Jump to content

Recommended Posts

Posted
Can similar clarifications be requested from NI, Scotland and Wales education departments?

 

I'll put this to our DPO.

Posted (edited)

https://ico.org.uk/for-organisations/guide-to-data-protection/key-definitions/

 

So following on from the DfE's positive response to GroupCall regarding the UPN, it might be useful for future readers to have the definition of a Data process from the ICO site (retrieved 10/7/2017)

 

Data processor, in relation to personal data, means any person (other than an employee of the data controller) who processes the data on behalf of the data controller.

Example

A utilities company engages a company which operates call centres to provide many of its customer services functions on its behalf. The call centre staff have access to the utilities company’s customer records for the purpose of providing those services but may only use the information they contain for specific purposes and in accordance with strict contractual arrangements. The utilities company remains the data controller. The company that operates the call centre is a data processor.

 

Data processors are not directly subject to the Act. However, most data processors, if not all, will be data controllers in their own right for the processing they do for their own administrative purposes, such as employee administration or sales.

 

Please see our guidance Data controllers and data processors: what the difference is and what the governance implications are (pdf). This explains how to determine whether an organisation is a data controller or a data processor, and the governance implications of a controller and processor working together to process personal data.

 

Example

An organisation engages a company which provides business services to administer its employee payroll function. The organisation also engages a marketing company to carry out a satisfaction survey of its existing customers. The business services company will need information about the organisation’s employees, and the marketing company will need information about its customers. Both companies will be processing the information on behalf of the organisation, and so they are both data processors. However, they will also be processing personal data about their own employees and, in respect of that personal data, they will be data controllers.

 

Data controllers remain responsible for ensuring their processing complies with the Act, whether they do it in-house or engage a data processor. Where roles and responsibilities are unclear, they will need to be clarified to ensure that personal data is processed in accordance with the data protection principles. For these reasons organisations should choose data processors carefully and have in place effective means of monitoring, reviewing and auditing their processing. We have published guidance on Outsourcing - a guide for small and medium-sized businesses (pdf), which gives more advice about using data processors.

Edited by psydii
  • Thanks 4
Posted
Thanks @GREED. So the question is firmly down to schools to decide if processing UPN to do student entity matching is appropriate or even if functions in their data processors software such as the ability to transfer arbitrary data to another school. The problem is the guidance for schools on this issued by the DfES strongly suggests the latter is not appropriate where storing UPN in your cloud MIS and transferring data from that to another school via CTF will be OK. Personally, that doesn't move my understanding any further forward :-(.
Posted
Provided appropriate DSAs are in place, and that either Groupcall (with Xporter, or other data aggregator/extractor with their respective products) and/or the third party (direct or via Xporter/other product) are acting as the data processors on behalf of the school, then the use of the UPN is, and I quote, "admissible to share data in accordance with the usual transfer controls."

 

Don't we still come back to the question of need? So, the guidance says we can share UPNs if we want, but unless the data processor actually needs a UPN (i.e. can't use an admission number for unique identification), we shouldn't share it with them. Just like we wouldn't share ethnicity or postcode without a reason.

Posted

From my understanding, the guidance suggests that if a school is using a system to 'do things in school', and they need that same data in another system to 'do things in school', then it is fine (assuming the usual DSAs and all that). The DfE is un-clearly saying that the data cannot be used for a purpose that is not the school/LA/etc - e.g. using the UPN to create a national database, giving it to a local sport centre for their records, etc.

 

These softwares are provided for schools to use, and in that analogy is no different to having the data in the MIS or any other database.

 

The need is nearly always to have a consistent identifier for the child, so that one system the school is using has a consistent link to other systems. This is pretty good justification for need. The fact that there are alternatives is somewhat irrelevant when sticking to the one point.

Posted
These softwares are provided for schools to use, and in that analogy is no different to having the data in the MIS or any other database.

Sorry, but where companies build solutions that involve school to school transfer of arbitrary information and that is predicated on UPN, then that is NOT equivalent to having the data in the MIS. This is not a question of just where the data resides, the key question is what is the data being used for - i.e. what processing is being done with it and is that processing fair. The problem with the fair part is that the advice issued by the DfES in 2013 strongly indicates that schools should not be processing UPN as a means to synchronise data transfers between systems.

Posted
Sorry, but where companies build solutions that involve school to school transfer of arbitrary information and that is predicated on UPN, then that is NOT equivalent to having the data in the MIS. This is not a question of just where the data resides, the key question is what is the data being used for - i.e. what processing is being done with it and is that processing fair. The problem with the fair part is that the advice issued by the DfES in 2013 strongly indicates that schools should not be processing UPN as a means to synchronise data transfers between systems.

 

I refer you back to the statement given to Groupcall yesterday which states the decision is down to the data controllers...

Posted
Sorry, but where companies build solutions that involve school to school transfer of arbitrary information and that is predicated on UPN, then that is NOT equivalent to having the data in the MIS. This is not a question of just where the data resides, the key question is what is the data being used for - i.e. what processing is being done with it and is that processing fair. The problem with the fair part is that the advice issued by the DfES in 2013 strongly indicates that schools should not be processing UPN as a means to synchronise data transfers between systems.

 

I took the comments from @GREED to think back to how we used to have programmes and services hosted inside the school that may have used UPN to sync systems together ... as there was no guarantee that the AD environment was set up to allow that to do management of accounts ...

Posted

This is correct under the DPA and under the GDPR in terms of definition of controller and processor, but under the new GDPR the data processor will have direct and enforceable obligations to comply with the GDPR themselves.

 

Under the DPA the Data Controller (school for example) are responsible for ensuring that processors keep data secure but under the GDPR the data processors themselves have to maintain appropriate technical and organisational measures to ensure appropriate levels of security for the personal data they are processing. They will need to provide evidence in some form to the data controller to allow the data controller to assess this and agree/disagree before they allow the processor to process the personal data and there will need to be a legally enforceable contract that sets out in detail what personal data is to be processed, how, where, for how long, by whom etc.

 

Under DPA, data processors are fairly well protected from penalties/repercussions from data breaches or other compliance issues as the responsibilities lie with the data controller. Under GDPR, they each have responsibility and are both liable for any non-compliance issues. Processors have an obligation to assist the ICO on request. The ICO will have its enforcement powers extended to processors as well as controllers, enabling them to fine etc. processors in the same way as controllers as well as being able to halt processors from continuing to process data, enter their premises to investigate non-compliance etc.

 

This is a major (and much needed) shift that will make sure that data processors have to take just as much care of personal data as controllers or face the consequences.

  • Thanks 2
Posted
This is a major (and much needed) shift that will make sure that data processors have to take just as much care of personal data as controllers or face the consequences.

 

Just as well we do :)

 

Oh the joys of working in the data industry...

  • Thanks 1
Posted

Sorry if I am being a pedant, but my reading of that is that they are saying the UPN should not be shared or used by external companies. If a school wishes to use it for something then they have to make sure they follow DPA/GDPR for the purpose they wish. So any company saying "To use our service you must give us the UPN" is wrong. A school saying "We would like you process this data for us, of which one field is the UPN" is OK as long as they set up a contract, are careful and have a reason to use it.

 

Those two scenarios are very, very different even if they look like they are the same thing coming from different directions.

Posted
Sorry if I am being a pedant, but my reading of that is that they are saying the UPN should not be shared or used by external companies. If a school wishes to use it for something then they have to make sure they follow DPA/GDPR for the purpose they wish. So any company saying "To use our service you must give us the UPN" is wrong. A school saying "We would like you process this data for us, of which one field is the UPN" is OK as long as they set up a contract, are careful and have a reason to use it.

 

Those two scenarios are very, very different even if they look like they are the same thing coming from different directions.

 

Understand what you are saying, and you are right. The school has to authorise the use of the field - like any field. If the school wishes to, or is happy to, then all great (follow DSAs etc) - software suppliers can ask for that field of the school, but it is unreasonable to say they HAVE to. The guidance says the schools can share the UPN, for the purposes outlined above... that is the limit of the advice.

Posted
Sorry if I am being a pedant, but my reading of that is that they are saying the UPN should not be shared or used by external companies. If a school wishes to use it for something then they have to make sure they follow DPA/GDPR for the purpose they wish. So any company saying "To use our service you must give us the UPN" is wrong. A school saying "We would like you process this data for us, of which one field is the UPN" is OK as long as they set up a contract, are careful and have a reason to use it.

 

Those two scenarios are very, very different even if they look like they are the same thing coming from different directions.

 

Not quite right ...

 

The school always has the choice of whether they want UPN to be used or not. If the company says that to use our product we need a unique identifier and to ensure that this is one that can be unique across a group of school, we presently use UPN ... then the school can choose not to send it ... by not taking the service.

  • Thanks 1
Posted
Not quite right ...

 

The school always has the choice of whether they want UPN to be used or not. If the company says that to use our product we need a unique identifier and to ensure that this is one that can be unique across a group of school, we presently use UPN ... then the school can choose not to send it ... by not taking the service.

 

Why is the bit I've highlighted of interest to a school, other than in order to use the service at all (i.e. we do not have a requirement to process this information in this way to achieve the stated result)?

 

Also how does that scenario square with "However if a third party can evidence that their work has been initiated by one of these parties"?

Posted

If the data has been transferred to the Data processor by Data Controller X, then the Data Controller can only use it as agreed with Data Controller X. If the DP says, "we will use this to ensure uniqueness of accounts" and Data Controller X agrees (initiates), as has Data Controller A-Z, then the Data Processor can compare the Data between schools to examine for uniqueness.

The return response to Data Controller X should a student not be unique would be to contact Data Controller X and say the student is not unique and that they should check their records, look to see if they are dual registered, etc.

The DP should have policies and procedures in place to manage this without any release of data.

It may be that there is also agreement to contact a designated authority (e.g. LA, DfE) to help resolve duplications.

But this is all initiated by the school agreeing to the service and DSA.

Posted
If the data has been transferred to the Data processor by Data Controller X, then the Data Controller can only use it as agreed with Data Controller X. If the DP says, "we will use this to ensure uniqueness of accounts" and Data Controller X agrees (initiates), as has Data Controller A-Z, then the Data Processor can compare the Data between schools to examine for uniqueness.

The return response to Data Controller X should a student not be unique would be to contact Data Controller X and say the student is not unique and that they should check their records, look to see if they are dual registered, etc.

The DP should have policies and procedures in place to manage this without any release of data.

It may be that there is also agreement to contact a designated authority (e.g. LA, DfE) to help resolve duplications.

But this is all initiated by the school agreeing to the service and DSA.

Assuming this is in response to my post, I'd translate it as : "it is of no interest to a school, other than in order to use the service at all".

Posted
The school always has the choice of whether they want UPN to be used or not. If the company says that to use our product we need a unique identifier and to ensure that this is one that can be unique across a group of school, we presently use UPN ... then the school can choose not to send it ... by not taking the service.

 

Not taking the service is option 1. Option 2 is to ask the data processor if they can use a different field instead. UPN is an easy one for third parties to ask for, because every MIS includes it under the same name, but some MISs might not have an admission number of whatever. So, we could a) refuse the service, b) refuse to provide UPN and offer admission number instead, or c) (based on DfE advice posted by GREED earlier) give them UPNs as long as we are satisfied they aren't being mis-processed.

 

Would MATs have more of a problem here though? My school can use admission numbers to differentiate between students, but would that work in a MAT? Are admission numbers unique across the chain or just within each school?

Posted
Not taking the service is option 1. Option 2 is to ask the data processor if they can use a different field instead. UPN is an easy one for third parties to ask for, because every MIS includes it under the same name, but some MISs might not have an admission number of whatever. So, we could a) refuse the service, b) refuse to provide UPN and offer admission number instead, or c) (based on DfE advice posted by GREED earlier) give them UPNs as long as we are satisfied they aren't being mis-processed.

 

Would MATs have more of a problem here though? My school can use admission numbers to differentiate between students, but would that work in a MAT? Are admission numbers unique across the chain or just within each school?

 

A and C are the most common options as it is less hassle for both school and supplier. Option B becomes an option where suppliers are flexible (or are scared of losing too much business due to option A) ... and some suppliers may use things like DfE number to pad out the admission number (this can be used to link families of schools together, if the supplier works that into their product) ... but then you have to think about *why* suppliers and schools want uniqueness of accounts ... what happens for dual registered children that may end up with 2 accounts? Are the educational institutes not working together to ensure a properly managed curriculum for that learner? What happens if part of the service includes email or collaboration tools? Will they use 1 account for most things and then use the other account to hide messages away?

Posted
what happens for dual registered children that may end up with 2 accounts?

Hmm, good point. I hadn't considered them (possibly because we don't have any!).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...