Jump to content

TheSysAdminLife

Members
  • Posts

    6
  • Joined

  • Last visited

Everything posted by TheSysAdminLife

  1. Is patch 24068 a server only patch or do the clients get updated too? EDIT: Found the answer just after posting - it's server only.
  2. GDPR could be regarded as a way to discourage organisations and individuals from allowing data to be where it shouldn't be. In this case I would count Students having access to pigeon holes a potential breach waiting to happen. Our pigeon holes are in a corridor that is used by many students regularly, no lock on the door at all. I think this needs to change. If the money is there for it, we'll push to get a card reader lock installed (which we use elsewhere) I think the OPs setup is okay, but they should think about the security of the room, too. Perfect world = Authorised access only on the pigeon holes themselves, all logged. Never going to happen, though. There's an element of trust placed on the staff, so securing the room should be adequate. djrscally is right.
  3. We've got several policies that require a signature. We're going to bring these together to a single document that signposts these policies and asks for a signature instead when the individual (student, staff, etc) joins or does work on behalf of the school or trust. For existing staff or students we'll get them to re-sign the updated and newly created policies. Not sure what to do about those that don't wish to sign, though. Disable their accounts I guess.
  4. This is the crux of the issue. Under DPA the fines just aren't big enough to scare anyone into being compliant. The fines being boosted under GDPR for everyone should change this attitude, though I'm not sure the ICO will fine schools quite as highly as a bank or other commercial enterprise. I think they should, but I don't think they will.
  5. That makes sense. It would be scarier for organisations if the ICO bumped up their fines up, which is kind of the point of GDPR if you look at it from a certain perspective. "Percentage of maximum fine" based rather than "value of fine" based... if that's worded correctly.
  6. I wonder how much this fine would have been under GDPR... I don't know if this is the right number, but: "Total revenues in the year to 31 July 2017 were £200.5m" - from a PDF here. 4% of £200,000,000 = £8,000,000
×
×
  • Create New...