-
Posts
12,876 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by GrumbleDook
-
Staff Subject Access Request - Deleted mails?
GrumbleDook replied to mikes's topic in Data Protection & Information Handling
Re-read them. The clauses give cause and exception, and explain where it fits within other legislation ... that actually have equal or higher principles of protection. And even where exemptions apply, the ring-fencing also provides additional protections and does not completely eliminate all Rights. No matter what, it has to be logged and justified. -
Staff Subject Access Request - Deleted mails?
GrumbleDook replied to mikes's topic in Data Protection & Information Handling
And this is where your retention schedule is key. If the data needs to be kept, for whatever prupose you have, then it has to be kept. If the data is being purged by people in contradiction to the retention schedule, then that is a complaint in itself and can come back to bit the organisation and the managers deleting things. Remember that emails are a 2-way thing and you will often find copies of them, even in hard copy, because person X thinks that if they delete it, then it is gone ... not realising that person Y also has a copy. And no ... nothing 'trumps' data protection, you will usually find that data protection actually supports what is needed. -
Staff Subject Access Request - Deleted mails?
GrumbleDook replied to mikes's topic in Data Protection & Information Handling
Also remember that the email is *not* the data. If the data has been put into the relevant system (e.g. MIS, assessment record, etc.) then the data is stil there. -
Staff Subject Access Request - Deleted mails?
GrumbleDook replied to mikes's topic in Data Protection & Information Handling
Because deleting it after receiving a SAR is illegal. -
If you put down time limited qualifications (PRINCE2, etc.) put in the years in which you were covered.
-
Bett 2022 - enter our biggest competition EVER!
GrumbleDook replied to VeryPC's topic in Our Advertisers
I've had a rethink about my reason. I was wondering about whether this was the machine that would start The Matrix ... then I realised that it wasn't. It is in fact Deep Thought ... and with it, I shall discover the answer to Life, the Universe and Everything! -
It will be good to see you. Pop over to SK51 for a catch up?
-
Bett 2022 - enter our biggest competition EVER!
GrumbleDook replied to VeryPC's topic in Our Advertisers
Hmm ... Another monitor or two and I'd set it up with Scrivener so I can crack on with writing my book. -
They can contractually set limits on what resellers do. Resellers cannot collude to fix prices, but it is possible for a fixed price to come from the original provider to the reseller. This is why some resellers use other 'services' to add additional markup.
-
This has been an interesting thread and is obviously more about the roles and responsibilities than any cost/benefit analysis. Looked at this 15 years ago now and this is the basic proposal that was in place. Put all monitors on their own electrical feed that can be centrally isolated in a classroom. Depending on the use of the room, the last person in turns off this circuit so that no monitors are left on stand-by. The desktops are on a separate feed and have automated shut-down / start-up in place. This would also allow for scheduling of routine jobs needed to cover the security and protection of the network. This was part of a patch management and AV management program. Without the update or the AV scans, it would mean the system would fail external security audits, or leave the school open to serious cyber-attacks (internal and external) The separate feeds would have energy monitoring on them, so that costs could be tracked and changes to any scheduled work could be planned. Finally, an inital time and motion study would run to allow a review accuracy of the cost/benefit analysis. The electricians put a meter on the ring for one of the suites and over a few weeks we tried to replicate the model above. The electricians also helped with the risk assessment for the fire risk too. The fire risk was low (lowered further by changing the fuses in the leads to monitors and not using Y-leads, ensuring that the PAT testing was done correctly and also involving visual checks once a term by IT staff) The costs did not justify the additional feeds being retro-fitted to manage a circuit just for monitors. The costs did not justify the additional feeds being put in for any new-builds/room conversions. Similar was looked at as an option on PFI builds in the area too ... and thrown out. If there is a concern about cost, then solving it using retro-fitting solutions, buying kit or the labour cost to do things manually ... it does not give any cost benefit. If the concern is about fire, then it is risk assessed and managed. If this is about power and control, then it will only be resolved by the school leadership. You may need wait for them to do something stupid that damages things or leaves the school open to an issue. You just have to raise the concern to the appropriate level and wait for the brown stuff to hit the rotating thing.
-
Going to an ecommerce site will have cookies hitting you as soon as you arrive (you are a user until you make a purchase - then you are a customer). They are part of the function of the site, but the extent depends on how far in you are. You are informed of this in the privacy notice *and* cookie controls. If you are not happy you can leave the site and scrub the cookie. This is for the ecommerce section of a site though. It may be that other sections of the site do not need those levels of cookies. Some might be about language preference. The site may pick up the default language of your browser, but offer you options. You choose UK instead of US, so they drop a cookie as a result. You go to a .com page but the Geolocation of the IP address suggests UK, they offer you an option, then drop a cookie based on that. The problem is that a number of sites and services drop cookies to establish 'defaults' when they are not needed. These 'defaults' *can* (but not always) affect other services you go to as a result (assists?). The discussion about whether these are essential or assists is part of the argument on these cases. The fact that some cookies can also be used for tracking and fingerprinting is that crossover into GDPR. There are lawyers who specialise and get paid serious money to trawl through case law and legislation on this. There are two main gripes about it all. Companies are not transparent (sticking it up there but in legalese does *not* make it transparent) and the use of dark patterns, or other means, to make it difficult for the end-user to control anything getting dropped on their machines. Anything involving AdTech will hit these. It is down to companies to manage it better. But the bulk of cookie issues are still going to be PECR-based rather than GDPR (thought it may easily involve the two).
-
Even with UK data centres, whilst the company processing your data remains a US company then there are law enforcement grabs of data that can be made, so that international transfers are still a risk. To be honest, there are already mechanisms that international law enforcement agencies can make requests via the countries within which the data is processed, but that means it *has* to follow the laws of that land, not the US. That is the problem. It makes life easier for US firms to have the data in the US as it saves grief with LEAs. For many of us in schools, or working with schools, the risks of law enforcement agencies grabbing children's data is going to be small, but where the services are for social media, banking, etc. ... well there are real risks associated with it.
-
Contract between Controller and Processor
GrumbleDook replied to markberry's topic in Data Protection & Information Handling
A few things for all reading this ... you will get a very mixed response from many EdTech vendors when you approach them. As mentioned previously, the school (in general) will be the Data Controller and the vendor will be the Data Processor. If they have someone doing something for them (but still within the contract for you), then these will be sub-processors. The term 'third party', whilst correct in some aspects of contract law, is completely wrong within Data Protection. A third party is a separate Data Controller and if you hand over data to them, they can do with it as they deem fit. If you see the term third party in any T&Cs, Data Processing Agreement or Contract, get them to clarify if they mean sub-processors or do they really mean they will hand your data over to some additional company to do with as they want. And yes, T&Cs can for the bulk of your contract or agreement of service. Realistically though, you will be looking for someone who can give you a clear picture on what is going on and not a bunch of legalese. Have a look at the following for what we are moving to over at NetSupport https://classroom.cloud/data-processing-agreement/ is an example of a plain English Data Processing Agreement. https://classroom.cloud/wp-content/uploads/2021/11/classroom.cloud-Security-Request-for-Information.pdf is a standard response for details on Information Security. https://classroom.cloud/privacy-by-design/ even helps you understand how to take a privacy-first approach when you are setting up and running software. Feel free to share these examples with other vendors. If anyone is interested in training around GDPR I can recommend you to some good folk. -
If you are looking at Records Management advice I would heartily recommend membership of IRMS (https://www.irms.org.uk), as there is a lot of discussion and guidance on using M365 for management of documents, including a working group with Microsoft to look at this for the public sector. There are also discussions about using Google Workspace as well, such as the brilliant presentation at the IRMS conference earlier in the year about things to be careful of with Google Workspace.
-
Senso.cloud alternatives - Had enough
GrumbleDook replied to TheRobins's topic in Network and Classroom Management
Drop the team a line and I’ll sort out a demo for you. -
Senso.cloud alternatives - Had enough
GrumbleDook replied to TheRobins's topic in Network and Classroom Management
NetSupport covers the range of platforms over a range of different products, depending on what you need. If anyone wants a run through about it, including advice on risk assessments for safeguarding and monitoring, just drop me a line or request a session through out online chat on https://www.NetSupportsoftware.com -
New Edugeek Users - Introduce yourself here :)
GrumbleDook replied to tarquel's topic in General Chat
Good to see you Chris.- 4,289 replies
-
- assistance
- background
-
(and 2 more)
Tagged with:
-
GDPR - Students Doctors details
GrumbleDook replied to markberry's topic in Data Protection & Information Handling
So you have a purpose, a lawful basis, data retention and minimisation in place. It's inline with data protection legislation and also with KCSiE too. Just make sure any contact/data sharing gets logged. -
GDPR - Students Doctors details
GrumbleDook replied to markberry's topic in Data Protection & Information Handling
What??!!!! You have a conflict of interest here. Do you have anyone providing external advice/support? If there is no one else in-house to do it then get an external DPO and just be the internal DP lead. Protect yourself. Back to the question in hand. Yes, it is historic and does need reconsidering. If nothing else, the needs may have changes. The information is generally held from a safeguarding well-being perspective, allowing the school to send information to the nominative primary health care provider should they need to be informed (the is controller to controller data sharing). Most of the time this is not needed due to inter-agency cooperation under such circumstances. If there is inter-agency work going on (or possibly going on) then you might consider moving to only collecting at this point. The child’s NHS number is a significantly important piece of personal data, and not really something for a school to use. It may be that collecting the GP details is less invasive when you consider what it is needed for. Also consider what the method of getting the information might be once you actually need to use it. I would speak with your DSL and SENDCO about it, and even give the local MASH a call for advice. Also read any guidance you may have had from your LADO. -
Hmm ... I wonder what will happen with any code/data/botnets that they had running?
-
Staff Personal Mobiles using school apps
GrumbleDook replied to tmleafs's topic in How do you do....it?
Except that this is against the Data Protection Principles. You don't *have* to wipe everything that is not related to your organisation. You have no lawful basis for doing anything with data that is not yours. There are way too many scenarios to go into here, but wiping everything is just wrong. As a general message to all on this thread, if you are looking at management of personal devices / BYOD, please make sure the school is covering your backside and doing a DPIA on it. You need to make sure that anything you do to mitigate/lower the risks are recorded and signed off. Then also make sure that it is unbelievably clear to staff what happens during a selective wipe process. Also remind staff about backing up personal devices, how they can remote wipe it themselves, etc. -
I think certain people melt in daylight don't they? @ZeroHour ?
-
If they hold a record of her as a qualified teacher, who has previously worked at the school (safeguarding, pension, employment history and other reasons), then there could be a Public Interest arguement for the use of the data. It all depends on what may have been in any contract of employment. It's one of those things that is never cut and dried. We also need to remember how desperate some schools are, but I am sure that if she contacted the school to say "thanks, but no thanks ... and please only contact me for strictly required reasons in future", and I am sure the school will oblige. It can be considered the use of the Right to Object.
