Jump to content

Recommended Posts

Posted

Until schools start to look at what data they've got ... no one will know the percentage.

 

If only there was a Quasi-Autonomous Non-Governmental Organisation to help look at that sort of thing ;)

  • Thanks 1
Posted

anything anectodal out there from any school at all?

 

If we don't know yet, should we be seeing notes suggesting that "Most data in schools will be legally processed under the Public Interest umbrella "? Shouldn't there be at least some nod to the legal obligation umbrella too as this forms the core data in a school? Admission register, attendance register, common transfer files, absence recording, SEN data, medical data, accident books, census data, reports, exclusions, etc

  • Thanks 1
Posted

There will be times when data could be processed due to a range of possible reasons.

 

Until we see the final Bill, it is hard to say what order or precedence the reasons will out with.

 

One thing we do know, is that Public Interest is a valid reason (I still see that to comply with Legal Obligation needs someone to set these out clearly including reference and guidance on appropriate existing laws ... i.e. DfE), but in the same manner, I can see why saying it 'will' be processed under Public Interest could better be rephrased as 'Is likely to at least be processed under Public Interest'.

  • Thanks 1
Posted

the public interest umbrella comes across as too vague in my mind whereas the legal obligation is a reference to existing legislation re the education sector (which we should focus on later to check what comes out)

 

This thread started off (wrongly) with the premise that the students would be able to stop sharing data with parents when they reach the age of 13. This change is just aimed at the online services operating "at a distance" and clearly does not apply to day to day school administration. The Govt may do something sneaky here but they couldn't tie that back to the GDPR which is fairly clear on the intended change.

 

We already have legislation that ensures parents have access to educational records in maintained schools until students are 18, regardless of whether the student consents or not. This sort of detail may get changed though I doubt it.

Posted

GDPR says access at 16, but U.K. govt has said they will (tbc) change that to 13.

 

Any existing legislation to say parent can access will have to have clarifications as we progress with the new bill. Until then we have possible conflicts.

 

The thread, to some extent, is to try to say that don't believe any scare mongering about everything needs to be about consent.

 

And yes, Public Interest is going to be vague until best practice is established or until further guidance comes out ... but it effectively becomes the lowest common denominator until things are cleared up.

  • Thanks 1
Posted (edited)

Yes, it’s all conjecture until we see the final act and I was merely stating possibilities not fact. What is clear though, a fixed age has never been suggested to be part of legislation before as it is here.

 

In view of all these considerations, we will legislate to allow a child aged 13 years or older to consent to their personal data being processed.

 

In the past there’s been ‘suggested’ ages and very woolly statements.

 

As for using public interest as legal basis for processing, it’s a minefield.

 

Take the standard text messaging service – a school could argue, correctly in my opinion, that communication with parents regarding attendance, progress, behaviour is the public duty of a school and therefore the data may be processed legally as being of the public interest. However if the school uses the same messaging service to tell parents about the school fete or barn dance – this is definitely marketing and consent needs to be sort. The data map for the same data fields for the same processor needs to carry 2 legal basis for processing.

 

Welcome to my world!

Edited by maturelady
  • Thanks 1
Posted
Take the standard text messaging service – a school could argue, correctly in my opinion, that communication with parents regarding attendance, progress, behaviour is the public duty of a school and therefore the data may be processed legally as being of the public interest. However if the school uses the same messaging service to tell parents about the school fete or barn dance – this is definitely marketing and consent needs to be sort. The data map for the same data fields for the same processor needs to carry 2 legal basis for processing.

 

You don't think using a text messaging system could be argued as being in the public interest as its use saves the school public money?

Posted
You don't think using a text messaging system could be argued as being in the public interest as its use saves the school public money?

 

It's not the system used to send them that's the issue. It's taking information recorded/processed for one reason (informing them about their kid) and using it for another reason (marketing some random event at school).

 

Processing the data for marketing purposes requires consent. And a method in the system to ensure you don't email/txt marketing bumpf to people who haven't opted in.

Posted
You don't think using a text messaging system could be argued as being in the public interest as its use saves the school public money?

I think if saving money "in the public interest" was justification, we could just forget DP as it is fabulously cheaper to just ignore it!

Posted
It's not the system used to send them that's the issue. It's taking information recorded/processed for one reason (informing them about their kid) and using it for another reason (marketing some random event at school).

 

Processing the data for marketing purposes requires consent. And a method in the system to ensure you don't email/txt marketing bumpf to people who haven't opted in.

 

We already have their active consent to use the address information they give us to contact them with matters relating to their child and the school, we don't go into detail about either how or why we would contact them. So I think we're okay...

 

One issue we could face would be if the GDPR has us spell out our usage, at which point we could have problems with a parent who doesn't want things they view to be marketing (which is subjective in itself), as our mailing system doesn't differentiate - either we can mail them or we can't.

Posted
I think if saving money "in the public interest" was justification, we could just forget DP as it is fabulously cheaper to just ignore it!

 

Please don't twist my words like that. I did not say we should ignore any legislation which costs money. I said sending information via email which previously we would have sent via paper saves the school money, and our processing of their email address would therefore in the public interest.

Posted

 

In view of all these considerations, we will legislate to allow a child aged 13 years or older to consent to their personal data being processed.

 

I mentioned previously that the line quoted in the DCMS statement/document goes back to the GDPR and online services.

 

Article 8 "Conditions applicable to child's consent in relation to information society services"

1. Where point (a) of Article 6(1) applies, in relation to the offer of information society services directly to a child, the processing of the personal data of a child shall be lawful where the child is at least 16 years old. Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child. Member States may provide by law for a lower age for those purposes provided that such lower age is not below 13 years.

 

This article is aimed at those organisations that come under the Information Society Services definition. These are defined in a separate EC Directive 98/34/EC :

 

Information Society service, that is to say, any service normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient of services.

For the purposes of this definition:

— “at a distance” means that the service is provided without the parties being simultaneously present,

— “by electronic means” means that the service is sent initially and received at its destination by means of electronic equipment for the processing (including digital compression) and storage of data, and entirely transmitted, conveyed and received by wire, by radio, by optical means or by other electromagnetic means,

— “at the individual request of a recipient of services” means that the service is provided through the transmission of data on individual request.

 

So if you are a supplier of Information Society Services and you are claiming Article 6(1)(a) (ie the consent of the data subject) as the basis of your lawful processing then you need to be mindful of the age of the data subject.

 

A school is not an Information Society Service so Article 8 does not apply at all.

 

If the definition did somehow apply to a school and the school was claiming Article 6(1)© (ie legal obligation) or the more fluffy Article 6(1)(e) Public Interest as the basis of lawful processing then the Article 8 line re age does not apply.

  • Thanks 2
Posted
Please don't twist my words like that. I did not say we should ignore any legislation which costs money. I said sending information via email which previously we would have sent via paper saves the school money, and our processing of their email address would therefore in the public interest.

I'm simply trying to highlight why your thinking is wrong by highlighting that DP has nothing much to do with the means by which you process data but rather it is the actual processing (what you are doing with it and why you are doing that) that is key. The example you were replying to was distinguishing between data processing for the purposes of marketing and data processing for statutory purposes. Your query seems to be that you do something now which is DPA compliant but which will likely not be under GDPR precisely because it is the PROCESSING that requires a lawful basis and the same piece of data can be processed in any number of ways each of which might be covered by a different condition as it's basis. So sending marketing is likely to require explicit consent where sending a yearly school report is necessary for compliance with the legal obligation of the school, so you are unlikely to need explicit consent.

  • Thanks 1
Posted

A school is not an Information Society Service so Article 8 does not apply at all.So if you are a supplier of Information Society Services and you are claiming Article 6(1)(a) (ie the consent of the data subject) as the basis of your lawful processing then you need to be mindful of the age of the data subject.

 

A school is not an Information Society Service so Article 8 does not apply at all.

 

If the definition did somehow apply to a school and the school was claiming Article 6(1)© (ie legal obligation) or the more fluffy Article 6(1)(e) Public Interest as the basis of lawful processing then the Article 8 line re age does not apply.

 

We're not providers of them, but we do require our students to use them (ActiveLearn, Vocab Express, Kerboodle, Animatron, GCSEPod, AppShed, Mathswatch and the list goes on). Since we're processing data for those under the banners of legal obligation and/or public interest, does also mean Article 8 doesn't apply and students can't withdraw consent?

Posted
ISo sending marketing is likely to require explicit consent where sending a yearly school report is necessary for compliance with the legal obligation of the school, so you are unlikely to need explicit consent.

 

That could be tedious for us if that is the case. Our messaging system doesn't enable us to include a parent in the school reports and absence alerts but exclude them from the "marketing" emails, so we would have to opt them out of everything and then send the legal obligation letters in the post instead. We have explicit consent anyway, so this would only factor if that consent were to be withdrawn.

Posted
We're not providers of them, but we do require our students to use them (ActiveLearn, Vocab Express, Kerboodle, Animatron, GCSEPod, AppShed, Mathswatch and the list goes on). Since we're processing data for those under the banners of legal obligation and/or public interest, does also mean Article 8 doesn't apply and students can't withdraw consent?

 

The school is not legally obliged to use the services or online material of any of the suppliers. I don't think it would be possible to claim public interest.

 

the suppliers listed are all potentially Information Services suppliers so they have to take heed of Article 8 if they are offering services to children where they claim consent as the basis of their lawful processing. I suspect that the GDPR text was intending a direct "contract" between the data subject and the Information Society service supplier.

 

Where consent is the basis then Article 7 and Withdrawal of Consent needs to be added to the mix.

 

The GDPR change is geared towards children and their use of social media. It's not intended to get in the way of schools and education but this is an area where it could.

Posted

 

Take the standard text messaging service – a school could argue, correctly in my opinion, that communication with parents regarding attendance, progress, behaviour is the public duty of a school and therefore the data may be processed legally as being of the public interest. However if the school uses the same messaging service to tell parents about the school fete or barn dance – this is definitely marketing and consent needs to be sort. The data map for the same data fields for the same processor needs to carry 2 legal basis for processing.

 

 

Having to have a think about this one.

 

The school is required to ask for a telephone number to put on record for the purpose of contacting a parent in an emergency ie :

 

"The admission register for every school shall contain an index in alphabetical order of all the pupils at the school and shall also contain the following particulars in respect of every such pupil—

(a) name in full;

(b) sex;

© the name and address of every person known to the proprietor of the school to be a parent of the pupil and, against the entry on the register of the particulars of any parent with

whom the pupil normally resides, an indication of that fact and a note of at least one telephone number at which the parent can be contacted in an emergency;

(d) day, month and year of birth;

(e) day, month and year of admission or re-admission to the school; and

(f) name and address of the school last attended, if any. "

 

There's nothing that gives the school permission for any other use of the phone. Nothing in the legal obligations re collecting an email address for parents.

 

If a school is looking to save paper and plans to use email/text I'd be tempted to say they should be seeking consent regardless of if it supports legal obligations or marketing.

  • 2 weeks later...
Posted

I'm still stuck on the consent / agreeing to terms of use with online platforms such as MathsWatch. Pages 43-44 of https://publications.parliament.uk/pa/ld201617/ldselect/ldcomuni/130/130.pdf (from another post on this forum) do seem to suggest we would need active consent to the terms of each of the online subscription services we use. That could be a logistical nightmare, not to mention a problem for teachers while we gather consent and then if anyone refuses.

 

What do you think?

Posted

No, it is an educational tool that you are using to deliver a curriculum, so it comes under Public Interest.

However, you do have to inform and you do have to do Due Diligence that the data is only being used for the purposes *you* want and can justify.

 

I'm going to be off EG for a week or two whilst I get through a chunk of work, but first week in Sept I'll try to cover this in more detail.

  • Thanks 1
Posted
I'm still stuck on the consent / agreeing to terms of use with online platforms such as MathsWatch. Pages 43-44 of https://publications.parliament.uk/pa/ld201617/ldselect/ldcomuni/130/130.pdf (from another post on this forum) do seem to suggest we would need active consent to the terms of each of the online subscription services we use. That could be a logistical nightmare, not to mention a problem for teachers while we gather consent and then if anyone refuses.

 

What do you think?

 

to turn the question around slightly, what do you think MathsWatch need to so as an "Information Society Service"?

 

Currently, they have no data notice, cookie notice or any passing reference to data protection as other providers do e.g. SAM Learning, Doddle, GCSE Pod, MicroLib. Nothing on the website mentioning the GDPR.

 

How well does the MathsWatch website meet the legal requirements re Company Registration Number, T&Cs etc?

Posted

If what you say is correct MathsWatch does not come anywhere near today's requirements and regulations. These are clearly laid out - here's one site that outlines what is required https://www.amityweb.co.uk/blog/is-your-website-legal

 

Today you can take the risk using a company that does not meet regulations, on 25th May 2018 it will be illegal for you to use them.

 

I would not expect any company yet to be publishing how they are GDPR compliant although I would hope that they will be letting their customers know that becoming compliant before 25th May 2018 it is of the highest priority for them.

Posted
No, it is an educational tool that you are using to deliver a curriculum, so it comes under Public Interest.

 

That's my thinking too, but some people - @jdoyle for one - are saying "public interest" doesn't cover things like this.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...