-
Posts
12,876 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by GrumbleDook
-
GDPR Data Protection and Memory Sticks
GrumbleDook replied to ITGURU's topic in Data Protection & Information Handling
The good, old-fashioned Fair Processing Notice is going to take a beating ... If only there was a way of having a central system that could classify and manage data, including adding meta-data about where it was being shared with and how it was being processed (IIRC, originally suggested as a requirement for MIS at a Becta Working Group in 2008 ... and pretty sure it has been a regular mention over the years at SIFA(UK) sessions ... remembering that portability is important under GDPR) -
GDPR Data Protection and Memory Sticks
GrumbleDook replied to ITGURU's topic in Data Protection & Information Handling
I've been waiting to comment on this one, based on something I am chasing with the ICO, and also concerned that there is still a lot to cover on this so advice is sparse. More guidance for schools will be available and it will be pushed out through a variety of sources, from DfE themselves, ICO, suppliers ... in fact pretty much everyone who has a stake will be shouting at schools about the change ... partly to cover themselves (as per Liam's comment above about 'shared responsibility'. There are a mountain of good practices that should already be in place that only need tweaking or extending (e.g. the opt-in for photographs can apply to more data sets and situations) and most MIS can be customised to cover this. Your CCTV policies and system (which includes access control lists, maintenance schedules, audit logs, etc.) is a good *starting* point ... and remember that the updates will affect CCTV too so expect further guidance on that anyway. The biggest shock is still likely to be forcing people to understand what data is, who is managing it and getting decisions about how/why it is processed. The changes to Sensitive, Personal Data (special categories of personal data) will be interesting to see how some institutes react. Being honest though, until some clarifications and final guidance is made available, it is going to be a tough sell to SLT in school. Realistically, you (the school) will have from August to get started ... and between August 2017 and Feb 2018 I would be prepared to get as much verified advice you can get on it ... and at this point I remove myself from being considered even close to verified advice. Instead, I will probably be blathering on about planning instead ... Get yourself on LA training. If an academy, speak to your MAT now and start asking who is going on training ... and when they will be providing *you* with advice. You can bet the unions will be running training events on this, as part of making sure the school and SLT are covering backsides on this! Start emailing your MIS provider about how they could be supporting the additional needs around managing data and information on GDPR. Start looking making a list of where all data is held (including hard copy) so that you can get a tick list of suppliers / data sets that are covered off. I can almost guarantee that BETT will be interesting around this next year ... as will a few of the other events. If you are concerned, speak to your Governors. If you are a Governor, then start asking your advisory service when they will be running training. Whatever you do though, no matter what your position or role, don't panic. Be logical, be practical and (most of all) be prepared to communicate. -
I once had to put out a small fire in barracks due to one of those damned three-way adapters. The RSM then had it sawn in half so we could show people how fired it would get inside. Hair dryers into extension blocks, 4 kettles all running at once on an extension block, a 10 metre extension reel that was tightly wound but being used to power a condenser tumble dryer, one of those tea warmers you plug into your cigarette lighter in the car had the plug taken off and was jammed into a wall socket using another plug ... just a few things I dealt with in the army that caused fires. Decent extensions cost money, need regular examination to check they are fine and any mains ring they are on checked that they are not drawing too much.
-
Declaration of interest ... I now work for an MDM provider. THIS IS NOT A PITCH To have the remote wipe feature you are looking at a mangling of Profile Manager (password protect the configuration profiles to prevent removal) combined with iCloud remote wipe tools (remembering that this is based on AppleIDs, which are personal accounts) or purchasing the devices on a business account and get them enrolled in the Apple Device Enrolment Program (DEP for short), as this allows for your MDM to flag that profiles cannot be removed. The configuration payloads you are looking to make use of are around password policy enforcement, including having complex pass codes (alphanumeric) and wipe after x number of failed attempts to access. To ensure that remote wipe is available, the devices would need to have cellular connectivity in them, as there is no guarantee that they will be connected to a wireless network. All of the above applies in education as well for where staff are using iOS devices ... so it is not just relevant to business.
-
Nowt wrong with watching broadcast TV ... some of even read real books, buy magazines and even listen to live radio.
-
Data Protection and Student Data
GrumbleDook replied to DNM's topic in Data Protection & Information Handling
The ICO is reviewing this at the moment. The probability is that Model Clauses will win out until new legislation is in place. -
Data Protection and Student Data
GrumbleDook replied to DNM's topic in Data Protection & Information Handling
The US is an interesting one at the moment as Privacy Shield has had a roasting. However, if the company involved delivers the services as per the EU's Model Clauses then that is fine. If it is $random_web_host, then probably not. -
Data Protection and Student Data
GrumbleDook replied to DNM's topic in Data Protection & Information Handling
Firstly, Principle 8 states Secondly, there are other countries outside of the EEA where it can be transferred. https://ico.org.uk/for-organisations/guide-to-data-protection/principle-8-international/ gives more details about it. Thirdly, there are several countries that data can be transferred to and https://ico.org.uk/for-organisations/guide-to-data-protection/principle-8-international/#adequate gives more details And finally ... even then, you can also use other countries if the following hoops can be jumped https://ico.org.uk/for-organisations/guide-to-data-protection/principle-8-international/#not-approved So it all boils down to risk assessment. In short, for a lot of schools ... it is a no, because they haven't done the risk assessment. It is possible to do it, and it does need consideration. The paper on cloud services from HM Gov't goes some way to doing the risk assessment for you ... but it is a self-certification for those companies on there. -
Looks like you are about to say, "Oh, Matron!"
-
I still think my t-shirt on Friday night was best.
-
Thanks to the folk @ GitHub.
-
One of my FB contacts raised the interesting point that we have BETT this week, when schools are brassic ... Personally, I think that some schools are going to have to make a major change and choose tech before teaching ... choose the most cost effective options even if it forces how T&L happens ... the tail wagging the dog!
-
It has gone from screw driver mangler to service owner and integrators
-
The combined map is only likely to be available on Wednesday. Since the move from Olympia there is still some horse trading that goes on quite late, so whilst the final changes to the map are not included in the brochure you get, they will be online. Also, the map is now there to supplement the app, not the other way around. Use the app to pinpoint the stands then mark it on your map. The intention is to eventually phase out a map, in favour of the app.
-
I used to joke that I would see 1 incident a day, when commuting from the Hampshire coast into North London. But from early this year it became true ... every single day there would be something, and it is luck if the draw if you are involved. If people are too close to your rear you are meant to increase the distance to the car in front (consider combined stopping distances in the event of a collision) but that means other cars dart into the slightly increased gap. In fact, even if you are short on the normal stopping distance between you and the car in front, you get cars squeezing in. And yet when a car that is driving dangerously is pulled over you see people take to Facebook to ask why proper criminals aren't being chased down ... People fail to realise they are in giant killing machines. I would strongly recommend that we go for a renewal system for licences ... we all have to be tested again annually. Cars should be blackboxed... so they can be checked for how far from other cars, how they were driven and the speed .... And for anyone saying that this is an infringement of liberties ... yes it is, because a large proportion of drivers cannot be trusted. People ignore speed limits. People ignore stopping distances. People ignore lane instructions (stay in lane, variable speed limits). I'm looking forward to driverless cars ... take the stupid humans out of the equation.
-
I miss breakfast at Frank's, or nipping up there for a 'meeting'. I miss the Pizza Express for the TeachEat on the Friday evening (#TMSocial tickets are now available for those who are going to TMBett ... look for the #tmsocial hashtag on twitter for more details) I don't miss the sparks who think it is ok to drop power to your stand whenever they like with no notice, I don't miss the constant worry of whether it will be our stand that has the complete internet failure, I don't miss that the place would only start getting warm late on Friday ... And I don't miss the stupid train journey (driving in on Tuesday for the week, probably leave in in Royal Victoria multi-storey), I don't miss the standing in the cold and wet waiting to meet people to give them badges to get in through the exhibitor gate, and I don't miss battling through clouds of cigarette smoke trying to get in through the exhibitor gates from those who have nipped out for a breath of alternative air!
-
That was the year of LWF as well? Recovering from Flu I had tons of stuff to get from the train station to the hotel (other side of British Library) and collapsed at the taxi rank. Got a raft of expletives because I only wanted to go round the corner ... and then we watched a heavily laden bloke go apex over cranium ... so the cabbie let me in the taxi and took the fare.
-
Fantastic to hear Russell will be there.
-
Moving .sch.uk to new Domain Registrar
GrumbleDook replied to ITGURU's topic in Internet Related/Filtering/Firewall
You could leave it where it is and just get the NS changed to whoever you want to handle DNS, such as Dyn.com? -
Russdev shared a photo again a few days ago of me, him and Dos_box on the SSAT stand, meeting Ken Walsh and Tony Parkin ... 11 years ago! The same year as HUGTB (Help Us Get To BETT - a series of Moodle evangelists who set up a pop-up stall to promote Moodle) ... and HUGTB was the inspiration for the EG stand at BETT.
-
External photographer taking / keeping photographs
GrumbleDook replied to Foresthippy's topic in e-Safety
First thing, if he is selling photos then he should be treated as a company. Well, he should be a company, to be honest! Secondly, if he is coming on site and taking photos he should have written permission to do so. That permission is effectively a contract, setting out how long images can be retained for, what the images may be used for (backed up by an entry with the ICO's data register), and limits on when permission is needed from parents if they are to be used for anything other than being sold back to the parents. If he is doing this as a 'favour' ... e.g. Money going back to the PTA, etc. then he needs to realise that he could be causing more problems than he is solving. If he is doing it as a business then he has a responsibility to ensure he has any relevant insurance, has relevant contracts / legal checks / etc. Finally, if he does not have a valid DBS then he should be drop kicked straight away, and demand all images are handed over the school, with his copy of images destroyed. The parent use is a red-herring ... that is about *their* permission to take photos for *personal* use ... this is not personal use. ICO helpline can give more advice on this, but also speak to your LA / legal support for a definitive position. Sorry to be negative over someone who may be helpful but both the school and the photographer need to be transparent about responsibilities and safeguarding. -
The general direction is to use the app.
-
Public IP Used Internally
GrumbleDook replied to Gibson335's topic in Internet Related/Filtering/Firewall
A school I was at many moons ago had public ranges in use, partly to allow for VC to be used ad-hoc and a range of other reasons. We slowly but surely moved over to private ranges and handed the bulk of the public ranges back. To use a public range belonging to someone else is shameful and asking for problems. It could be worse ... you could also be using the domain belonging to someone else too! -
BETT 2017 - travel and transport questions and alerts
GrumbleDook replied to CAM's topic in BETT 2026
More information will be available closer to the dates ... -
BETT 2017 - travel and transport questions and alerts
GrumbleDook replied to CAM's topic in BETT 2026
Will check this one out and add it to the #tips4bett hashtag I'm running at the moment. Thanks for the info
