Jump to content

Recommended Posts

Posted

I believe comon practice suggested is too broad, compared with guidance. DfE UPN Guidance is clear that it should be a ‘blind number’ and ensure that personal data is only transferred to those with a genuine right and requirement for its receipt. See page 17: "the data protection restrictions associated with UPNs mean that it is only possible for UPN data to be shared by CTF between schools/academies, LAs, DfE and other prescribed government departments (OGDs)." https://www.gov.uk/government/publications/unique-pupil-numbers

 

To all

 

Noting that there has been a lot of discussion around what fields can and cannot be used/transferred out of the MIS to third party systems, particularly the UPN, and as an organisation that provides this service to third parties, we (Groupcall) have a statement to announce on this. Mods: I hope this is appropriate, tweak if anything is too advertise-y!

 

---

 

We have received enquiries regarding the use of the UPN within data transfers between school MIS and third party software, and also noted the queries around this here too.

 

This is covered by the DPA and under the DPA transfers are allowed provided the requirements of the DPA are met. Where we are instructed by a partner to include UPN in their data extract we ensure that the third party has appropriate Data Sharing Agreements with the schools that allow for the UPN to be transferred before undertaking the transfers, thereby ensuring that all is correct under the DPA. If the UPN is not clearly designated within the DSA as a data item to be included in the transfer, we do not transfer the UPN at all. The same due diligence checks apply to all other data fields that we are instructed to include into data extracts for our partners.

 

Guidance from the Dept of Ed is unclear on the use of UPN. On one hand they state that it should only be used for transfers between schools, local authorities and other government departments whilst on the other hand it states that UPNs should only be disclosed to people with valid consent or legitimate reason.

 

Whilst we believe that an appropriate DSA between the school and the third party supplier is a legitimate reason and the school, as data controller, has given consent to the transfer, we have also asked the Dept of Ed for clarification on this and will feed back their response once we receive it. Based upon this response we will also be liaising with our third party customers to ensure that they are compliant with any recommendations made.

 

---

 

If any school, or third party, that uses Groupcall products, particularly Xporter, wishes to discuss further please get in touch (third parties, via your Partner Manager). We are also happy to discuss any concerns, particularly from schools, publicly here as it will absolutely benefit others.

 

Regards

 

Graham Reed

Consumer Products Manager

Groupcall

Posted

"The UPN must be a ‘blind number’ not an automatic adjunct to a pupil’s name.

 

That's quite clear. We've asked the ICO for specific advice on this point. Will reply as soon as we hear back.

Posted
I believe comon practice suggested is too broad, compared with guidance. DfE UPN Guidance is clear that it should be a ‘blind number’ and ensure that personal data is only transferred to those with a genuine right and requirement for its receipt. See page 17: "the data protection restrictions associated with UPNs mean that it is only possible for UPN data to be shared by CTF between schools/academies, LAs, DfE and other prescribed government departments (OGDs)." https://www.gov.uk/government/publications/unique-pupil-numbers

 

That guidance on p17 refers specifically and explicitly to use of UPN and associated data in educational research and so is not really relevant to the current discussion. A discussion that, as has already been noted, is a result of the DFE guidance being somewhat open to interpretation. I suspect that the DFE 'clarification' as received by GREED is deliberately fuzzy because they don't want to get involved and are basically pushing the buck back to the schools.

 

One could argue for ages about the precise interpretation of each word or phrase in the September 2013 guidance, but you could end up just dancing on the head of a pin. For me the two key things for a 'sensible' interpretation are; first what is the context of the discussion and secondly what interpretation would a 'reasonable' person (the Man on the Clapham Omnibus) put on it?

Context: a school wishes to share personal data (including UPN) with a SAAS Service Provider with whom they have a clear data processing / sharing agreement. The school is satisfied that the service provider has taken all necessary steps to keep the data secure.

 

Now, given that context, how do we interpret this para on p7 of the 2013 guidance?

"The UPN must be a ‘blind number’ not an automatic adjunct to a pupil’s name." 'Blind' in this context means not routinely displayed i.e not visible to the casual user and not printed out.

"It must be held electronically and only output when required to provide information to the LA, central government or another school/academy to which the pupil is transferring." Well, it's clearly held electronically; but what does 'outputted' mean? In the context of the statement, it implies either printing onto paper or into an electronic file (CSV, CTF) from where it would be visible. As this would not happen in our scenario, is this caveat relevant to the discussion?

"Under the Data Protection Act 1998, the UPN is designated as a ‘general identifier’ making its use for any purpose unrelated to education illegal." If the school's interaction with the service provider is not for the purposes of education, what is it for?

"A pupil’s admission number, rather than the UPN, should be used as the general pupil reference number on the admission register or paper files." In other words, if you are printing out an exam hall seating plan, and you don't want your 3 John Smiths mixing up, print the admission number, not the UPN, on the sheet.

 

When interpreting any sort of guidance, context is of paramount importance.

  • Thanks 2
Posted

You're right that context matters - however it apperas that the UPN has very specific purposes (namely information to the LA, central government or another school/academy to which the pupil is transferring) which have since been overly broadly interpreted as "useful" rather than "necessary" in an educational context. For example, is educational purposes any purposes as defined by a school? No. So there needs to be precision where it is given out to a third-party payment provider, or for admin purposes which are indirect, rather than direct educational purposes.

 

We have asked the ICO to make a clarification, and aligned with Scottish and Welsh practices. I hope this will help and we'll have it before the end of the summer, and that will help interpretation by third parties and schools alike.

Posted
I'll be interested to see what they say. When I have contacted the ICO in the past their advice has usually been along the lines of 'Well, it depends ...' and 'Well, that's up to the data controller ...' so it'll be interesting to see if they come with something more concrete.
Posted
I'll be interested to see what they say. When I have contacted the ICO in the past their advice has usually been along the lines of 'Well, it depends ...' and 'Well, that's up to the data controller ...' so it'll be interesting to see if they come with something more concrete.

 

Also, interesting to see whether any clarification they do give relates to the DPA or GDPR...

Posted

Great discussion - no closer to any difinitive answers but good conversations!

 

There is something that does confuse me - the UPN is an identifier, like the ULN, the Admissions number, the MISID, the NI number, the NHS number, the 'Graham has just made up an identifier' number. OK some have greater scopes than others, but all identify an individual just like their name does - only an ID number (depending on the scope) uniquely identifies them against other people of the same name in the same location/class/school/area/country.

 

Lets disregard for the moment that all (or we hope all) the companies that want the UPN follow DPA now, GDPR next year, and so the information is secure and is only being used to match Johnny A from the MIS to Johnny Adams in their system, which they are providing to the school and only the school. Lets ignore all that for the moment.

 

So the concern is around the UPN being against the person's name - whereas another ID is perfectly fine. Unless between systems we do not want to match, or want to purposely not be able to match, that Johnny A is Johnny Adams, to provide a single record collection about their progress... What makes the UPN a no no but another ID - an ID (whether is be a single number or compound value from several) that does uniquely identify that individual, acceptable?

 

Take this further, someone rolls out another ID, say SIMS - their MISID and all providers use that (which most do actually) - then the proliferation of this ID now matches or over-takes the UPN.

 

My point - is the concern here about the identification of an individual via the use of the UPN (which, sort of, is what the DfE is talking about), or because the DfE 'said a thing'? And to be fair, said that thing long before 2013 and when systems that want/need to talk to each other were in their infancy... Which their clarification does seem to take into account, and that some seem to not be...

Posted

In other news, we have has a (sort of) response from the Scottish Government on this:

 

"Pupils in publicly funded schools in Scotland will be uniquely identified either by their Student ID which is allocated within the schools’ MIS or by their Scottish Candidate Number. The schools’ MIS is operated by SEEMiS Group on behalf of Scottish local authorities. Scottish Candidate Numbers are allocated by the Scottish Qualifications Authority."

 

Scotland does not have the same UPN as the UK. I should also note, not specifically mentioned in their response but eluded to, that the SCN is printed for the students to see and use on papers and in schools, school IDs etc.

Posted

The DfE UPN Guidance is only from 2013, and was not just a nice-to-have. I don't know its origins but it *might* be that it was when DfE changed national laws 2012/13 and started handing out identifiable pupil data to third parties from the NPD, so was the first time that the UPN was potentially a national identifier, for non-direct education purposes (assuming every use at local level is for the purposes of a child's schooling, care, or direct school purposes) compared with say, national academic research, or tutoring website heatmaps, or journalists.

 

It's not the ID that's not acceptable, it's some people's use of it, for purposes it was not designed for.

 

Someone 'rolling out a new system' now requires a privacy impact assessment, so *in theory* (as you might say, let's ignore that for the moment?) the risks should be identified and the data subjects made aware of them, and data collected with consent and/or mitigating secure procedures.

 

The NI number, the NHS number, the 'Graham has just made up an identifier' number - are (in most applied contexts) considered personal data. They must be protected as such, must meet the requirements of common confidentiality law (not only DPA) and can't just be sent around the system by others, unless with direct or implied consent with legitimate interests ie. for purposes that children/parents reasonably expect and are fairly and legally processed. Where *that* boundary lies, is pretty clear in health, and what needs tightened up in education.

 

The current issue is often more generic. Pupils and parents don't know all these third party uses exist, or how their data is used by them at national or local level. Or tracked across systems, jigsawed with other sources by providers, or sent to an app provider because the school thinks they need it, when it is the schools that needs the information and may have the legal obligation to collect, but not the system provider. Companies make no effort to give school audit reports and schools don't fairly process meet data controller responsibilities - responsibilities that processors share from next May. If schools don't tell kids what happens to their data, suppliers in the chain are liable too.

 

"Lets ignore all that for the moment," is the fun stuff we're advocating to help fix for everyone in that chain. UPN was never intended to be part of it and other local identifiers exist for local purposes.

Posted
Note also though that in Scotland, "the dataset that we hold at a national level doesn’t include pupil names." It's not a national ID in the same way that the UPN held by DfE is stored agsint pupil names and contact details. (See FOI.)
Posted

Summarising a bit here now.

 

To some extent, the concern around UPN is the routine manner it is being attached to other data.

 

This, as discussed, has had such a wide interpretation that in England we have many suppliers that use it instead of other viable options ... purely because it is there.

 

We've had discussions showing concern on this (understandably), as well as discussions about why a supplier might request it on a valid basis.

 

As pointed, those suppliers that do their job well will only use it were needed, will have assessed risks against it (especially if ISO27001 accredited or as part of the approach towards GDPR with Privacy impact Assessments), and then informed the school.

 

This is good practice under DPA but now mandatory under GDPR.

 

Yes, I do expect some suppliers to struggle in their justification in requesting schools for permission to capture and processes, so we may see a change in how some suppliers work.

 

There is a some history of UPNs being used as an LA / regional / national identifier prior to the change to the acts in 2013 ... it has been vague for a long time, and most schools have been unaware of this.

 

NI numbers have a more noted history for refusal to have permission granted for shared use / use outside of agreed remit. This is because employees (and their unions) are a lot more protective of themselves and have seen how misuse can happen.

 

LAs would use payroll or employee number instead ... but GM and foundation schools out paid to that long before academies came along.

 

Even if a new national identifier came along, it would end up being tied up in the same way UPN is ... but even more restrictive.

 

A supplier could say that they generate a unique id generated from the UPN ... take view of how it has been done in Wales.

 

In section 1 of the HWB Privacy notice it covers how a uniqueID is generated and used. This was shared out via LAs to schools. https://hwb.wales.gov.uk/privacy

 

This was no easy feat, but was done and continues to be done.

Posted
My point - is the concern here about the identification of an individual via the use of the UPN (which, sort of, is what the DfE is talking about), or because the DfE 'said a thing'? And to be fair, said that thing long before 2013 and when systems that want/need to talk to each other were in their infancy... Which their clarification does seem to take into account, and that some seem to not be...

 

For me, it is a combination of those two, but because the DfE said so has to be a big factor. Whether we think the instruction is stupid or whether we think it isn't far-reaching enough shouldn't really come in to it. DfE said don't, so we don't.

 

If Company A wants a way of differentiating Johnny A Adams from Johnny B Adams, or linking Jonathan Adams to Johnny Adams, that's fine - they can have the MISID or admission number. I understand why some ask for UPN, because it is something which every MIS will contain so simplifies to the application development, but ultimately that's Company A's problem not the school's.

 

Also, as with any other data which someone asks a school for, it must be very clear what they intend to do with it. If the UPN is requested simply to link/differentiate records, then the answer is simply "no because DfE told us not to, have the MISID instead". If the UPN is requested because the company wants to do some more extensive data mining and follow a student around the country throughout their education for some commercial purpose or other, the answer is simply "no because that's not why we want to share the data with you".

  • Thanks 1
Posted

All fair points. What is being said here is that the UPN is an attribute of a student (record), not an identifier - unless the DfE or LA, or another school is involved, and then they have legislative power to use that attribute as an identifier.

 

With my professional hat on, I care little which schools want to share, or what third parties want/ask for - Groupcall (and I am sure the other data integrator) can provide UPN, MISID, 'Graham's made up ID' just as easily.

 

School switching MIS - now there is a fun time, with all the local IDs changing!

Posted
All fair points. What is being said here is that the UPN is an attribute of a student (record), not an identifier - unless the DfE or LA, or another school is involved, and then they have legislative power to use that attribute as an identifier.

 

With my professional hat on, I care little which schools want to share, or what third parties want/ask for - Groupcall (and I am sure the other data integrator) can provide UPN, MISID, 'Graham's made up ID' just as easily.

 

School switching MIS - now there is a fun time, with all the local IDs changing!

 

And this is where we get into the use of the same data element for different functions!

 

Folk need to remember that UPN is a unique record ... MISID has no guarantee it will be ... and if it is and is being used as a differentiator, then it is related to a student record ... which makes that student in question identifiable, especially when considered in the case of a data breach ... so with a risk management hat on, it makes no difference whether you use the UPN or the MISID ... and you are meant to taking a risk based approach.

 

The creation of yet another UniqueID will end up with another ruling being required about how it is handled, so we get into the same situation again ...

 

The definition of insanity is doing the same thing again and again and expecting a different outcome!

Posted
School switching MIS - now there is a fun time, with all the local IDs changing!

 

Ah, but we (i.e. schools) can use the UPNs, we just can't share them. So the school could run a report from %outgoing-MIS% listing admission number and UPN, then match that against the same report from %new-MIS%, using =vlookup to generate a list of %old-local-ID% to %new-local-ID%, and then share that with Company A.

Posted
The definition of insanity is doing the same thing again and again and expecting a different outcome!

I've upset people with that quote before now :-)

Posted
Ah, but we (i.e. schools) can use the UPNs, we just can't share them. So the school could run a report from %outgoing-MIS% listing admission number and UPN, then match that against the same report from %new-MIS%, using =vlookup to generate a list of %old-local-ID% to %new-local-ID%, and then share that with Company A.

 

And so Company A needs to build in a matching feature - fair.

 

Schools are happy for this onus to be on them?

Posted
Ah, but we (i.e. schools) can use the UPNs, we just can't share them. So the school could run a report from %outgoing-MIS% listing admission number and UPN, then match that against the same report from %new-MIS%, using =vlookup to generate a list of %old-local-ID% to %new-local-ID%, and then share that with Company A.

 

This is starting to look like a request to the supplier to say, "we want to do the data cleansing and matching so give us some data about where it doesn't match!"

 

Are we not stepping into the territory of asking the DP to process data from other schools based on *your* instruction?

 

With a UniqueID the DP can simply say, "We cannot process that student record as it is already controlled by another data controller."

Posted
Are we not stepping into the territory of asking the DP to process data from other schools based on *your* instruction?

 

Other schools? No. I'm suggesting the DP would run a script across my school's entry within their database which swaps old-ID for new-ID. I don't see where I'd be asking them to process your data.

Posted
"no because DfE told us not to, have the MISID instead".

 

The problem is that the DFE have NOT said no. They say that the decision is ultimately down to the data controller, provided they are satisfied that suitable conditions and precautions are in place. Third party applications can viewed simply as extensions of the school MIS. Ok, the data may not actually physically be on the school premises (but then neither is it with some MISs); but data security aside, to all intents and purposes it might as well be. I say this because the service provider has no rights on the data, they can't just do with it whatever they want. Data is coming out, being processed in a defined way, then returned.

Because the the guidance from DFE is not explicit and concrete it can be interpreted, and indeed misinterpreted, according to whatever axe you have to grind. If you really don't want providers to use the UPN, then you could argue that; if you don't mind, then you can argue that as well. However, for my money, any disinterested, impartial reading of the guidance would come down on the side of there not being any specific interdiction on the use of the UPN. There, see, I said it.

Posted

@EdWhittaker - you mean if you ignore:

 

"The UPN must be a ‘blind number’ not an automatic adjunct to a pupil’s name. It must be held electronically and only output when required to provide information to the LA, central government or another school/academy to which the pupil is transferring. Under the Data Protection Act 1998, the UPN is designated as a ‘general identifier’ making its use for any purpose unrelated to education illegal. A pupil’s admission number, rather than the UPN, should be used as the general pupil reference number on the admission register or paper files."

 

and....

 

"The data protection restrictions associated with UPNs mean that it is only possible for UPN data to be shared by CTF between schools/academies, LAs, DfE and other prescribed government

departments (OGDs)."

 

Yes if you compteley ignore the statements made in writing by the DfE in their guidance document then it would be the case that they have not said no. Apart from where they did actually say no in writing.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...