In this month’s newsletter:

It’s Here!! Version 2 upgrade of the SchoolPro TLC Data Protection Portal

Read our reminders about cyber security threats including staff training

Review the latest data protection-related DfE update and other key stories that may impact Data Protection in schools

Throw a spotlight on a partner we recommend working with

Ensure that you are aware of some of the latest cyber threats

Discover what Data Protection question we have answered this month

New and updated compliance templates from our online platform

A round up of data protection in the news

Nothing says Merry Christmas like a chunky upgrade to your favourite support software so this month we have started off focused on our Version 2 upgrade to the Data Protection Portal. Ho ho ho! 🎁🎅

There is also:

We have also created another staff guide for this month. The focus is on common breach risks (linked to email as that is the main vector for breaches currently) as well as some further cyber advice for staff. The more we can all raise staff awareness of these issues, the more we can reduce the risk for individuals and organisations.

As always, if you have any further questions about the topics below, or if you would like to book your next visit from us, either online using video conferencing or onsite, please get in touch via DPO@schoolpro.uk.

Don’t forget, if there is anything else that you need support with at this time, please ask and we will do whatever we can within our capacity to assist.

Stay safe and healthy!

 

 

SchoolPro TLC Data Protection Portal – V2 Launch!

If you haven’t seen already, we launched our Version 2 upgrade of our Data Protection Portal earlier this week. We’re excited about it and we’re sure you are too. After all, it is Christmas and it is a time for giving!

Find out what we’ve given you here…


Data Protection Portal Upgrade – Version 2!

Staying Safe Over Christmas and into the New Year

Schools are experiencing cyber threats at an ever increasing rate from simple phishing attacks to more sophisticated penetration methods. We want to encourage all schools to reduce their risk as much as possible and this can be done at a technological level with your systems, as well as working with your staff and pupils to reduce their risk.

Cyber Threats

The risk of cyber threats can be reduced using simple but effective cyber hygiene practices including taking regular backups, using antivirus and keeping it updated, and being particularly careful with email security and not clicking on any suspicious links in emails. Staff training (as well as raising awareness) is also key to this and can be completed using our Cyber Security for School Staff training course (written by the NCSC) on our website.

Good password practice is also an important step for your staff and pupils. This includes using strong passwords (14 characters using a combination of letters, numbers, symbols, capitals/lowercase, or a technique such as combining three or four completely random words) and using different passwords for each system used. Not sharing passwords is also important and using multi-factor authentication, where possible, dramatically increases the effectiveness of security.

Last month, we highlighted parts of the Cyber security standards for schools and colleges | GOV.UK including the need to conduct a DPIA, ensure that you have at least 3 backup copies of your data, and, as we’ve mentioned before, make sure that staff are adequately trained in cyber threats.

Email Risks

We have published this advice before but it has been a while since we last did. Always worth a reminder:

Data Protection and DfE Updates

Fewer updates from the DfE regarding data this month. The one that has come through is as follows:

Some other general data protection updates of note, however, are as follows:

Partner Spotlight

ShredPro UK

Each month we throw the spotlight on a different partner. This month it is ShredPro.

ShredPro is a professional paper shredding company that offers a secure, efficient and cost effective shredding service adhering to the highest standards in the industry to ensure maximum protection of your confidential information.

Delegated Services Logo

Recent and Current Cyber Threats

NCSC Annual Review 2022

The National Cyber Security Centre (NCSC) has published its Annual Review for 2022 including topics such as ‘Threats, Risks and Vulnerabilities’, ‘Resilience’, ‘Technology’ and ‘Ecosystem’. You can read the full report here:

NCSC Annual Review 2022  NCSC.GOV.UK

How to assess and gain confidence in your supply chain cyber security

Useful guidance for Multi-Academy Trusts and large schools – practical steps to help medium to large organisations gain assurance about the cyber security of their organisation’s supply chain:

How to assess and gain confidence in your supply chain… | NCSC.GOV.UK

Choosing the right type of authentication methods

We would certainly recommend that organisations are looking to move away from just using passwords wherever possible and we know that many schools and Trusts are already implementing multi-factor authentication. Here are some recommended authentication models for organisations looking to move ‘beyond passwords’:

Authentication methods: choosing the right type | NCSC.GOV.UK

Recent Threats Identified…

 

Previously Asked Question

We are asked data protection questions by schools on a daily basis and there are some questions that come up regularly. We now have an FAQ section on the website for these and all of our answers are published there. You can find this on the Data Protection page of the website or in the blog. As it is relevant for this time of year, and we are still being asked this even this close to Christmas, here is a classic question. We will publish more in future newsletters:

Answered December ’20.

From a pure data protection point of view, giving out the names of the children within a class or year group to all of the parents is not a good idea if they haven’t given consent. Whilst a first name on its own might not seem like a lot of data (because it isn’t), it can then be matched to the year and class of the child and someone could start to build a picture (even if it is a very blurry one at this point). And it only takes one parent to complain that they didn’t want their child’s name given out for the school to have to answer some awkward questions. Here are some alternative ideas though:

  • Add a line on the consent form regarding sharing a first name only with other members of the class/group etc for the purposes of Christmas/Birthday lists when the child joins the school or at the start of the year. Not helpful at this point for the current cohorts we realise but useful for next year onwards.

     

  • Ask consent at this point. This may not be practical depending on the size of the classes but it could be as simple as the class teacher asking parents that they are happy for their child’s name to be on the list as they pick their child up at the end of the day and ticking them off. Or, if the school is using online solutions for communication with parents, putting the question out on that or posting a poll for them to complete.
  • Finally, the other thing a lot of schools are doing now, is they are getting the parents to collate the list between them. Then it is the parents that are giving each other the children’s names and not the school at all. Some parents have done this by creating a sign up sheet to go on the outside of the class door so parents add their child’s name at pick up time and then the list is circulated by one of the parents. Others have parents that setup WhatsApp or Fb groups for the other parents in their class and they share the children’s names that way.

Answered December ’20.

From a pure data protection point of view, giving out the names of the children within a class or year group to all of the parents is not a good idea if they haven’t given consent. Whilst a first name on its own might not seem like a lot of data (because it isn’t), it can then be matched to the year and class of the child and someone could start to build a picture (even if it is a very blurry one at this point). And it only takes one parent to complain that they didn’t want their child’s name given out for the school to have to answer some awkward questions. Here are some alternative ideas though:

New & Updated Resources on the Portal

Since our last newsletter, we have added 9 new documents and updated 1 document:

New Documents

Updated Document

When did our phone numbers become the new identifier du jour? | IAPP

Twitter confirms vulnerability exposed data of anonymous account owners | Engadget

Twilio customer data exposed after its staffers got phished | The Register

Slack exposed hashed passwords for years | The Register

Mozilla: 18 top reproductive health apps share your info | The Register

Ransomware attack on a UK water company clouded by confusion | The Register

Twitch Confirms Massive Data Breach, Said a Hacker Accessed Company’s Servers | Crossover 99

Tech News : Major NHS Supplier Hit By Ransomware Attack | ReformIT

Facebook and Instagram apps can track users via their in-app browsers | Engadget

Edtech companies breaking UK data laws, privacy campaigners claim | Financial Times

ICO acting against eight individuals over alleged theft of road traffic accident data from garages | ICO

Former health adviser found guilty of illegally accessing patient records | ICO

Most hacked passwords revealed as UK cyber survey exposes… | NCSC

Gloucester Council planning site still disrupted from cyber attack | BBC News

Manx Care faces ÂŁ170k fine over patient data breach | BBC News

Sydney school’s use of fingerprint scanners in toilets an invasion of privacy, expert says | The Guardian

Instagram fined €405m over children’s data privacy | BBC News

Classroom app Seesaw abused to send ‘inappropriate image’ | The Register

Nearly Half Employees use Risky Login Practices | ReformIT

When did our phone numbers become the new identifier du jour? | IAPP

Twitter confirms vulnerability exposed data of anonymous account owners | Engadget

Twilio customer data exposed after its staffers got phished | The Register

Slack exposed hashed passwords for years | The Register

Mozilla: 18 top reproductive health apps share your info | The Register

Ransomware attack on a UK water company clouded by confusion | The Register

Twitch Confirms Massive Data Breach, Said a Hacker Accessed Company’s Servers | Crossover 99

Tech News : Major NHS Supplier Hit By Ransomware Attack | ReformIT

Facebook and Instagram apps can track users via their in-app browsers | Engadget

Edtech companies breaking UK data laws, privacy campaigners claim | Financial Times

ICO acting against eight individuals over alleged theft of road traffic accident data from garages | ICO

Former health adviser found guilty of illegally accessing patient records | ICO

Most hacked passwords revealed as UK cyber survey exposes… | NCSC

Gloucester Council planning site still disrupted from cyber attack | BBC News

Manx Care faces ÂŁ170k fine over patient data breach | BBC News

Sydney school’s use of fingerprint scanners in toilets an invasion of privacy, expert says | The Guardian

Instagram fined €405m over children’s data privacy | BBC News

Classroom app Seesaw abused to send ‘inappropriate image’ | The Register

Nearly Half Employees use Risky Login Practices | ReformIT

If you have any other questions about this or any other data protection topic, please contact us at DPO@schoolpro.uk.

Stay safe and healthy,

The SchoolPro TLC Team

SchoolPro TLC Ltd (2024)

SchoolPro TLC guidance does not constitute legal advice.

SchoolPro TLC is not responsible for the content of external websites.


Fatal error: Uncaught Error: Call to undefined function wc_get_cart_url() in /home/schoolpro/public_html/test.schoolpro.uk/wp-content/themes/hello-theme-child-master/functions.php:122 Stack trace: #0 /home/schoolpro/public_html/test.schoolpro.uk/wp-includes/class-wp-hook.php(324): redirect_menu_cart_to_cart_page('') #1 /home/schoolpro/public_html/test.schoolpro.uk/wp-includes/class-wp-hook.php(348): WP_Hook->apply_filters(NULL, Array) #2 /home/schoolpro/public_html/test.schoolpro.uk/wp-includes/plugin.php(517): WP_Hook->do_action(Array) #3 /home/schoolpro/public_html/test.schoolpro.uk/wp-includes/general-template.php(3208): do_action('wp_footer') #4 /home/schoolpro/public_html/test.schoolpro.uk/wp-content/themes/hello-elementor/footer.php(24): wp_footer() #5 /home/schoolpro/public_html/test.schoolpro.uk/wp-includes/template.php(810): require_once('/home/schoolpro...') #6 /home/schoolpro/public_html/test.schoolpro.uk/wp-includes/template.php(745): load_template('/home/schoolpro...', true, Array) #7 /home/schoolpro/public_html/test.schoolpro.uk/wp-includes/general-template.php(92): locate_template(Array, true, true, Array) #8 /home/schoolpro/public_html/test.schoolpro.uk/wp-content/themes/hello-elementor/index.php(36): get_footer() #9 /home/schoolpro/public_html/test.schoolpro.uk/wp-includes/template-loader.php(106): include('/home/schoolpro...') #10 /home/schoolpro/public_html/test.schoolpro.uk/wp-blog-header.php(19): require_once('/home/schoolpro...') #11 /home/schoolpro/public_html/test.schoolpro.uk/index.php(17): require('/home/schoolpro...') #12 {main} thrown in /home/schoolpro/public_html/test.schoolpro.uk/wp-content/themes/hello-theme-child-master/functions.php on line 122