Jump to content

Recommended Posts

Posted

Well its official then! GDPR will stand after Brexit and more.

 

For those that want to read the official release here it is:

https://www.gov.uk/government/news/government-to-strengthen-uk-data-protection-law

https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/635900/2017-08-07_DP_Bill_-_Statement_of_Intent.pdf

 

However this has to be the scariest statement in the release:

 

In view of all these considerations, we will legislate to allow a child aged 13 years or older to consent to their personal data being processed.

 

The full impact of this is not yet clear. Most data in schools will be legally processed under the Public Interest umbrella - that's good, kids can't stop standard personal data flows. However, it is now clear that any child over 13 is a fully recognised data subject and thus all rules apply. So the student not the parents must be informed of what, where, how and why their data is used and they can be given the opportunity to challenge its use. Data check sheets will need to go to students first not parents.

 

...and a question I can't answer - does the legal basis for public interest data processing pass on to the parents or can a student of 13 say?

 

"I know you can process my data without my permission to do things in school but you don't have my permission to share it with my parents."

 

I dare not think of the consequences were this to be true.

 

Your thoughts and comments please

  • Thanks 2
Posted (edited)
Well its official then! GDPR will stand after Brexit and more.

 

For those that want to read the official release here it is:

https://www.gov.uk/government/news/government-to-strengthen-uk-data-protection-law

https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/635900/2017-08-07_DP_Bill_-_Statement_of_Intent.pdf

 

However this has to be the scariest statement in the release:

 

In view of all these considerations, we will legislate to allow a child aged 13 years or older to consent to their personal data being processed.

 

The full impact of this is not yet clear. Most data in schools will be legally processed under the Public Interest umbrella - that's good, kids can't stop standard personal data flows. However, it is now clear that any child over 13 is a fully recognised data subject and thus all rules apply. So the student not the parents must be informed of what, where, how and why their data is used and they can be given the opportunity to challenge its use. Data check sheets will need to go to students first not parents.

 

...and a question I can't answer - does the legal basis for public interest data processing pass on to the parents or can a student of 13 say?

It just gets worse. You can bet your bottom dollar that the guidance for education settings will come too late and be incomplete

 

"I know you can process my data without my permission to do things in school but you don't have my permission to share it with my parents."

 

I dare not think of the consequences were this to be true.

 

Your thoughts and comments please

 

This business of students not wanting to share with parents aged 16 was bad enough... aged 13?!

 

And then there's the whole of year 9 trying to be forgotten :(

Edited by elsiegee40
Posted

I've had some responses back from DfE ... which basically points you to ICO or getting your own legal advice.

 

ICO is working on stuff but no date yet.

 

To be honest, whether the age of consent was 16 or 13, you will still need a process for requesting explicit consent from parents and explicit consent from the learners when they turn the relevant age.

Posted

...and a question I can't answer - does the legal basis for public interest data processing pass on to the parents or can a student of 13 say?

 

"I know you can process my data without my permission to do things in school but you don't have my permission to share it with my parents."

 

It's in the public interest for schools to communicate with the legal guardian about how the kid is (or isn't) doing at school.

 

If the parents are a safeguarding concern (insert crazy/violent parent example), then issues may be discussed with social services instead, but ultimately the person under discussion is the shared responsibility of the school, parents and government. They need to communicate with each other about the person they're looking after.

Posted
It's in the public interest for schools to communicate with the legal guardian about how the kid is (or isn't) doing at school.

 

If the parents are a safeguarding concern (insert crazy/violent parent example), then issues may be discussed with social services instead, but ultimately the person under discussion is the shared responsibility of the school, parents and government. They need to communicate with each other about the person they're looking after.

 

Unfortunately the new law doesn't mention public interest. It says 13 year olds decide. Until guidance is issued, schools have to abide by the law as it is written.

 

It is ridiculous for the government to expect every school to take independent legal advice

Posted

IANAL - But don't forget that there are also other laws which state (very specific) types of access such as the The Education (Pupil Information) (England) Regulations and Education (Independent School Standards) Regulations 2014.

 

JB.

Posted

it's a good job we only have one legal system rather than separate ones for England, Scotland, Wales, Northern Ireland and that we have a cohesive education system that does't have a different legal status for the various types of schools..........

 

Now, if we had a Government able to put together a National Pupil Database without compromising the security of that data.......

 

 

Re the line about 13year olds, it stems from the GDPR entry re online services and isn't aimed at schools and educational records

 

What about Data Subjects under the age of 16?

Parental consent will be required to process the personal data of children under the age of 16 for online services; member states may legislate for a lower age of consent but this will not be below the age of 13.

 

 

If the concern is about consent for educational records, then I'd go along with the ICO statement on page 61 of their subject access guide

 

"The law on educational records does not lie within the regulatory responsibilities of the Information Commissioner"

 

 

and would add the following from the 2016 Commons Briefing Paper CBP-7657, page 2

http://researchbriefings.files.parliament.uk/documents/CBP-7657/CBP-7657.pdf

 

"According to Department for Education (DfE) advice, parents have a right to access their child’s educational record, even if the child does not wish them to access it. This applies

until the child reaches the age of 18. "

  • Thanks 1
Posted

Microsoft and Google Cloud Services will be both hosts (storage) and Data Processors, depending on what you are asking them to do with the data. Microsoft have already released a toolkit to understand what you need to ask yourself and document with regards to their services and I am sure we will see similar from Google shortly.

 

It is fairly easy for them as they both already do a large chunk of the background work needed as part of their accreditations for ISO 27000 series standards.

  • Thanks 1
Posted
I've not had the opportunity yet to digest the documents and information, but if a child age 13 decides that the school can't use their data for online services such as revision tools, cloud based software etc, isn't this a good opportunity for students to avoid work - or am I totally wrong?
Posted

Let's look at article 6(1)

 

1. Processing shall be lawful only if and to the extent that at least one of the following applies:

 

(a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;

 

So the scenario is that the 13 year old does not give consent ... so any other lawful reasons apply?

 

(b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;

 

This is likely to be relevant in HE/FE where payment is made as part of a contract between student and institute.

 

© processing is necessary for compliance with a legal obligation to which the controller is subject;

 

Schools are legally obliged to educate the learners. You may get parents that argue about the tools ... but that is the choice of the school. As long as the tools used do not breach compliance with the new Act, then we are down to a school being sued by parents / learners for the choice of tools used to deliver the curriculum ... at this point, speak to a lawyer.

 

Other things like registration ... the school has to do it. Simples!

 

(d) processing is necessary in order to protect the vital interests of the data subject or of another natural person;

 

Again, you could argue that it is in their interest to educate as well as use services that protect them (walled garden of a VLE instead of social media as prep for being a member of an online society?)

 

(e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

 

Public interest ... probably going to be the most used reason.

 

(f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

 

Point (f) of the first subparagraph shall not apply to processing carried out by public authorities in the performance of their tasks.

 

And this last bit seems to say (and I need clarification on this) that (f) is not going to apply in schools should other legal reasons for processing apply.

 

(Making a note to ask another question of DfE and ICO)

  • Thanks 3
Posted

Not at all, my goodness, it's not scary. There was never any question of "kids [can't] stop standard personal data flows".

 

"So the student not the parents must be informed of what, where, how and why their data is used and they can be given the opportunity to challenge its use" is not correct. Data subjects [Parents, staff, and pupils in this case] need to continue to be informed of all data processing for it to ahve a legal basis, just as today, Principle 1 of the current Data Protection Act. Consent is not a matter of age, even in existing law, but of capacity.

 

This GDPR Article 8 age, where parental consent is required is NOT for all data processing, but personal data collected by information society services i.e. online applications. And only where consent is the legal basis for processing. It will change little for schools. Consent rarely applies as a legal basis for data processing in schools, and for example on school census data is only 4 items: country-of-birth, nationality, ethnicity and first language, just as it already has done to date.

 

Until you see the draft bill, you cannot make any further assumptions on implications. There is no "age of consent" for generic data processing in GDPR. It is likely only to be pushed as such, by companies that want to sell a consnet solution, which for schools is likely to be unnecessary, and certainly no one can no yet unless you have seen the UK draft legislation, and how it will be finalised.

 

Our comment: Comment on Data Protection Bill DCMS Statement of Intent

 

Well its official then! GDPR will stand after Brexit and more.

 

For those that want to read the official release here it is:

https://www.gov.uk/government/news/government-to-strengthen-uk-data-protection-law

https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/635900/2017-08-07_DP_Bill_-_Statement_of_Intent.pdf

 

However this has to be the scariest statement in the release:

 

In view of all these considerations, we will legislate to allow a child aged 13 years or older to consent to their personal data being processed.

 

The full impact of this is not yet clear. Most data in schools will be legally processed under the Public Interest umbrella - that's good, kids can't stop standard personal data flows. However, it is now clear that any child over 13 is a fully recognised data subject and thus all rules apply. So the student not the parents must be informed of what, where, how and why their data is used and they can be given the opportunity to challenge its use. Data check sheets will need to go to students first not parents.

 

...and a question I can't answer - does the legal basis for public interest data processing pass on to the parents or can a student of 13 say?

 

"I know you can process my data without my permission to do things in school but you don't have my permission to share it with my parents."

 

I dare not think of the consequences were this to be true.

 

Your thoughts and comments please

  • Thanks 3
Posted

If anyone has questions that are still unclear due to data protection changes, please do keep posting here, and if they are of broadly applicable interest and it would be useful to have national policy / ICO clarifications, I will add them into this collaborative working document, for discussion and to get their views. Clarifications / recommendations / any still open questions will be included in a report to be published in autumn.

 

Anyone can add comments into the GDPR google doc which is open to all https://docs.google.com/document/d/10KD1adCAeWXG_5SioUNBSzu-yfsNdIdtlj5xlOqbIFQ/edit?usp=sharing

 

GDPR should mean more of good practice for those who have it today, and offer clear direction for improvement where there is not. Unless you currently ignore current Data Protection principles and laws, it's unlikely very significant change will be needed. The GDPR won't explicitly change where consent is or is not needed compared with today for children, except on Internet services that collect personal data.

 

Take a couple of practical scenarios: for example on fingerprinting in schools, if your school does not clearly state that biometric solutions are optional and must be consent based, yes, you will need to change policy and practice, but that's to process data to meet today's legal basis, not [only] GDPR driven. And that's not only about a consensual process from children, but must involve those with parental responsibility.

 

One area we think clarity is needed for schools for example, is regards your legal basis for the necessity of data collection as part of a school's authority to process data, vs requiring the method of how that data is collected. (Reporting absence app for example, over a phone call or email).

 

 

The GDPR offers a good opportunity to review all current practice, and if improvement is needed, a reason to make change.

 

Schools that have good practices and treat parents' and pupils' data fairly, should be confident they can carry on as is, and where practices are not in line with good data protection practice and law, changes needed must be clear so that the DPO can explain them to decision makers, and change can be made as easily as possible. For that everyone needs a common understanding.

 

We are trying to support the sector by getting awareness of your real-life practical questions in front of policy makers, and show up gaps that we know of. We want to ensure ICO and DfE guidance will be clear and consistent, and that everyone can apply it in practice, in confidence, with common understanding for Data Controllers and Processors (suppliers and schools) to know their responsibilities, and for Data Subjects (parents, staff and students) to understand theirs, and their rights. Share your practical scenarios if you need support, and we'll make sure they get addressed.

 

The DfE will always defer to ICO for recommendations on your practice. The ICO does plan to issue more guidance.

 

It's important for people not to worry right now, but to be taking positive action to do a data audit, take stock to know what data you have, where, why, and on what legal basis.

  • Thanks 3
Posted

One of the problems is so many schools still do opt-out for consent, rather than explicit consent.

 

I've already come across a few schools who have said it is too late to change this year so they will do it from next year, also giving time to chat to parents.

 

There are quite a number of schools that really do ignore the existing law, as well as a lot of data protection good practice.

Posted
... There are quite a number of schools that really do ignore the existing law, as well as a lot of data protection good practice.

 

As there are suppliers. I have lost count the number of times and the number of hours i have spent arguing with companies and ending with conversations with usually the MD or CEO and their legal depts, with me telling them what they need to be doing only for them to ignore or argue their own intertrpetation. Despite sending them highlighted ico documentation, inviting them to talk to the ICO themselves as well as involving LA legal; there are *many* companies who (currently) would rather lose 1 schools' custom because they know there are plenty more out there who are less demanding (about standards, complaince, liability, etc.) and will hand over the money.

 

/dismountHighHorse

JB.

  • Thanks 1
Posted
I've already come across a few schools who have said it is too late to change this year so they will do it from next year, also giving time to chat to parents.

That's fine, isn't it, since the GDPR doesn't come into effect until May anyway? So our current practices will be fine for the new intake in September, then we can GDPR-ify things for them and everyone else ahead of May.

Posted
Apologies ... to clarify, they are saying that they are not getting explicit permission for the coming intake (or existing cohorts) and will have it all ready for *next* September ... after the May deadline.
Posted
That's fine, isn't it, since the GDPR doesn't come into effect until May anyway? So our current practices will be fine for the new intake in September, then we can GDPR-ify things for them and everyone else ahead of May.

I wanted to make the changes before we handed out forms to all the new intake to avoid having to re-obtain permissions from everyone before next May.

 

From the past tense at the beginning of the sentence, you can guess how that went....

Posted

 

Most data in schools will be legally processed under the Public Interest umbrella - that's good, kids can't stop standard personal data flows.

 

 

wouldn't most school data be processed under the 6(1)© legal obligation umbrella rather than 6(1)(e) public interest umbrella?

 

There are a large number of education related Acts of Parliament and Statutory Regulations that schools are subject to that define data to be collected, processed, shared and published.

  • Thanks 1
Posted

Items such as attendance, census, etc would fall under legal obligations, then you start with the areas required to allow you to fulfill safeguarding obligations (including H&S) ... but then you start getting areas that DfE need to clarify on ... whereas most grey areas, even without clarification, could come under public interest.

 

Progress data sheets, timetable, behaviour ...

 

And once you have looked all though there, you then start looking at which need consent.

 

First thing though, is understanding what you have, where it is, why do you use it, how did you get it and when do you get rid of it.

 

Think ROT. What data you have, is it redundant, is it obsolete or is it trivial? This is where you start clearing out things you don't need or shouldn't be processing.

  • Thanks 2
Posted

Wouldn't progress data sheet, timetable, behaviour be under "educational record" based on the text in the various Pupil Information/Pupils' Educational Records regulations?

 

Has there been any work to determine what percentage of data is likely to fall under the legal obligation and what percentage under the public interest obligation in a typical(?) maintained school?

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...