Showing posts with label European Union. Show all posts
Showing posts with label European Union. Show all posts

Friday, 23 February 2018

GDPR and PHYSICAL security – How important is it?


Regular readers of this newsletter will know that I have paid a lot of attention and focus to the General Data Protection Regulation (GDPR). To recap, the GDPR is EU Data Protection legislation which is coming into force in May. It is a ‘beefed up’ version of the UK’s Data Protection Act 1998 and aims to introduce a common standard of data protection across the European Union – particularly covering the latest advances in social media. Despite Brexit, the UK will be under the legislation from May 25th 2018 and the legislation is expected to make its way into British law after our exit from the European Union.

In the last couple of articles that I have covered the topic of GDPR in, I have focused primarily on GDPR in cyberspace – the need to focus on cyber security in order to keep on the right side of the legislation. Cyber security in the context of GDPR is no doubt extremely important, but for this article I would like to move away from technology and focus on GDPR in the context of physical security.

When referring to GDPR and compliance, very few commentators refer to the necessity to secure physical data. However, personal data is still stored in a physical format and therefore is still subject to GDPR legislation. For example, many schools use physical folders with pupil and parent information. Remember that Article 4 section 12 of the GDPR states that a “‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;”. This means that a member of staff, or worse a pupil, accessing sensitive data without proper consent is classed as a breach.

Think also of physical computers. Most staff will have access to a computer that they use for their work. In many cases, this will contain sensitive information. Do you have a policy in your school that staff must lock their computers if they leave their desk, even if it is only for a short while? Are those computers protected with strong passwords? In my experience working in the IT industry for many years, most users will not set strong passwords. They are usually easy to guess, or in the most worrying cases, system defaults such as ‘password’.

A report for the Telegraph newspaper in 2017 found that the top 10 most common passwords are as follows:
1.       123456
2.       123456789
3.       qwerty
4.       12345678
5.       111111
6.       1234567890
7.       1234567
8.       Password
9.       123123
10.   987654321

Granted, passwords are difficult to remember, especially when you have lots of different passwords for lots of different user accounts. Nobody wants to have to keep phoning their IT department because they’ve forgotten their password again.

Nonetheless, a strong password is absolutely critical to keeping sensitive data secure. A handy tip for creating passwords is to think of a phrase that sticks in your mind. For example: ‘the quick brown fox jumps over the lazy dog’. Now take the first letter of every word in that phrase and combine them to make a word: ‘tqbfjotld’. The password itself is unlikely to be guessed, but because you remember the phrase, you remember the password.

What about the security of your devices and servers? If you keep a server on-site a determined intruder could gain access to it on location. This would allow them to copy data onto an external drive and remove it from school grounds. If you do keep a server on-site, make sure that it is in its own locked room – and preferably that that room is air conditioned to avoid overheating. If you would like an extra level of security, then CCTV is a really good option. It is now possible to get ‘Cloud CCTV’ options, whereby a camera (or network of cameras) are installed in your school and connect to the internet network. It is then possible to access a live video feed of all your cameras in one online portal. The cameras can also record snapshots or video, allowing you to obtain the evidence you need to prosecute should the worst happen. The cameras are small and unobtrusive and are reliable – speak to me if you would like to find out a little more.

A good starting point for getting your physical data security up to scratch would be to assess what data you hold in physical form, where you keep it, and whether you need to keep it any longer. First of all, any data that is not crucial to running your school should be destroyed – there is no use keeping data unnecessarily.

Build up a list of your data sources and the data you hold. Then consider who has access to it, both intentionally and possibly unintentionally. If you keep folders with sensitive information in on school grounds, are they kept in an area away from unqualified staff? Are they kept in locked cabinets? Do your staff know exactly who should have access to what and can you be sure that they know not to share information with others? If you have important data stored on hard drives in servers and computers, do you ensure that you encrypt that data?

It is also worth introducing a policy around external hard drives and USB sticks, as well as personal cloud drives such as DropBox and Google Drive. We recommend that use of external drives is at least restricted, but preferably banned outright, and the use of personal cloud storage should also be banned – it is untraceable. Personal accounts for these services follow users wherever they go, meaning staff could potentially access sensitive material even if they are no longer employed by your school.

By ensuring all your staff (and pupils) understand and appreciate GDPR and how it affects your school, you can make sure everyone is pulling in the right direction to help your school be compliant. GDPR compliance involves an effort from all stakeholders in your school and the first step is strong, unambiguous policies surrounding data security.

For more information on GDPR, or for an IT security audit of your school, please do not hesitate to get in touch with me on 0330 002 0045 or contact schools@entrustit.co.uk.

Tuesday, 10 October 2017

GDPR - top tips to get compliant

It’s that time of year again, the summer break is over and it is back into the routine for another academic year. Any bursar will tell you that September is an extremely busy time of the year with a seemingly endless list of things requiring attention. In the hubbub of the new academic year, it is easy for tasks to be put on hold, which is why I am taking an opportunity in this edition of ‘educateIT’ to gently remind headteachers and bursars of a deadline that is now two months closer – the GDPR regulation.

I’ve spoken so much with bursars about GDPR recently that I am starting to feel like a broken record, but the reality is that it is so important that it will be on the agenda right through until the 25th May 2018 deadline and beyond.

After a well-deserved 2-month break, you may be racking your brains to remember exactly what GDPR entails. The General Data Protection Regulation (GDPR) is a piece of EU legislation designed to provide a common data protection policy amongst EU member states. When it comes into effect next May, it will supersede all existing data protection regulations (in the case of the UK, that is the Data Protection Act 1998). Because current data protection legislation differs across member states and was introduced before the cloud and social media, it was clear that modern legislation was required.

No doubt that if you have heard about GDPR, you will have heard the scare stories about fines of up to €20 million for non-compliance. As an independent school, it is unlikely that you could ever face such an astronomical fine for non-compliance, these fines are reserved for the worst offenders. However, it is a safe assumption that under GDPR fines for non-compliance will move up the value chain. For more on GDPR, read my blog from March 2017 entitled “GDPR – What’s it all about and how does it affect Independent Schools?”

During my visits to Independent Schools at the tail end of last term, I was frequently asked when would be a good time to start tackling the issue of GDPR compliance. At that time, I urged schools to begin work as soon as possible – since compliance is not something that can be attained overnight. In the new academic year, with the deadline less than 9 months away, my message is that if your Independent School hasn’t begun the process of GDPR compliance, it should be as near to the top of your agenda as possible.

With that in mind, what are some key considerations an Independent School should make as it progresses towards GDPR compliance?

Firstly, it is a good idea to get acquainted with the Information Commissioners Office. This is the Data Protection Regulator in the UK. Under GDPR, an organisation that experiences a data breach of any kind is obligated to inform the ICO of the breach, exactly what was exposed and what measures are being taken to mitigate damage, within 72 hours of discovery. Failure to do so is an offence and will result in a fine. Furthermore, GDPR requires certain businesses to appoint a dedicated ‘Data Protection Officer’ who is an expert on GDPR. The details are a little cloudy on this at present, but it is quite possible that schools will fall into this category.

The next consideration involves processing of personal data and consent. GDPR gives individuals more control over the use of their personal data. At a recent visit to an Independent School, this topic came up when the bursar mentioned that they perform wealth screening on prospective parents. Whilst this is a savvy business practice, under GDPR withholding personal information for the purposes of wealth screening can only be legally performed with the explicit consent of the individuals in question. Furthermore, the school must keep a record of exactly when consent was given and must make it clear to the individual the basis for which the school requires this information. The individual may also withdraw consent at any time, at which point withholding personal information becomes illegal.

In certain instances, passive consent is allowed. For example, when a pupil enrols at a school, it is implied that the individual gives consent for personal information to be stored by the school for the purpose of providing them with an education and pastoral care.

Once you have collected that data, the question of where that data is stored arises. Whilst many Independent Schools still store all their important data in servers on-site, cloud adoption is accelerating. Popular cloud services such as OneDrive or Dropbox are provided by U.S. based companies and are powered, for the most part, by U.S. based datacentres. U.S. data protection law is not as stringent as EU legislation and reliance on U.S. based storage could lead to compliance issues.
That doesn’t mean that storing data on-site is a preferred option. In almost all cases I have dealt with in my long career in the IT industry, on-site storage options are less secure than their cloud counterparts. The only exception is for organisations that make their cyber-security a top priority, throwing vast amounts of cash at servers, monitoring software and antivirus. A cloud storage option such as ShareFile is a strong offering if security is mission critical.

A final important consideration is that of Social Media and pupil internet usage. This links back to my earlier paragraph on consent. Because most school pupils are under 16, they can never legally give consent online. An Independent School, particularly one that has boarding pupils, acts as a legal guardian for those pupils while they are on school grounds. The school is therefore legally responsible for the information they share online, and the websites and social media accounts they sign up for while on school grounds. Having a stringent acceptable use policy in place for pupils’ internet use is a good first step, but educating the pupils on the dangers of posting personal information online would go a positive step further.

As the GDPR deadline looms, I cannot stress enough the importance of taking action now. In the business sector, GDPR is getting increasing air time and most parents will be aware of the regulation by now. To show that your Independent School is on top of the changes, I recommend a letter to inform parents that your staff are aware of the changes, and that your school is making the necessary steps to reach GDPR compliance by the May 2018 deadline. Proactively reassuring parents that the personal information of themselves and their children is safe will put minds at ease.

Towards the end of the last academic year, I received a number of requests for assistance with GDPR. To Independent Schools with a genuine need and interest, I met with bursars to discuss further. I am continuing to offer this service at the beginning of this academic year. If you would like advice on GDPR compliance, please do not hesitate to get in contact with me on 0330 002 0045 or email schools@entrustit.co.uk