CGeorge

Uploaded from authorPOINT
Views:
 
     
 

Presentation Description

No description available.

Comments

Presentation Transcript

Slide1: 

JISC Legal Issues of Online Learning Environments 2005 Data Protection – Peeking Over the Study Cubicle… Online! Dr. Carlisle George Middlesex University, UK c.george@mdx.ac.uk

Summary of Presentation: 

Summary of Presentation Introduction Brief Review of the Data Protection Act Managed Learning Environments (MLEs) Security of Data in MLEs Data gathered through use of VLEs Personal data Appropriate notice to students Uses of data Goods records management Potential objections

Introduction: 

Introduction Networks and Internet used to facilitate activities in the HE sector New capabilities New risks

A brief Review of the Data Protection Act (DPA): 

A brief Review of the Data Protection Act (DPA) Obligations on those who process personal data (data controllers) Rights to those who are the subject of that data (data subjects) Information Commissioner (IC)

DPA Review: 

DPA Review Personal Data (Durant decision) Sensitive Personal Data ‘Processing’ of Data 8 Data Protection principles Subject rights (exemptions) General Exemptions

MLE : 

MLE Managed Learning Environment (MLE) Concerned with institutional systems Student Record Systems Library Systems, Management Systems Virtual Learning Environment (VLE’s) Timetabling Systems

Slide7: 


Security of Data in MLE: 

Security of Data in MLE Obligation under 7th Principle to take all appropriate technical and organisational measures against unauthorised/unlawful processing (and destruction of data)

Organisational measures can include:: 

Organisational measures can include: Contractual arrangements Appropriate training and notices Role based security Advice on data handling and storage Measures to restrict physical access Appropriate policies on 3rd party disclosure

Technical measures can include:: 

Technical measures can include: Adequate network security (C2 standard, BS7799) Access control lists Appropriate firewall and proxy servers Anti-virus and anti-spyware Encryption Strong password measures Knowledge partitioning Physical access restrictions

Data Gathered through use of VLE: 

Data Gathered through use of VLE Possible types of data gathered What constitutes Personal Data in this context Appropriate notice to students

Data Gathered through use of VLE: 

Data Gathered through use of VLE Uses of data gathered Good Records Management Procedures Tackling potential Objections