-
Posts
1,927 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by DavR
-
THIS! This is what I've been looking for! I've been stuck with the same "welcome-win10" screen for ages. I was fixing this with a file bodge, but this is the setting I wanted. I'd overlooked it as I knew I didn't want to set Chrome as default, but using it as an inverse has done the trick. I've now got my Chrome deployment running with no first-run annoyances, using GPO and the master preference file ONLY, no additional files or bodges required
-
Data Processing Agreement - What Is Required?
DavR replied to DavR's topic in Data Protection & Information Handling
Support is something you'd potentially need a DPA for. The amount of times I've had to upload SIMS databases to Capita in the past to diagnose and fix errors. -
Data Processing Agreement - What Is Required?
DavR replied to DavR's topic in Data Protection & Information Handling
My understanding was that your contract / T&Cs with the company constituted your Data Processing Agreement. It would seem a bit of an unnecessary doubling up and conflict to have two legal documents covering the same thing. -
Data Processing Agreement - What Is Required?
DavR replied to DavR's topic in Data Protection & Information Handling
Hang on.... are you writing up your own Data Processing Agreements and sending them to suppliers, as well as the T&Cs on their contracts? This sounds a bit OTT, and surely the big players like Capita or Google aren't going to sign up to the customers T&Cs. -
Data Processing Agreement - What Is Required?
DavR replied to DavR's topic in Data Protection & Information Handling
I think as a general rule, the Data Processing Agreement is something that forms part of your contract with the company. It's not for you to draw up and them to agree to, it's the T&Cs of what you've signed up to when buying / using their service. -
Data Processing Agreement - What Is Required?
DavR replied to DavR's topic in Data Protection & Information Handling
Off topic a bit, but I'm doing contract reviews at the moment. For info, MyMaths haven't updated their DPAs and Privacy Notices for GDPR compliance yet, it's still in progress. As seems to be the case for 90% of all other suppliers! -
Data Processing Agreement - What Is Required?
DavR replied to DavR's topic in Data Protection & Information Handling
That's a good question actually! Most of the contracts that I've read thus far are at pains to point out that you remain the data controller, you're merely using their system to generate the data. I don't know if they would be considered the data controller at any point in this process. -
Data Processing Agreement - What Is Required?
DavR replied to DavR's topic in Data Protection & Information Handling
A point to consider with some of these services is that it's not just the information you share with them, but the information they create. For instance, we use MyMaths for maths homework, and whilst we've only shared class lists, those class lists are to create individual student users who then use the system and generate attainment and assessment data. -
GDPR Responsibility in your school
DavR replied to prad-ucs's topic in Data Protection & Information Handling
Probably not very much - ultimately, it's the school / DPO who carry the can if data protection is not implemented right, not the IT dept. You can only tell them, it's up to them if they listen. The more poignant question is whether you can work with this person and implement your end successfully. Very few SLT, if they're taking on this role, actually have the expert knowledge, so someone somewhere is going to be making a good buck on training courses. -
GDPR Responsibility in your school
DavR replied to prad-ucs's topic in Data Protection & Information Handling
That's the rub @ronnoco, nowhere is it written in black and white in the EU law who can and cannot be DPO. Even when the UK law comes in, it's unlikely to give a list across all industries what roles can and cannot be the DPO. Like a lot of law, it's all down to interpretation. Hopefully DfE or ICO will clarify one day exactly who can or can't, but til then you have to look at the rule of do they have control over how or why data is processed. If you make decisions on how, or why, the data is processed, it can't be you. That accounts for Network Manger, Headteacher and a lot of SLT, all have conflict of interest. The DPO needs to audit these decisions, and you can't audit yourself. That's why this is such a long thread, no-one can find a role in their organisation senior enough to have the clout, but detached enough to be free of conflict. It's a right pain! -
Data Processing Agreement - What Is Required?
DavR replied to DavR's topic in Data Protection & Information Handling
Regarding the contents of contracts with data processors, I'm just sitting down today to fire off emails to all our suppliers to request copies of their/our DPAs. My evaluation procedure will essentially be the checklist on page 27 of the draft ICO guidance mentioned above. It's not the definitive answer yet, but it looks to be the best working document we'll get for a while! -
Data Processing Agreement - What Is Required?
DavR replied to DavR's topic in Data Protection & Information Handling
I've been taking the line that we need a DPA with anyone we expose personal data to, so in the case of helpdesk software I guess you'd have to evaluate whether you're putting anything personal in there. "Mary in 3A needs a new mouse", maybe not so sensitive. "Child XYZ is not appearing on the free school meals printout when they should", that is personal data. Same with any other third party service that sees your data. I had assumed the data processors would want to update / implement DPAs, as they will now be jointly liable for data breaches, but I must say I've not heard squat from most of our contractors yet! -
I've got Remove Common Program Groups on, Start Menu redirected, and layouts defined by XML (Office "apps" pinned to Start Menu, 3 x browsers pinned to Taskbar). This combination seems to be working for me! Have you got the SpecialRoamingOverrideAllowed setting on? I seem to recall this was important - https://blogs.technet.microsoft.com/askpfeplat/2017/05/08/mysteriously-disappearing-start-menu-tiles-and-roaming-user-profiles/
-
Update - just tested my mandatory profile with the Edge settings off, as per @eddyc's suggestion. Sadly not an immediate fix, bah! I do need to attempt a new version of my mandatory profile though, with a number of tips and tricks to try. BUT, good news, my Start Menu and Taskbar layouts via the XML and GPO work under mandatory profiles as well as roaming. I'm guessing this is another not supported, rather than can't be done...
-
The roaming profiles bit is definitely "not supported", rather than "can't be done". I've got Start Menu and Taskbar layouts running fairly reliably with roaming profiles here (note *fairly* reliably....)
-
Oh really? FFS Microsoft £$%^! That said, I could have sworn I had Start Menu layouts working with mandatory profile when I last tried... I could be wrong though.
-
GDPR - Network & Systems Security
DavR replied to booths's topic in Data Protection & Information Handling
+1 for Google Drive on this one. I'm not going to encrypt USB drives until I've got our school implementation of Google Drive in use as an alternative to USB sticks.- 21 replies
-
- gdpr
- networking
-
(and 1 more)
Tagged with:
-
Ooooooh, this sounds good! Must give that a go, thanks for sharing @eddyc. I guess it's a fair bet that a lot of the people who want a mandatory profile are also locking down Edge extensions with policy. And, given that there are myriad different reasons why Edge dies like this, it's been impossible to Google search....
-
GDPR - Network & Systems Security
DavR replied to booths's topic in Data Protection & Information Handling
We're looking at either Bitlocker, or banning USB drives completely, probably the former. Be aware though if you enable Bitlocker, the drive will become unreadable to Mac and other OSs, including Windows pre-7. Our guest WiFi is routed to be Internet access and DNS only, so hopefully that's secure. I hadn't thought of that one though!- 21 replies
-
- gdpr
- networking
-
(and 1 more)
Tagged with:
-
Just an update on this one, I'd forgotten about this thread! Ordered a solenoid online, not easy to find, I had to buy a similar one and change the connector. Reassembled and working again now, no jamming Thank you @difinity for your help on this one!
-
I have not tried that, what does that do then? No idea what Spartan could refer to in relation to Edge, perhaps it relates to some inbuilt warrior function that rampages through your profile and f***s it up to biblical proportions? Spartan=disabled, please. I hope to have another bash at mandatory profiles on 1703 at some point, I will note this and @mshill's tip about not ticking the mandatory box in my next attempt. Thanks both!
-
Sorry @mshill, I never did. Gave up on mandatory profiles and went for local profiles in the end, which I'm not happy with, but they are working.
-
By the looks of it, they haven't hung around on that score. I've just had an email from my old account manager who is now at PCM, pretty much offering to pick up where we left off. Even the logo is weirdly similar. Apparently PCM did try and buy Misco out but it didn't happen, so they've mopped up most of the Misco staff. Anyone know anything about PCM?
-
Probably a bit late for a closing down sale now! I'm not sure how much Misco ever kept in stock tbh, a lot of the deliveries we got from them were direct from suppliers, Misco were merely an intermediary with a nice website.
-
I can't speak for the mobile site, but the iOS app bypasses all filtering, it accesses the content via a completely different set of addresses. We removed it from all our student devices.
