djrscally
Members-
Posts
447 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by djrscally
-
Freedom of Information request
djrscally replied to Jobos's topic in Data Protection & Information Handling
Is that hard to do in SIMS reporting? I was previously somewhat surprised at people saying it would take too long on the grounds that it took me about 10 mins in Progresso. -
Freedom of Information request
djrscally replied to Jobos's topic in Data Protection & Information Handling
Concerns like this aren't really unique to this format though; you also wouldn't know that was the case if the request came in an email body and you responded likewise, relying on the requester to input the data into their db. However you respond, it'd be important to retain a log of what your response was so you're not relying on the requester accurately recording that. -
Freedom of Information request
djrscally replied to Jobos's topic in Data Protection & Information Handling
No definitely not, I bet that's the costliest abuse of it too. Yeah you're probably right. -
Freedom of Information request
djrscally replied to Jobos's topic in Data Protection & Information Handling
Data miners working for marketing companies submit thousands to gov. -
Freedom of Information request
djrscally replied to Jobos's topic in Data Protection & Information Handling
Depends on your google-fu; his site is #6 in Google results when I search for "Brian Maloney FOI", so it's risky to try and use that criteria to judge safety I think. Edit: Hit number 1 is this page: https://www.kelsi.org.uk/news-and-events/news/primary/update-regarding-response-to-foi-request-from-mr-maloney Last paragraph: This is the kind of thing that irritates me about this whole affair. The request is invalid for the reasons the ICO and appeals court outlined, but this advice to *make up the time it takes you to deal with the request* is indicative of a pretty poor attitude towards FOI. -
Freedom of Information request
djrscally replied to Jobos's topic in Data Protection & Information Handling
The only part I'd disagree with in there is this: If you're going to say it's reasonable to have a policy of never opening links to "unknown" websites then surely it follows that they must be expected to have a means of investigating a website to discover it can be suitably accessed, otherwise they'd never be allowed to stray past their intranet. But yeah, the judgement is right. -
GDPR and dropbox for staff and students
djrscally replied to genesis's topic in Data Protection & Information Handling
Definitely not ok if these are their personal accounts. If it's an enterprise subscription that you control access to then it's fine; no different from Google Drive or OneDrive for education. -
GDPR for staff laptops and phones
djrscally replied to genesis's topic in Data Protection & Information Handling
Use Bitlocker to encrypt the laptops asap. Or if that's not available for some reason, Veracrypt. The problem as I see it with emails on phones is two-fold; 1) They sync, and so store sensitive data on the device itself, which will usually be unencrypted (unless it's an iphone or the newest Android). 2) The phones are the personal property of those staff so you won't get them back when they leave, which means you can't verify that any personal data has been removed. You can use exchange's policy thingies to enforce encryption on devices which sync, so that's a good idea. You can of course remotely wipe the phones, but probably most staff won't realise they signed up to that and there'll be hell to pay if you actually do it. The compromise we've gone for is to insist that staff only use the Microsoft outlook app to sync emails to their phones, as that app gives you a "Wipe Outlook data only" option in 365 as well as the "Wipe the whole phone" one, which means we can remove those emails when they leave without it touching their personal stuff. This doesn't prevent them downloading attachments and what have you, so we've written that prohibition into our policies and training (same as for Personal computers at home). As Roberto says, these things need to be formal policy - this is bigger than just "IT would like this to happen". -
Why on earth RDP on site? Enforcing RDP externally as opposed to just encrypting the disk is already pretty tinfoil, RDP on site is baffling me. I think unless you're super duper confident in your VPN and RDP connections that one might cross the "stuff needs to be very easy to use too" line. Edit: Actually I guess it's just "enforce RDP" which means it has to be used on-site too. So ignore me; makes sense. Everything else you listed seems pretty in line with what I've seen around here. For other encryption thingies; VeraCrypt is the FOSS one, and works really well. Not sure it can be deployed by an NM though as I've never tried to use it like that.
-
Missed this yesterday sorry. Mine was given to me when we first started with XoD - I imagine you can just email their support team and they'll get it set up.
-
On mine there's 4 identical rows for each area for some reason If you get the docs let me know - I keep meaning to ask.
-
No it's similar to the API Licenses; you go to System | Web API V2 | Manage Companies Access then hit add and pick "Wonde" as the company, then fill in a Username (IIRC they have a specific format like "Wonde dfe+estab" they want you to use) and just tick the boxes that are listed to grant access to each area of the database. Progresso then emails them the password for the Username that you set up and they can start calling the API immediately. No need to involve Advanced unless they forget the password. I think you can download the logs from https://login.groupcall.com/
-
You don't need to expose everything. I just ignored the direction to grant access for everything and just granted access to the bits I thought the software we were linking to Wonde would need, and it works fine.
-
Mostly the latter I expect, and you'll have to review and ensure that the DP terms in their standard contract include everything necessary to comply with the GDPR. The ICO will likely publish some default terms to be included (something not yet done but specifically allowed for in the GDPR) at some point in the future, and at that point I'd probably auto-reject any contract not including those published terms.
-
https://ico.org.uk/media/about-the-ico/consultations/2014789/draft-gdpr-contracts-guidance-v1-for-consultation-september-2017.pdf Page 13 outlines what needs to be written into the contracts
-
GDPR data protection fee?
djrscally replied to Meldrew's topic in Data Protection & Information Handling
Outstanding. -
GDPR and Primary Schools
djrscally replied to CommodoreS's topic in Data Protection & Information Handling
Bin the advertising and blacklist anything coming from their company from now on. Ideally, don't look at any kind of GDPR marketing. It's like Googling your symptoms when you're sick; you'll rapidly go from blithe confidence to "AM I ABOUT TO DIE!?" (they're not all being scaremongering gits by any means, but a great number of companies are behaving poorly) -
GDPR and School reports
djrscally replied to nicholab's topic in Data Protection & Information Handling
The educational records law? It does - it's one of the examples the DofE specifically gives actually. -
GDPR and Exam bodies
djrscally replied to Smokebomb's topic in Data Protection & Information Handling
If only. -
Freedom of Information request
djrscally replied to Jobos's topic in Data Protection & Information Handling
No you have to ensure both parents are treated equally in almost all respects (unless one of them has a court order saying the other gets nothing). So for things like information home to parents, voting on school governors, invites to parents evenings, newsletters, reports about their child and so on - all that must go to both parents if they're separated; neither the live-in parent nor the student has the right to stop that. Consent for stuff is pretty much the only bit you can just speak to one. Questions 1 and 6 on the request are, really, pretty darned legit. -
Freedom of Information request
djrscally replied to Jobos's topic in Data Protection & Information Handling
Does it? Which bit? I thought the first question was specifically targeted at seeing if we comply with that guidance actually. -
Freedom of Information request
djrscally replied to Jobos's topic in Data Protection & Information Handling
Only the resident parent's consent is needed, unless it's a matter of "long term and significant impact" orthe separated parent has specifically asked for their consent not to be inferred. If that's the case, you have to specifically ask them. EDIT: Gov's guidance here: https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/489901/Parental_Responsibility_Advice_for_School_January_2016.pdf -
GDPR and School reports
djrscally replied to nicholab's topic in Data Protection & Information Handling
No, they can't. There's a separate law governing Parents access to their child's education record and the right to access that is explicitly granted till age 18. Students can of course also demand to see the report, but presumably they are at least shown a copy anyway. -
Freedom of Information request
djrscally replied to Jobos's topic in Data Protection & Information Handling
I'm gonna chip in again and say: there's no way this request legitimately takes longer than the 18 hour time limit. If you can't dump everything requested out of the MIS in way way WAY less than that you either need training for your staff or a new MIS. So, if I were getting responses from schools saying they had to manually check each individual record I think I would be pretty annoyed too. The technival invalidity of this request not withstanding I think it's pretty crummy for an LA to be organising a refusal on those grounds. -
Freedom of Information request
djrscally replied to Jobos's topic in Data Protection & Information Handling
I assume you're doing the whole internal review / complaint to ICO thing for those?
