Jump to content

Recommended Posts

Posted

Hi

I've recently had a sales pitch from Capita, saying how much money InTouch will save because student reports can be emailed home, saving money on printing costs, etc.

I asked about Data Protection and how SIMs InTouch encrypts its emails & the sales guy didn't know the answer.

Since then, I've spoken to three different people at SIMS and all I am told is that it IS encrypted - but they don't know how.

 

I've read a few technical documents, and it seems that when someone clicks "send message" or "send report" in SIMS, then InTouch send the message/report via an encrypted tunnel to Capita, who then send out the email UNENCRYPTED, so anyone can read it.

 

Our local LEA has sent out a document saying that we can't send emails with student names in, as its not safe.

So, I don't see how Capita are allowed to do this.

 

Of course, I could be wrong, but I can't get any information from Capita about this.

Does anyone know ?

Thanks

Posted
Nobody will give you a definitive answer on issues such as these as they haven't ever been tested in court. However the ICO has issued some helpful advice and I've engaged with a senior policy officer at the ICO who also spoke at two of our conferences. In essence you should not include sensitive data in emails - names are not sensitive data. Anything that gets in the way of critical communication needs to be dealt with practically - so email/txt that a child is not at school should not be encrypted. Anything that could cause embarrassment such as sexual health, special needs should be encrypted. In general a school report does not contain "sensitive" data as "defined by the act" (which is deliberately vague).
Posted

With thanks for the reply.

I completely understand your definition of sensitive data.

But I wonder at what point a name become sensitive for example "Bob Smith" is just a name and can't really be identified.

BUT the same name on a report with a school letterhead, becomes more of an issue - as that student can be uniquely identified.

 

Its a shame SIMs doesn't have options to encrypt data. For example, I am doing a trial of CipherPost Pro messaging and this is very good.

I just wonder if SIMs will offer any sort of options to integrate this in the future.

 

Since there is so much "Grey" its seems dangerous to use InTouch, especially since I can't get any real answer from Capita on the phone / via email.

 

With thanks for the advice.

Posted

I did discuss the use of InTouch to send school reports out with the ICO policy advisor - she understood what we were doing and didn't raise any red flags based on the "normal" content of a school report. BTW printed school reports aren't encrypted and could end up in the wrong place. One huge message that the ICO gave was that they are there to encourage the appropriate sharing of data and not to block it.

 

I'll take on-board your observations on encryption options for future consideration.

Posted (edited)

The reality of modern email is that much more of it *can* be encrypted end to end than you think although not all providers choose to make use of this.

 

We use a mail sending platform which attempts to negotiate a TLS encrypted connection with the recipient's mail service (e.g. Hotmail) if this is successful then the mail (and attachments like student reports which can also be emailed from Schoolcomms in bulk) are sent encrypted to the mail service, and if the recipient views their mail through a web client then you have end to end encrpyted mail. This is with no need for additional passwords (e.g. CipherPost).

 

Hotmail, Google, AOL and others all provide those TLS connections.

 

So can you guarantee that *all* email you send is encrpyted end to end? No

 

If the recipient *wants* their email to be encrypted end to end (and is willing to choose a mail provider and access method on that basis) will it be? Yes

 

Like Phil, I would make the comparison to the alternative - sending in the post (or worse still pupil post). You could send it secure signed for delivery, if the recipient choose to open it in front of the postman, stick it on their noticeboard in view of a window, or throw it in the bin without shredding it, then it's all for nothing.

 

Email through a provider like Schoolcomms who makes these encrypted connections direct to email services I would say is significantly more secure than other practical alternatives.

Edited by Schoolcomms

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...