Jump to content

djrscally

Members
  • Posts

    447
  • Joined

  • Last visited

Everything posted by djrscally

  1. Are you running a report already that you want to filter? Which report is it?
  2. Naw, the DP2018 bill makes it crystal clear that that's the appropriate provision. If I was the EU I might have kicked up some stink about the UK implementation of that one, but I doubt that'll happen between May and March.
  3. God I hate legalese. It's coming back to me. The DP 2018 bill does actually make it clear. Basically Schedule 1 Part 2 of that bill lays out the conditions that the government thinks meet the substantial public interest test, and the second one is "processing is necessary in order to comply with a legal obligation" (paraphrased). Does kind of seem like a back-handed way of making legal obligation also apply to special categories, but that's what the bill says.
  4. Oh sorry my bad, I thought I'd checked that but looked up the 'normal' personal data list! I think we settled on relying on (g) substantial public interest for all the things you listed, again excepting biometrics which we don't collect. EDIT: I wonder if the new Data Protection bill makes this a bit clearer, as reporting ethnicity and so on IS a legal obligation. I shall have a looksee...
  5. You're legally obliged to report Ethnicity etc on the census returns, so that's your basis for processing those. You don't have to report medical information but you have a legal duty of care to the children in your school, which you can only effectively fulfill if you collect information about their medical needs. Tl;dr your legal basis is fulfilment of a legal obligation. Almost nothing a school does will require consent as a basis for processing. Edit; almost missed the biometric stuff. That one might actually be one of the exceptions! I'm not sure myself there, as we don't use it so I haven't thought about it.
  6. In your position I'd just reply to Wonde and tell them you have no interest in using their service and that Xporter is working fine for you. Unless Softlink have indicated to you that they'll discontinue their support for Xporter in the future. I suppose they prove they're secure by promising faithfully in their terms of service and so on; that's not really any different from anyone else though.
  7. Yeah that is definitely how it will go. Fortunately most of the reputable ones are putting out a lot of information already. Google's is quite comprehensive, including detailing their security stuff : https://www.google.com/cloud/security/gdpr/
  8. If it's cloud hosted I'd be looking to contact Bromcom's support and get them to sort it; make sure your contract doesn't say something daft like they'll host you on Express or something though.
  9. Hmm yeah; https://support.microbit.org/support/solutions/articles/19000013695-how-do-i-use-micro-bit-with-bitlocker- That's annoying. I wonder if the other micro boards have the same problem. I'm pretty sure you can flash arduinos or the cheaper clones using GPIO but that'd be super irritating.
  10. I wouldn't be happy with that set either, but I acknowledge myself to be pretty tinfoil at times. @Mic_Impero that thingy still exists yeah - we used to use it quite a lot. It's basically like having an Excel sheet and mail merging from that, except you're hitting Progresso directly so it's always live.
  11. To be honest I've never tried exporting to Word; I basically only ever export stuff to PDF. There are differences between how SSRS renders Word and PDF exports for some reason, so I just picked one and stuck to that. So, it doesn't surprise me if it works poorly in word. If they want to do that, I'd just knock up a list report and get them to mail merge in word. 2016 has the Avery L7159 Labels included as a default format for labels.
  12. Yes! See attached. Errr I can't attach it, why not... It won't let me attach a .rdl file for whatever reason, so here's the next best thing: https://nas.djrscally.me.uk/index.php/s/RHSHo7HfRTCiDZn/download
  13. He's trying to gather an image of how this topic (which is clearly of interest to him) is treated across the country. edit: or do you mean why not just ask a randomly selected sub-set? That would have been a better option probably.
  14. Yeah you're right, I missed that it was a shared device!
  15. I'd say "not yet" for that one but basically 100% chance that it will be when they leave. The school's internet connection is down so the data team takes their laptops and goes to McDonalds to use their free public wifi to work on the cloud MIS. Is that a data breach? The Performing Arts teacher records their students dance recital on her iPad and sends it to the website manager to stick on the schools website (with the permission of the students/their parents). The teacher then deletes the video from their iPad, is that a data breach?
  16. When you're a public authority, to a certain extent yes it does. People have a right to request information in your emails under the FoI unless one of the exemptions applies (trawl WDTK and you'll see plenty of released emails). If you used your email for personal things then that's obviously exempt, but having read an FoI request is obviously not. As I say, he could literally log another FoI asking if you'd read the first one - your receipt of that request is a matter of public record, so what's the problem?
  17. Even if we ignore the whole load of way, way, WAY bigger fish that are carrying out this monitoring on your personal account...is it really a problem for someone to track if an email sent to a public authority's email account was opened. He could literally send a follow up FoI saying "did you read my previous email" and you would be obliged to answer.
  18. Let's not get carried away here. He doesn't have to protect the information identifying which schools didn't respond; failure to respond to an FOI (or refusal to respond to one) is a matter of public record - as it should be. He's acting as a private individual, he's no more responsibility here than does someone hosting a private blog. Previous posters saying people need to chill out about this are absolutely right.
  19. Not certain. I'm pretty sure the "Not for Profit" thingy means private clubs and that schools will have to pay.
  20. Every single marketing email that has ever been sent to you attempts to do this, without you even noticing, by including content like an image of a single white pixel that is loads a file (linked to your email address, I.E. named [email protected]) from a server under their control. It's a well established practice to enable them to target their emails at people who actually read them. It's perfectly legal. Ref: https://en.wikipedia.org/wiki/Web_beacon EDIT: Besides, in this case he's just checking the school has responded since he said he's just getting the generic school email address. Given the volume he has to go through, pretty reasonable.
  21. They can only refuse the latter request though.
  22. Same way you'd prove you responded to a physical mail request; you show them your FOI log. I guess you could screenshot it if you were super paranoid, but I'd consider that unnecessary. Same applies to proving what data you sent when you respond via snail mail. Hardly seems likely anyway; if someone was gonna fudge the data regardless of the responses I doubt they'd bother making the requests in the first place; recent news has shown nobody bothers fact checking anyway.
×
×
  • Create New...