crispybits
Members-
Posts
225 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by crispybits
-
Hi all We run two alternative provisions at our school. We have SSC (student support centre) - this is where our kids go when they have extra needs such as dyslexia, ADHD, etc; and ACE (alternative centre for education) which is where the kids who have behavioural issues not caused by a diagnosable condition go to prevent disruption to classes when they start acting out. I've set up Alternative Curriculum in SIMS for the SSC kids no problem. That side of things is actually quite simple as they are being removed from regular lesson blocks in the main curriculum and attending the alternative curriculum session effectively as a regular part of their normal timetable. I'm thinking of setting up similar for ACE but I have some questions, I'm just wondering if anyone else has done similar and can provide some insight: 1) If a kid hasnt been removed from their normal timetabled lessons via Focus - School - Curriculum Assignment (by Scheme or Student) and they are allocated to a session of alternative curriculum, can the clash be left in place with the AC over-riding the normal lesson, or will we need to resolve the clash every time we add a session (ACE sessions can last anywhere from a single period to a full week depending on the situation and context)? If an ACE session is due to last more than a single period I don't want that kid to appear on normal class registers - only on the AC register for those extra periods. 2) Is there a way of reporting on the AC sessions such that I could get the date(s) and period(s) a student has been assigned to the AC, even if that assignment only lasts a single period on a single day? Even better if the report could also still include the regular timetabled lesson they would have been in had it not been for the AC assignment. I wish there was a way of having a sandbox mode on SIMS where I could just mess with the data and try things out knowing that when I close SIMS none of the changes get saved because I'd be more than willing just to experiment with stuff like this but I don't just want to start adding sessions in case there's no easy way to remove them again. Before anyone suggests it, we have looked at using interventions, detentions and behaviour events for tracking this but they've all come up short for various reasons. I will happily look at suggestions involving these again as left-field alternatives to using AC but don't be offended if I shoot them down because we've already trodden that road a bit in various staff meetings about this... Thanks in advance for any hints, tips and shared experiences.
-
Hi all Couldn't find anything on this in search but point me to the thread I missed if it's been done before. I know we can automate reports to run at certain times automatically, and I know we can write custom VBA code to run when we run a report from SIMS, but what I would like to do is to have a report (call it report A) run with some VBA code that then tells SIMS to run a second report (report B) to get additional data from another core area and then combine them. I've tried creating a single report that contains all the data I want in SIMS and if I try and get it all out in one go it messes the data up a fair bit, creating duplicate rows etc etc. I could VBA my way out of that but it would be clunky and I'd probably spend months finding new exceptions to rules to code into the macro so it keeps working as it should. If I run a simplified version of this report (A), and then run a second simplified report (B), then I can manually splice the two together quite simply without the duplications etc. But I'd like staff to be able to run this themselves without a load of faffing about in Excel splicing 2 reports together. So ideally the custom macro I write on report A would automatically call report B from SIMS and then combine them behind the scenes. Does anyone know if this is possible?
-
You'll probably find the 90% mostly refers to rent arrears and/or a short term deal while the company gets stabilised again - and it depends how much money they already owe the landlords - what's that old saying? "You owe the bank £100 - you have a problem - you owe the bank a million pounds - the bank has a problem"...
-
Whoever Jacob Spence is needs to move over too - he's nuking us all.... nearly 40 points clear already after just 3 GWs in the old league
-
Only just noticed this had changed - sitting second in the old one - looks like I'd be joint first if I was already in the new one :-)
-
Gender and DOB for test fairness?
crispybits replied to crispybits's topic in Data Protection & Information Handling
Never mind - just found someone who knows all about those tests and they also get reported to the DfE for analysis at national level, so I think it's a necessary thing to be sent after all. Now just to argue with them about wanting a spreadsheet full of kids details to be emailed to them rather than some sort of secure upload process :-P -
Gender and DOB for test fairness?
crispybits replied to crispybits's topic in Data Protection & Information Handling
But we can do our own through our MIS system - the data all gets uploaded onto there. I've asked around all the usual suspects for this kind of analysis and I haven't found anyone who does it. (I know that doesn't mean it doesn't get done, just that I haven't found the right person yet) -
Hi Just looking to see if I'm being reasonable before I argue the toss with one of our suppliers. They run some CATs assessment software for us and they have sent a template spreadsheet that includes such items as DOB, ethnicity, SEN provision, etc that they want us to fill in for all of the kids we want them to test. Having queried why they need all this, we've now been told we only need name, gender and DOB on the spreadsheet and all the other columns are optional. The relevant bit about these fields is in their privacy policy as follows: - Student information including gender and age - this data is provided to us from the school as part of the setup process. It is used to ensure our assessments are fair and to provide detailed analysis of performance. We don't need or use analysis based on gender or age within the year group from this company (if we did need that sort of analysis, we could just roll our own from our MIS system). So we're down to "it is used to ensure assessments are fair". My instinct is that personal data about our kids should not be provided so that external companies can quality control their products. If they want QA, they should do what every other company does and hire in people to test their product. I couldn't imagine providing our catering company with a list of kids details including DOB and gender against their purchases so they could run detailed nutritional analysis by gender and age for example. Or is this because it's standardised testing I'm just being too sensitive to DP concerns and we can just provide it? Thoughts from the eduhivemind welcomed :-)
-
England vs South Korea final, Harry Kane to score the first ever World Cup Final double hat-trick. It has to be that - I saw it in a dream last night (yes, I had spent all night drinking vodka and eating "special" mushrooms but that's got nothing to do with it...) :-P
-
We've got 4 - they will fit 16 laptops each. Cables all included for charging. All in decent (but not perfect) condition - some scratches and scuffs commensurate with use and not all the rubber lining mats are in the bays (to be expected after several years in a school). They all still function just fine, no dead charge points or anything like that. Looking for around £70 each - willing to do a deal for multiples Collection from Mid Hertfordshire area, or if you ask nicely there may be the option to deliver within reasonable distance for some extra dosh but it would have to be outside normal working hours (full disclosure: the laptop trolley money would go directly back into school funds, the delivery money would be to me personally for time and petrol spent) I'm normally hopeless at checking back on my own threads so please PM me if you have any questions or are interested in buying 1 or more trolleys
-
I think we're into safeguarding here rather than GDPR :-P As part of an actual lesson I think we're in a grey are as MrBitey stated, however I think you could get round that by saying "the local paper are doing the thing - any student that wants to join in and send a message can come to the ICT suite at break, lunch, or after school and send one." That way it's not the school that are doing anything, kids are coming in and doing it voluntarily during their own time. I might see it as an opportunity to discuss data security with the kids if I were a teacher tho - show a real world example of something that's easily thought of as harmless and some of the potential negative side-effects.
-
Emailing Staff Contracts outside of the EU
crispybits replied to BKGarry's topic in Data Protection & Information Handling
I would assume the contract only has the personal details of the person applying/being hired? In that case i don't see the problem at all. If there's more personal data in there than just your new guy/gal's then that might be different... -
Further down the same page: The restriction only covers solely automated individual decision-making that produces legal or similarly significant effects. These types of effect are not defined in the GDPR, but the decision must have a serious negative impact on an individual to be caught by this provision. A legal effect is something that adversely affects someone’s legal rights. Similarly significant effects are more difficult to define but would include, for example, automatic refusal of an online credit application, and e-recruiting practices without human intervention. Edit - so quick answer no - filtering isn't covered by GDPR - the most hooky claim I could think of is that you're removing the right to free speech on specific platforms, but as we don't technically have free speech rights enshrined in law in this country, and as I suspect even the harshest filtering will still allow access to government websites to access public services, I just don't see how it could be...
-
Data Breach during school holidays
crispybits replied to Bigbird7's topic in Data Protection & Information Handling
In that case you've still lost a device that contains the data - I'd report it to be on the safe side knowing that the ICO would look at the fact it's encrypted etc - no encryption is 100% unbreakable, and humans are very vulnerable to social engineering to get passwords etc... -
SAR during school holidays
crispybits replied to gdrinkall's topic in Data Protection & Information Handling
I would guess it also depends on what the SAR asks for. "Please give me all the information you have about me" is a very different and more complex request than "what contact details do you have on file for me" - I think it's reasonable that whoever is acting as DPO would have, or would be able to call on someone who has, access to information like just current contact details within the 30 day timeframe even in the holidays. The summer holidays is 44 days long, but do even the smallest schools shut down completely over that time? Isn't there someone in the office for a day here and there dealing with admissions / progressions to other schools or paying bills and invoices with 30 day payment terms, etc? I think it has to be a case by case thing. -
Data Breach during school holidays
crispybits replied to Bigbird7's topic in Data Protection & Information Handling
And if they are aware immediately (while still on holiday) that the laptop bag is stolen they they have methods to communicate with their neighbour then they also have a method to contact the ICO and say "hey, my house got broken into, pretty sure this has been stolen with X, Y, Z personal data, I'll fill in all the details when I get back in a week..." I can't remember exactly where but there was definitely some stuff in the training I did that said that you need to report the breach asap but they will be sensible and reasonable when it comes to filling in every detail and/or working to rectify whatever went wrong, it's not like you have 72 hours from noticing the breach to know every detail of what is missing, contact the data subjects (if necessary), rewrite policy and procedure documents, re-do staff training, and be back to being totally compliant in every imaginable way. The 72 hours is just so stuff does get reported. You can imagine without it somebody sitting on the knowledge of this laptop burglary and thinking "I'll gather all the data together that might have been in that bag and work out if the laptop was properly encrypted first so I can give a thorough report in", and then waiting for email responses from the outsourced IT contractor a week goes by, and then waiting for someone to answer one or two other questions takes another week, and the incident kinda just edges out of focus and then it becomes "ah, well that was a coupla months ago now and nobody has said anything and it's gonna look pretty bad on me if I report it this late" and the thing doesn't get reported at all. The ICO need to know that something went wrong immediately. The details can follow later. -
Getting staff to take it seriously...
crispybits replied to Gongalong's topic in Data Protection & Information Handling
Got some wording on the poster now that seems to have passed muster with the relevant departments. I've attached the poster to this in case anyone else wants it for their school (our school logo has been removed) Please note that the images are not royalty free, so use at your own risk and definitely no commercial use (they're heavily modified versions of random google image searches) - can't see anyone chasing a school over it but if you're paranoid about that sort of thing you might want to use plain colour backgrounds or take some of your own pictures... Also sorry for PDF - it was made in Publisher and I can't upload .pub files - send me your email address by PM if you want the editable copy. Poster Edugeek.pdf -
Getting staff to take it seriously...
crispybits replied to Gongalong's topic in Data Protection & Information Handling
Yep that's why I switched it to "Identity" in the poster - everyone has heard of identity theft but I'm not too sure how many link proper data protection at work to preventing identity theft as basically the same issue and the same principles to apply. -
I'd just change that top one to read something like: Personal data must be looked after properly following the GDPR legislation, which include ensuring personal data is accurate, secure and processed fairly and lawfully. And then change the "under the Act" at the end of the second one to "under the GDPR legislation" Afaik (and I am not a lawyer) the principles for the stuff listed here aren't really changing in a way that would invalidate the text you've posted beyond altering the references to the precise legal documents.
-
Getting staff to take it seriously...
crispybits replied to Gongalong's topic in Data Protection & Information Handling
One of the things we're thinking of is linking data protection, which is taken lightly, to health and safety and child protection, which are both taken with appropriate seriousness, by combining the three into a single poster I'm still struggling to write the blurbs for each section (if anyone has any suggestions for how to present the text in the three sections I'm all ears), but this is the general layout to give you an idea of what I mean: -
School Noticeboards
crispybits replied to crispybits's topic in Data Protection & Information Handling
I'm not IT staff any more - I don't have any power over what IT systems we use or control of any budget for any data software (I only have an advisory role with regard to that stuff now) -
School Noticeboards
crispybits replied to crispybits's topic in Data Protection & Information Handling
It's not official yet and may not happen but I may well become the DPO come May - if I do it will be after some more training to get more familiar with this minefield but for the time being I'm trying to muddle this all out as far ahead of schedule as possible... -
Hi all - question about physical information displays within the school. We have a number of noticeboards up for various reasons round the school, and often on these noticeboards personally identifiable information is displayed like names and photographs. Some of these noticeboards are in areas where we also do public hire of school rooms on evenings and weekends. Am I right in thinking that this constitutes a data breach, not just when GDPR comes in but under the current DPA? We get consent from parents to use information on in-school displays but I know not 100% of parents give this and I'm fairly sure the lists will still contain their child as there isn't any awareness (as far as I can tell) on which kids are not under consent. Also, if a list is on the wall in a locked room only accessible to staff, but I can stand at the window with any half decent camera and get a legible copy of that list, this would be a breach too? Thanks for any pointers
-
Not an educational job, but there's a new government job going in the North east if anyone is interested... https://www.northeastjobs.org.uk/job/Cold_blooded_and_Spineless_Officer/159704 I know a few people who might fit the bill...
