Jump to content

Recommended Posts

Posted

If you have any questions (as regards for schools /public sector/ GDPR in general as applies to you) please feel free to post them here.

 

This week GDPR meetings offer us an opportunity to ask questions of the ICO regulators and a cross sector of child's rights' acdemics, technologists, industry and NGOs. We will be considering consent, profiling, and age verification, among the broader issues. I will gather the questions up, and respond in bulk next week as a post, after the discussions. I can also offer to repeat on a regular basis after that, based on need.

Posted

By an odd coincidence I got this on twitter DM from a school technician. They're okay for me to put it on here.

Does GDPR replace, supplement or work alongside DPA?Does GDPR just apply to data held electronically?In the context of schools, what constitutes an organisation (ie individual schools or LA?) and should the Data Controller be local or at LA level, given the requirement to be "Suitably qualified and an expert in DP law"?I am thinking that a whole school information audit would be a very useful exercise, recording types of data, how long it is kept for, why it is kept, where it is kept and how it is tagged for searching purposes. Also, who it is shared with - which is why identifying the "organisation" is critical - if the organisation is at school level then we need to document any sharing at LA level and DFE etc? Management ie HT, must be involved in this audit to ensure compliance to what is documentedWill there be a template consent letter provided by LA or RBC?Are children's photos "personal data" - they won't have names but could have uniforms identifying school? In the age of facial recognition I am not sure how long we can argue that the photos need names to be personally identifiable?Do we now need express (& separate) permission from parents to store children's photos and work on school servers?It will be very difficult to provide requested information to a subject on photos stored by school as they aren't tagged and won't be searchable in a database?Now we are using MyDrive/ email etc is it irrelevant whether photos of children are taken on personal or school devices, given the ease of transfer of data to outside of school?"Transferring personal data outside the UK" - would this include student usernames, account etc transferred to various software suppliers? eg Scratch

Posted (edited)
By an odd coincidence I got this on twitter DM from a school technician. They're okay for me to put it on here.

 

Just going to tidy this up so we can see the questions in full, making it easier to see the range and depth of them.

 

Does GDPR replace, supplement or work alongside DPA?

 

Does GDPR just apply to data held electronically?

 

In the context of schools, what constitutes an organisation (ie individual schools or LA?) and should the Data Controller be local or at LA level, given the requirement to be "Suitably qualified and an expert in DP law"?

 

I am thinking that a whole school information audit would be a very useful exercise, recording types of data, how long it is kept for, why it is kept, where it is kept and how it is tagged for searching purposes.

 

Also, who it is shared with - which is why identifying the "organisation" is critical - if the organisation is at school level then we need to document any sharing at LA level and DFE etc?

 

Management ie HT, must be involved in this audit to ensure compliance to what is documentedWill there be a template consent letter provided by LA or RBC?

 

Are children's photos "personal data" - they won't have names but could have uniforms identifying school? In the age of facial recognition I am not sure how long we can argue that the photos need names to be personally identifiable?

 

Do we now need express (& separate) permission from parents to store children's photos and work on school servers?

 

It will be very difficult to provide requested information to a subject on photos stored by school as they aren't tagged and won't be searchable in a database?

 

Now we are using MyDrive/ email etc is it irrelevant whether photos of children are taken on personal or school devices, given the ease of transfer of data to outside of school?

 

"Transferring personal data outside the UK" - would this include student usernames, account etc transferred to various software suppliers? eg Scratch

 

 

 

There are a lot of questions there and there is a lot of information already available to answer these.

 

@jenatddm is it worth responding to questions where the answers are already known?

Edited by GrumbleDook
Posted

I'll answer the first 4 as they are easy!

 

Does GDPR replace, supplement or work alongside DPA?

 

GDPR replaces DPA although much of the DPA is still in place

 

Does GDPR just apply to data held electronically?

 

No any Data Protection Law is about all personal data. However the reason GDPR has been introduced is because so much personal data is stored, and often used unlawfully, electronically.

 

In the context of schools, what constitutes an organisation (ie individual schools or LA?) and should the Data Controller be local or at LA level, given the requirement to be "Suitably qualified and an expert in DP law"?

 

Any organisation that is registered with ICO (and all schools should be) identifies who is the data controller https://ico.org.uk/about-the-ico/what-we-do/register-of-data-controllers/

 

I am thinking that a whole school information audit would be a very useful exercise, recording types of data, how long it is kept for, why it is kept, where it is kept and how it is tagged for searching purposes.

 

I agree 100% that an audit should be done as it would be difficult for you to demonstrate compliance without it. However be warned it wont be a 5 minute job!

Posted

I wanted to ask about this ;

 

The scope of the term “personal data” is being expanded, so it is now defined as “any information relating to an identified or identifiable natural person”.

 

If students are signed up to an online system with just their name and email address does this constitute identifiable information?

Posted

I think it does, the regulation makes a few references to anonimisation.

A potential issue I thought about the other day was this..

There is a very popular primary on-line system which helps with maths, english etc etc

'Behind the scenes' it records a huge amount of information about each child in the class in the school.

eg - how many times they took particular tests, how long on each question etc.

 

If that data was hacked it could easily be used by the 'outside school education providers' to spot trends in any particular school.

Come school fete - book a stall - make sure that you emphasise one or two particular features of your offering, or at least make sure that the general theme of your presentation actually matched the holes.

 

Heres a second interesting question .. a head of key stage signed up to that facility. Are they now the data controller for that part of the school adherence?

Posted

Mike thanks for the questions. I need a little help to understand these two better:

 

1. Come school fete - book a stall - make sure that you emphasise one or two particular features of your offering, or at least make sure that the general theme of your presentation actually matched the holes.

 

2. Heres a second interesting question .. a head of key stage signed up to that facility. Are they now the data controller for that part of the school adherence?

Posted

Yes I agree there is, but I'll gather up weekly and do a bunch at once if OK with you. If we gather questions over time here, and I do the leg work to get the answers and collate the materials into a decent format, could someone help me build the behind-the-scenes structure of an open and free at-a-glance searchable FAQ on GDPR-in-education on a single page here? I believe it would be helpful for you. I'll get and post answers to all questions asked - including the basics - and whereever possible signpost the answer to official definitions, rulings, opinions and make clear where there is fact, or different opinions (as some GDPR is imprecise). The risk is that there is a lot of misunderstanding - and poor quality materials even from commercial GDPR providers out there don't help. Much of the concerns will be addressed by clear understanding of the legal basis for data collection. Is it a census need? Is it a requirement or nice-to-have? How can schools make something 'required' where must they offer an alternative (apps for health and absence reporting for example). A good starting point is to look at current policies and sharing practices which should already be in place. But that starts with a data audit and 'fit-gap', first recognising what the future (GDPR) process model should look like, what today's is, and targeting the gap in between, to identify what needs to change.

 

One good place to start is the ICO presentation for education: https://youtu.be/RZUlsdyREvg

  • Thanks 1
Posted
Yes name and email address are both personal data. So is IP address.

I think this is a little confusing but perhaps that is because the definition is.

 

When we talk about personal data in the context of the DPA or GDPR, the key is whether it identifies a unique living individual within the context of the data. So the name "John Smith", is not by itself personal data (because there are many John Smiths around). However usually that data will have some context, so a list of students in a particular school (even where that metadata does not appear in the list) will usually make that unique so in that context, name must be treated as personal data. Occasionally, people come along with an unusual name that is itself globally unique. So while a name by itself may not be personal data, it is dangerous to assume that a list of names and other attributes should not be treated as if it is personal data - because those people might be in the list.

 

I think it would be highly unusual for an IP address by itself to be able to be considered personal data, more likely it will be data that is recorded along with other data that does personally identify you, so needs to be managed and disclosed under the terms of the DPA.

Posted
I think this is a little confusing but perhaps that is because the definition is.

 

When we talk about personal data in the context of the DPA or GDPR, the key is whether it identifies a unique living individual within the context of the data. So the name "John Smith", is not by itself personal data (because there are many John Smiths around). However usually that data will have some context, so a list of students in a particular school (even where that metadata does not appear in the list) will usually make that unique so in that context, name must be treated as personal data. Occasionally, people come along with an unusual name that is itself globally unique. So while a name by itself may not be personal data, it is dangerous to assume that a list of names and other attributes should not be treated as if it is personal data - because those people might be in the list.

 

I think it would be highly unusual for an IP address by itself to be able to be considered personal data, more likely it will be data that is recorded along with other data that does personally identify you, so needs to be managed and disclosed under the terms of the DPA.

 

This was one of the problem with the use of the old Impact Levels.

 

People would sometimes look at them in isolation. Full Name could be IL1, but add in the school name as context and it collectively goes to IL2 ... but the school name itself is not IL2 ... it is the context of the collated data. You don't say that a number of data elements that are all IL1 will remain at IL1 ... if the context when collated makes the uniqueness more obvious *and/or* the data elements increase in the sensitivity ... then the IL would rise.

 

To some extent I can understand why they ditched them ... but it makes it more difficult to explain context at times to some folk.

  • 2 weeks later...
Posted
I suspect that the query about data controllers and 'suitably qualified and an expert in DP law' is actually asking about the Data Protection Officer role rather than the Data Controller...
Posted

Sorry for late reply on this -

my comment about 'school fete' is borne out of experience. I was one of Dorling Kindersley Family Learning top selling individual reps. Prior to any school event , I would ask the head or teacher responsible which areas of curriculum were being flagged to parents. I'd then make sure I brought lots of copies of relevant books and CDs along. The comment about 'behind the scenes' above shows how valuable the info could be.

 

The second comment happens all the time..

"I've signed u up for this from my xyz budget .. it will need a llt the children from these classes adding"

Posted

Hi Mike - the first scenario, you are not getting any personal information though ... you are getting information on the curriculum and making sure your stock is adjust appropriately. If the school was to say that x number of pupils are likely to need more resources at home on particular areas, then you are still not getting personal data, just an anonymised set of information.

 

The second ... where a member of staff signs up for something that involves the transfer of personal data and then tries to organise adding students ...

In that case, the school needs to have it clear within their policies that entering into any contract or arrangement which involves the sharing of data (e.g. signing up pupils and/or parents) need authorisation by the DPO. Failure to do this would be a breach of the school policies and subject to disciplinary action. Organisational measures rather than technical measures.

  • 1 month later...
Posted

Dear All - work-in-progress collaborative doc is here, and open for contributuons. It is shared between academics, legal-, data protection-, and child rights' specialists, as well as regulators and more, and open to all.

 

As yet, it does not intend to offer answers (some are known, some are unknown) but it aims to capture and highlight some of the applied, and perhaps the slightly more tricky thematic areas, under the relevant aspects of the GDPR. especially those which may mean a change or review of current policy and/or practice in schools in education in England today. It is not everything by any means. But it's open to all for comment, and open for suggestion for other things that are missing. It's welcome to be shared widely, and you can post questions to me via comment, email, here, or DM on twitter. Or comment here.

 

There will be some legal unknowns until some of the UK interpretations are defined in the coming UK legislation to finalise the derogations, and there is more to come that is not expected from the Article 29 Working Party until December on consent.

 

Work-in-progress. Feel free to join in. It will contribute to a report on data privacy and protection in education, with a view to GDPR readiness.

 

(Full link: https://docs.google.com/document/d/10KD1adCAeWXG_5SioUNBSzu-yfsNdIdtlj5xlOqbIFQ/edit# )

 

If you have any questions (as regards for schools /public sector/ GDPR in general as applies to you) please feel free to post them here.

 

This week GDPR meetings offer us an opportunity to ask questions of the ICO regulators and a cross sector of child's rights' acdemics, technologists, industry and NGOs. We will be considering consent, profiling, and age verification, among the broader issues. I will gather the questions up, and respond in bulk next week as a post, after the discussions. I can also offer to repeat on a regular basis after that, based on need.

  • Thanks 3

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...