Jump to content

Recommended Posts

Posted

Someone has raised the first hypothetical question that we cannot answer. Please can someone give me some insight as to the following:

 

We monitor and record students internet activity, out of school time and in their homes. This is currently done with parents permission and is a service that the school offers.

With GDPR will we need the students permission to do this?

Our understanding of the regulation of investigatory powers act (RIPA) says that as a service provider we must retain the data for 12 months. If parents and or students ask for the data to be deleted is this possible? We cannot work out which regulation we need to adhere to. My gut says RIPA but has anyone got a legal perspective on this ?

Posted
Our understanding of the regulation of investigatory powers act (RIPA) says that as a service provider we must retain the data for 12 months. If parents and or students ask for the data to be deleted is this possible? We cannot work out which regulation we need to adhere to. My gut says RIPA but has anyone got a legal perspective on this ?

 

Right to erasure under GDPR is not absolute. According to the ICO, "You can refuse to comply with a request for erasure where the personal data is processed ... to comply with a legal obligation or for the performance of a public interest task or exercise of official authority;" (source: https://ico.org.uk/for-organisations/data-protection-reform/overview-of-the-gdpr/individuals-rights/the-right-to-erasure/) so in this instance, you can refuse to delete within 12 months because RIPA requires you to keep it.

 

I think you would need the consent of children 13+ to continue offering this service, but that's a separate topic.

  • Thanks 1
Posted

I think you would need the consent of children 13+ to continue offering this service, but that's a separate topic.

 

Perhaps a popup asking for consent to access the internet would do it. They could always opt out of that.

Posted
Perhaps a popup asking for consent to access the internet would do it. They could always opt out of that.

 

I think you might need something like that, otherwise how would you ensure other family members or visitors to the house who might use the computer have given their consent? It could get thorny if one household member refuses consent, as you would then have to withdraw it from the PC, which would remove it from all users - that's between you and the specific family, though.

 

Out of interest, is this just a basic filtering/blocking service you offer, or do you review the activity and report anything of concern to the parents?

Posted

Out of interest, is this just a basic filtering/blocking service you offer, or do you review the activity and report anything of concern to the parents?

Our procedure is to report concern to Head of Year or to the Safeguarding team. We (IT) don't have a procedure to report to parents, but the other teams might do after we report to them.

Posted
Our procedure is to report concern to Head of Year or to the Safeguarding team. We (IT) don't have a procedure to report to parents, but the other teams might do after we report to them.

 

And how do you know the concerning activity came from the student, not their sibling or parent?

Posted
And how do you know the concerning activity came from the student, not their sibling or parent?

 

We just report it

Posted
And how do you know the concerning activity came from the student, not their sibling or parent?

 

That is not a matter for IT to investigate.

Posted
That is not a matter for IT to investigate.

 

True, just thinking through potential pitfalls with the service. Still worth offering the families, though.

Posted

Following from this bit:

I think you would need the consent of children 13+ to continue offering this service, but that's a separate topic.

 

Suppose the students refused consent, and we blocked internet access at home/school. It would then follow that they would be reprimanded for not handing in a piece of work because all homework is set via IT systems.

Given that is our legal obligation to educate students would GDPR allow us to not ask consent ?

Posted (edited)
Following from this bit:

Suppose the students refused consent, and we blocked internet access at home/school. It would then follow that they would be reprimanded for not handing in a piece of work because all homework is set via IT systems.

Given that is our legal obligation to educate students would GDPR allow us to not ask consent ?

 

Can we back up a bit and ask who owns the device you're filtering? The school or the parents of the child?

Edited by pete
Posted
Following from this bit:

 

 

Suppose the students refused consent, and we blocked internet access at home/school. It would then follow that they would be reprimanded for not handing in a piece of work because all homework is set via IT systems.

Given that is our legal obligation to educate students would GDPR allow us to not ask consent ?

 

Aren't they personally-owned devices in this instance? If so, I think they're well within their rights to refuse consent, you then stop monitoring their home computer and they do their homework unfiltered (or rather, under parental supervision if the family wishes that).

 

Yes, you have a legal obligation to educate them, and a legal obligation to monitor their activity while within school, but you have no legal obligation to offer a filtering service on the family computer, so if they refuse consent I think that is between the child and their parents.

Posted

I guess that's the problem.

We offer the scheme whereby parents buy a Chromebook for the child; This has been deemed necessary for Teaching and Learning to the extent that they pay no tax and must have one.

The Chromebook is normally owned by the parents unless they have not paid in full, or there is a bursary of some kind.

 

I suppose the easiest answer is to not offer the service, but the question is how do we offer the service and comply with GDPR.

 

If it was just in-school. Do we have to allow students opt-in then ? because it's basically asking them to opt-into education...

Posted

At Smoothwall we're doing a lot of work to get our customers ready for GDPR. We are working closely with our lawyers to determine what needs to be done in the areas of filtering and monitoring.

 

On the issue of consent our understanding is that if you have decided that one of the conditions in Article 6(1) or Article 9(2), other than those which are consent-based, apply to your processing of personal data then you will not need to obtain consent.

 

You may decide that the appropriate conditions for your processing of filtering are one or more of:

· Article 6(1)© – compliance with a legal obligation which you are subject to

· Article 6(1)(e) – performance of a task in the public interest

 

Retention is not an issue as long as you make a declaration on what retention period you are working to.

 

The right to erasure or the right to be forgotten, as it is also known, is not an absolute right. As a data controller, you will need to consider each request on an individual basis to determine what, if any, personal data relating to the individual making the request, needs to be deleted.

  • Thanks 3
Posted

@mjk I think you're going to have to make this service opt-in with the ability to remove the monitoring if a parent/13+ student declines consent. The Chromebook itself is deemed necessary for their education and you can filter the school's Internet connection without consent on the grounds of legal obligation, but I don't see you have any legal grounds for monitoring non-educational activity over the families' home Internet connections.

 

I would suggest you clarify the question of ownership of the devices for students on bursaries though, as that could be a factor, but my view is unless you are taking the devices back when the students leave the school, the devices are 100% theirs even if they were given a bursary towards it. We operate a similar scheme here, where all families are offered the opportunity to buy the device through the school, thus saving the VAT. They are not given the device until they have paid in full, which for some means we hang on to it while monthly instalment cheques clear. FSM-eligible students are supported in this purchase, but the device is still theirs from Day 1.

Posted

Providing a service outside of school has been a significant discussion point for about 5-6 years in one particular LinkedIn group, run by Dr Brian Bandey.

 

His approach has been to look at the H&S risks associated with this as this is an area that cover mental health and well-being.

 

From his conjecture we can see that a service provided by the school, to be used outside of school as well as in school, has an onus on the school to ensure the safety of the learners.

 

If you approach it from that position when you talk to Legal then they may agree that you have the right approach and so you are complying with a legal obligation.

 

Speak to your MDM provider on this to get their position ... as they are more likely to have access to legal folk to discuss.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...