Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. If anyone is sharing, please make sure any data is anonymised, that the audit files are encrypted, etc.
  2. 1 - If you don't have explicit consent (where consent is required) then yes, you need to send the forms out again. 2 - It is your responsibility ... some will be proactive and send you info before you ask, but it is your responsibility. 3 - Have a chat with HR about what is covered in their contract. In a recent BBC article it was incorrectly implied that you have to consent for everything. You don't. https://ico.org.uk/for-organisations/data-protection-reform/overview-of-the-gdpr/key-areas-to-consider/ covers it quite well with the 6 sections dealing with lawfulness of processing conditions.
  3. I'd also recommend joining the MacEnterprise mailing list ... Mailing List - MacEnterprise ... as a handy resource.
  4. Can similar clarifications be requested from NI, Scotland and Wales education departments?
  5. If you take a look at the likes of ZenDesk, they are already updating their privacy policy to take into account what is known on GDPR.
  6. This has been an interesting discussion in some circles ... a few folk even raised queries about where dash cams could have problems. The last thing I saw was folk were going to ask the ICO if the CCTV Code of Conduct was going to get an update. Will go and see if there was a response.
  7. There is when it is purchased by LAs, Academy groups or MATs that look at progression.
  8. The problem is trying to get a unique identifier that will track across a student's life in a school, or even between schools (conversations about that become quite interesting when dealing with national projects)
  9. We use Google Drive too. Allows for those of us with devices and for offline / hard copy fanatics too.
  10. I love the stuff from IRMS. It is clear, contextual (includes reference to relevant laws /statutory guidance). The ICO does not provide specific guidance as it is down to the relevant department to provide it (I called up the helpline last week to double check they hadn't had anything specific from DfE ... and they told me I need to contact DfE for it). The IRMS stuff is due an update to take into account GDPR. Unfortunately, they can only fully do that once the guidance comes out from DfE. You can see where this is going.
  11. Hi Mike - the first scenario, you are not getting any personal information though ... you are getting information on the curriculum and making sure your stock is adjust appropriately. If the school was to say that x number of pupils are likely to need more resources at home on particular areas, then you are still not getting personal data, just an anonymised set of information. The second ... where a member of staff signs up for something that involves the transfer of personal data and then tries to organise adding students ... In that case, the school needs to have it clear within their policies that entering into any contract or arrangement which involves the sharing of data (e.g. signing up pupils and/or parents) need authorisation by the DPO. Failure to do this would be a breach of the school policies and subject to disciplinary action. Organisational measures rather than technical measures.
  12. Data Protection is not IT, the same way Safeguarding is not just for tutors. Have a look in the resources thread for more information you can pass to your Head (no one else ... as the Head is the person who will cop the blame for problems) and then step back and wait for the look of panic. Don't panic though ... and don't be pressured to be the DPO (you are not allowed to be ... see other threads for that discussion).
  13. Apply to add an entry. If the schools is an Academy conversion, and the LA did the work previously, it may be that the LA told the ICO the school was closing and it was the school's job to get a new entry in.
  14. I know that some of your devices may not be able to do it because of age, but any that can take on iOS11 (when it is released) will be able to be put on DEP, even if not originally purchased for DEP. This will be a massive help to many schools who suffer from teh problem of randomly purchased devices!
  15. If you are using O365 or G Suite, then look at these to have your intranet / daily bulletin. For parental permissions ... you can only receive them electronically if you are sure the sender is actually the parent. Things like ParentPay, where only the parents have the account, would work well and I am sure that if you spoke with ParentPay they will see if they can sort something for free trips. Even accepting emails from parents is questionable ... after all, how many parents have smart phones with mail on there ... and then let their kids play on their phones, never mind shared computers.
  16. This is quite an important question ... I've just been asking the same in a Governors' group ... quite wide range of responses. Also just seen the same conversation start in the ICT & CS FB group too. If you don't want to publicly post, please PM me and I'll put it up.
  17. It's just one of those things ... something connected with me for Stardust. If I take out how I personally feel, I can appreciate that most would find other books better ... but not me.
  18. His 3rd best book ... Good Omens, Stardust, American Gods.
  19. Because of the growth of centralised systems. Previously it was a nightmare to collate different data sets together, but it started to get a lot easier.
  20. Btw ... DPA covering hard copy isn't stupid ... it is about consistency.
  21. Just because an individual requests to have data removed it doesn't mean you *have* to. An example would be attendance data. You are not granted consent to collect and process it by individuals because it is a legal obligation for schools to collect such data and process it, including passing it on to other bodies such as DfE. The problem is the the DfE do not have a clear list of this anywhere that is easily found. ICO have now said speak to DfE, so that's the next step (others are already contacting DfE on things so we can ask if this can be included).
  22. Thread started about backup software. Please contribute. Backup software responses /showthread.php?t=185805
  23. This thread is to look at what software people are using for their backups and to give others a chance to see any responses to questions that have been posed to those vendors. If we can keep to the following format? Vendor name Software Name Version Systems supported Question Responses With GDPR coming into force on 25th May 2018, how will your software support my school in compliance with the updated law? How does your software support the right to be forgotten? How does your software support the need for reporting and accountability? What versions of your software are these features available on? Will there be any change in licence model and/or cost as a result of any updates you are making to your software?
  24. Just chased and had a response. Yes, the DfE are the people who will give further advice about data that is required to be processed, data that has to be retained (and agreed periods) and so on. General rule of thumb, if it is data where consent has to be given to process, then removal of consent means you stop processing it and you should destroy the data within the timelines in your agreed policy. If it goes a step further and needs to be erased sooner (right to be forgotten) then that is processed as per your policy. Relevant departments should help with example policies in due course. As for backups ... Backups are generally on re-writeable media, and the database holds the information where the data sits. Backup software should be able to remove from the backup instead of restore ... and some companies are coming out of the woodwork to say that they can do x, y and z for you ... but often as part of a large information management piece which is completely unaffordable for school. I love the stuff K2 are doing ... but it is just not feasible in most schools. I might make a separate thread where people can put in Backup vendors and folk can volunteer to go off and ask about what their software is capable of doing.
  25. They cannot be completely forgotten. Schools have legal requirements to retain certain data. This is where I get worried ... as I have seen no advice yet about what can and can't be retained. No had an update to my query to ICO on it, but expecting it to be to wait for DfE instruction
×
×
  • Create New...