Jump to content

Recommended Posts

Posted
to turn the question around slightly, what do you think MathsWatch need to so as an "Information Society Service"?

 

An information society service has been defined as "any service normally provided for remuneration at a distance, by means of electronic equipment for the processing (including digital compression) and storage of data, at the individual request of a recipient of the service" (quoting from various websites, not sure off-hand the original source). Here's why I think that covers Mathswatch, GCSEPod and so forth:

"provided for remuneration" - yes, the school pays them

"at a distance" - obviously

"by means of electronic equipment" - again, obviously

"for the processing and storage of data" - yes, names, dates of birth, email addresses, activity and progress data

"at the individual request of the recipient of the service" - strictly speaking, the school requested it on their behalf but that was for reasons of convenience and consistency (same username format, default password for first use, etc.), we could tell the students to do it themselves.

 

 

Currently, they [Mathswatch] have no data notice, cookie notice or any passing reference to data protection as other providers do e.g. SAM Learning, Doddle, GCSE Pod, MicroLib. Nothing on the website mentioning the GDPR.

 

How well does the MathsWatch website meet the legal requirements re Company Registration Number, T&Cs etc?

I'm sure I've seen a lot of that info before, perhaps on their previous website?! That said, assessing Mathswatch's compliance with the various legal requirements would come under the Privacy Impact Assessment, which is GDPR-related but not consent/age-related so is a topic for another thread.

Posted (edited)

I think we need to be very careful as we're into uncharted territory assigning what is the legal basis for processing data.

@GrumbleDook and I spend a lot of time in this area and I think @GrumbleDook would agree with me that there are so many unknowns still to be clarified.

 

I think its fair to say that a school is a public body, carrying out a duty for the public interest, ie educating children. Thus it would follow (in my opinion, and only my opinion, as no one has said Yes you are right or No you are not) that everything which is done in schools which can be classed as a normal task or processes in the education of children the data processing can be classed under the public interest umbrella. Attendance, progress tracking, school meals management, teaching and learning, keeping kids safe and informing parents, in my opinion, are tasks that are normal in school and therefore the data used has a legal basis for processing in the public interest. Inviting parents to barn dances would not (in my opinion) as neither would Ski trip communication, taking photographs or selling school uniform.

 

We need so desperately directions from the DfE but as yet there are none. The regulations are quite simple to understand, setting them to a school context is the challenge. Whatever you do you are going to have to justify your decision and saying 'this guy on Edugeek said so' wont carry much weight.

 

Please be assured that we at GDPRiS are pressurising ICO and DfE for more information and you have my promise as soon as we know anything we will share it with you.

Edited by maturelady
Posted

A quick response on this. The data subject is not signing up as an individual, the school is contracting a services and so it would not be deemed as using an Information Society Service. It falls under the Public Interest bracket and that is an area clarified with @jdoyle already.

 

Saying that, the school *is* obliged to ensure that children's data is being processed fairly and lawfully.

 

This is the point where the company needs to show compliance (processing as instructed, etc.) and give you the information to inform data subjects and parents.

Posted
That's my thinking too, but some people - @jdoyle for one - are saying "public interest" doesn't cover things like this.

 

I'm wary of just lumping things in the category "public interest". On the other thread we got to the point where the reference re public interest stated that there had to be a basis in EU/State Law.

 

Given that so much potential student (and staff) data would come under legal obligation, I'd be looking at what definitely falls in this category (and referencing the relevant Act/Statutory Reg/Directive) and labelling anything else as 'other', then iterating through the 'other' and questioning why it is needed before determining the category.

Posted
The data subject is not signing up as an individual, the school is contracting a services and so it would not be deemed as using an Information Society Service.

 

 

is this a personal view or based on legal advice?

 

My understanding is that the EU has already broken the link between who pays for an ISS and who uses it (Recital 18 in the Ecommerce Directive) but happy to be corrected.

Posted
is this a personal view or based on legal advice?

 

From a range of conversations with DP/IM folk, but I will add it to the list of specific legal questions on @jenatddm's collated questions when I get chance.

 

My understanding is that the EU has already broken the link between who pays for an ISS and who uses it (Recital 18 in the Ecommerce Directive) but happy to be corrected.

 

Yes, Recital 18 is interesting (especially when you look at the exceptions) ... I once asked the question (at RBC level) about whether there was any difference between a school hosting their own services (e.g. running HAP+) and an LA/RBC running a hosted file sharing service ... as was told no. When Live@Edu came on the scene (and then O365) I asked again if an RBC delivering services using these, rather than their own hardware, made an difference and was told no.

 

So what is the difference between a school running the service in house and using a contracted provider? What if the service is provided within the school, but is run by a Managed Service provider?

Posted
I'm wary of just lumping things in the category "public interest". On the other thread we got to the point where the reference re public interest stated that there had to be a basis in EU/State Law.

IMO this is correct (there has to be a basis in law). I think you have to be very careful with this as a reason because while you can broadly argue that processing personal information for the purposes of running a school is "in the public interest" (backed by various legislation), the GDPR and other legislation means there are equally arguments that it is in the public interest that individuals have control over their data, how that is processed and shared and how all that is made clear (transparent) to data subjects. If the processing is driven by legislation (i.e. there is a basis in law which would justify "public interest"), why would you not peg to "Legal Basis" as the basis for processing?

 

IMO to claim "public interest" you would have show that not processing the information would be detrimental to the health or well-being of the data subject (or possibly others). If it is not and you can operate without the data (despite that that might be quite inconvenient), consent should be the basis. You should also be aware that if you use "public interest" the data subject has a right to object and the burden is then on the Data Controller to demonstrate that it either has compelling grounds for continuing the processing, or that the processing is necessary in connection with its legal rights. So using "public interest" as the basis might get you through the audit quicker but leave you holding a can of worms if parents or students want to be awkward.

Posted
I'm wary of just lumping things in the category "public interest". On the other thread we got to the point where the reference re public interest stated that there had to be a basis in EU/State Law.

 

Given that so much potential student (and staff) data would come under legal obligation, I'd be looking at what definitely falls in this category (and referencing the relevant Act/Statutory Reg/Directive) and labelling anything else as 'other', then iterating through the 'other' and questioning why it is needed before determining the category.

 

I've asked the DfE that on a number of occasions ... for a list of all relevant acts/legislation that affect EdTech ... and asked Becta before that, but they had the closure notice before they could respond ... and so got passed to the DfE (bless Sir Humphrey!)

 

Effectively it is going to mean that someone, somewhere, is going to have to pay people with slim watches to stitch it together. I know ASCL have a good list of things (no longer a member so can't get to it), but come September it is on my list of things to follow up on, and I know that @jenatddm is already pushing a so many worthy questions too.

Posted
So what is the difference between a school running the service in house and using a contracted provider? What if the service is provided within the school, but is run by a Managed Service provider?

IMO, the difference is in how you exercise your duty of care. Staff employed by the school are subject to the contractual terms of the school which will bind them to school policy and procedure - all of which should be geared to exercising that duty of care. Staff who are employed by the contractor are not contracted to follow the schools process and procedure, so you need to somehow bridge that gap and ensure the contract binds them into operating in a way that is compliant with the schools duty of care to its data subjects.

 

(or am I not understanding the issue?)

Posted
So we are saying that it is down to duty of care and contractual obligations?

Your question was : "what is the difference?". My reply is from the schools POV but a complete answer would look from all points of view, that of the data subject, the data processor and the data controller. "There is no difference" might well be correct from the POV of the data subject (ETA under DPA, not quite under GDPR).

  • 1 month later...
Posted

I was invited to a heads of MAT meeting yesterday regarding GDPR. The exec principal has had some information from our solicitors regarding consent. They are saying that with GDPR, consent by default is with the student, not the parent. Only if the student had say, learning difficulties would the consent switch to the parent. This is rather different than I had understood the consent situation being.

 

Thoughts?

 

Meldrew

Posted
Possibly true, but you can do most of your data processing without consent because of legal obligation, contract delivery and/or public interest.
  • Thanks 1
Posted
If someone makes an SAR and asks for info to be deleted, does it have to be removed from the backups as well?
Posted
If someone makes an SAR and asks for info to be deleted, does it have to be removed from the backups as well?

Yes. The right to be forgotten includes backups.

 

However, in schools, it is quite possible that the data retained has to be retained in any case so they can jump up and down all they like but it won't be deleted.

Posted (edited)
If someone makes an SAR and asks for info to be deleted, does it have to be removed from the backups as well?

There is nothing in the Data Protection Act that compels you to delete data simply on the request of the data subject, they would have to show that processing causes unwarranted and substantial damage or distress. This will change somewhat under GDPR but the right is still not absolute. Data held on backups is data under both - so if the circumstances warrant deletion, then backups will be in scope. It may be reasonable to actually handle the deletion by disbarring further processing and allowing the data to expire naturally.

Edited by pcstru
Posted
There is nothing in the Data Protection Act that compels you to delete data simply on the request of the data subject, they would have to show that processing causes unwarranted and substantial damage or distress. This will change somewhat under GDPR but the right is still not absolute.

True, but the balance shifts with GDPR. Where previously you had to have a reason to ask for deletion, under GDPR, data controllers must comply unless they have a reason not to. The ICO says we must comply "When the individual objects to the processing and there is no overriding legitimate interest for continuing the processing" (https://ico.org.uk/for-organisations/data-protection-reform/overview-of-the-gdpr/individuals-rights/the-right-to-erasure/). Schools do have some overriding legitimate reasons, of course, but presumably any data not being held for those reasons should be deleted on request. So - we wouldn't have to delete safeguarding data about a former student but we would have to delete their Year 7 essay on Romeo and Juliet or their list of house points.

 

If someone makes an SAR and asks for info to be deleted, does it have to be removed from the backups as well?

 

As for the question of backups, yes data must be removed from all places it is stored, but I don't actually know how you're meant to do that in some backup environments. I don't actually think it is possible with our backup system (I should look into that!)

  • 2 months later...
Posted
i raised this point with our data manager and she said she is unsure of it will apply to us as we are a special needs school but i feel like it then means a case of which laws take precedent over another comes into play. I don't think i know of a single e13 year old that understands what really happens to data and how its a scary topic.
Posted
I was invited to a heads of MAT meeting yesterday regarding GDPR. The exec principal has had some information from our solicitors regarding consent. They are saying that with GDPR, consent by default is with the student, not the parent. Only if the student had say, learning difficulties would the consent switch to the parent. This is rather different than I had understood the consent situation being.

 

Thoughts?

 

Meldrew

 

Very little if any data processing in schools is consent based. Most processing is on a different legal basis. Children don't use the Internet in school on a consent basis, they can't revoke it, and you require them to use certain services for teaching. That's bot consent. Consent as a result of GDPR remains generally unchanged based on capacity in law, not GDPR.

 

The change through Article 8 is only for most Internet /online services ("Information society services" not counselling or preventative services) targeted at a child, and it is not exactly consent of the child, it is rather the the age at which parental consent is no longer required. Any cosnent based processing will have to still make other legal considerations, like "best interests of the child" test. Default is not a good word to use. It is advisable that all data collection from a child should involve a parent. And for example, it is a legal obligation for biometrics in schools >>Protection of Freedoms Act 2012.

  • Thanks 2
Posted

We also have to remember that legal reasons for processing is not a list with Consent as the last ditch reason.

You should choose the most appropriate reason, taking into account all other considerations (including other legislation, guidance from SoS, etc.)

  • Thanks 1
Posted
Children don't use the Internet in school on a consent basis, they can't revoke it, and you require them to use certain services for teaching. That's bot consent. Consent as a result of GDPR remains generally unchanged based on capacity in law, not GDPR.

 

*cough* - Internet access is a yes/no option on the parental consent form here, mirrored in SIMS.

 

The HOY will contact the parents to explain the heavily-filtered nature of school Internet provision and how a lack of Internet access will affect their child's education and participation in class activities, but if the parent refuses consent we abide by it.

 

Admittedly, we've had a few interesting parents with odd ideas about the Internet in the past.

Posted
*cough* - Internet access is a yes/no option on the parental consent form here, mirrored in SIMS.

 

The HOY will contact the parents to explain the heavily-filtered nature of school Internet provision and how a lack of Internet access will affect their child's education and participation in class activities, but if the parent refuses consent we abide by it.

 

Admittedly, we've had a few interesting parents with odd ideas about the Internet in the past.

 

Use of the Internet is not consent. It would probably be under public interest but the student / parents are using their right to restrict processing, which the school has chosen to allow them to do.

 

There is a difference.

Posted
*cough* - Internet access is a yes/no option on the parental consent form here, mirrored in SIMS.

 

The HOY will contact the parents to explain the heavily-filtered nature of school Internet provision and how a lack of Internet access will affect their child's education and participation in class activities, but if the parent refuses consent we abide by it.

 

Admittedly, we've had a few interesting parents with odd ideas about the Internet in the past.

 

We inform parents their child will have filtered Internet access (and include some disclaimer text that no filtering system is 100%). We don't offer parents the opportunity to opt in/out of their child having Internet access, and would strongly discourage any parent who wanted us to withhold it - too much of our curriculum delivery is web-based for us to be able to support this without a lot of additional work from the teachers.

 

As far as I'm aware, no parent has requested such, but it may well have happened and been handled by someone else, as that sort of request would possibly only make it to my desk if we needed to block the Internet for that child.

  • Thanks 1
  • 3 weeks later...
Posted
This is where I would like Smoothwall et al to post the legal basis for processing they understand they operate on today and explain if there is any change expected under GDPR. If Internet access is 'tick here or no access' it's not consent based. (Even if "consent" is in the title of the parent/pupil home agreement.) What I believe is unclear, and must be clarified for schools and parent/children, is who can refuse what and why. i.e. can a school impose home monitoring 365 days a year. Can a parent / child refuse the imposition of software on BYOD. Can parent/child refuse filtering/monitoring and school still permit Internet access by child. If not, can school refuse child access to the Internet in school, and on what legal basis vs school opinion. Collecting questions you want answered right now and will be used in discussion: please add here near end in coments in section "IT questions from current schools in practice" starting on page 18. and I'll edit them into body of text anonymously - unless you tell me you *want* to be named. Thanks.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...