Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. Done with consent. The difficult thing will be when consent is removed. At that point we need to see solutions that have a way of tagging digital artefacts so that if a learner (or their parent) removes consent then the artefacts will either have to be removed / deleted or restricted for only school use (a legitimate use within school for the monitoring and improvement of T&L). I had this discussion a few weeks ago with a school that was adamant that sharing between schools was legitimate for T&L too, and they refused to accept that they were handing over data to a third party and had no control over it. No doubt IRIS and other solutions will update their policies, practices, guidance to schools and software to sort this out ...
  2. Is this in reference to my comment on school networks and suppliers?
  3. If they are being hacked then they have other problems as well. Data profiling is already a well known issue within identity theft ... there are many out there who are extremely surprised that schools are not being targeted more to get base data that is being built on as part of wider identity farming. School networks are likely to be easier to compromise, but commercial suppliers are going to have larger data pools if people can get in.
  4. Apologies ... to clarify, this only refers to the issuing school and cannot be used to derive any other school. UPN should not (and generally is not) used for validation of school.
  5. No ... you should not be able to derive this from the UPN. This would be a breach of any DSA and a breach of the DPA. If a Data Controller has allowed the DP to process the data on their behalf, then it will be for the reason stated in the DSA / Privacy Notice. Sharing with other companies is not likely to be part of that, and if it is ... then don't use that company. Same as point 2 To be honest, if we were looking at doing all of this correctly then we would be chatting about SIF. Again, there has been little appetite to make the change to SIF, and schools are unlikely to agree any associated additional costs ... in fact there was a lot of pressure on RBCs to stop looking at it because it was seen as "a stupid way of just forcing schools to stay with LAs" to quote on Academy group!
  6. I would suggest 2 accounts, one as an author (work is moderated) and one as an admin. Now we are talking safeguarding rather than data protection .... follow your existing safeguarding guidance.
  7. And this is why you start looking at whether suppliers have ISO27001, etc. At some point you need to see if they have done the work for you rather than reinventing the wheel. Due diligence is one thing ... but most firms have an interest in keeping your data safe anyway and work hard at it. Yes, manage the risk ... but don't stick in overly complicated (and sometimes unachievable) risk mitigation plans.
  8. hmmm ... do I join the wait list?
  9. It is fair to say though that there are some that happen to ignore this ... unfortunately. And that starts to stray into safeguarding too ...
  10. Usually, the school will be requesting a service which functions in variety of ways. The suppliers tells the school what the pre-requisites are for doing this, based on their infrastructure and technology ... whilst there may be alternative ways of doing it, the DfE has not explicitly said that suppliers cannot process this data ... only that the initiation (instruction) needs to be from the data controller. Yes, there are semantics here and the wording is very carefully ambiguous. Because of that you will get a lot of variation in what it is saying ... what it is not saying though is that suppliers cannot use UPNs. Independent schools don't usually work in families of schools in such a way that they uniqueness is needed. See earlier comments about dual registered learners, safeguarding needs around ensuring single accounts, etc. Please remember that you should *not* focus purely on the technical measures but the organisational measures as well ... some methods have been put in place to help schools with organisational measures (working between schools, etc.) I know of some companies that keep their State and Independent school services separately for this reason, and some that just avoid independent schools completely because they don't want to develop 2 or 3 different variations on their product otherwise this will put up the costs to schools ... taking into account the increase in time and resources to develop, implement, support, maintain and improve. They are businesses. Please remember that. They will work within the law and guidance, and generally do the best they can for schools (some are better than others) but they still need to be viable businesses.
  11. Or, if like many existing Privacy Notices, they categorise the recipients and they have online learning systems in there.
  12. A and C are the most common options as it is less hassle for both school and supplier. Option B becomes an option where suppliers are flexible (or are scared of losing too much business due to option A) ... and some suppliers may use things like DfE number to pad out the admission number (this can be used to link families of schools together, if the supplier works that into their product) ... but then you have to think about *why* suppliers and schools want uniqueness of accounts ... what happens for dual registered children that may end up with 2 accounts? Are the educational institutes not working together to ensure a properly managed curriculum for that learner? What happens if part of the service includes email or collaboration tools? Will they use 1 account for most things and then use the other account to hide messages away?
  13. If the data has been transferred to the Data processor by Data Controller X, then the Data Controller can only use it as agreed with Data Controller X. If the DP says, "we will use this to ensure uniqueness of accounts" and Data Controller X agrees (initiates), as has Data Controller A-Z, then the Data Processor can compare the Data between schools to examine for uniqueness. The return response to Data Controller X should a student not be unique would be to contact Data Controller X and say the student is not unique and that they should check their records, look to see if they are dual registered, etc. The DP should have policies and procedures in place to manage this without any release of data. It may be that there is also agreement to contact a designated authority (e.g. LA, DfE) to help resolve duplications. But this is all initiated by the school agreeing to the service and DSA.
  14. Not quite right ... The school always has the choice of whether they want UPN to be used or not. If the company says that to use our product we need a unique identifier and to ensure that this is one that can be unique across a group of school, we presently use UPN ... then the school can choose not to send it ... by not taking the service.
  15. That is for Wordpress.com If you self-host or host it elsewhere then you are running the service and so set the terms yourself. One reason why most school Wordpress blogs are not on Wordpress.com
  16. Get them to answer the standard questions ... Where is it hosted? (Location and company) Do students have accounts? What personal data was used to create those accounts? Who has access to that data? And then go into the safeguarding questions ... Audience, contributors, moderation, etc. Blogging on Wordpress is generally fine when done right. Have a look at @deputymitchell on twitter for good examples.
  17. Instead of the Data Controller having to sue the Data Processor for breach of contract ...
  18. Perfect ... thank you.
  19. I took the comments from @GREED to think back to how we used to have programmes and services hosted inside the school that may have used UPN to sync systems together ... as there was no guarantee that the AD environment was set up to allow that to do management of accounts ...
  20. To be honest ... I really can't find anything that I want, even at a reduced price. If anyone see a dirt cheap 8TB external drive let me know.
  21. Please remember that this is applicable to England. Comments from NI's DfE, Education Scotland or Wales' DfES have not yet been published.
  22. Present advice on Privacy notices is here - https://ico.org.uk/for-organisations/guide-to-data-protection/privacy-notices-transparency-and-control/ and here - https://www.gov.uk/government/publications/data-protection-and-privacy-privacy-notices Advice for GDPR compliant Privacy Notices is here- https://ico.org.uk/for-organisations/guide-to-data-protection/privacy-notices-transparency-and-control/privacy-notices-under-the-eu-general-data-protection-regulation/ and it is worth noting it says "Any recipient or categories of recipients of the personal data" ... and whilst there is further advice to come, it would look like to you bundle recipients into categories and leave it at that within the notice ... I've not seen anything else specific yet to say otherwise, but perhaps @maturelady has seen anything?
  23. And yes, you still need to know what you are sharing, with whom and why. The Why bit is very important.
  24. Consent, no ... notification of sharing, yes. You also need to have done the due diligence to ensure that they are GDPR compliant when that comes into force. You also need to remember that you are not sharing the data with these providers for them to do with as they wish ... you are sharing the data with them, or authorising they to capture it, so that it can be processed *on your behalf*. If you are sharing it for them to do with as they want, then consent is needed ... though why you would do this is questionable.
  25. Part of teaching and learning, so no explicit consent needed *where the information shared is relevant to what is needed for T&L to take place* but you do have to inform parents / learners about what is shared / processed
×
×
  • Create New...