-
Posts
12,876 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by GrumbleDook
-
Senso.cloud alternatives - Had enough
GrumbleDook replied to TheRobins's topic in Network and Classroom Management
Happy to have a chat with you on alternatives. Drop me a PM and I'll sort one of the team having a chat. -
Spamming FOI Requests
GrumbleDook replied to garbage46's topic in Data Protection & Information Handling
Really good points, and it is worth saying that a senior leadership decision not to patch increases other risks. Cyber-crime and cyber security are noted in Keeping Children Safe in Education. This approach could be challenged (and should be) and it could even result in some of the DPIAs of the school running high risks. And if that is the case, they should be talking with ICO about those DPIAs. That is before we get to Cyber Essentials. There is a balance to be had between declaring where public money is being spent and protection of the school, the children, the staff, its data and its assets. I get that, but I also worry about uninformed decisions by senior leaders in schools. -
Spamming FOI Requests
GrumbleDook replied to garbage46's topic in Data Protection & Information Handling
@localzuk and @paulkerton This has been an interesting dialogue between you both (with some good interjections from others) and, in my typical fence-sitting fashion, I can honestly say that I can see both positions and feel your frustrations. The problem with the use of FOIA is that there is scope for arguing about lots of things, and many will make the most of small things to justify why they work in a particular way. But we all know that anyway. Yes, there is annoying, but it is a reasonable request. It is not nasty, aimed at wasting your time or trying to trick you into say/doing/sharing something. It is not vexatious. But that is not to say that some exemptions might not wholly or partially be relevant. These exemptions need to be looked at very carefully though, and with the support of experienced advice. The requestor knows this and so has worded the request carefully so there is little chance of it being thrown away. Be very careful about refusing requests. If you do, then make sure they are still logged and all decisions are noted and justified. Be professional and, most importantly, treat each request on its own merits. -
Spamming FOI Requests
GrumbleDook replied to garbage46's topic in Data Protection & Information Handling
At the risk of sounding like a grumpy old git, it is not spamming. He is using a legitimate method of identifying what printers/copiers/services a school has. Yes, it will then be used for business, but because it is via what do they know, then all their competitors have the same info. -
GDPR, consent, ISS and age under 13
GrumbleDook replied to Ditto's topic in Data Protection & Information Handling
I would strongly recommend reading the original report from the Digital Futures Commission, looking at the use of data within education - https://digitalfuturescommission.org.uk/wp-content/uploads/2021/06/Governance-of-data-for-children-learning-Final.pdf, reading with an open mind and remembering it is just a starting point. There was a follow up roundtable, and the report from this is a significant improvement - https://digitalfuturescommission.org.uk/wp-content/uploads/2021/11/Roundtable-report-25112-final.pdf Also have a look at the FAQs for schools and EdTech providers around the Age Appropriate Design Code (aka the Children's Code) - https://ico.org.uk/for-organisations/childrens-code-hub/additional-resources/faqs-for-education-technologies-edtech-and-schools/ The ICO also has other information about children and their rights - https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/children-and-the-uk-gdpr/what-rights-do-children-have/ In short, Consent is not a common lawful basis within schools except for some specific areas, often governed by other legislation (e.g. Protection of Freedoms Act 2012 for biometrics). Where Consent is required as covered purely under GDPR (and not other legislation) then the above link from ICO about rights of the child also covers how it applies to parental responsibility. https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/consent/what-is-valid-consent/#what9 also gives details on what is valid consent where children are concerned. We should also not confuse Consent (article 6 lawful basis) and Explicit Consent (article 9 lawful basis for processing special category data), even though the two do tend to go hand in hand. In short, only use Consent where it is the most appropriate lawful basis. If you do need it, then look at where parental responsibility is expected and where a child's competence is to be considered. Also remember that rights are not absolute. Also consider when you are being asked to gather consent to use particular solutions because a vendor says you must ... you (the school as the Data Controller) decide the lawful basis, so is it the right one for you? If you are looking specifically for what an ISS is? https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/children-and-the-uk-gdpr/what-are-the-rules-about-an-iss-and-consent/#a3 gives a details definition. If what is being offered by the school is not part of the core aspect of the school (delivering the curriculum, pastoral and well-being, or for the management and operation of the school ... basically, look at what comes under OFSTED framework) then consider whether Legitimate Interest is relevant (and complete a Legitimate Interest Assessment to identify the balance between the person's rights and the organisation's needs/delivery). Not a complete answer for you, as the school needs to decide that with the support of your DPO. Hopefully it gives you a significant amount of helpful information though. -
Hi Ben It has been interesting to see how the project has developed and I wish you the best with it.
-
Moving away from LGFL Web filtering/Firewall
GrumbleDook replied to xicor's topic in London Grid for Learning (LGfL)
This was the model we operated whilst on embc around 15 years ago. I got grief about it to start with, but then it became an established model ... to the joy of a lot of other schools in the area (and to the joy of a number of filter/firewall providers too ... mentioning no names!) and also adopt more of a monitoring approach rather than explicitly blocking things. It has downsides though. When something goes wrong (and it will) it takes more time and effort to get sorted. You may have to have a fall back option of going back to the 'default config' to get something fixed and then turn it back to how you want again. You can also lose the flexibility of some resources that can come with using an RBC's filters. If you are that annoyed, tell LGfL and ask them for a more flexible option. -
NetSupport DNA - Script or Command to Uninstall
GrumbleDook replied to Fazza's topic in Enterprise Software
NirSoft is still going? Wow. Must go over and see what tools are there. A shame to see you go @Fazza. Give us a shout if you want to come back. -
I love marketing and sales spin. "Lack of change means stagnant products", "Refusal to change shows poorunderstanding of users", "Limited vision slows down progress in schools". "Stability of functionality", "rigorous change process, ensuring improving functionality meets customer needs and requests", "Established features and functionality that have a strong track record on supporting school improvement". Two different groups talking about the same thing. This is an argument about contract length and any risk included within that.
-
3rd parties have a very specific definition under GDPR. They are a separate Data Controller, using the data for their own purposes. This should not be confused with a Data Processor, who processes data on your behalf, for your purposes and under your instructions. They should also not be confused with sub-processors, who are following instructions from your Data Processors, instructions that actually come from those you have issued. Unfortunately, 3rd parties is also a term used in contracts and property law. Yeah … it gets murky. This is why I spend a lot of time explaining things to EdTech providers about how to phrase things that go into DPAs.
-
Looking back at the question, there would be no DPA for a locally installed build, but there may be a DPA for a support and training programme from whoever you get you MIS support from. That all depends on who is doing what and with what data. From the options of cloud and hosted, we need to separate out if we are talking about ‘hosted’ or ‘cloud’. Hosted - meaning you have it hosted somewhere u see your control … i.e. a data centre somewhere that you run the direct contract for them as hosting provider (Azure, AWS, etc). In this case you have a software/services contract with the MIS vendor and a DPA with the hosting provider (dependant on the caveat about training/support). Cloud - meaning the MISaaS option, where the cloud hosting is part of the arrangement with the MIS vendor. In this case, the DPA is with the MIS vendor and they run the contract and agreements with the hosting provider as *their* sub-processor. The DPIA will be on the same basis, as it is for the same purpose, but the difference technologies may require different implementations and have different risks associated with them. I do have all the resources from the disbanded Education Data Matters site, which include some template DPIAs, and I’ll try to get them up as soon as I can.
-
The material change in contract is one relevant to contract law, not to data protection law. If there was no initial complaint about the software provider no longer being Capita, they are on shaky ground to claim DP law as the issue. There is a change of risk. But I’ll feed my other comments into the other thread
-
The issue is that for most schools, ESS is not a processor but a supplier of software that allows *the school* to process data. They could be deemed not to provide you software that allows you to meet your requirements under UK GDRP and DPA2018, but unless a full review of how your SIMS has been configured has been done, then that is a brave thing for a DPO to say. The purpose for you processing it has not changed, the technology has not changed, you are just arguing about the contract and any limitations it includes ... and that is a risk thing for the school to judge (hence the DPIA). It might be that this is a short-hand way of saying a whole bunch of things about risk, future plans of the school(s), guidance from DfE, and so on ... but saying they don't meet the obligations of a compliant Processor ... feel free to pass on my details to them or to say hello at the IRMS conference tomorrow.
-
I know you have said that this is very early on in the conversation, and I would heartily recommend you keep in mind every so far, as well as continuing to talk to schools that have done similar. If any supplier offers you a chance to talk to another school as a reference, then take it ... even talking to a reference school to a supplier can give you a lot of insight of what went well and what didn't. Ages ago I used to be a reference for Dell and for the leasing firm ... and we were fairly open about the issues we had to learn to manage. The other thing you need to do is really decide what you need and see what is the best fit. Are you managing devices as in putting software on them, putting in place configurations, applying filters, setting limits on usage? Is this location specific and/or time specific (inc. certain days/dates)? What protections will be in place should remote teaching/learning start up again? What sort of management do you want to do? Lesson based? All the time? Blocking things or monitoring things? Once you have a full picture of what you would like then you can look at the options, including any compromises or where different solutions can provide slightly different approaches. Then you *have* to do your risk assessment. I say you ... but I mean the project team working on this, drawingin in whichever stakeholders are needed. Work with your DPO on this to make sure it happens. And, as always, if you want a direct chat, then let me know. Yes, we do have solutions that could help, but I'm more interested in helping you work out the right approach.
-
It can be legal ... but it can also be morally dubious and an extremely expensive nightmare. It all depends on what we mean by MDM and device management. It is possible to have tools available but to restrict when they can access and do things. This is Privacy by Design and by Default (PbD2), and should be a significant part of any DPIA/Risk Assessment that is done. I'm presently going through all our tools and writing up about PbD2, and the first example can be found here - https://classroom.cloud/privacy-by-design/
-
New Edugeek Users - Introduce yourself here :)
GrumbleDook replied to tarquel's topic in General Chat
Wow ... you are an Aircraft Launch Control Officer? Respect!- 4,289 replies
-
- 1
-
-
- assistance
- background
-
(and 2 more)
Tagged with:
-
I'll be there for the 3 days. Looking forward to being on a stand again (never thought I would say that) and catching up with everyone.
-
The following setsOut what is needed with respect to record keeping around Consent. https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/consent/ for more information. Keeping an actual record of the consent being given is a simple way to manage this, As it also supports the accuracy side of data protection. You do need to be carful of ROT though.
-
Email retention from the ground up
GrumbleDook replied to Jobos's topic in Data Protection & Information Handling
Email retention ... a tricky thing for some but simple for others. Have a look at a few cardinal rules 1 - Do you need to keep the email or just something within the email? 2 - Do you have a different system for holding things like HR, safeguarding, behaviour data? 3 - Do you have the practice of deleting the email once the information is in that other system? 4 - Are there other things which need archiving (emails from exam boards, discussion groups for professional development)? Can these be dropped into particular folders? 5 - Once all this is done, then consider ROT - redundant, obselete, trivial. Can a ROT folder be created with a short life-span? 6 - Until you have a different way of storing things and people are trained on it, accept that your email will be a sorage system! -
Age for consent is to do with Internet Society Services, so that’s why I say it wouldn’t be relevant within schools.
