Jump to content

djrscally

Members
  • Posts

    447
  • Joined

  • Last visited

Everything posted by djrscally

  1. I don't think this is an automatic no. Nothing in the GDPR says you can't give data to people just because they don't directly work for you. Worst case, have HR tweak your contracts to specify that the duties of confidentiality apply to any personal data they see prior to their first day on site. My biggest issue would be that they would presumably not yet have ICT equipment that's vetted by your team. I'd want them logging in through rdp or something rather than just getting sent the data and using their own computers to work on it.
  2. It can work; I work for a Special Academy, which is doing really well.
  3. So how's it work? Are you just selling x509's for S/MIME?
  4. There's nothing in the GDPR or Data Protection Bill that I can see that exempts a data controller from the response times just because your staff are all on holiday. As it's the ICO that'll be enforcing this kind of thing, I'd say the best thing to do is ask them how they'd view this situation. edit: crc-ict's solution seems to me to be a good one.
  5. I'd quite like to run Staff training as one of the online courses that schools often use for Safeguarding, as they're nice and trackable and quick and easy to set up and a lot easier to organise than getting all the staff in one place in one go. Does anyone know of any decent ones?
  6. "The head and DPO are on holiday" isn't an exception to the reporting rule, so I guess we either need a process that can adapt to situations like that or a way for the head to keep private documents at home secure (her laptop is encrypted anyway ofc, so that's not a reportable breach anyway).
  7. Broadly speaking, they're a processor. The basic distinction is decision making authority over the data. If they can decide to process the data in a certain way without your input, then they are a controller of that data. As the ICO says:
  8. You are covered under (e) for any messages directly related to the running of the school, including behaviour, attendance and achievement. "Other general messages" is too broad a category to say; stuff like "School is closed" is fine, but stuff like "Please buy tickets to a school play" is probably not without refreshing consent to ensure they've opted-in to marketing.
  9. I don't know that they sound sketchy; they just look like a re-seller who'll just add on a fee for the X509 certs you can buy from any CA or something. I really don't think S/MIME is a good solution for schools anyway. The whole methodology means hardly anybody uses it, so you're paying for something that will basically never see any use, and it wont let you send encrypted emails to others anyway unless they've bought their own certificates.
  10. Yeah that report didn't live up the the hype in the original twitter thread. It's also avoidable by not loading remote content, which almost all 'corporate' email setups do anyway as a matter of course.
  11. Does S/MIME let you set a password to open emails? I thought it was key based auth only.
  12. I think that emails specifically about you are definitely included in a SAR, unless one of the exemptions that would apply to any document about you applies to that specific email.
  13. You send 50,000 emails through your MIS every month!?
  14. Honestly, I'd say you need it. I think the inconvenience of writing an email as a password-protected word file or PDF is a high enough usability barrier that you will find people simply don't bother (maybe not initially, but in 6 months or so for sure). Security needs to be as transparent and easy as possible, or it swiftly falls by the wayside; so whilst I think you could do that as an interim measure I don't think it should be your long term solution. Google is a tough one. There's free plugins but they invariably use PGP which is perfect for sending mail to people who know what they're doing, and useless for recipients who don't. Even S/MIME isn't a great option because it relies on recipients setting up and publishing their public keys, which is pretty unlikely frankly. It's weird they haven't built in a system already to be honest.
  15. What's the deal with the email limits then?
  16. This is fine really. The methods you use to protect data from loss don't have to be GCHQ proof, they just need to mitigate the risks associated with the processing you're doing. With regards to a posted USB stick, the risk is obviously that it will be lost along the way and found by an unauthorised person; emailing the password obviously mitigates that risk.
  17. In general, you should do a), unless they say they have no plans to change their contracts in which case you should do b) (with the proviso that it needn't be a contract; a "data sharing agreement" that supplants the data protection section in your contract is fine). However you probably have a bunch of processors with whom you do not have a contract (independent specialist teachers in our case), and I'd try and do b) for those (again though, can be an agreement rather than a full contract) c) is not sufficient; it needs to be a legal, binding agreement between you.
  18. Mostly some variation of that suggested in page 37 of this document: https://irms.site-ym.com/resource/collection/8BCEF755-0353-4F66-9877-CCDA4BFEEAC4/2016_IRMS_Toolkit_for_Schools_v5_Master.pdf tl;dr retain student records till the pupil is 25 (Anyone born prior to September 92)
  19. I think this is a bit shaky tbh; Facebook's privacy notice says they can use your photos in promotional material, but I think people would be apoplectic if it turned out Facebook was sharing photos of you, say, drinking a bottle of coke to CocaCola™ for them to use on their own website.
  20. 1) No I don't think so. In the example you gave I don't think you're "sharing" data at all, as that term implies passing it off to another data controller. Instead, you're just giving data to your processor to process on your behalf. You don't need to list all your processor's sub-processors in the privacy notices. 2) We're lumping people like that into "various independent specialists such as consultants, specialist teachers etc"
  21. Mm yeah, tricky one to be honest. We are definitely having to get consent in a different way now; we can no longer simply assume it unless parents object - it has to be the result of a positive action now (I.E. they have to "Tick to consent" rather than "Tick to opt out"), which is tricky enough for us. I would say that this depends on your status. If you're a processor and if schools rely on parental / student consent to use photos for marketing and publicity purposes, they probably cannot pass that consent to you. If you're a controller, you might be able use the legitimate interests basis for processing to justify your use of the photos in marketing. If you're the one determining the purpose and means of processing the data (I.E. it's you organising and running the event and just inviting schools to participate and deciding to take the photos) you might well be a controller, but I'm not totally sure.
  22. Other; Deputy Head (I know...)
  23. Hello Sanity check please. Wonde and GroupCall - I'm treating them as subProcessors and expecting the companies who get the data from their exports to have a contract or agreement binding them with the same terms we have to bind our Processors, rather than us having them with both the company and middleman - is everyone else doing the same? Ta Dan EDIT: I'm going ahead and asking the people who use 4th party exporters like this for a copy of their agreements with that company; I'll report back what happens (so far one company has gone "sorry what?")
×
×
  • Create New...