clangstaffnhts
Members-
Posts
20 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by clangstaffnhts
-
Thanks for the response. Did you have to apply any settings for CuteDPF to produce a single file? I've just tried this but I'm having the same issue.
-
Hello, I've seen a few other threads that don't quite answer my queries so starting a new one for advice. We are a secondary school who is seeing an increasing number of complex SARs/ERRs. Providing emails and other Office 365 content is by far the most challenging aspect of handling requests. CURRENT PROCESS: 1. We are currently using Microsoft Purview and the Content Search to find email content and export this as a PST. Before the Purview updates it used to be relatively easy to search for and export emails on mass. This tool used to remove duplicate emails and provide us with a .PST file output. I understand that E-Discovery Premium will be required to remove duplicates now. 2. Once the .PST has been exported this is imported into the Outlook Classic 2019 desktop app. I am able to create a single folder with all email content in one place (which is my preference). From the desktop app we can then review, manage and delete specific emails. Once happy with the content remaining, we would export to PDF so that can be redacted as necessary. **ISSUE** Recently it seems further changes have been made and I am unable to print all emails to a single PDF file. I am using the 'Microsoft Print to PDF'. Previously this would print all emails into a single PDF however, it is now prompting me to save each email as a new file instead. Does anyone have any ideas how I can print to a single PDF file again? --- Does anyone have any suggestions how we can improve our process and any solutions to the PDF export option?
-
@Olliedawg did you manage to find a solution to this? We're having a similar issue with 2500 emails to sort through!
-
We have created an account namely 'School Calendar' the member of staff that manages the school calendar then creates and manages events on this calendar. The calendar is shared with our all staff distribution list/security group which grants any member of that group access to the details of the calendar as long as your group is up to date everyone will have access. For most the calendar automatically appears in their calendars area however, if it does not all they need to do is click 'Add calendar', 'From directory' and then search for 'School Calendar'. To expand on this further we then have separate calendars for other purposes - for example a publicly accessible calendar for parents that is then pulled through our website. Rather than recreating all events on a new calendar, relevant events are just shared with the relevant calendars.
-
@GrumbleDook can you shed any light on this topic? It seems that every school I talk to is struggling to decipher what is classed as a communication falling under legitimate interest and what requires consent. Where do we draw the line is a school trip seen as essential communication or do we require consent for this? As a school that prides itself as being at the centre of the local community it seems a shame to be forced to into ending advertisements for local events or seek consent from all parents which will take time to launch, collate and additional time to update mailing lists before sending each communication.
-
Retention Periods
clangstaffnhts replied to gmonks's topic in Data Protection & Information Handling
@GrumbleDook we are currently investigating the automatic deletion/retention of emails within Office 365. Although just in the testing phase at the moment I think we will most likely look at a 3-5 year turnover (5 would take us to the lifespan of a student at the school) for staff emails allowing staff to go back and find emails that may still be useful or relevant and unless categorised for a specific purpose they will then be deleted at the end of the time period. We're taking the stance that if an email contains important info such as Safeguarding data that we are required to keep by law a record of this should be kept within the designated Safeguarding system (CPOMS in our case) and then it doesn't matter that the communication has been deleted from the email platform. -
@tracyousedale I would be tempted to hold off. We have committed to using this as it seemed like a great option for us to manage data collection securely and our initial testing worked without issue. However on launching on a wider level in school we've had issue after issue with this - Capita have provided us with factually incorrect information regarding the SIMS Parent capability as well as their being on going technical errors in their system that we have been waiting weeks with solution yet to be provided. The potential is huge however it comes down to Capitas poor customer service on this one.
-
With regards to the 'Contact can only see self' option - would this result in a data breach if divorced parents were able to see each others contact details? It seems ridiculous that Capita would launch a product to schools with the default option resulting in a potential data breach for the school! Why would the option be there at all if there was a risk of a data breach? Any clarification around this would be useful. @GrumbleDook can you offer any guidance on this?
-
Visual Data Map
clangstaffnhts replied to clangstaffnhts's topic in Data Protection & Information Handling
Thanks for the info Narwhal that sounds like a fairly simple way of doing this. Just to confirm do you show the actual data flow or list list all the source points? For example would the map show that data data coming from parents goes into specific internal systems and not others and then moves into specific external systems. -
We are well underway with our schools data audit exercise documenting all data that comes into the school on a spreadsheet but to date have not created any visual representations of this data. Has anyone created any visual data maps? - if so do you have anything you can share your examples. Is this a legal requirement? I've found the attached example from the latest DFE guidance however with the vast amount of data and systems we use in a secondary school I've no idea how to begin mapping this visually.
-
data mapping for GDPR
clangstaffnhts replied to ryoung's topic in Data Protection & Information Handling
DPO... what DPO? Unfortunately the school is yet to appoint a DPO hence me chasing my tail trying to make some progress with this in advance of 25th May! Thanks for the info though - this is useful. I did think it was a big ask to have to list every date field processed by each external platform. I think I will take the approach of listing a data set data is pulled from and then listing individual data fields only for Special Category data such as ethnicity. For example the GCSEPod online learning platform processes data from our 'Student personal data set' (which is their general personal info such as name, DOB etc) and the following data field from the 'Student Special category data set' 'Ethnicity'. -
data mapping for GDPR
clangstaffnhts replied to ryoung's topic in Data Protection & Information Handling
Just to confirm is it a requirement to list which data fields are transferred to external systems or is it enough to say that personal or special category data is transferred to the system? Also do we have to list each element of data within our privacy policies or is it enough to say that personal and special category data is processed to the third party system in question? -
Thanks for the response @rom1984 - there are a couple of US companies we currently use. Just to confirm if a company self certifies to the privacy shield are they complaint with GDPR or would we still be required to create a contract between ourselves and the company? I know one company certainly is certified under the EU-US Privacy Shield but another may not be.
-
I am struggling to find a clear answer to this one... If we are using a third party company whose data centres are based outside the EU - what additional measures do we need to take to ensure compliance with GDPR? Are we still able to use 'Public interest' as our lawful basis if this is a day to day function required to run our school?
-
Accelerated Reader - Data residency
clangstaffnhts replied to ozydave's topic in Data Protection & Information Handling
I have received the following from the DPO at Renaissance Learning. --- Thanks for reaching out. I am the Data Protection Officer for Renaissance and am spearheading our GDPR compliance issues. You are correct that right now data is transferred to our US data centres. While that may change later this year, that is the current state of things. Renaissance is certified under the EU-US Privacy Shield for such transfers. We will be rolling out a data processing addendum in April related to GDPR compliance and anticipate that it will address any data-transfer issues not already address by our contracts. If you have any other questions, please feel free to reach out. Best regards, Eric Eric Barber | CORPORATE COUNSEL AND DATA PROTECTION OFFICER -
Accelerated Reader - Data residency
clangstaffnhts replied to ozydave's topic in Data Protection & Information Handling
Any updates on this would be greatly appreciated - I'll send them an email too. Hopefully they'll consider using the EU model! -
Accelerated Reader - Data residency
clangstaffnhts replied to ozydave's topic in Data Protection & Information Handling
Did you hear anything back about this from Accelerated Reader? This is a system we are also using and we are desperately trying to avoid the data outside of the EU situation as there are lots of hoops to jump through! -
Recommend me an outsourced DPO
clangstaffnhts replied to enjay's topic in Data Protection & Information Handling
It may be worth getting in touch with your local authority - I know our LA are looking at working with DP services including DPO's that can be shared by multiple schools to spread the costs out. I also had a quote of £4000 per annum from a private It support company local to us. -
data mapping for GDPR
clangstaffnhts replied to ryoung's topic in Data Protection & Information Handling
It looks clear and simple ryoung I agree with enjay though as it is an issue we are also having. Many of our data collections are then processed into up to 10 other systems for various reasons. It would be very hard to map all this so clearly. Are you going to the degree of listing each data field? For example within a student enrolment we collect many data fields.
