CommodoreS Posted September 5, 2017 Posted September 5, 2017 I just wondered if there was any clear guidance of what a primary school will need to do regarding GDPR to become compliant. I recently heard that schools will have to get rid of their paper based signing in books for visitors and get an electronic system due to this. Any other information on what would be required would be helpful.
synaesthesia Posted September 5, 2017 Posted September 5, 2017 If you don't mind me asking, where did you hear about the paper based signing in system? I don't believe it would be legal or ethical to have electronic signing in as a requirement regardless of convenience or efficiency let alone data protection. 1
elsiegee40 Posted September 5, 2017 Posted September 5, 2017 I am somewhat gobsmacked by the paper based signing in book rumour. I am sure that's what it is. GDPR doesn't tell you how to store things. It tells you about only taking necessary data and only using it for the purpose intended. And about maintaining data security ... arguably a paper based system is more secure, not less! Someone at your school needs to go on a proper training course before the salesman and their fake news take to deep a grip! 2
GrumbleDook Posted September 5, 2017 Posted September 5, 2017 Data Protection applies to both electronic and paper systems. Data is data. The argument (that has been around for some time) is the signing in books allow others to see who has been in. That is why some schools have different processes for general visitors and parents. We will be sharing more guidance shortly that will be able to help you on your journey to compliance, but have a look at https://www.gdpr.school/wp-content/uploads/2017/07/Preparing-for-GDPR-in-schools.pdf to start with. 3
elsiegee40 Posted September 5, 2017 Posted September 5, 2017 Data Protection applies to both electronic and paper systems. Data is data. The argument (that has been around for some time) is the signing in books allow others to see who has been in. That is why some schools have different processes for general visitors and parents. We will be sharing more guidance shortly that will be able to help you on your journey to compliance, but have a look at https://www.gdpr.school/wp-content/uploads/2017/07/Preparing-for-GDPR-in-schools.pdf to start with. A paper based system is still possible, and not impossibly complicated, without showing the list of names to everyone.
synaesthesia Posted September 5, 2017 Posted September 5, 2017 Keep it simple, effective, cheap. Schools shouldn't have to pay out for expensive signing in systems when it's perfectly simple to run a paper signing in system, comply with DPA/GDPR and remain safe.
jmak Posted September 5, 2017 Posted September 5, 2017 why do you need a sign in book? DAHO? Feeling old again. Please enlighten me? I'm working from a starting point that your question is sarcastic?
jdoyle Posted September 5, 2017 Posted September 5, 2017 DAHO? Feeling old again. Please enlighten me? I'm working from a starting point that your question is sarcastic? Devils Advocate Hat On. Is there anything I've posted in any of the GDPR realted threads to suggest sarcasm?
DJ-1701 Posted September 5, 2017 Posted September 5, 2017 Devils Advocate Hat On. Is there anything I've posted in any of the GDPR realted threads to suggest sarcasm? I believe he was going off the basis that most time when people use non-existant code tags (like me) they are usually being sarcastic (like me ). I would assume to ensure that visitors are accounted for if there is a fire, also can be used as evidence someone was on site during a crime. 1
localzuk Posted September 5, 2017 Posted September 5, 2017 why do you need a sign in book? Fire register.
GrumbleDook Posted September 5, 2017 Posted September 5, 2017 Safeguarding requirements, keeping a track of all visitors within school.
CommodoreS Posted September 5, 2017 Author Posted September 5, 2017 I think everyone has their own views on the actual GDPR requirements as they have no specific information and is more guidance which can be intereperited differently. I expect the LEA will eventually also have their own take on it and what needs to be done which is different to everyone elses views and opinions. So with a paper signing in system, what do people here think would have to be done or used to make it compliant.
synaesthesia Posted September 5, 2017 Posted September 5, 2017 The most common ones are already nicely compliant, where people write out their ID badge/slip, tear it off and wear it, the only visible information left is signing in and out time. Easily available from espo and the likes. 2
elsiegee40 Posted September 5, 2017 Posted September 5, 2017 The most common ones are already nicely compliant, where people write out their ID badge/slip, tear it off and wear it, the only visible information left is signing in and out time. Easily available from espo and the likes. That's what our MAT schools use
CommodoreS Posted September 5, 2017 Author Posted September 5, 2017 Does anyone know what company makes the visitor stickers that put red lines over the sticker after 24 hours?
jmak Posted September 5, 2017 Posted September 5, 2017 I believe he was going off the basis that most time when people use non-existant code tags (like me) they are usually being sarcastic (like me ). What he said. Devils Advocate Hat On. Is there anything I've posted in any of the GDPR realted threads to suggest sarcasm? I was judging you by my own low standards - sorry. I like your hat though 😀. I need to add one to my collection. 1
jdoyle Posted September 6, 2017 Posted September 6, 2017 What he said. I was judging you by my own low standards - sorry. I like your hat though 😀. I need to add one to my collection. actually highlights assumptions and ties in with why I ask the question. Is the sign in book to do with fire, health & safety, security, safeguarding, evidence for criminal investigation? a mix of all? do we do it because it's convention/assume it's the right thing to do? On the surface it looks such a simple thing but we'll get different answers from different people/sites. DPA suggests we should know why we collect data, be clear about informing people, retention etc. GDPR adds an extra need to be clear. I like to have a statute to tie things to and would potentially link this to section 547 of the Education Act 1996 and suggest it is part of the security measures taken by the school to confirm who has a licence to be on premises (in conjunction with issuing an ID badge and related procedures re supervision etc).
jmak Posted September 6, 2017 Posted September 6, 2017 actually highlights assumptions and ties in with why I ask the question. Is the sign in book to do with fire, health & safety, security, safeguarding, evidence for criminal investigation? a mix of all? do we do it because it's convention/assume it's the right thing to do? On the surface it looks such a simple thing but we'll get different answers from different people/sites. DPA suggests we should know why we collect data, be clear about informing people, retention etc. GDPR adds an extra need to be clear. I like to have a statute to tie things to and would potentially link this to section 547 of the Education Act 1996 and suggest it is part of the security measures taken by the school to confirm who has a licence to be on premises (in conjunction with issuing an ID badge and related procedures re supervision etc). I'd say mix of all, but pretty sure we don't have it documented WRT data protection. From memory it is included in safeguarding and fire policies. Neither of those would specify how long we should retain the information.
GrumbleDook Posted September 6, 2017 Posted September 6, 2017 actually highlights assumptions and ties in with why I ask the question. Is the sign in book to do with fire, health & safety, security, safeguarding, evidence for criminal investigation? a mix of all? do we do it because it's convention/assume it's the right thing to do? On the surface it looks such a simple thing but we'll get different answers from different people/sites. DPA suggests we should know why we collect data, be clear about informing people, retention etc. GDPR adds an extra need to be clear. I like to have a statute to tie things to and would potentially link this to section 547 of the Education Act 1996 and suggest it is part of the security measures taken by the school to confirm who has a licence to be on premises (in conjunction with issuing an ID badge and related procedures re supervision etc). And we should not forget about retention and destruction. Do you know how long to keep the records for? When no longer needed how are they destroyed! Welcome to the world of Data Protection and Information Handling!
pcstru Posted September 6, 2017 Posted September 6, 2017 And we should not forget about retention and destruction. Do you know how long to keep the records for? When no longer needed how are they destroyed! And with old records, do you know what data they contain, what that means, why you collected it then and why you are holding it now? Might we need to contact people on who we hold historical data and gain consent for some of that?
GrumbleDook Posted September 6, 2017 Posted September 6, 2017 And with old records, do you know what data they contain, what that means, why you collected it then and why you are holding it now? Might we need to contact people on who we hold historical data and gain consent for some of that? Public interest or compliance with legal obligations. And you are storing not processing if historic ... it is an interesting point about how you would inform them though ... Another question on the list.
pcstru Posted September 6, 2017 Posted September 6, 2017 Public interest or compliance with legal obligations. I suspect we (and many others) hold historical data that will not fall into either criteria. And you are storing not processing Mmmm. We do not hold it just for the sake of it. We must have some intent to process it to justify the storage. If not, we should not be storing it.
jmak Posted September 6, 2017 Posted September 6, 2017 I suspect we (and many others) hold historical data that will not fall into either criteria. Mmmm. We do not hold it just for the sake of it. We must have some intent to process it to justify the storage. If not, we should not be storing it. At our paediatric first aid trading this week, we were advised to keep records of any treatment we give until the pupils are 21 (some are 2 years 7 months when they join us) as there have been cases of ex-students exercising their right to sue when they turn 18. We don't have any intention of processing that, but we will be storing it. I've also wondered about keeping a school archive. I'm sure it's not uncommon to keep photos from opening ceremonies and school productions as part of the school's history - and I'm sure most people would be charmed to see photos from when they were kids. Don't think we could justify public interest if we were challenged though.
Love_Sausage Posted March 26, 2018 Posted March 26, 2018 (edited) Back onto this, our BM had a letter insisting anything paper based is not GDPR compliant. That, coupled with websites like this one: https://www.proxyclick.com/subscription-gdpr?ads_cmpid=1001805055&ads_adid=52351302474&ads_matchtype=b&ads_network=g&ads_creative=249318249784&utm_term=gdpr%20visitor%20book&ads_targetid=kwd-387622852020&utm_campaign=&utm_source=adwords&utm_medium=ppc&ttv=2&gclid=Cj0KCQjwtOLVBRCZARIsADPLtJ1UYLywVOcXqZS9VzHsymwSZ-5RTw9XLNpXAPImErpF5PBdlzbv0JMaAjapEALw_wcB meant she was keen to press the button on buying something in. Interestingly, this is how the letter sells the system: 4 Reasons why paper-based signing in systems could cost you under GDPR 1: Right to Erasure If an individual requests that you delete their personal information, and you have no legitimate reason to keep it, will you be able to find it? How long will it take to redact the individual entries? 2: Data Privacy Visitors signing in on your paper-based systems can see the personal details of other visitors who have already signed in. 3: Data Security Paper-based systems are not robust and can be easily lost, damaged or end up in the wrong hands. 4: Data Disposal Legislation states that personal data must be disposed of in an appropriate manner and not simply thrown in the recycling. What is the solution? Electronic staff and student management system costing £3k! ...or a 23 quid book from Viking and some organisation Edited March 26, 2018 by Love_Sausage
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now