-
Posts
12,876 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by GrumbleDook
-
Email Retention Period / Policy
GrumbleDook replied to timbo343's topic in Data Protection & Information Handling
I make heavy use of rules and categories for this. It also means that I can set aside a day every so often to review anything that might be useful in the future and have a rolling approach to reviewing things. Generally, anything I know will be stored in another system will be moved to a given folder and a desktop notification is sent. I tag other items remaining in my inbox and move those to other places too. It is not perfect and because I have done it this way for about 20 years now, I know it works for me. I know I will loose some emails that I have sent, but it is more about the email recipient also needing to reetain. That said, I think I have tried pretty much most of the add-ons for Outlook on my Windows machines and Mail on my Macs. Some are just plain strange and create more work for me, but have saved time for any assistant/support I have had. -
Hahahahahaha ..... Forget any reference to them being students, at a Uni or so on. Tutor agency wants contractors to take on an independent status rather than being considered an employee or agent, and in doing they must make sure they comply with all relevant legislation as a business, including for data protection, information security, financial management, tax, etc. They are targeting Uni students as they might presume the students don't know any better. There are other things I could say about some such agencies (most are really good and do it right, just for the record) that are really stories for in the bar after the next EG conference. The stuff about being closer to the age of the customer is partly correct, but there is strong reasoning about cheap and unqualified labour within what is effectively another part of the gig economy!
-
Email Retention Period / Policy
GrumbleDook replied to timbo343's topic in Data Protection & Information Handling
Would that email have information that could have been recorded elsewhere? A ticket within a service management solution, that also supports any change management you might be involved in? It sounds like there would have been a reason the email was kept. If so, then have areas within your mail account with different retention periods. Or make sure it is recorded in the relevant system. -
KCSIE 2023 - updates that may impact IT
GrumbleDook replied to Ditto's topic in Internet Related/Filtering/Firewall
There is a long-running conversation about how records are kept and/or shared between schools during and after any transition. The most common one we have all been involved in at some point is the Year 6 into Year 7 transition. Data Sharing between schools is both a reasonable and manageable concept, and there can be essential information that needs passing on that may not always be in the Pupil Record file. In the same way that KCSiE has had to explicitly mention that Data Protection concerns should not stop you from sharing vital information when it is needed, it does also state you should follow the 7 principles of data protection. Likewise, making sure that personnel in the new school have the right info from the previous school can also be vital. This can be an informal agreement, or it could be through tools such as https://sixintoseven.co.uk/. As adoptive parents, there is so much we knew had to be shared between schools and having a paragraph or two in KCSiE means that parents also have something to point to when making sure information is passed on. -
School email address for external consultant
GrumbleDook replied to StevieM's topic in Data Protection & Information Handling
A fairly normal request, and access control is key to management of this. The use of a single account by multiple individuals is a pain and there are risks associated with this, especially for when there is a data breach ... the blame management that can happen seriously causes all sorts of things to come out of the woodwork, so ensuring organisational measures are carefully followed is important. Ideally, a restricted set of accounts for each individual with access to a shared mailbox is technically the easiest option, but organisationally might not be. Also, having multiple accounts accessing a shared mailbox doesn't get around the needs to ensure that all account holders need to be trained on data protection, privacy, safeguarding and information security to *your school's* standard ... not anyone elses. Risk assess ... log it in the risk register and assign someone in manglement as the risk owner. -
Filtering and Monitoring log retention
GrumbleDook replied to sigma's topic in Internet Related/Filtering/Firewall
The retention period is not strictly mentioned as the logs are only an operational set of temporary records. If any information within the logs is pertinent (e.g. behavioural information), then it should be managed and a copy moved/stored in the appropriate system. If you know you only have 1 month of logs, then you need to adjust your procedures to complete checks on a very regular basis. I would push back on the ISP as the retention period should be your choice, but it does mean you might need to export the data into another system. KCSiE refers you to the Online Filtering and Monitoring stuff, and that may be beefed out over time ... I'm not aware of anything specific going into the updated Schools Record Management Toolkit, but will ask. -
That was planned a while ago. It has been a discussed item within one Google edu group for about 2 years now ... if not a bit longer. It has been included in their guidance for some time and discussed on here previously too, IIRC. The difficulty I have is the terms they use. Some of the apps are indeed third-parties ... nothing to do with the school and users are just using their school account as part of login/verification. These are the ones that should be blocked asap. If there are some you are happy for users to keep on using, then yes ... consent will be needed and there will be things from the Children's Code to consider too ... but that is a completely separate conversation and speak to your DPO on that one! Others will be services you buy into which you use the Google accounts as SSO (NetSupport's classroom.cloud integration with Google Workspace and M365 is an example). Unfortunately, because of the common language used in Regions, they get lumped in with 'third-parties'. These are the service providers who should be able to give you instructions about how to ensure that any integration remains working during the above change. This is why you need to review what is in the list of apps using you for sign-on and making sure you only allow the ones you want ... but please make sure you discuss this with DPO, DSL and relevant senior leaders ... have a comms plan in place to let people know of the change and give others a chance to come forward with things they still want to access. They may not be granted permission to have that integration ... but better to have them come forward. I've got a guide on this somewhere that I have previously shared on some google groups. I'll see what I can dig out.
-
I'm going to jump in quickly now to share a few things I (and many others) have covered before. What we are really talking about is understanding Security by Design and by Default and Privacy by Design and by Default. As any cloud ecosystem grows and changes there will be things that need to be adapted. The problem is having a baseline to start with, and then having an understanding of why it is this way. As an EdTech vendor, I'll hold my hands up and say that this is not always easy, and since a number of cloud services that get used within education have come from a consumer base originally, it can be even harder. I know I bang the drop about how important helping schools with this is (indeed, my day job involves me writing this up and trying to find ways to make it better), but for this to change we *really* need to see widespread engagement with this. If I was to ask everyone here what the key principles they wanted to see with any new cloud system, what would be the top 3? Zero Trust? Granularity in controls/permissions? Clear information labelling? Encryption? Integration controls? Readable agreements? AI to identify gaps? I know there could be a lot more (hmmmm ... poll time?) but I am interested to hear what all of you are finding as the requirements, and the subsequent approaches we all take as a result of what we are given when cloud services finally get handed over.
-
PTAs are (generally) separate entities to the school, and so need to cover their own data protection requirements. It is possible for PTA 'staff' to have access to school systems as school volunteers, and to also make use of the school data ... but only if there is a clear data sharing agreement in place, relevant safeguards are in place and it is made completely transparent to school staff, children and families. It can be helpful to have this sort of relationship established, as it can cover H&S requirements, safeguarding concerns during PTA events (as school staff may be doubling up on their roles ... school staff and PTA volunteer), and simplify fundraising projects (yearbook, etc.) Shared mailbox? No. Email forwarding? No. Ensuring they are data protection/privacy/safeguarding/H&S trained? Hell, yes! If that is easier to do under the school banner and the payback is some email access (appropriately restricted, monitored and audited) then why not?
-
Captain Flashheart for AirMail stamps?
- 3 replies
-
- blackadder
- commemorative stamps
-
(and 1 more)
Tagged with:
-
What words do you (or someone you know) say incorrectly...?
GrumbleDook replied to Koldov's topic in General Chat
Having to deal with both slypexia and roticity, I have done some fun ones over the years. Having had a very broad scouse accent as a kid hasn't helped either. As a young and innocent child, on a camping trip in Yorkshire, we were short of pegs to hold onto the ropes. I was given a few quid and sent to the camp shop. In I trot, wait my turn and eventually get to the front of the queue. I struggle to understand the deep, Yorkshire voice of the bloke serving and eventually I manage to ask for the tent pegs. In a high pitched scouse accent that comes out as "Tenpex" ... and after some discussion behind the counter I am passed ... a box of Tampax. Being too embarrassed I go back to the tent and explain to my Mum .... and she and my older brother roll around on the floor laughing. In years to come, my eldest brother (a different one) was my best man ... and in the wedding speech he mentions this ... and so the laughing continued. I also say spare and spur the same, and avoid many words that have a strong r in them ... A team needs to gain a high position in the table, rather than saying they need to improve their rank ... as I am sure you can guess the problem! -
You have to remember that most data protection legislation comes from a history of human rights. It is a very long history but things like the United Nations Declaration of Human Rights, Council of Europe Convention 108 and the UN Convention on the Rights of the Child all form a strong basis on how Privacy and Data Protection legislation is built and balanced against the needs of the supplier. This means you can start considering things like freedom from slavery and torture, freedom of opinion and speech ... Within GDPR, the WP29 Recital 75 does give more information and context, in particular to vulnerable data subjects and where special category personal data may be in use. Basically, vulnerable groups are often those most likely to be affected by problems from the use of personal data. You have to think about what these problems are and remember that it is about the data subjects, not the organisation. Not sure if this helps to clarify it but hopefully it gives a bit more background prior to doing any DPIA.
-
A long one .... The scene is the inside of the Three Broomsticks in Hogsmeade ... Some time after Deathly Hallows but before Cursed Child. Madame Rosmerta is behind the bar, waving her wand around as she restocks ... and the door starts to open. with a beaming smile, a slightly bedraggled wizard walks in, who apparently has been dragged through a hedge backwards ... possibly several times! Afternoon Rosmerta. Sorry for tracking mud in, I’ve just been up discussing a few things with the centaurs in the Forbidden Forest. The local muggles have started to treat it like normal woodland and have tried cutting down a few trees. I’d been sent up to get an idea of the damage that has been done. Imagine my surprise when I see a bunch of new trees, growing quite healthily. I asked the centaurs what had happened. Apparently, this always happens. If a tree gets cut down, a witch or wizard turns up the next day, cleans up the old trunk, pulls out a nut from a canvas knapsack they have slung over their shoulder, puts it in the ground, covers it up and then starts waving their wand about, singing a long and complicated spell. The next thing we know is that a tree starts sprouting up and grows very quickly until it looks like a 10-year-old tree. No idea why, but it has happened that way for centuries. Now this has me completely confused, and I was determined to find out why. I’ve been sitting up there for a few days now and finally, a tree must have been cut down somewhere as a wizard turned up and started the strange ritual. Within minutes a small tree stood there. I leapt up and called after the wizard as he was leaving. It took a bit of fast talking but we eventually agreed to have a sit down and chat. It turns out that when Hogwarts was being built the founders employed a legendary poacher as their gatekeeper and master of the grounds. He was the person that helped introduce so many magical animals to the Forbidden Forest and helped bring it into balance as well. However, he was quite vain and had a wonderfully full head of glossy hair, which was his pride and joy. Due to an argument with Salazar Slytherin, he had been cursed and every autumn, as the leaves fell in preparation for winter, so did some of his hair. Each year his hair became thinner and thinner until the last few strands were falling out of his head as he lay on his death bed, surrounded by his nearest and dearest, in the family cabin just at the edge of the forest. With a final effort of will, he sat up in bed and looked out of the windows at the bright reds, yellows and gold of the autumn leaves. “Look at my hair,” he said to his gathered kin, “It used to be magnificent but now it is completely gone.” “My hair couldn’t be saved,” he went on, “but look outside at the forest. It truly is a magical and wonderful place, so full of trees and the life within those trees would not survive without such magnificent plants. However, sooner or later there will be someone who wants to cut them down, and then the forest will look as bald as my head.” The family looked on, agreeing with him as many of his children had also become carers of nature. “What I want you to promise to do to is this. I have cast a spell across the whole forest which will alert you when a tree has been cut down or dies. When that happens you must take my knapsack and journey to the site of the destruction, take a seed from inside the bag, plant it next to the old trunk and sing the spell that is stitched into the cover of the knapsack. It will make the old trunk or dead tree become absorbed back into the forest floor. The nuts are magically created so that no matter which one you place down it will grow into the same species as the missing tree.” His voice starting to fade, he lay back down with his head on the pillows. “And this must be done by you, and then your children, and your children’s children and so on for years to come.” And so he closed his eyes one last time and breathed his last, with a smile on his face for the legacy he had created. And true to the promise they made to their dearly departed head of family, they have been doing this task ever since then. Rosmerta sits down on a bar stool … waiting … just waiting …. And so the Forbidden Forest has remained as vast and lush as it is due to one man and his re-seeding heir-line.
-
Happy retirement @elsiegee40. I can't express how happy I am to hear you are retiring as it is well and truly deserved. The place will be quieter without you and you leave a massive pair of shoes for any future Mod to try to fill. Take care, don't be a stranger, and looking forward to seeing more of your trials and tribulations with wildlife.
-
I've just checked mine ... Whaaaaaaaaaattttttt? Seriously? I can still remember being pointed here by @russdev when things suddenly went quiet on the RM forums and on the UK.Education.Schools-IT newsgroup (yes ... UseNet ... remember that?) I can vote from July and whilst considered as an adult at that point ... that will never mean that I will stop coming in to play about and have fun, as well as the more serious side of things. So happy birthday @StevieM and to all others who are celebrating *anything*
-
New KCSIE recommendation: Social Media checks on candidates
GrumbleDook replied to RLR's topic in How do you do....it?
Absolutely spot on. Probably the best summary out there. KCSiE does *not* say that you need to be able to take over any SM of a candidate. Heck, from a Data Protection/Privacy point of view, this would be a nightmare to manage for any organisation. If I was to see this on any job application, or even using any service where I give authorisation to access my SM, then I would be asking what else are the doing wrong. An FoI request to see the risk assessment/DPIA on this would be sent in and actively challenged. -
Saw it with the kids and loved it. Yes, it is a bit generic at times but still good fun. It really does play on Bowser being the big bad *and* the comic relief at the same time. I can easily see it being turned into a film franchise or at least a running series the way Trolls and Boss Baby have done.
-
@NorrthDown2 You are not the only one missing Saturday. That would often be the best day for meeting up with people and would take a lot of pressure of catching up with others. If you could see them on Saturday, then brilliant, if not then look at an alternate day. As it was, I was down on Thursday and a bit of Friday morning, was lucky enough to not be on the main stand this year, but in meetings with others instead. A chance to wander around and see what was going on was also helpful, but despite many attempts, as I was not down as a school/buyer, I could not book a meeting with other exhibitors, which is a drawback as it is a perfectly reasonable expectation. I did use the Connect@BETT area for a few meetings though and only got moved on once. I did feel the atmosphere was better than last year, and the moving of the arena was an interesting one, and I think could be workable. Whilst the footfall might drop away, having better arena experiences is a plus point for those attending based on CPD. Feedback I have had about panels and lectures was very positive, and there seems to have been some better curation this year. I would still love to see more of the sessions recorded and available later.
-
As you might have guessed, I've done a fair bit of reading on it and there is a long way to go before we get a definitive position on what it is going to be like. There are a lot of lobby and advocacy groups chucking their tuppenceworth in on this and so it is still hard to say what could happen. Key outtakes so far? DPOs are replaced with Senior Responsible Individuals - this is one of the most heavily contested areas as it reduces accountability and could end up with disparity to the EU ... which could affect adequacy. From a supplier point of view, if you trade within the EEA then little changes for this. Other accountability changes include narrowing the requirement on Records of Processing ... but that is unlikely to affect schools, as RoPAs will still be needed where there is a high risk to the rights and freedoms of data subjects ... and it would be a brave school that said that this didn't include them! ICO is meant to then produce guidance on what high risk would look like, and I would not be in the slightest bit surprised if schools get included in that. A possible area of change would be that a recognised Legitimate Interest list would include "processing that is necessary for the purposes of ensuring the security of network and information systems" ... so anything that is part of the ops and security of your network and data might shift to LI ... though there is little difference if you are doing this under Public task right now ... apart from having to do a balance test ... oh, so it could create more work rather than less ... so I guess most would still go with Public task then! Linked to this ... on Friday 31st, The Digital Futures Commission will be running a showcase of the activities they have been doing for the last 3 years around children's data and online activities. In the afternoon, we see their Blueprint for Education Data published and discussed. Baroness Kidron will chair a panel discussion (she was the principal architect in getting the Children's Code written and out there, as well as helping to make an IEEE standard from it and support other countries adopting similar codes). No doubt some of this will get raised during the panel discussion, and possibly the Q&A afterward, and if there is anything I can share back I will do. The panelists will include ICO senior staff, legal expertise, privacy advocacy, and vendor/school specialist (yours truly), and is likely to be a lively debate.
-
BETT 2023 GIVEAWAY - What is your earliest gaming memory?
GrumbleDook replied to VeryPC's topic in Our Advertisers
BBC B and Yellow River Kingdom, and some of the text games like Philosopher's Quest. Some handheld LCD games such as Space Invaders, Donkey Kong and so on. -
Edugeek pins at (not) BETT 2021
GrumbleDook replied to Kitkatninja's topic in Comments and Suggestions
(Goes hunting through the EG archive) ... I think I have them all but a chart to show each year would be good. -
For the processor, they are doing something on behalf of/instructed to. A controller makes the decision about the purpose and method of processing ... so yes, there are many occasions where schools are controller and processor, as most controllers will be in that situation. For the photographer, yes, that is generally correct. Many photographers now have a direct to parent offering, but not all schools do it that way. For some, they will still do it via the school, but be instructed to manage the engagement with parents. Some will even be Joint Controllers with the school due to the way commision is paid to the school. It is all in the agreements that are made.
-
You also need to think about which are Data Processors and which are Independent Data Controllers. Where data is extracted to be used to manage other systems, then thayt are a data processor and you would have a data processing agreement in place. If the data is share to an independent data controller, e.g. the DfE, then this is data sharing and there is a data sharing agreement/instruction in place. Try not to use the term Third Party as it has a specific definition in GDPR and too often you hear it to mean both of the above, when really it just means the independent data contoller.
