TechMonkey Posted July 11, 2017 Posted July 11, 2017 Not quite right ... The school always has the choice of whether they want UPN to be used or not. If the company says that to use our product we need a unique identifier and to ensure that this is one that can be unique across a group of school, we presently use UPN ... then the school can choose not to send it ... by not taking the service. I guess we are getting into semantics now and how strict a school will be with a service. By asking for the UPN the company is going against DfE guidelines. By stating they want it to uniquely identify a pupil across schools they are overstepping their data processing, there are other ways to uniquely identify a person and the company (generally) has no need to identify that pupil across schools. So I guess it does come down to schools dropping services, or threatening to, for them to change but how many will? Or how many teachers will understand the reasoning we are 'blocking teaching and learning'? It is getting a bit self referential though and I would say could be shaky if challenged. The service wants the UPN so the school is giving it to them, the reason the school is giving the UPN to them is because the service wants it. Is that a reason? I guess another way to look at it is Independent schools don't have UPNs. So if those services can cope with those schools then it shows it is not necessary, so the data processor is storing data it doesn't need.
GREED Posted July 11, 2017 Author Posted July 11, 2017 I think the point here is legally, the UPN CAN be used (assuming following the above guidance), that is point 1. If school is happy to use it, then great. SHOULD it be used, probably not. Can it a company pressure school to allow the use of UPN, very much not. A question that has not been raised - if we ignore the previous advice from DfE for the moment, what issues to schools have in using the UPN over any other ID number?
Michael Posted July 11, 2017 Posted July 11, 2017 This is an interesting discussion, as I recently found out BCC (Birmingham City Council) require a full CTF export every week, so presumably this will include the likes of UPN and other? This is regardless if you're a state school or an Academy. I think the DfE need to get a grip and understanding of why this submission is required (telling LAs they must do so), rather than telling schools we're the data controllers. Really is frustrating why they cannot be black and white about it.
GREED Posted July 11, 2017 Author Posted July 11, 2017 This is an interesting discussion, as I recently found out BCC (Birmingham City Council) require a full CTF export every week, so presumably this will include the likes of UPN and other? But this is fine under DfE, because it is with a bona-fide education department. OK we might sit here and say it is probably excessive (not to mention inefficient!), but is basically the same as the DfE demanding the census.
enjay Posted July 11, 2017 Posted July 11, 2017 A question that has not been raised - if we ignore the previous advice from DfE for the moment, what issues to schools have in using the UPN over any other ID number? For me, no other objection. DfE say we can't share UPN, so we don't. As DfE relax their stance, so will we and if a service provider has a valid reason (differentiating between our students is valid, tracking them from one school to the next is not - IMO), we will start sharing it.
elsiegee40 Posted July 11, 2017 Posted July 11, 2017 I I guess another way to look at it is Independent schools don't have UPNs. So if those services can cope with those schools then it shows it is not necessary, so the data processor is storing data it doesn't need. Wrong! Every student in every school has a UPN including those educated entirely in the Independent sector. Source: Me working in an Independent School! 2
pcstru Posted July 11, 2017 Posted July 11, 2017 I think the point here is legally, the UPN CAN be used (assuming following the above guidance), that is point 1. If school is happy to use it, then great. SHOULD it be used, probably not. This seems to be two very odd (incompatible) statements. How could a school be happy to use it if it probably should not be used? What is informing the school of the "probably not" (i.e on exactly what basis is that "probably not" call being made? A question that has not been raised - if we ignore the previous advice from DfE for the moment, what issues to schools have in using the UPN over any other ID number? That it is processing that is disproportionate to the requirement (an ability to uniquely identify a student at a national level when all that is required for us as a data controller is that duplicate records are not created between systems that operate at a school level). There is another issue that can crops up given the lack of transparency surrounding this. If your UPN data is wrong - perhaps because of some corruption or perhaps because someone decided that they should not send the real UPN but one they made up, then there could be data leakage (i.e. someone gets access to the data that they should not have).
TechMonkey Posted July 11, 2017 Posted July 11, 2017 Wrong! Every student in every school has a UPN including those educated entirely in the Independent sector. Source: Me working in an Independent School! I was under the impression that the school generated the UPN, so if a child starts at an Independent that does not use them it would only be generated if they left and went to a State school.
pcstru Posted July 11, 2017 Posted July 11, 2017 For me, no other objection. DfE say we can't share UPN, so we don't. As DfE relax their stance, so will we and if a service provider has a valid reason (differentiating between our students is valid, tracking them from one school to the next is not - IMO), we will start sharing it. I don't see this as them "relaxing" their stance, merely clarifying it in response to a query. Sometimes the clarity of a response can be helped by knowing exactly what was asked.
GrumbleDook Posted July 11, 2017 Posted July 11, 2017 It is getting a bit self referential though and I would say could be shaky if challenged. The service wants the UPN so the school is giving it to them, the reason the school is giving the UPN to them is because the service wants it. Is that a reason? Usually, the school will be requesting a service which functions in variety of ways. The suppliers tells the school what the pre-requisites are for doing this, based on their infrastructure and technology ... whilst there may be alternative ways of doing it, the DfE has not explicitly said that suppliers cannot process this data ... only that the initiation (instruction) needs to be from the data controller. Yes, there are semantics here and the wording is very carefully ambiguous. Because of that you will get a lot of variation in what it is saying ... what it is not saying though is that suppliers cannot use UPNs. I guess another way to look at it is Independent schools don't have UPNs. So if those services can cope with those schools then it shows it is not necessary, so the data processor is storing data it doesn't need. Independent schools don't usually work in families of schools in such a way that they uniqueness is needed. See earlier comments about dual registered learners, safeguarding needs around ensuring single accounts, etc. Please remember that you should *not* focus purely on the technical measures but the organisational measures as well ... some methods have been put in place to help schools with organisational measures (working between schools, etc.) I know of some companies that keep their State and Independent school services separately for this reason, and some that just avoid independent schools completely because they don't want to develop 2 or 3 different variations on their product otherwise this will put up the costs to schools ... taking into account the increase in time and resources to develop, implement, support, maintain and improve. They are businesses. Please remember that. They will work within the law and guidance, and generally do the best they can for schools (some are better than others) but they still need to be viable businesses. 1
enjay Posted July 11, 2017 Posted July 11, 2017 (edited) I was under the impression that the school generated the UPN, so if a child starts at an Independent that does not use them it would only be generated if they left and went to a State school. Students need UPNs to take SATS, which many independent schools do. I think they need them for GCSE and A-Level exams too, but can't remember now. Edited July 11, 2017 by enjay
GrumbleDook Posted July 11, 2017 Posted July 11, 2017 Wrong! Every student in every school has a UPN including those educated entirely in the Independent sector. Source: Me working in an Independent School! It is fair to say though that there are some that happen to ignore this ... unfortunately. And that starts to stray into safeguarding too ...
skunk Posted July 11, 2017 Posted July 11, 2017 Irrespective of whether the DfE say the UPN can be shared. The onus is on data processors and controllers to ensure psuedonymity, so if the UPN (sensitive data) db/table is breached, this would not be stored in the same table and/or database as other sensitive data. e.g. name and contact details, FSM, etc. We should all probably have our own unique identifiers to match data with each supplier. Otherwise multiple breaches outside our control as a school could match our student's details together and then.........lots of fines for all involved!
GREED Posted July 11, 2017 Author Posted July 11, 2017 Irrespective of whether the DfE say the UPN can be shared. The onus is on data processors and controllers to ensure psuedonymity, so if the UPN (sensitive data) db/table is breached, this would not be stored in the same table and/or database as other sensitive data. e.g. name and contact details, FSM, etc. We should all probably have our own unique identifiers to match data with each supplier. Otherwise multiple breaches outside our control as a school could match our student's details together and then.........lots of fines for all involved! So firstly, one would assume that unless they are completely isolated databases/storage location/encryption keys/etc, if hackers do breech the table, they will have access to the related tables and the relationships to find what they need. Secondly, what about the MIS - if someone breaks into SIMS for example, that is all in the same database...
GrumbleDook Posted July 11, 2017 Posted July 11, 2017 And this is why you start looking at whether suppliers have ISO27001, etc. At some point you need to see if they have done the work for you rather than reinventing the wheel. Due diligence is one thing ... but most firms have an interest in keeping your data safe anyway and work hard at it. Yes, manage the risk ... but don't stick in overly complicated (and sometimes unachievable) risk mitigation plans.
mavhc Posted July 11, 2017 Posted July 11, 2017 Seems like the first thing to do is to decide on what you're guarding against. From this thread I can think of: 1. UPN has personal info in, year, area, school 2. UPN would be the same across multiple companies, allowing matching of info 3. UPN could allow different school data to be mixed so a) unless the service needs to mix school data, don't use UPN b) Isn't this what GUIDs are for?
GrumbleDook Posted July 11, 2017 Posted July 11, 2017 Seems like the first thing to do is to decide on what you're guarding against. From this thread I can think of: 1. UPN has personal info in, year, area, school No ... you should not be able to derive this from the UPN. 2. UPN would be the same across multiple companies, allowing matching of info This would be a breach of any DSA and a breach of the DPA. If a Data Controller has allowed the DP to process the data on their behalf, then it will be for the reason stated in the DSA / Privacy Notice. Sharing with other companies is not likely to be part of that, and if it is ... then don't use that company. 3. UPN could allow different school data to be mixed Same as point 2 so a) unless the service needs to mix school data, don't use UPN b) Isn't this what GUIDs are for? To be honest, if we were looking at doing all of this correctly then we would be chatting about SIF. Again, there has been little appetite to make the change to SIF, and schools are unlikely to agree any associated additional costs ... in fact there was a lot of pressure on RBCs to stop looking at it because it was seen as "a stupid way of just forcing schools to stay with LAs" to quote on Academy group!
mavhc Posted July 11, 2017 Posted July 11, 2017 No ... you should not be able to derive this from the UPN. UPN contains school and LA number, and a year, which is probably when you were 5. This would be a breach of any DSA and a breach of the DPA. If a Data Controller has allowed the DP to process the data on their behalf, then it will be for the reason stated in the DSA / Privacy Notice. Sharing with other companies is not likely to be part of that, and if it is ... then don't use that company. I meant in terms of a hack of 2 different systems would allow Company A, with names and addresses, to match with Company B, with "anonymised" health data or something To be honest, if we were looking at doing all of this correctly then we would be chatting about SIF. Yeah, but we're apparently talking about people who can't cope with a GUID
GrumbleDook Posted July 11, 2017 Posted July 11, 2017 UPN contains school and LA number, and a year, which is probably when you were 5. Apologies ... to clarify, this only refers to the issuing school and cannot be used to derive any other school. UPN should not (and generally is not) used for validation of school.
enjay Posted July 11, 2017 Posted July 11, 2017 UPN contains ... a year, which is probably when you were 5. Yes, but... this information is also present in the date of birth field, which we're entirely allowed to share. Plus, we can share all sorts of other information (if justified, of course) which is far more personal and sensitive than the year in which they might but might not have turned 5.
GrumbleDook Posted July 11, 2017 Posted July 11, 2017 I meant in terms of a hack of 2 different systems would allow Company A, with names and addresses, to match with Company B, with "anonymised" health data or something If they are being hacked then they have other problems as well. Data profiling is already a well known issue within identity theft ... there are many out there who are extremely surprised that schools are not being targeted more to get base data that is being built on as part of wider identity farming. School networks are likely to be easier to compromise, but commercial suppliers are going to have larger data pools if people can get in.
ryoung Posted July 12, 2017 Posted July 12, 2017 Hi. It would be very helpful to know the source of your two statements ie are they quotes from say ICO documents, or your own understanding.
GrumbleDook Posted July 12, 2017 Posted July 12, 2017 Hi. It would be very helpful to know the source of your two statements ie are they quotes from say ICO documents, or your own understanding. Is this in reference to my comment on school networks and suppliers?
pcstru Posted July 17, 2017 Posted July 17, 2017 (edited) A question that has not been raised - if we ignore the previous advice from DfE for the moment, what issues to schools have in using the UPN over any other ID number? I'm going to answer this for a second time, this time at more length : First, it is not possible to ignore the advice from the DfE pertaining to UPN. That is because : "Under the Data Protection Act 1998, the UPN is designated as a ‘general identifier’ making its use for any purpose unrelated to education illegal.". For the definition of a "general identifier" we need to look at the Data Protection Act, Part II, 4.1. Which says : "Personal data which contain a general identifier falling within a description prescribed by the [F2 Secretary of State] by order are not to be treated as processed fairly and lawfully unless they are processed in compliance with any conditions so prescribed in relation to general identifiers of that description." IMO that means that you cannot process UPN fairly unless your processing complies with the 2013 Guidance. So for schools as the Data Controller, to decide you can use UPN for matching, your use of UPN has to comply with that guidance or it cannot be said to be fair processing. Looking at that guidance there are a number of things that would make me wary, the first and most obvious is simply the statement : "The UPN must be a ‘blind number’ not an automatic adjunct to a pupil’s name." This is a little difficult to parse. What does it mean to be a 'blind' number? What exactly do they mean by "automatic adjunct"? Looking at the wiki for the NPDB, we can see how they have interpreted this : "To address privacy concerns the UPN should be a blind number held on the pupil’s electronic record and only output when required to provide information to the LA, DfE or QCA. Individual pupil information held centrally will be encrypted to prevent unauthorised access. Schools should continue using pupils’ admission numbers, rather than the UPN, for their own internal purposes. The UPN should not be regarded as an automatic addition to the pupil’s name routinely appearing on any record or document relating to them. The only exception to this at present is the paper copy of the Common Transfer File, where the pupil name and UPN occur together."" I struggle to see how using it as an identifier that guarantees uniqueness at a national level, is not using it as "an automatic adjunct" (if you are producing data extracts with the name and the UPN, you are "automatically" placing that information "adjunct" to the name). Further into the document there is some wriggle room introduced when they say UPN must not be used for purposes "outside of education". That does not IMO override the requirements stated at the beginning, that the UPN should not be an automatic adjunct within education. There is a further complication for external systems in the 2013 guidance Section 6. Anyone doing systems development should get an antenna twitch when they read about temporary and former UPNs because processing that information is part and parcel of the proper (fair) processing of UPN. Do external systems support tracking those and dealing with changes properly? However, where the goosebumps should really mottle the skin is around adoption and those at risk : "Should children at risk be issued with a new UPN" "Schools/academies may receive pupils who, for their own safety have changed their identity. This will be the case for children in the witness protection programme and for those fleeing from abusive family members. As part of their new identities these pupils should be issued with new permanent UPNs, their previous UPN must be deleted and not recorded under ‘former UPN’. " Obviously, if you get that stuff wrong, you (and the data subject) can end up in the deep stuff. So I come back to my first answer, proportionality. When needing to match data between systems why would I want to use a piece of data which to be processed fairly HAS to be processed in accordance with quite stringent guidelines (including dealing with change/repudiation), rather than (say) the local admission number which has no such constraints placed on it? There is no question that the guidance and advice from the DfE is ... 'difficult' (!) to interpret and understand, (if it wasn't we would not be having these discussions) where none of that difficulty arises if we choose to use our own local ID. My problem with the DfE 'advice' is it is just a statement of what we already knew. The School is the Data Controller and it is up to them. Sure! So how do they make a decision about it other than by looking at the DfE guidance that relates to that data item. If they actually read that, I struggle to see how could they come away thinking that using it would be appropriate. Meanwhile I get teachers who say "why aren't YOU uploading MY data to this system" after all, "everyone else is doing it" simply because the suppliers have built their application before they understand the constraints placed on the data their application requires us to process in order to make any use of it at all. Edited July 17, 2017 by pcstru 1
EdWhittaker Posted July 21, 2017 Posted July 21, 2017 Hi Graham Have you received any official feedback from the DFE yet?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now