Jump to content

Recommended Posts

Posted

I just wondered if there was any clear guidance of what a primary school will need to do regarding GDPR to become compliant.

 

I recently heard that schools will have to get rid of their paper based signing in books for visitors and get an electronic system due to this.

 

Any other information on what would be required would be helpful.

Posted
If you don't mind me asking, where did you hear about the paper based signing in system? I don't believe it would be legal or ethical to have electronic signing in as a requirement regardless of convenience or efficiency let alone data protection.
  • Thanks 1
Posted

I am somewhat gobsmacked by the paper based signing in book rumour. I am sure that's what it is.

 

GDPR doesn't tell you how to store things. It tells you about only taking necessary data and only using it for the purpose intended. And about maintaining data security ... arguably a paper based system is more secure, not less!

 

Someone at your school needs to go on a proper training course before the salesman and their fake news take to deep a grip!

  • Thanks 2
Posted

Data Protection applies to both electronic and paper systems. Data is data.

 

The argument (that has been around for some time) is the signing in books allow others to see who has been in. That is why some schools have different processes for general visitors and parents.

 

We will be sharing more guidance shortly that will be able to help you on your journey to compliance, but have a look at https://www.gdpr.school/wp-content/uploads/2017/07/Preparing-for-GDPR-in-schools.pdf to start with.

  • Thanks 3
Posted
Data Protection applies to both electronic and paper systems. Data is data.

 

The argument (that has been around for some time) is the signing in books allow others to see who has been in. That is why some schools have different processes for general visitors and parents.

 

We will be sharing more guidance shortly that will be able to help you on your journey to compliance, but have a look at https://www.gdpr.school/wp-content/uploads/2017/07/Preparing-for-GDPR-in-schools.pdf to start with.

 

A paper based system is still possible, and not impossibly complicated, without showing the list of names to everyone.

Posted
Keep it simple, effective, cheap. Schools shouldn't have to pay out for expensive signing in systems when it's perfectly simple to run a paper signing in system, comply with DPA/GDPR and remain safe.
Posted

 

why do you need a sign in book?

 

DAHO?

 

Feeling old again. Please enlighten me?

 

I'm working from a starting point that your question is sarcastic?

Posted
DAHO?

 

Feeling old again. Please enlighten me?

 

I'm working from a starting point that your question is sarcastic?

 

Devils Advocate Hat On.

 

Is there anything I've posted in any of the GDPR realted threads to suggest sarcasm?

Posted
Devils Advocate Hat On.

 

Is there anything I've posted in any of the GDPR realted threads to suggest sarcasm?

 

I believe he was going off the basis that most time when people use non-existant code tags (like me) they are usually being sarcastic (like me :D).

 

I would assume to ensure that visitors are accounted for if there is a fire, also can be used as evidence someone was on site during a crime.

  • Thanks 1
Posted

I think everyone has their own views on the actual GDPR requirements as they have no specific information and is more guidance which can be intereperited differently. I expect the LEA will eventually also have their own take on it and what needs to be done which is different to everyone elses views and opinions.

 

So with a paper signing in system, what do people here think would have to be done or used to make it compliant.

Posted
The most common ones are already nicely compliant, where people write out their ID badge/slip, tear it off and wear it, the only visible information left is signing in and out time. Easily available from espo and the likes.
  • Thanks 2
Posted
The most common ones are already nicely compliant, where people write out their ID badge/slip, tear it off and wear it, the only visible information left is signing in and out time. Easily available from espo and the likes.

 

That's what our MAT schools use

Posted
I believe he was going off the basis that most time when people use non-existant code tags (like me) they are usually being sarcastic (like me :D).

 

What he said.

 

Devils Advocate Hat On.

 

Is there anything I've posted in any of the GDPR realted threads to suggest sarcasm?

 

I was judging you by my own low standards - sorry.

 

I like your hat though 😀. I need to add one to my collection.

  • Thanks 1
Posted
What he said.

 

I was judging you by my own low standards - sorry.

 

I like your hat though 😀. I need to add one to my collection.

 

actually highlights assumptions and ties in with why I ask the question.

 

Is the sign in book to do with fire, health & safety, security, safeguarding, evidence for criminal investigation? a mix of all? do we do it because it's convention/assume it's the right thing to do?

 

On the surface it looks such a simple thing but we'll get different answers from different people/sites.

 

DPA suggests we should know why we collect data, be clear about informing people, retention etc. GDPR adds an extra need to be clear.

 

I like to have a statute to tie things to and would potentially link this to section 547 of the Education Act 1996 and suggest it is part of the security measures taken by the school to confirm who has a licence to be on premises (in conjunction with issuing an ID badge and related procedures re supervision etc).

Posted
actually highlights assumptions and ties in with why I ask the question.

 

Is the sign in book to do with fire, health & safety, security, safeguarding, evidence for criminal investigation? a mix of all? do we do it because it's convention/assume it's the right thing to do?

 

On the surface it looks such a simple thing but we'll get different answers from different people/sites.

 

DPA suggests we should know why we collect data, be clear about informing people, retention etc. GDPR adds an extra need to be clear.

 

I like to have a statute to tie things to and would potentially link this to section 547 of the Education Act 1996 and suggest it is part of the security measures taken by the school to confirm who has a licence to be on premises (in conjunction with issuing an ID badge and related procedures re supervision etc).

 

I'd say mix of all, but pretty sure we don't have it documented WRT data protection. From memory it is included in safeguarding and fire policies. Neither of those would specify how long we should retain the information.

Posted
actually highlights assumptions and ties in with why I ask the question.

 

Is the sign in book to do with fire, health & safety, security, safeguarding, evidence for criminal investigation? a mix of all? do we do it because it's convention/assume it's the right thing to do?

 

On the surface it looks such a simple thing but we'll get different answers from different people/sites.

 

DPA suggests we should know why we collect data, be clear about informing people, retention etc. GDPR adds an extra need to be clear.

 

I like to have a statute to tie things to and would potentially link this to section 547 of the Education Act 1996 and suggest it is part of the security measures taken by the school to confirm who has a licence to be on premises (in conjunction with issuing an ID badge and related procedures re supervision etc).

 

And we should not forget about retention and destruction. Do you know how long to keep the records for? When no longer needed how are they destroyed!

 

Welcome to the world of Data Protection and Information Handling!

Posted
And we should not forget about retention and destruction. Do you know how long to keep the records for? When no longer needed how are they destroyed!

And with old records, do you know what data they contain, what that means, why you collected it then and why you are holding it now? Might we need to contact people on who we hold historical data and gain consent for some of that?

Posted
And with old records, do you know what data they contain, what that means, why you collected it then and why you are holding it now? Might we need to contact people on who we hold historical data and gain consent for some of that?

 

Public interest or compliance with legal obligations. And you are storing not processing if historic ... it is an interesting point about how you would inform them though ...

 

Another question on the list.

Posted
Public interest or compliance with legal obligations.

I suspect we (and many others) hold historical data that will not fall into either criteria.

And you are storing not processing

Mmmm. We do not hold it just for the sake of it. We must have some intent to process it to justify the storage. If not, we should not be storing it.

Posted
I suspect we (and many others) hold historical data that will not fall into either criteria.

 

Mmmm. We do not hold it just for the sake of it. We must have some intent to process it to justify the storage. If not, we should not be storing it.

At our paediatric first aid trading this week, we were advised to keep records of any treatment we give until the pupils are 21 (some are 2 years 7 months when they join us) as there have been cases of ex-students exercising their right to sue when they turn 18.

 

We don't have any intention of processing that, but we will be storing it.

 

I've also wondered about keeping a school archive. I'm sure it's not uncommon to keep photos from opening ceremonies and school productions as part of the school's history - and I'm sure most people would be charmed to see photos from when they were kids. Don't think we could justify public interest if we were challenged though.

  • 6 months later...
Posted (edited)

Back onto this, our BM had a letter insisting anything paper based is not GDPR compliant. That, coupled with websites like this one:

 

https://www.proxyclick.com/subscription-gdpr?ads_cmpid=1001805055&ads_adid=52351302474&ads_matchtype=b&ads_network=g&ads_creative=249318249784&utm_term=gdpr%20visitor%20book&ads_targetid=kwd-387622852020&utm_campaign=&utm_source=adwords&utm_medium=ppc&ttv=2&gclid=Cj0KCQjwtOLVBRCZARIsADPLtJ1UYLywVOcXqZS9VzHsymwSZ-5RTw9XLNpXAPImErpF5PBdlzbv0JMaAjapEALw_wcB

 

meant she was keen to press the button on buying something in.

 

Interestingly, this is how the letter sells the system:

 

4 Reasons why paper-based signing in systems could cost you under GDPR

 

1: Right to Erasure

If an individual requests that you delete their personal information, and you have no legitimate reason to keep it, will you be able to find it? How long will it take to redact the individual entries?

 

2: Data Privacy

Visitors signing in on your paper-based systems can see the personal details of other visitors who have already signed in.

 

3: Data Security

Paper-based systems are not robust and can be easily lost, damaged or end up in the wrong hands.

 

4: Data Disposal

Legislation states that personal data must be disposed of in an appropriate manner and not simply thrown in the recycling.

 

What is the solution?

Electronic staff and student management system costing £3k!

 

...or a 23 quid book from Viking and some organisation

Edited by Love_Sausage

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...