Popular Post elsiegee40 Posted May 1, 2016 Popular Post Posted May 1, 2016 Suggested privacy notices for schools and local authorities to issue to staff, parents and pupils about the collection of data. https://www.gov.uk/government/publications/data-protection-and-privacy-privacy-notices 5
fiza Posted October 7, 2017 Posted October 7, 2017 This guidance has just been updated on 5th Oct so worth a look. 1
jenatddm Posted October 8, 2017 Posted October 8, 2017 As you might imagine we have ongoing discussion with ICO and DfE about their privacy notice template. Questions: 1. Do you think these privacy notice templates can be easily understood by a child? (Note that "concise,transparent, intelligible and easily accessible, using clear and plain language, in particular for any information addressed specially to a child" is a Data protection legal obligation) 2. Do you understand from this, that the Department for Education will give children and workforce identifiable and sensitive personal confidential data (not anonymous) to commercial companies, journalists, charities, think tanks and researchers without asking for consent? 3. Therefore, do you think these privacy notice templates are useful? 3
enjay Posted October 9, 2017 Posted October 9, 2017 2. Do you understand from this, that the Department for Education will give children and workforce identifiable and sensitive personal confidential data (not anonymous) to commercial companies, journalists, charities, think tanks and researchers without asking for consent? That's the real catch, isn't it. We say share information with the DfE, and data owners can't opt of that processing because we are legally obligated to provide it. What the DfE do with it after that is another matter entirely, and not mentioned in our privacy notices. So I guess the follow-up questions are: Can data owners opt out of DfE sharing their data? Should our privacy notice indicate some of the processing the DfE will do with our data? And of course the other question, why are we allowing DfE to compel the data when they're going to share it in those ways? If a commercial company or journalist asked us for that same data, we would refuse...
pete Posted October 9, 2017 Posted October 9, 2017 Should our privacy notice indicate some of the processing the DfE will do with our data? Yes. Ours has this (we specifically highlight the DfE/LA/LRS earlier in the doc): As noted above, we are required by law to pass some information about you to the DfE and, in turn, this will be made available for use by the LA. The DfE may also share information we provide to them with third parties. This will only take place where legislation allows it to do so and it is in compliance with the Data Protection Act 1998. Decisions about whether the DfE releases this personal data to third parties are subject to a robust approval process and are based upon a detailed assessment of who is requesting the data, the purpose for which it is required, the level of sensitivity of data requested and the arrangements in place to store and handle the data. To be granted access to pupil level data, requestors must comply with strict terms and conditions covering the confidentiality and handling of data, security arrangements and retention and use of the data. For more information on how this sharing process works, please visit: https://www.gov.uk/guidance/national-pupil-database-apply-for-a-data-extract. For information on which third party organisations (and for which project) pupil level data has been provided to, please visit: https://www.gov.uk/government/publications/national-pupil-database-requests-received. If you would like more details about how the DfE and/or LA store and use your information, please go to the following websites: http://www.lincolnshire.gov.uk/local-democracy/information- governance/data-protection/ and https://www.gov.uk/guidance/data-protection-how-we-collect-and- share-research-data.
enjay Posted October 9, 2017 Posted October 9, 2017 Decisions about whether the DfE releases this personal data to third parties are subject to a robust approval process and are based upon a detailed assessment of who is requesting the data, the purpose for which it is required, the level of sensitivity of data requested and the arrangements in place to store and handle the data. To be granted access to pupil level data, requestors must comply with strict terms and conditions covering the confidentiality and handling of data, security arrangements and retention and use of the data. Of course, some of these third parties might leave the data on the train or in the back of a taxi... Here's a thought - would the school still be liable if that happened? Under DPA, it is only the processor who takes the hit for a breach, i.e. the person/organisation who left it in the taxi, but under GDPR the processor and controller will be liable. So when the DfE pass data we gave them on to a third party, are we still the Controllers of that data, or did DfE become the Controller when they forwarded it on? 1
elsiegee40 Posted January 14, 2018 Author Posted January 14, 2018 Updated 3 Jan 2018 and available in link on opening post 3
elsiegee40 Posted July 21, 2018 Author Posted July 21, 2018 Updated 20/7/18 Link in opening post of thread
jenatddm Posted November 1, 2018 Posted November 1, 2018 Of course, some of these third parties might leave the data on the train or in the back of a taxi... Here's a thought - would the school still be liable if that happened? Under DPA, it is only the processor who takes the hit for a breach, i.e. the person/organisation who left it in the taxi, but under GDPR the processor and controller will be liable. So when the DfE pass data we gave them on to a third party, are we still the Controllers of that data, or did DfE become the Controller when they forwarded it on? The Controller determines the purpose and method of processing. So when the DfE pass data a school collected for its own purposes, which DfE gives on to a third party, the school is still the Controller of that data -- for the purposes for which the school collected it, *and* DfE then becomes the Controller when they require the data under a lawful basis and determine the purposes they collect it for, and it will be forwarded on for -- so DfE becomes joint controller *and* the third party if they then use it for their own purposes, not determined by the DfE -- could even also become joint controllers. Because the data are copies, not a single thing, you can end up having multiple joint-controllers of the same data -- each copy may be under the control of a separate body, for separate purposes. What fails today, is transparent communication of all those purposes to the child and/or parent. (and to the school in the case of the DfE distribution).
elsiegee40 Posted August 3, 2019 Author Posted August 3, 2019 The DfE has updated the model documents on 30/7/19 https://www.gov.uk/government/publications/data-protection-and-privacy-privacy-notices 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now