phone number). How is that data handled? Is there any automation on there? What does their privacy notice say they will do with your data that they hold? As with scenario 1 - access control and audit of actions is important here. What data is held on those devices? Is anoy of it Personal Identifiable Information? If not then they are not going to be handling relevant data. The things you have to make sure of is that they *only* have access to that device and that staff know *not* to put PII on there. The above comments are mainly based on how they would also be covered under ISO 27001 as well (the data audit and risk management crosses over) but only you know whether there is any PII being processed. If they are processing PII, then yes, a contract / agreement is needed. We would need to see the code of conduct to see where it sits within the PIA. Remember, organisational as well as technical methods are suitable, but you have to assess the risk ... If you have a code of conduct, you need to show that it is understood, that it is being followed and that you check on a regular basis. Historically, organisations have used technical measures as it is cheaper and less risky than organisational measures. Nowadays it has to be a blend, but we won't know how much until we start seeing cases on breaches under the new Act.- 1 reply
-
- 1
-
-
Microsoft and Google Cloud Services will be both hosts (storage) and Data Processors, depending on what you are asking them to do with the data. Microsoft have already released a toolkit to understand what you need to ask yourself and document with regards to their services and I am sure we will see similar from Google shortly. It is fairly easy for them as they both already do a large chunk of the background work needed as part of their accreditations for ISO 27000 series standards.
-
I've had some responses back from DfE ... which basically points you to ICO or getting your own legal advice. ICO is working on stuff but no date yet. To be honest, whether the age of consent was 16 or 13, you will still need a process for requesting explicit consent from parents and explicit consent from the learners when they turn the relevant age.
-
Many RBCs and LA connections have similar ... you do have to ask and yes, there are time you have to show you are not a muppet due to some dreadful requests LAs and RBCs get.
- 50 replies
-
- 1
-
-
- internet access
- isp
-
(and 1 more)
Tagged with:
-
RE specialised in fixing problems though ... usually major problems like "the artillery did *what* to the bridge?"
-
And so we get into a narrow view of what problem solving is and who can deliver the curriculum around it. Ex-forces folk will probably remember the mantra of Improvise, Adapt, Overcome ... and the headache during basic training of *that* recruit who never seemed to get it ... we all had one in our platoon (troop/flight/etc.) Not everyone gets it ... not everyone can join the dots between different scenarios. As much as I hate the phrase "thinking outside the box", it is a good introduction to problem solving ... except you have to know what other boxes are out there and instead of thinking outside the box, you pull in ideas from other boxes! (And yes, there was a training exercise where you had to do exactly that ... to fix a situation you had to barter with other groups to get the right solution ... except there was no right solution ... they all had to be adapted!)
-
It is not trouble shooting ... it is called problem solving and there are very clear strands in the curriculum about this. The problem (forgive the pun) is that this tends to be done in silos, and not spread across subjects / concepts. This is about breadth and not depth ... and the present educational focus does not allow for much interaction between subjects. Again, this is why folk got peeved about STEM and insisted on STEAM instead. In EY, problem solving is making a come back, and so we should see improvements in about 8 years in Secondary as a result.
-
I am seriously surprised at this paper ... Prensky shifted from Digital Natives to Digital Wisdom back in 2012. This is not new in any shape of form, in fact, if you look at curriculum developments over the last 5 years, it already takes this into account. Digital Leaders, the Maker community ... all show that young learners are not natives, but gain Digital Wisdom through engagement and building of skills and competence ... as with pretty much anything else!
-
When I built a short course for ISO27001 in my last place, the quickest it was done in was 25 mins ... and then they had to do a follow up session a few weeks later (to compare answers) and you could spot those who were good at guessing things. The trick is not to do a course to become accredited, but for an organisation to use the results from the course, along side information from internal audits, to focus on more in depth materials.
-
This is only a valid defence if you can show that staff are well trained, their training / knowledge / compliance is assessed on a regular basis (and to a given standard, if necessary) and that you have lifecycle management in place around the whole arena ... Oh, doesn't this sound a lot like H&S, COSHH, etc.?
-
You ask for their reference number as provided by the accrediting body. You check with the accrediting body. You then check that the accrediting body is themselves accredited by UKAS, the UK Accreditation Service, or the equivalent in the relevant country.
- 3 replies
-
- certification
- cloud hosting
-
(and 2 more)
Tagged with:
-
Third party data sharing
GrumbleDook replied to enjay's topic in Data Protection & Information Handling
Schools that are put in special measures have the reasons included in the OFSTED report. That is a requirement. No relevant information is excluded. All ICO decisions are published and are available for inspection. You will even see notices where they had a go at folk like CEOP. If you are aware of anything that has not been published please PM me. -
GDPR & UPN use - Statement from Groupcall
GrumbleDook replied to GREED's topic in Data Protection & Information Handling
And this is what groups like Defend Digital Me raise questions through FOI requests, to some extent. -
GDPR & UPN use - Statement from Groupcall
GrumbleDook replied to GREED's topic in Data Protection & Information Handling
Except that it is down to a school to consider whether it has been automatically adjunct editor to a pupil's name or if it has added as part of a reasoned requirement... so it is still the school's decision. The problem is that many schools have little experience of performing risk-management on suppliers to cover areas like this. -
GDPR & UPN use - Statement from Groupcall
GrumbleDook replied to GREED's topic in Data Protection & Information Handling
This is starting to look like a request to the supplier to say, "we want to do the data cleansing and matching so give us some data about where it doesn't match!" Are we not stepping into the territory of asking the DP to process data from other schools based on *your* instruction? With a UniqueID the DP can simply say, "We cannot process that student record as it is already controlled by another data controller." -
Third party data sharing
GrumbleDook replied to enjay's topic in Data Protection & Information Handling
In reality though, no school has ever been fined by the ICO, so for schools to suddenly get a massive fine would be a PR disaster for ICO. However, that should not be an excuse not to get it sorted, but we are yet to see what OFSTED are saying about failure to meet GDPR as a safeguarding issue, or a failure to meet legal requirements (puts note in notebook to go ask again). Undertakings will still exist (may be named differently) and an Undertaking may end up having more of an impact to a school than a fine. There are too many companies out there selling their advice on the basis that you *will* be fined ... when criteria for this has yet to be published by any DPA in the EU (admittedly the IE DPA have said they will come down hard from word go but have yet back that up with anything concrete). If nothing else, the fact the London's Royal Free hospital did not get fined for their data breach of 1.6 million patients (Deepmind anyone), just goes to show that you cannot predict anything. -
GDPR & UPN use - Statement from Groupcall
GrumbleDook replied to GREED's topic in Data Protection & Information Handling
And this is where we get into the use of the same data element for different functions! Folk need to remember that UPN is a unique record ... MISID has no guarantee it will be ... and if it is and is being used as a differentiator, then it is related to a student record ... which makes that student in question identifiable, especially when considered in the case of a data breach ... so with a risk management hat on, it makes no difference whether you use the UPN or the MISID ... and you are meant to taking a risk based approach. The creation of yet another UniqueID will end up with another ruling being required about how it is handled, so we get into the same situation again ... The definition of insanity is doing the same thing again and again and expecting a different outcome! -
Retaining emails for old/left staff
GrumbleDook replied to E_G_R2's topic in Data Protection & Information Handling
I have an open query with DfE on this. Will feedback when I have an answer. -
GDPR & UPN use - Statement from Groupcall
GrumbleDook replied to GREED's topic in Data Protection & Information Handling
Summarising a bit here now. To some extent, the concern around UPN is the routine manner it is being attached to other data. This, as discussed, has had such a wide interpretation that in England we have many suppliers that use it instead of other viable options ... purely because it is there. We've had discussions showing concern on this (understandably), as well as discussions about why a supplier might request it on a valid basis. As pointed, those suppliers that do their job well will only use it were needed, will have assessed risks against it (especially if ISO27001 accredited or as part of the approach towards GDPR with Privacy impact Assessments), and then informed the school. This is good practice under DPA but now mandatory under GDPR. Yes, I do expect some suppliers to struggle in their justification in requesting schools for permission to capture and processes, so we may see a change in how some suppliers work. There is a some history of UPNs being used as an LA / regional / national identifier prior to the change to the acts in 2013 ... it has been vague for a long time, and most schools have been unaware of this. NI numbers have a more noted history for refusal to have permission granted for shared use / use outside of agreed remit. This is because employees (and their unions) are a lot more protective of themselves and have seen how misuse can happen. LAs would use payroll or employee number instead ... but GM and foundation schools out paid to that long before academies came along. Even if a new national identifier came along, it would end up being tied up in the same way UPN is ... but even more restrictive. A supplier could say that they generate a unique id generated from the UPN ... take view of how it has been done in Wales. In section 1 of the HWB Privacy notice it covers how a uniqueID is generated and used. This was shared out via LAs to schools. https://hwb.wales.gov.uk/privacy This was no easy feat, but was done and continues to be done.
