Jump to content

Recommended Posts

Posted

Hi,

I have a few things that i am confused about with regards to GDPR. Can anyone provide a definitive answer please.

 

1) We currently have 'non-explicit' consent to use Student/Parental details as provided on the 'Request for Information' sheet completed at the start of Year 7 or when a child starts if joining in year. This currently has an 'Opt Out' box and we have no one that has opted out of us sharing details required for the education of their Son/Daughter. We are changing this to an 'Opt In' box going forward to comply with GDPR.

The issue - Do we have to re-gain consent from all the 1200 parents that we currently technically have permission from?

 

2) Should third party suppliers such as Show My Homework, Kerboodle etc be approaching us to confirm they are compliant with GDPR or do we need to contact them and request this and what is it exactly we need from them. Do we have to compile and store all of these so they are available should we need them.

 

3) What happens with regards to Staff. Should they be signing an agreement that allows us to share their information with third parties such as SMH, Strictly education (Our payroll provider) etc.

 

Thanks for anyone who can help.

 

Regards,

Dean.

Posted (edited)

1 - If you don't have explicit consent (where consent is required) then yes, you need to send the forms out again.

 

2 - It is your responsibility ... some will be proactive and send you info before you ask, but it is your responsibility.

 

3 - Have a chat with HR about what is covered in their contract. In a recent BBC article it was incorrectly implied that you have to consent for everything. You don't.

https://ico.org.uk/for-organisations/data-protection-reform/overview-of-the-gdpr/key-areas-to-consider/ covers it quite well with the 6 sections dealing with lawfulness of processing conditions.

Edited by GrumbleDook
  • Thanks 2
Posted

GrumbleDook is spot on! Here’s a bit more though on consent and the legal basis for processing

Non- explicit consent will no longer be acceptable. However, you need to consider that for much of the data processed in school consent may not be needed. That applies to both staff and pupil data.

Get your head around 'what is the legal basis for processing data' then the muddy waters become clearer.

Here’s the basis for legal processing:

 

1 Consent of the data subject

This is the obvious one - someone has given you consent to use their data

 

2. Processing is necessary for the performance of a contract with the data subject or to take steps to enter into a contract

Staff are contracted to school and you can’t fulfil that contract, ie pay them, without a payroll package.

 

3 Processing is necessary for compliance with a legal obligation

Schools have a legal obligation to send data to the local authority and/or the DFE and other bodies.

 

4 Processing is necessary to protect the vital interests of a data subject or another person

An interesting one this – a school can argue that in many cases data is processed to ensure child is safe and well cared for.

 

5 Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller

This is the one schools will rely on the most. Teaching kids in a school is in the public interest and therefore data may be processed to ensure the school functions effectively

 

6 Necessary for the purposes of legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests, rights or freedoms of the data subject.

As a silly example - you may decide to process data regarding which football team students support because you legitimately want to offer red cakes and blue cakes at lunch time and want to know how many to bake. That’s OK. However, if you physically partition the students or say Man Utd supporters can only have red cakes you would fall foul of the law.

 

Saying all that the data subject must still know Where, What, Why and When their personal data is processed.

  • Thanks 2
Posted

3rd Party Suppliers

 

I cannot stress enough how important it is for any 3rd party to which you send personal data of any kind demonstrates they are GDPR compliant. On 25th May 2018 it will be illegal for you to use any that are not.

 

Very few will be compliant for sometime but get assurances that they are working on it.

  • Thanks 2
Posted
Thank you maturelady very useful as well! Could you argue for example that sharing information with Show My Homework is covered under Point 4/5 or would we need explicit consent from Parents/Students to share this data with SMH.
Posted
Part of teaching and learning, so no explicit consent needed *where the information shared is relevant to what is needed for T&L to take place* but you do have to inform parents / learners about what is shared / processed
Posted

Let me check I'm reading this correctly - data we are sharing with a supplier/provider we use for educational purposes (Show My Homework, Kerboodle, Google, etc.) can be deemed the "exercise of official duty" and data shared with providers of things which ease administration and therefore reduce cost (Schoolcomms, Parent Pay, Seating Planner, etc.) can be deemed to be "in the public interest". Therefore we would need neither consent nor notification to share that data. Yes?

 

If that is the case, would we still need to maintain an audit of what we share with these providers, and could that be viewed if requested? Obviously we would still ensure the provider is in compliance with the GDPR regardless.

Posted

Consent, no ... notification of sharing, yes.

 

You also need to have done the due diligence to ensure that they are GDPR compliant when that comes into force.

 

You also need to remember that you are not sharing the data with these providers for them to do with as they wish ... you are sharing the data with them, or authorising they to capture it, so that it can be processed *on your behalf*.

 

If you are sharing it for them to do with as they want, then consent is needed ... though why you would do this is questionable.

Posted
Consent, no ... notification of sharing, yes.

Okay, follow-up question. How much detail do we need to go into in the notification? At present, our privacy/DP policy and ICO registration say we share data with "suppliers/service providers - details of whom are available on request". Is this sufficient, with us giving someone the relevant bits of the GDPR data audit spreadsheet on request, or do we need to give more information on what and/or with whom in our notification? If the latter, do we have to notify everyone every time we add a new service provider?

 

 

You also need to have done the due diligence to ensure that they are GDPR compliant when that comes into force.

 

You also need to remember that you are not sharing the data with these providers for them to do with as they wish ... you are sharing the data with them, or authorising they to capture it, so that it can be processed *on your behalf*.

 

If you are sharing it for them to do with as they want, then consent is needed ... though why you would do this is questionable.

Of course, I would have done all that anyway (as I put in my post). Worth emphasising though, thanks.

Posted

Present advice on Privacy notices is here -

https://ico.org.uk/for-organisations/guide-to-data-protection/privacy-notices-transparency-and-control/

and here -

https://www.gov.uk/government/publications/data-protection-and-privacy-privacy-notices

 

Advice for GDPR compliant Privacy Notices is here-

https://ico.org.uk/for-organisations/guide-to-data-protection/privacy-notices-transparency-and-control/privacy-notices-under-the-eu-general-data-protection-regulation/

and it is worth noting it says "Any recipient or categories of recipients of the personal data" ... and whilst there is further advice to come, it would look like to you bundle recipients into categories and leave it at that within the notice ... I've not seen anything else specific yet to say otherwise, but perhaps @maturelady has seen anything?

Posted

So we can categorise the types of data we share and we can categorise the types of recipients? That makes it a lot easier!

 

Interesting to note is says the notification must be made before the data is shared. Obviously this makes sense, but it does have some possible implication on new intake, as we start processing data the moment we get it from County which is often before we have any direct contact with the families (I think, I need to clarify the sequence of events for admissions with a colleague...)

Posted

I think people have become too focused on the consent bit and less on the reason for sharing data.

 

Number one priority is that you and your 3rd party are lawfully processing data. In my earlier post I have explained what these are. You MUST be able to assign a lawful basis for processing data. In many many cases as @GrumbleDook says you will be able to demonstrate a lawful basis for processing which does not request gaining consent.

 

However your data audit is much more than just establishing the lawful basis for processing. You must demonstrate why you are processing, where this happens, when including your retention of this data and how by ensuring the processing whether its you or a 3rd party are carrying it out compliantly.

 

I am working on advice regarding privacy statements for schools, I will create a template and will publish this through this forum in the next few weeks. That is the place to say who, what, why, when and how.

  • Thanks 1
Posted
I think people have become too focused on the consent bit and less on the reason for sharing data.

...

I am working on advice regarding privacy statements for schools, I will create a template and will publish this through this forum in the next few weeks. That is the place to say who, what, why, when and how.

 

Obviously we ensure the reason is valid (as we already have been doing under DPA) but consent/notification is a big question. If we are to list and gain consent for every company we share with and every bit of data we share with them, re-obtaining consent from everyone before a new service provider is added, that would be a big job. If - as appears to be the case - the vast majority of the data we share is notification only, not consent as well, that makes it significantly easier. Hence why I may seem hung up on consent.

Posted

Sorry @enjay - I didn't mean you were hung up on consent - many of the threads are.

 

There will be times where consent is needed and Yes you are right if consent is required it will be more painful.

 

I think it would be valueable if we expand this thread to listing when we think consent is required.

 

I'll kick off:

Payment systems (that's the one I know best) - if you use your payment system to collect money for anything other than the standard processes in school, ie dinner money and curriculum related trips and I believe most schools will, then consent will be needed. Many schools sell uniform, resources, tickets to productions, etc - it would be difficult to justify these under the public interest tag.

 

Messaging system - if these are used only for standard school related communications then provided you can demonstrate that's all you do its OK. However if you bombard parents with messages about non-essential school issues parents could be justified saying these are not under the public interest umbrella and therefore their consent is required before you send them

  • Thanks 2
Posted
Payment systems (that's the one I know best) - if you use your payment system to collect money for anything other than the standard processes in school, ie dinner money and curriculum related trips and I believe most schools will, then consent will be needed. Many schools sell uniform, resources, tickets to productions, etc - it would be difficult to justify these under the public interest tag.

Surely uniform and resources both come under the label of standard school processes...

 

That has got me thinking though - we don't sell our uniform directly, but we do give out order forms for the (only) company who does and allow them to sell on school premises at various events. We do not handle any money for them, nor do we take orders etc; the only admin is including an order form in the new parent info pack. Staff from this company wear school staff IDs not visitor IDs, even though they are not technically staff. Are we sufficiently removed from that company, or should we include them in our GDPR statements?

 

Messaging system - if these are used only for standard school related communications then provided you can demonstrate that's all you do its OK. However if you bombard parents with messages about non-essential school issues parents could be justified saying these are not under the public interest umbrella and therefore their consent is required before you send them

Interesting one. The problem there is one person's view of whether the message is essential will differ from another. Also, we occasionally send messages which are not school-related but certainly in the public interest, e.g. a recent email about Snapchat Maps. There are perhaps less than 5 of these non-school emails in a year, though. All others are school-related, but whether they are essential or not is a matter of personal opinion. If we didn't send emails about "non-essential" things, we would instead communicate that via paper, which costs money - therefore our use of a messaging system is arguably always in the public interest, regardless of whether the message is essential or not. We are fairly restrained with how much we use it though, and take care to send to relevant recipients only.

Posted

The bottom line on all of this is accountability.

 

If you can justify that selling uniform is a part of the public interest banner then its OK. I personally have reservations about that but it will be every school's own decision. Their DPO will advise them if they believe their justification is sound.

 

Remember the decisions you make will only be challenged if you are investigated. Whilst I cannot say this with 100% certainty but if an organisation has carefully thought and DOCUMENTED its decisions about how personal data is legally processed the ICO must take this into account when deciding the outcome of the investigation.

 

I believe schools are in a much, much better position than many private organisations. Protecting data has been in our 2nd nature. GDPR brings a lot of common sense and things we already do. Its the proof and documentation where effort is needed.

Posted

I have to agree with maturelady here - the 'public interest' legal basis will definitely cover a great deal of the personal data processing within schools, but not all of it. Think about it more in terms of 'could the school/this task within the school, operate/be done WITHOUT processing the personal data or sharing it with another party? Parents buying uniform can easily do that by going into the suppliers premises and buying it there, without need for the school to share data with the supplier...

 

Looking at homework software etc. - many schools manage without using this kind of software, so it is difficult to argue that this is necessary under the public interest basis.

 

Equally, as schools are classed as 'public authorities' they cannot also use the final legal basis of 'in the legitimate interest of the controller etc' as this is not allowed to public authorities to processing carried out by public authorities in the performance of their tasks.

  • Thanks 1
Posted (edited)
Looking at homework software etc. - many schools manage without using this kind of software, so it is difficult to argue that this is necessary under the public interest basis.

I see where you're coming from there, but I don't think it is as simple as saying "some schools don't, therefore it isn't public interest". If we use a particular product as part of our T&L and can justify educational merit, I think it is in the public interest. Also, if that tool allows us to simplify a task or remove some personnel burden, it is also in the public interest as it saves money.

 

Electronic homework planners, for example, allow department heads and leadership to quickly review the homework which is being set (quantity, frequency, duration of task, level-appropriate tasks, etc.) and so improve the quality of homework, the outcome of which is presumably higher attainment for the students. They can also be used to ensure the students get clear instructions on the task, without the teacher having to go round and manually check each student has recorded the task in their paper planners correctly; that allows more lesson time to be spent teaching and supporting the students, again improving attainment. Both of those bring improved attainment, which is surely in the public interest.

 

Edit - obviously we can review quality of homework tasks even if it is recorded in paper planners, but electronic trackers make this a quicker and easier task, which brings us back to saving money.

Edited by enjay
  • 10 months later...
Posted
I see where you're coming from there, but I don't think it is as simple as saying "some schools don't, therefore it isn't public interest". If we use a particular product as part of our T&L and can justify educational merit, I think it is in the public interest. Also, if that tool allows us to simplify a task or remove some personnel burden, it is also in the public interest as it saves money.

 

Electronic homework planners, for example, allow department heads and leadership to quickly review the homework which is being set (quantity, frequency, duration of task, level-appropriate tasks, etc.) and so improve the quality of homework, the outcome of which is presumably higher attainment for the students. They can also be used to ensure the students get clear instructions on the task, without the teacher having to go round and manually check each student has recorded the task in their paper planners correctly; that allows more lesson time to be spent teaching and supporting the students, again improving attainment. Both of those bring improved attainment, which is surely in the public interest.

 

Edit - obviously we can review quality of homework tasks even if it is recorded in paper planners, but electronic trackers make this a quicker and easier task, which brings us back to saving money.

 

Speaking with Show My Homework, who have been in many meetings with solictors, etc. regarding this, the operations manager there advised that we could use the 'Legitimate interest' as this is the way we provide homework in our school. This is also what I am relying on for many other online resources including 365 here.

Posted
Speaking with Show My Homework, who have been in many meetings with solictors, etc. regarding this, the operations manager there advised that we could use the 'Legitimate interest' as this is the way we provide homework in our school. This is also what I am relying on for many other online resources including 365 here.

 

School's shouldn't really be using Legitimate Interest as a basis for processing. Surely homework is part of the core purpose of a school providing education and should be covered under Public Interest?

 

From the ICO:

 

"(f) Legitimate interests: the processing is necessary for your legitimate interests or the legitimate interests of a third party unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests. (This cannot apply if you are a public authority processing data to perform your official tasks.)"

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...