Jump to content

Narwhal

Members
  • Posts

    113
  • Joined

Everything posted by Narwhal

  1. Hi, We are trying to achieve the same things as the original post but some of our teachers now only have a Chromebook. Does anyone know of a system that can be used to send alerts to both Windows computers and Chromebooks?
  2. Happy New Year! A new laptop bag would be lovely!
  3. Just bumping this thread as I have just been doing the same as jthompson and have come to the same conclusion. Does anyone have an opinion on this?
  4. Let's face it most Ministers who do use computers still have very little idea about how they work.
  5. I am not sure I want to know why you would be applying your haemorroid cream at the beach...
  6. I think in some cases the wording exists to cover the American law that requires explicit consent from parents for the processing of data that relates to children under the age of 13. They are just being lazy as, in theory, consent would also cover GDPR.
  7. "Customer will obtain and maintain all required consents from End Users" This is the clause in that document that you linked to but the school does not require active consent.
  8. Breath?
  9. I don't think licenses expire. support can expire but the system should carry working regardless.
  10. That looks like the American version. COPPA is an American law.
  11. A secret A prisoner is told "If you tell a lie we will hang you; if you tell the truth we will shoot you." What can he say to save himself?
  12. Where in their terms does it say that?
  13. You do not need explicit consent for most of the activities that take place in a school. Most will be covered under Article 6© compliance with a legal obligation or 6(e) necessary for the performance of a task in the public interest (educating the child). this would cover your MIS and most cloud-based educational sites such as GfE. The sites that you use must be GDPR compliant however. Some activities, it could be argued, are not specifically required for teaching or if you are passing control of the data to and external company, in these circumstances you would need specific consent. For the collection of biometric data you will always need consent. It will depend on the wording with any contract, if it says "you or the educational organization you work for has proper permission to register the Child" you would be ok but the line "and that you have obtained the necessary parental consent for Code.org’s collection of the Child’s personal information" could pose a problem. You shouldn't need the consent but you would be agreeing that you have obtained it.
  14. footsteps. What has four legs and one arm.
  15. The first point relates to individual decision making but filtering will block anyone who trys to access banned sites.
  16. I wouldn't have thought this would be relevant for GDPR as the automated decision making is not related to a person but only to webpages that are being requested. Automated decision making would relate to things such as applying for a mortgage where the answers to questions asked about you and your circumstances may result in you being refused funds.
  17. I haven't shown a flow because that could get really complex. Realistically you could show the flow from 'sources of Data' to 'Internal Processing' then from there to 'External Processing' and 'Data Destinations' but for anything in more depth you would require a different document. I have many different documents that go into more depth.
  18. I have created one that just has four columns. Sources of Data - list all the places we receive data from (CTFs, parents etc), Internal Processing - Lists all the places within the school where data is processed (SIMS, internal paperwork etc), External Processing - Lists all the companies that process on our behalf where we remain the Data Controller (wisepay, show my homework etc), Data Destinations - Lists all those places that we send data on to who will then become a Data Controller in their own right (DfE, other schools that students have moved to etc)
  19. A few years back I got a premium bond win for the occupant before last. They hadn't lived there for at least 25 years but with a bit of detective work I managed to send it on to them
  20. We have them but our sixth formers don't so they seem a bit pointless to me. Visitors are given a badge but often workmen who are on site don't seem to. As far as I can see they are a box-ticking exercise for Ofsted. We are a relatively small secondary school so "strangers" should stand out and be challenged but this doesn't always happen.
  21. Slightly off the original topic, I have been pondering the relationship between schools and the exam boards.Would the exam boards be Data Controllers in their own right or are they Data Processors for us? I am thinking that they are Data Controllers but other people's views would be appreciated.
  22. So what language would you use to inform a 4 year old starting primary school about the processing of their data? I don't mean to be flippant but there has to be a point at which you decide "this is the age at which the student needs to know about the processing of their data". I believe that GDPR (or the new Data Protection Act which will actually be the law in this country) will state that 13 is the age at which children can make informed decisions on this matter, therefore a privacy policy accessible by 13 year olds would be the lowest we would have to go.
  23. I think the the purpose of making privacy notices that are written for children is for services that are aimed at, or can be used by, children. We will not be asking for the children's consent for the processing of their data for the most part. Parents will be providing consent for those elements that require it (biometrics, use of images). Maybe at a later date students may have to re-affirm their consent to those elements and those parts may have to be written in terms that they can understand but the majority of the notice is aimed at adults.
  24. I can answer the first two for you. You can install and manage the papercut install on the devices yourself if you own and maintain them. If they are leased you will need to either have lessor install it or have their permission to do so. If they are leased you can ensure that Papercut is an included part of the deal.
  25. I can't actually see any link so I don't know the site you are referring to but if it is the likes of easyfundraising.org then I believe that they themselves would be the Data Controller. Your users and PTA are just users of the site.
×
×
  • Create New...