Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. I have had no further update to say anything has changed from my previous points on it. If anyone is seriously concerned still then drop an email to the UK Safer Internet Centre for more formal advice. They are always happy to help on things like this.
  2. Surprised no-one has talked about changing platters yet! Being called a sad, old fart that is jumping on the bandwagon because I had a 1st gen iPod Mini ... and that Apple kit was for young people. I was only just turned 30!!!
  3. Free as in kittens ... nice to have when given to a loving and caring home, but still needs feeding, taking to the vets, time spent playing with them, etc ... *NOTHING* is free!
  4. "There are always two ... the master and the apprentice"
  5. A big thank you to everyone. Just to let you know that I won, but since it so much of it was for the work through EduGeek (and most of the shortlist are users / contributors) then this should be considered the first award EduGeek has won! Well done to a fantastic and supportive community!
  6. I think we need to understand the relationship between the data controller, the data subject and the data processor. If we take the example of a solution where data from data subjects is moved to, and stored, in the cloud by a company, contracted to do so by the data controller, then there are responsibilities on all sides. Firstly the Data Subject has to trust the Data Controller to deal with their data as per the Notification, the laws of the land (mainly DPA for the sake of this example) and the contract. The Data Controller has a responsibility to ensure that the data is held in accordance to the law, processed accordingly and available if needed. The Data Processor has a responsibility (in this example case) to move, store and make available the data for the period of time for which they are a data processor. Once they are no longer a data processor they have no right to hold or process the data. They have to delete / destroy it. They do have to give the Data Controller all reasonable notice and reasonable access to the data before they do so, and they are accountable to the Data Controller to ensure that the data is destroyed correctly. All of this is usually covered by contracts between the Data Controller and any Data Processor (including the storage facility). A company who deals with the data, moves the data around, holds it in transit or otherwise is contracted to make sure that once the contract comes to an end then any data they have held or moved is deleted, then they might say the data is theirs to destroy ... it would be very poor wording but the intention might be that they have to take appropriate action to ensure they meet their contractual and legal responsibilities. It is messy ... which is why we have to be careful about saying someone is wrong to say that data can't be deleted by someone ... without a full picture (including good knowledge of any contracts, the Notification and history) then I think we need to be careful of trying to guess who is involved in this. I don't know who is (even after having a conversation directly with the OP) and I doubt many others would know (and if they did they would probably not be able to comment).
  7. Says it all really.
  8. DropBox do meet the DPA as they have signed Safe Harbor and publish which Amazon farms they use, and the rest is risk assessment on whether the local laws out your data at risk. It is a similar argument for Google Apps for Education.
  9. The only male panelist on there ... All others (inc the chair) are female ...
  10. The session is on Saturday and I will be arriving late Friday having been at the Naace conference. And Facepaint Friday wouldn't be the same without @Domino
  11. I'll be speaking on the panel about women in IT, as well as being around the stand. No facepaint this time though ...
  12. To add a clarification in here ... There are circumstances where a vendor might say we 'own' the data, when they actually mean they own the process of what you do with it. It might be that this is a 3 way agreement between parties (eg school, solutions provider, VLE) and the solutions provider gets the data from A to B. The solutions provider could be contractually obliged to ensure that only relevant data is moved, that they are responsible at the end of the arrangement (contract, project, etc) for ensuring that data is removed from the VLE (ie the provider no longer has agreement to process the data so it has to be stripped out as per DPA principle 5) and so on. All this should be written into contracts (including the Notification with the ICO), backed up with data processing agreements and involves clear communication. I am sure we can all point to when one or more of the above have been a problem. Again, to put things simply, if it is not written down, a clear process and backed up by the Notification then you don't do it!
  13. IMLS framework: advice and guidance - Schools for more information.
  14. This goes back to data protection principles, so it is not school specific and so the ICO has chapter and verse on it. If you have a look through the "your obligations" section Data Protection Act - Guidance For Organisations - ICO it covers off most of the things you are likely to need to know. IIRC the clarification about use / processing of data was around a vendor wanted to use 'live' data (including pictures) without agreement with the data owner / data subjects (ie parents / children (both 13+ and under 13) / staff / other data subjects). The Data Owner (person granting authorisation to process the data) and Data Subject (the individual the data is about) are usually the same person in most walks of life. The DPA doesn't actually mention the Data Owner though ... it mentions the subject, personal data, the Data Controller and the Data Processor. Data is held in care by someone (the Data Controller) and rather than being an assigned individual it is usually the legal body (eg the school). It has to be dealt with as specified by the Data Controller in their Notification. Within that Notification they might say they will share it with others, allow them to process it, and even allow others to do what they want with it too ... but the person who has ownership of that data is the data subject (and their legal guardian - under 13 it is covered under EU law that the minor is not the owner but the parent and 13+ it is covered as Duty of Care by the parent / guardian but open to challenge by the minor). Simple terms. The Data Controller (the school) processes the data. They control how this is done, what other parties have access and how *they* process it, put in place the safeguards that no others can access / process it, and are responsible for ensuring that the requirements of the DPA are met. The MIS provider might say that they own it (which they don't) but they are still required to meet the criteria set out in the original Notification. If the school gives them access and the MIS provider then use it for marketing / training, and this was not one of the requirements then they are complicit in the school breaching the DPA. The other conversations around the issues were not on public forums so I can't dig out an archive or share, but I will see what FoI stuff was around from the questions if you need any more. The ICO is your friend in this though ... if you have an issue and you believe that a vendor is being difficult, or plain wrong in their approach, then the ICO helpline is a wonderful resource. Failing that, if you know the vendor has a copy of the data then you draft a template letter to all your parents so they can make DP requests for what data is held on them, how it is used and follow up with instructions to delete / remove. If the vendor fails to do this then you report each failure to the ICO and they risk being fined for each, individual failure.
  15. The question has come up a number of times before and very few people seemed to have an answer. Anyone using LA / RBC provided services tended to say that little was available, and most others relied on backups if they needed to get something back. To some extent it is actually easier to have policies in place which state what types of content needs to be retained and these are done as .eml in given folders, in the same way you would save a word document.
  16. Also remember that under FoI any electronic communications / documents you have may be requested. If you are using an archiving solution it should be one where it is easy enough for you to be able to gain access to the relevant emails in a timely fashion. A number of schools have had their wrists slapped by the ICO for failing to respond in time to FoI requests and one excuse used by some has been the time it has taken to find the information (including emails).
  17. Congrats to you all ... you do all know it's not too late to politely decline and you will escape years of servitude and supplying @ZeroHour with quality coffee.
  18. An apprentice may be low-paid in money terms, but the other part of how they are paid is in training, access to expertise, mentoring and general help and support. Sometimes, that bit is hard to quantify and so much more important. That is why internships are sought after in some firm.
  19. Seems fine for me. Good luck to those who apply.
  20. *Definitely* manually set it on key hardware ... I had to deal with this for over 40 schools when they had new Cisco routers put in ... let's just say that there was a lot of frustration out there because of it.
  21. It'll be both you and the school (both the Head and the School as a body) will be in trouble should a data breach occur ... Likely areas where a breach could occur. The phone is not secured by a passphrase and others can access it with ease. The phone is secured but the passphrase is known by several others. The phone is secured but is unlocked by the user, then handed over to someone else to use (eg family member to make phone calls / play games / send emails using another account linked to the phone) Email is sent out using the wrong account (eg personal account on the phone rather than the work account) The phone has additional services enabled (eg bluetooth) which are not secured and allow for the remote connection and browsing of files saved from attachments. The phone is set to automatically sync saved files to a machine not allocated / secured via work. These are some of the areas ... I'm sure more scenarios could be covered if needed. A lot of the above can be dealt with via organisational policy rather than technical solutions ... but they can be covered. Manage risk ... don't avoid it!
  22. Other than the technical bit of this (being answered by others) have you included anything in your AUP about this. A few things for you to think about ... It is quite likely that the teacher will receive emails about the behaviour of students, details about them such as their date of birth, or even attachments with more details in ... all stuff which had previously only been available once you have authenticated via a web page or authenticated on a desktop / laptop and run a mail client. 1 - What policy do you have in place to insist that a complex passphrase is used to protect the device? 2 - Does the device have a setting on it so that after repeated (failed) attempts to log into the device it will wipe itself? 3 - What additional advice and training have you given staff around who can also use the device once this has been set up? 4 - Have you changed your leavers process to take into account ensuring that the account is removed from the device when a member of staff leaves? None of the above is a reason to stop allowing access to emails on mobile devices, but things that should be covered off ... and applies across all devices!
  23. The procedure was to work through your LA, but theoretically it is still possible ... give emPSN a shout and ask.
  24. There are a couple of ways of approaching this, some educational, some behavioural and some common sense. Stretching more able children is a problem in many schools, across all subjects. In English you get students bored with the set text, in PE you get young athletes bored of having a kick about with a football and in ICT you get folk bored with a basic curriculum. None of these is a valid excuse for breaking any law (Computer Misuse Act) but schools need to spot the problem early and address it. The answer will vary between schools and between students. Here are a few things that could be covered though. The fact that some of the work is boring it doesn't mean that isn't needed. Whilst having a kick about in PE can be a waste of time, it might be that the lessons is about demonstrating the results of skill drills ... it just isn't communicated very well, or the student doesn't want to listen. Likewise in ICT it might be boring to demonstrate correct use of presentation software based on previous lessons, but until they show they can do it then how can they justify moving on to the next level. It could be that a condensed curriculum and independent learning will help. In each ICT lesson they have half the time to do the same work as the other students, and once they have completed the work they can crack on with special projects. Ideally it would be related to what they are already doing. If they are working on presentation software then this could be coding in HTML5, developing a back-end data base to store information which will be displayed (eg a digital signage solution) and so on. These are extension tasks. The student needs help in understanding that pretty much all work out there will involve some mind-numbingly boring stuff at some point. Being able to deal with it, focus and get the job done is a valued skill. Musicians will play scales, athletes will train and do skill drills, copywriters will make us sample customers ... coding is often about reuse of code, or trying to find different ways of getting code to do the same thing. The other problem is that the teacher(s) involved also need to be talked with to see if this is part of an isolated issue or a wider problem with the school's approach to G&T. Even in the same department, using the same resources, you can find one teaching who is engaging and keeps all students working hard and another whose delivery leaves a lot to be desired. ICT does not have to be boring (in spite of some groups saying it all is) ... so the subject and matter is not the issue. The approach and the individuals (teachers and students) are usually where the issue lies. Groups such as Computing@School are good to get advice from.
  25. I use my main twitter account for professional and personal stuff, but like most things I do I try to keep my personal life up to the same professional standard anyway. When you are friends with many people you know professionally it is hard, at times, to separate when you are having a personal conversation and a professional one ... they tend to merge. I have recently done some training with the local police around this, as part of their CPD about balancing personal and professional life. I think some of this depends on the job you do and you have to deal with it accordingly, but inappropriate use can have a major impact when you try to get other work and can even affect whether the company you work for gets work as well ... you don't just lower your reputation but that of your employer as well. I do have a private account on twitter and I am fairly choosey about who I let see that ... I do cull on there every so often but that is mainly where I might mention if I am doing things out of the area, and there is almost certainly nothing work related on there. I have 2 other feeds ... one that I have previously used when attending conferences ... as I had my tweets being fed into an archive engine and I was using it as a form of note taking ... fun, but a bit of a faff to get going. The other one is where I tend to follow businesses / tweeple who only broadcast. I dip into it every so often just to see what is going on, but if you get moved onto that account you know that the person / account is a broadcaster, doesn't interact or respond to tweets back or is just not worth the precious space on my regular followers list.
×
×
  • Create New...