djrscally
Members-
Posts
447 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by djrscally
-
GDPR and publishing exam details in newpapers
djrscally replied to mdrabble's topic in Data Protection & Information Handling
How many of you actually send the results to the media? I've never quite understood why this is for some reason considered ok, so I've always just ignored the requests from the local papers to send them the results. -
[sims] Urgent Capita SIMS Data Issue - Issued by childrens services
djrscally replied to vikpaw's topic in MIS Systems
I'm too young to get this, had to google it edit: or possibly slightly too old, hard to tell. -
I use a 500gb external hard drive to backup external files at home. It's encrypted with VeraCrypt rather than Bitlocker but i've never had a problem with it. I really wouldn't be concerned by this at all; Bitlocker on internal drives is going to get way way more throughput in terms of read/writes than an external hard drive is so I imagine it's far less likely to corrupt a comparatively seldom used external drive. You're far more likely to find they forget the password, so remember to take a copy of the recovery key so you can open it for them when they do.
-
[sims] Urgent Capita SIMS Data Issue - Issued by childrens services
djrscally replied to vikpaw's topic in MIS Systems
Quoting hearsay no less! -
[sims] Urgent Capita SIMS Data Issue - Issued by childrens services
djrscally replied to vikpaw's topic in MIS Systems
I apologise! For some reason I only read Page 1 before replying, that was daft. -
[sims] Urgent Capita SIMS Data Issue - Issued by childrens services
djrscally replied to vikpaw's topic in MIS Systems
Capita say not their responsibility to report: -
Importing sats data into Progresso from NCA TOOLS
djrscally replied to jonrob81's topic in MIS Systems
Hey You should be able to import it into People | Learners | Import Data; if you select the CTF file in that screen it should go in fine. If it doesn't, there'll be an error message in the grey box - what does that say? Dan -
If I just handed you data with no precautionary measures and you put it online because you didn't know it was wrong, sure. But if I'm being responsible (by training you, reading you the riot act and giving you secure IT equipment) and you're simply being malicious then that's not how it works; go look at the ICO's "Actions we've taken" pages. Where an employee maliciously handles data it's the employee that gets prosecuted and fined for it. There's plenty of examples of people either stealing data when they leave, or looking up details that they had no right to access (which is generally health workers nosying on the records of their neighbours or something) and so on and so forth. I really don't see why the simple fact of employment or not is given such weight; particularly since we give out data to non-employees now.
-
But is that really any different from a current staff member? The bare fact that they don't currently work for you is meaningless - if they deliberately leaked the information on line then they'd be prosecuted just like any current member of staff who deliberately mishandled data would be. The risk you're mitigating is that this unknown person will accidentally mishandle data, and you mitigate that in exactly the same way you do for current staff members by having them read and agree to follow the policies, training them and giving them equipment that you know to be safe. Edit; Like I say, we ​very frequently​ give people who don't work for us access to our data. That is not automatic grounds for exclusion
-
I disagree with the ICO here, nothing in the GDPR says "Thou shalt not give access to people who don't work for you yet" and indeed we regularly give information to people who don't work for us AT ALL and this is not considered a problem...provided that you take the appropriate organisational and technological measures necessary to protect the data that the GDPR actually does mandate. Imma contact them too. Edit: Long story short: So my view is; if you are supplying the equipment they're doing this on, have put them through the same GDPR training that your staff sit and they've agreed to be bound by your data protection policy as part of the contract they signed - this is not an automatic no at all.
-
Poll: Student Photos
djrscally replied to Gongalong's topic in Data Protection & Information Handling
Voted Yes, but it depends what we want to use them for. -
Outlook, we do also do #2. #1 I use personally but for a different reason, but yeah that might be a good idea. Ah - I was looking for something like this. I'd still rather a "tick to confirm you've looked at the recipients list and that specific recipient is ok" but this is a very decent start - thank you!
-
I reckons this is one of the biggest risks for us. Problem is, I'm not entirely sure what's the best way to mitigate it. What's everyone doing to try and stop that from happening? The one idea I have is to find an Outlook add-on that prompts you to confirm the recipient is correct before actually sending an email externally, and to configure it to share attachments as OneDrive links so access can be revoked if you realise you made a mistake. Past that though, I'm not sure what to do.
-
Teachers access to OneDrive at Home
djrscally replied to MrWrighty's topic in Data Protection & Information Handling
Yeah we just have a policy to the effect of your last sentence there. -
GDPR data sharing agreement?
djrscally replied to leegcvcc's topic in Data Protection & Information Handling
We drafted our own agreement meeting the GDPR's minimum terms and basically when the processor replies to our request for an updated agreement with just their privacy /policy we send them our agreement and tell them that since they haven't supplied us with terms we need them to agree to ours. Our agreement specifies that by continuing to provide us with whatever service they're providing, that counts as acceptance of the terms we sent to them. -
Can confirm. I seem to recall they by default ask you to grant all access in your MIS but you don't need to (and shouldn't) comply; Wonde will fetch the data you did grant access to no problem.
-
CPOMs here too in both schools. We like it a lot it does have some neat features that are really nice, like the ability to record body maps and for a student's previous schools to directly transfer their entire safeguarding file from their CPOMS database to yours when the student joins you, which means you have the whole history. We've not had any complaints - except that their branded 2 factor auth app seems to "forget" that it's linked quite frequently which means the user can't log in without coming to an administrator to get their 2FA setup reset. This is not a huge deal as the 2FA method is just TOTP so you can use any TOTP app like FreeOTP or Google Authenticator and they all seem to work fine. Or you can get the Yubikeys from them which work fine too.
-
Not to my knowledge. I think this is just the same kind of stuff that often gets into contracts; it's there so that if they have to go to court over something you can just point to the disclaimer rather than have to argue that it was blatantly obvious the person you accidentally sent data to shouldn't have sold it on as a mailing list or whatever.
-
That's an rdl too. Lemme collate them for you then. Virtual coffee is almost as good as virtual beer!
