Jump to content

djrscally

Members
  • Posts

    447
  • Joined

  • Last visited

Everything posted by djrscally

  1. Why do you think this, out of curiosity?
  2. Yeah basically. It happens far less often than your network crapping out because of whatever. If you're really paranoid you can get backup connections.
  3. x Progresso It's an entirely viable SIMS alternative, and you should definitely at least look at it when you get Demos. Reports are super powerful (as long as you have someone who knows what they're doing) and you can stick em on dashboards to build pretty much anything you want. Assessments and behaviour and so on are all really configurable, so again you can set up whatever you want to suit you. It might not save you much money though and it does have some lingering frustrations (speed, clunkiness). But then again, what MIS doesn't.
  4. haha I laughed at the first one pretty good
  5. P p P Anyone aware of a "printer pitfalls" poster available online? For example something punchy that conveys important printer messages like; don't just assume that all your stuff came out, actually check in case it ran out of paper near the end of the run and the next person to fill it up is going to get all your datums. Had a bit of a google but can't find anything. If not I'll make one I suppose
  6. Thanks; I'd be interested in seeing it. I particularly like the idea of giving advice about data protection at home
  7. Restrict access to those services to internal traffic and configure a VPN to make traffic from authorised devices count as internal. I thought policy and training might be enough, but I'm coming to the conclusion that they're not.
  8. Yeah it's a fight, which is annoying. The distinction is hard for some yeah; the problem was basically trying to avoid having to go full MDM on people's personal devices which they would be unlikely to allow. home PCs might be secure locked up at home but at some point that staff member isn't going to work for you any more, and that makes their continued access to the data unauthorized, so it has to be either "Don't store PII on your home PC" or "allow an MDM solution to be installed". I'm beginning to think an MDM solution and blocking access to things without it may be the only real answer
  9. Yeah good point, easy to forget the adults. Lanyards to wear; any photo with a Lanyard in it gets destroyed. The other example of use that the company gives is sharing the images with their funders (it's a non-profit) who might want to see them as evidence of the events. This again to me seems like processing they're doing for themselves rather than on our behalf, so I'd call them the controller there too.
  10. You are pretty much spot on I think although the ICO guidance (which I've just managed to read through; as I say sort of rushing this one!!) does say: So my interpretation there is that *we* can collect the consent for them, which is likely to be a precondition of their providing the service. I think that's a reasonably sound interpretation?
  11. Yeah marketing for the org (they couch it in nice-sounding things like "a record of the educational activity" blah blah but the long and short is they're gonna stick it on their twitter). I guess we perhaps need to do a consent form for the event specifically then.
  12. ...again. Doing this in a bit of a rush as the marketing chap is no longer with us. When we run events, the company managing the event inevitably wants to get photos of the kids for what boils down in the end to marketing purposes; they want to stick photos of the kids having fun on their social media so more school retain them to run events. Obviously we have to obtain consent for that one (even if you're of the "basically no consent needed for school photos" persuasion I can't see this one passing the bar!) but my concern is; is it necessary for the actual company to be named when gathering consent? Or can we have something along the lines of "I consent to photographs and video of my child being shared to 3rd party providers whom perform services for the school. These parties may then use the images for marketing, analysis and research purposes." Replace "my child" with "me" for ages 13+
  13. I.E. working from home on their own computer or similar. How are you all handling this? We basically tried to be as accommodating as possible and came up with this: 1. 'viewing' data on personal devices, I.E. reading emails through the web app or logging into the seating planner or MIS online is fine. 2. 'storing' data on personal devices, for example any kind of download of data including email apps or clients that will sync emails is not fine, and if you want to do that kind of thing you need to RDP into the school network. We were hoping that we could rely on policy and training to get people to work in a safe way, but I'm starting to lose faith in that solution (not least because I've found at least one 'switched on' staff member using personal IT kit actually in school on the grounds that they prefer it over their issued laptop). So; how are you all doing this? The nuclear option is to close all our sites (sharepoint, rdp gateway, outlook, Progresso etc) to external access and then configure staff laptops with a VPN so their traffic behaves as though it's internal, which should prevent basically any working on personal IT kit at all. I really don't want to do that though given it's going to irritate a lot of people and it is possible to work with a good level of security without going that far. So what's everyone else doing to solve these problems?
  14. The Dropbox thing; you really ought to have a policy forbidding that now. Certainly if someone here did that nowadays they'd be having a conversation with me and HR. Same if this is a personal iPad as opposed to one under your control. iDoceo, the impression I'm getting from the site is that the data is stored locally unless they use the iDoceo connect thingy. At minimum they're going to count as processing data uploaded to iDoceo Connect so you'll need an agreement in place defining that processing.
  15. Loads of people. Banks, Doctor's surgeries, hospitals, lawyers, councils, the police... Post for sending confidential information is still very much a thing. I mean, every item of post inherently contains information about a person in the form of their address right? It's unavoidable. What matters is whether the levels of risk associated with sending the information in the post are acceptable. You just need to be able to demonstrate that you have assessed that risk and record that fact. Scenarios for example: 1. If the risk of harm if an item of mail goes missing and the scope of the mailshot (i.e. how many people it's about) are both low, it's probably fine. This might be "your son is behaving great lately, we'd love for you to come in to an awards meeting". 2. If the risk of harm if an item of mail goes missing is high, but the scope is very low (maybe detailed behaviour or CP logs about a single student) then it might be fine if you use signed-for or recorded delivery, or a special courier. 3. If it's high-risk data about every kid, you probably need to think of a better way to send the data. If you were going to send passwords I'd be tempted to try and apply some additional protection; for example perhaps instead of sending the actual password the letter might be "Your password is your son/daughter's initials and date of birth" or something like that.
  16. Sorry if this is a dumb question; when we tried to get Inventry writeback working we discovered it only worked on their full totem thingies and not the mini card readers. You're definitely trying on the main totem rather than the mini ones?
  17. Been a while since I did this but IIR you just need 4 columns: Learner Code Date Roll Call - I.E. either "AM" or "PM" Attendance - I.E. the code so for example; Learner Code Date Roll Call Attendance 123456 18/09/2018 AM /\ 123456 18/09/2018 PM N
  18. Progresso right? Have you got a tutor time scheduled into the timetable this year? If not they don't appear in the same widget as the others. I assume you're using "Lessons not Taken" - without a timetabled Tutor period the Tutor registers will only show in the "Roll Calls not Taken" widget.
  19. Sorry, I don't use SIMS so no clue!
  20. KS2 is often missing this early in the year. Try NCA Tools; they seem to get it first
  21. Yeah I'd split that out; separate Progresso accounts for every single staff member and give them delegated access to the mailbox. I do also have a "dummy" account for joint mailboxes like that in Progresso (I.E a staff member called "Admin Office" or "ICT Support Team" or whatever) but it only exists so report subscriptions can be sent to those mailboxes - the user accounts don't have permissions for anything else.
  22. I mean; what about Progresso, Bromcom, iSAMS and the others? The 1750 student secondary I work at has been running Progresso for 5 years, and in our recent MIS review I'd have happily switched to Bromcom or iSAMS and been 100% confident that I could continue to do everything the school wants in those systems. So why do people think there's no competition for SIMS? I'm in the opposite mindset; why anyone buys SIMS is beyond me (and honestly everyone who's had the issue in this thread should be switching at the earliest oppurtunity; why would you stay with a supplier with that attitude?). Particularly given the potential for savings; Bromcom and iSAMS are like half the price of SIMS.
  23. Oh; which rules do you mean?
  24. Well quite; it was a bunch of pre-filled fields but unless I can find an electronic way of doing it we'll probably can that.
  25. Hello Sort of board appropriate. Traditionally we annually send out data collection forms to staff and students to make sure we have the right information for them. Because GDPR I've been asked to make it be an access controlled electronic thingy this year rather than the paper forms we've historically done. Basically it's just a bunch of pre-filled fields about staff, and they correct any mistakes / fill in the blanks. No problem thinks I; I'm sure O365 Forms can do that. Turns out no they can't and although I could make Adobe Forms do it I would rather find an easier alternative. Anyone have a solution for this already? Dan
×
×
  • Create New...