Jump to content

DavR

Members
  • Posts

    1,927
  • Joined

Everything posted by DavR

  1. Seems fair, I was unlikely to use them tbh. I don't really like picking up suppliers through cold calls, much rather prefer to get them by reputation or recommendation...
  2. This Highgate? We already use them for toner and have a good relationship, so could well do more with them in future.
  3. Is it pure coincidence do you think that, during this conversation, I've received a cold email from a new supplier called Bluepoint? I wonder....
  4. Oh really? I've been boycotting Softcat because their sales calls were just so pervasive. I asked them to stop calling and they won't, I'm having nothing to do with them.
  5. Also, who would people recommend as their "bits and bobs" supplier now? I used to use Stuff UK, but I just find their website really clunky if I'm searching for things.
  6. Sad to see this, our account manager Mark Lee always came through for us. Not without their faults, but we always got a decent enough price. I was at their Expo show in Battersea just last Thursday setting up a whole bunch of new deals! Mandatory £12 delivery did stop us ordering small items from them though, that was a silly decision, they needed to grade their delivery costs. They sold us eight touchscreens for classrooms just this summer and managed the whole install for us, I wonder who holds the warranty for those works now?
  7. While there is going to be a lot of work involved, especially initially, I think long term you'd have to be a MAT or a very large school to need a full time person for the role. I think a lot of places would be looking at maybe a day or two a week, depending on whether they employ the DPO in a purely advisory / responsibility role, or whether they have them deal with all the paperwork as well. I'm increasingly thinking that we'll be paying an outside contractor to be the DPO, with them doing the consultancy and compliance side of things, and passing the grunt work back to school admin. You are right though, there's likely to be a budget hit for this regardless, at a time when we can ill afford it.
  8. Yeah, I've got that one set, plus the various import at first run settings, but can't recreate what you've done sadly! I've been deleting the AppData\Local\Google\Chrome\User Data each time in my testing to create a first run experience. FYI, deleting the AppData\Local\Google\Chrome\User Data\Default folder as your script does will not recreate the first run experience as this is determined by files in the route of AppData\Local\Google\Chrome\User Data. This may be giving you false positives. When you copy in bookmarks, are you copying a number of files to this User Data\Default folder, or just the single bookmarks file? I wonder if something there is fooling Chrome into thinking it's already done the first run.
  9. Interesting - I've got that setting in place, but we still get the Win 10 welcome page Is there any chance you could share your policy settings to see if it's a magic combination? What, for instance, are your restrictions around Chrome sign-in?
  10. We're using Integris and running a built in report, I haven't seen any options on this point. But that's off topic, just mentioning as an example.
  11. Yeah, it's definitely a good time to re-evaluate our data sharing. I know for us Junior Librarian really needs re-evaluating, they take name, DOB, home address, email, UPN even! Not required to run a library database.
  12. It would be interesting to see if anyone did switch major suppliers during the GDPR switchover, it's potentially a time when people would re-evaluate their suppliers for big services like MIS and online office platforms. I suspect most people will just agree to the new terms to avoid the hassle of changing though.
  13. My thought was that the positive opt-in was part of the new active consent requirements of GDPR, ie, you can't be assumed to consent to their T&Cs, you have to actively tick a box to say you've read them. We will all read them, of course... Not sure what happens if you don't confirm your consent by May 2018, maybe it will lock out your organisation until you agree to T&Cs? It's all very well changing the method of consent, but at the end of the day you will have to agree to their terms if you want to use their service.
  14. I was of the understanding that it's in the data processors interest to put these contracts in place, because the new rules make data controllers and data processors jointly liable for data breaches. They need to cover their arses legally now, where before it was the client / data controllers liability. That was my hope anyway, that our various third party firms were going to approach us with new agreements!
  15. Yay, more reading! Looks like that might have some helpful advice though, thanks. It's a bit crazy that we're drawing up and signing contracts before anyone is clear what's supposed to be in them. I assume people like Google have had some expensive lawyers draw up their own interpretations, but smaller firms must be pulling it out of the air at the moment.
  16. Latest question about GDPR - what does a Data Processing Agreement between our school and a third party need to contain to be GDPR compliant? I've had two come up in the last few weeks, and I was just wondering what I need to be sure of before I sign them. One is Google's latest terms of service, which I assume will be OK, but they are also asking for the name of our DPO, is this standard? Given it's Google, it's not like we can negotiate, but still. The other is the DPA with our electrical waste disposal company, who we've previously done business with informally. I am less certain this one will be compliant, so could do with some guidance (couldn't we all in this minefield....)
  17. Fair point, but neither are schools big enough to have a compliance department. We're stuck in the middle a bit!
  18. In fairness, larger organisations will often have people who have dedicated roles around compliance and auditing, so I guess it would be envisaged it lands on those people. Or to force the organisation to employ someone, as a way of ensuring data protection is a a serious, not secondary, concern. An exemption for smaller organisations might have been helpful though! Either that or someone was in bed with consultancy firms....
  19. I think the conflict of interest comes not from your position or stake in the organisation as such, but more if you have any input into decision making re data and the systems that data resides on. My argument against your governors holding the role would more be that surely they sign off on certain decisions about data and it's processing. Just out of a meeting with our governors where the workload, complexity and availability needs of the DPO role was cited as being beyond the call of duty. We're looking at LA or third party as our ideal, just looking at our options. We've recently done the safe with H&S responsible person, so it's perhaps not unreasonable.
  20. Fair point, but yes, you would be feeding into it, and presumably displaying it on your website somewhere.
  21. I'm still using roaming profiles on Win 10 1703, primarily to save Outlook settings. I've been pleasantly surprised actually, I haven't had to deal with any corrupt V6 profiles yet, although this system is only a few months old. Out of interest, does anyone have an alternative to roaming profiles to roam Outlook settings? Just in case I've spoken too soon....
  22. There's a lot that needs doing and to be aware of, but the organisational changes should really be down to management and your DPO. In terms of the IT Dept though, I would say you need to be looking at the following: - System security: the level of "reasonably expected security measures" is likely to be raised, so check up on passwords, screen locking, etc - Data transfer: as with the above, reasonable security expectation on transfer of data is likely to increase, so look at encrypting USB sticks and secure file transfer - Data sharing: who you share data with, what data do you share, and is there an agreement in place covering this - Equipment disposal: if you use a third party to wipe data on disposed equipment, they are now considered a data processor, and you will need a signed agreement with them - Student photos: if you routinely use photos on your website etc, be aware parents need to give specific consent, not assumed. Over the age of 13 you may need the student's consent directly. - Privacy notice: you will need to create and share this with the school community, explaining what you do with their data, including listing what data you share with which third parties (listed by name).
  23. You jest, I have been asked if this is something I could set up for lock down procedure - "We are under attack, stay inside!" Technically yes, but practically...... no.
  24. It's not a resolution as such, but I've upgraded to Sophos Central, the web-based EC, as this is included in my broadband services contract (LGfL). This has a different client (although a lot of the same underlying technologies) so hopefully won't have the issue.
  25. Well, it ain't gonna be me, that's the main thing! *jumps in air clicks heels* Sorry, that's not overly helpful is it. I'm just very glad I found this discussion as I'm in a GDPR meeting next week and this question is bound to come up. Thank you @enjay for the helpful document. Re DHs, I'm pretty sure all of our SLT have some input or decision making about what data is processed and how, so that would rule them out. Given that governors also can be said to have decision making rights over data processing, wouldn't that rule them out too? If we were to change MIS or have a massive IT investment, it would have to be approved by governors. It's a minefield isn't it - the best option would probably be shared DPOs from Local Authorities, as a buy in service. But the last thing any LA wants right now is to find the money for more staff.
×
×
  • Create New...