djrscally
Members-
Posts
447 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by djrscally
-
Surely selling / donating something isn't the same as discarding it, or ICT suppliers would count as discarding stuff whenever someone bought it from them.
-
I think it'd be fine, you can't access the actual data sent to / from the hotspots because those will be encrypted so all you can collect is the info about the hotspot; even if that constitutes PII it's obviously justifiable to monitor hotspots in your building for network maintenance and security. I have no idea why you'd bother though
-
Yeah I was more just meaning to express surprise that systems were built to be able to do it; I'm sure if they have the capability then I'm wrong about the law. But yeah, cool: Suppressing rogue APs
-
What system do you use to do this? I am also under the perhaps misguided impression that it would be illegal to generate noise to block an AP you don't own.
-
Curveball, I bet at least 50% of the kids have a smartphone doing this anyway. Certainly mine does (I.E. voice activated google assistant).
-
Many many thanks for the offer of help; really appreciated. The IT manager managed to figure out where we were going wrong though and we got it working - just a config setting on the ADFS server that was wrong in the end.
-
Is anybody using ADFS 2016 for Single Sign On to Progresso? If so, please help! We're struggling to get it working and would ideally like to have it running before the staff all leave so we can check it works rather than find out it doesn't in September. The guide advanced sent us is for the 2013 version so it's not quite the same, and we basically just want to check that the configuration is correct (as it's not working and we're not sure which end the problem lies) Cheers Dan
-
That's clever.
-
When it thinks it hears the activation phrase
-
Awesome, thank you.
-
So this is really the only point of contention. The method of withholding access in the MIS doesn't necessarily work with Progresso, and I'm of the opinion that convenience to me doesn't justify granting access to Groupcall to see data like salaries and health information that may or may not in the future be passed on by XoD to some 3rd party who's services we buy. I recognize however that a) lots of people probably disagree with me and think being able to just set it up and forget about it is totally worth it and b) the necessity for the guidance you issue to be appropriate to school staff with a wide range of technical capabilities makes this a very difficult balance to draw. I also acknowledge that: But it doesn't make me feel much better about granting access
-
I would err with them for now (I.E. don't send anything to the non-resident parent till you've made a firm decision either way); a delayed copy of an educational record is less of a problem to my mind than sending information that there really is a good reason to withhold. In your position, I would be asking the data protection team / legal team for a detailed explanation of the reasoning behind their decision and explain why I don't think they're right, since ultimately I think it's you who is legally responsible here rather than them it's important you understand and agree with the decision. Talk it through and it'll probably get cleared up. It might just be that they have some information that clarifies it that they assume you are aware of but haven't mentioned directly.
-
Yeah ok; I'm responding perhaps too narrowly in saying outright no - that answer is based on my reading of the situation that both School and Council are basing their decision to cut the parent off on the fact that the Student's age is >= 13 and the belief that the GDPR allows 13 year olds to dictate who can see their data: That interpretation of the law is definitely wrong. There may be some other reasons (safeguarding naturally, but maybe some others) that do justify blocking the parent.
-
Perhaps attitude is a poor choice of word; I don't mean to imply anything especially heinous. On the contrary I have a positive opinion overall of your company (particularly Support) and software. The 'attitude' part is meant as a response to the 'sucking up the SIMS data' complaint from ovek; I've had the same 'just grant access to everything' from you guys as Wonde gives, even though the applications we have linked in to Xporter/whatever Wonde call their software don't use some of those data items. I don't like that approach; although it's by no means just you two that do it. Practically every integration guide I've seen for setting up API access to an MIS for some software either says or implies "Just grant access to everything".
-
They're wrong. This one isn't really even a maybe in my mind. Did you send them the guidance file that I linked? It's pretty clear about this exact situation. EDIT: doubling down because I've already had this exact situation and told them no Double Edit: The GDPR says the right to object is only applicable to processing carried out under bases (e) and (f) of Article 6 of the GDPR (the bit that defines when processing is lawful). Supplying an education record to a parent is a legal obligation (under the Education (Pupil Information) Regulations 2005), which is base © of Article 6, so the right to object under the GDPR is just not applicable in this situation. Saying that the kids age is relevant in deciding the issue implies they think you're relying on consent to carry out the processing (I.E. send the info to the other parent), but you're not - you're fulfilling a legal obligation. Yeah, they're wrong.
-
InVentry and GDPR
djrscally replied to Anothername's topic in Data Protection & Information Handling
Two points: a) I think if it's in sight of reception, who would presumably see and stop someone obviously not a student from scrolling through the list of students, then the relatively low risk and harm of someone seeing a list of names is outweighed by the safeguarding benefits of the system. b) I'm pretty sure you can configure the front page so it doesn't have a Students tab anyway right? I assume they swipe a card rather than manually click so if you're worried about it maybe do that. Why was he mortified to find he's still on there? -
To elaborate on my previous answer, it's guided by this section in the guidance from the DofE on Parental Responsibility: tl;dr Data Protection legislation does not enable kids to cut their parents off from access to their school records. Only a court order does that. EDIT: and to further expound, the Data Protection Act 2018 amends the regulations that are behind the above guidance only to replace references to the DPA 1998 with the GDPR, so I see not reason why the above guidance should not still stand.
-
Nope. The law says a parent has the right to see the Education records of their child (or any other child for whom they have parental responsibility). Regardless of the GDPR, the answer is no. EDIT: Unless the kid is informing you a court has ordered the parent not have access in which case yes, but without a court order no.
-
The concept of Xporter and Wonde are not that bad ideas tbh. It's much easier for developers to just write their software to fetch data from one thing (Xporter / Wonde) than for lots of things (Progresso, CMIS, SIMS7, SIMS8, iSAMs, BROMCOM, RM Integris et al) and just let those companies handle writing the program to fetch data from all the individual MIS systems. I agree that they both have their issues though, in both implementation and attitude. But overall, the idea is not a bad one. Edit: One of the Wonde problems is the vague way they handle introducing themselves to the Network/Data manager, but you'll probably get an email from them at some point asking if they can remote into the SIMS server to install the thingy for you.
-
[sims] Urgent Capita SIMS Data Issue - Issued by childrens services
djrscally replied to vikpaw's topic in MIS Systems
Yeah particularly given they're supposed to be governed by the GDPR's minimum terms now; one of which is...
