edutech4schools Posted May 9, 2014 Posted May 9, 2014 I have just been handed an updated e-safety document for the primary school I work in and I have noticed the requirement for encrypted keys has been removed. I mentioned this to the head and he seems to think it is fine for the teachers to use non encrypted sticks. I pointed out that the LA have this in the e-safety doc but he says that the LA version is just for guidance. Is this correct and OK?
X-13 Posted May 9, 2014 Posted May 9, 2014 Is this correct and OK? It depends on what data the sticks are holding. If it's lesson plans, I think a regular non encrypted USB will be fine. If it's pupil assessment data or anything that can personally identify a specific pupil, parent or staff member... then it needs to be encrypted [by law IIRC].
Netwacky87 Posted May 9, 2014 Posted May 9, 2014 (edited) Give him the example of...teacher has private pupil data on a memory stick, medical info, address, DOB, etc etc etc...that teacher then loses it...Explain that one away? Wouldn't want to be in the situation Edited May 9, 2014 by Netwacky87 Speling
edutech4schools Posted May 9, 2014 Author Posted May 9, 2014 If it's pupil assessment data or anything that can personally identify a specific pupil, parent or staff member... then it needs to be encrypted [by law IIRC]. Where would I find that it is illegal to do this? My issue with having lesson plans on standard keys is how do you monitor it, How would I know what they have on them. I would have thought it simpler just to have encrypted keys and be done with it.
AngryTechnician Posted May 9, 2014 Posted May 9, 2014 (edited) I pointed out that the LA have this in the e-safety doc but he says that the LA version is just for guidance. It's "guidance" in the same way that many of the rules in the Highway Code are "guidance". It's a guide for "how not to do something that would probably be deemed illegal" and also "how we determine if a c***-up is your fault". There's no specific law saying that personal data on USB keys must be encrypted, because that's not the way the UK legal system works; in most cases, the law is never so prescriptive. Laws are passed, and guidance is issued to establish how courts would interpret the law in specific cases. The Data Protection Act (1998) makes it a legal requirement to use "appropriate technical and organisational measures" to protect personal data. Encryption is widely accepted as one of the most appropriate technical measures. The authority that issues the most authoritative guidance on the DPA is the Information Commisioner's Office, and they have a nice page about encryption here: ICO - Our approach to encryption The ICO recommends that portable and mobile devices including magnetic media, used to store and transmit personal information, the loss of which could cause damage or distress to individuals, should be protected using approved encryption software which is designed to guard against the compromise of information. If that isn't enough to convince your Head that his suggested policy will not be looked upon fondly, here's a selection of articles about how the ICO has also been regularly fining businesses, local authorities, and NHS trusts for the loss of encrypted laptops and USB sticks for years now: https://www.google.co.uk/search?q=ico+encryption+fine Edited May 9, 2014 by AngryTechnician 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now