Jump to content

Recommended Posts

Posted

We are currently laying the foundations for GDPR, and getting documentation ready for it, and at the same time trying to understand it!

 

We currently encrypt pretty much any device that leaves the school building, usb sticks, laptops etc. Our photo policy has been revised to only allow photos to be taken on school equipment, ie supplied cameras. My issue is that we are NOT allowed to use our own encrypted, password protected phones to take photos, however must now use unencrypted cameras for take photos. This is more directed when the photos are taken outside the school, ie class/year outings.

 

If phone is lost then it will be harder to get into, if a camera is lost - take card out and view photos - how is that safe? I can't justify £800 cameras that can encrypt photos. Obviously this loss would need to be reported as a data breach because of the content, and potential fines could be greater as it's not a protected device!

 

Thoughts most appreciated, this comes from me as the IT side of things - am I just opening a can of worms!

Posted
I get the impression that this isn't too much of a problem - the camera shouldn't contain any personally identifiable information. That of course can be dulled with name badges, school name on the side of a minibus in shot etc, but standard photos shouldn't be an issue. I could be wrong of course, wouldn't be new!
Posted

Remember that is about appropriate technical and organisational measures ...

 

Modern cameras do need to be looked at too as some may link to the interwebz for things like location ... and if that is tagged on a photo it adds extra info.

 

It needs to be part of the trip risk assessment ... as does what you do with the class list that a teacher takes with them for emergency contacts, etc.

Posted

In my view, the photos themselves are personally identifiable information and so the camera loss is something to think about. You could however reduce the risks involved by taking several SD cards and swapping them out and keeping used ones in a secure location. Its debatable that an SD card however is easier to lose than the camera itself though. An other view is that the photos are probably taken to end up on the website for publicity, so what's the difference...

 

Meldrew

Posted

We have a few cameras that can connect to a phone using an app, and send the photos. As we are not allowed to take pictures on personal devices this would probably be frowned upon, or it's another device that needs to be carried around!

 

Think this will be part of the risk assessment for the visit/trips - I suspect trips will be reduced due to the amount of paperwork and potential risks involved with going out, but that's another conversation.

Posted
What about wireless sd cards that can send the pictures to a phone? The phone could be password protected.

 

Would this work? Has anyone used these? do you need a wireless network to communicate through or can they send the data straight to the phone?

 

-edit- looks like it might https://www.cnet.com/uk/how-to/transfer-photos-from-a-camera-to-your-phone/

If that's the case why not just cut out the need for the camera and wireless SD and just take the photo on the phone in the first place?

 

I hadn't even thought about cameras in my GDPR plan. *adds it to the ever growing list.

  • Thanks 1
Posted

The use of personal devices is usually discouraged for Safeguarding reasons.

 

Far better to have photographs taken on a school device and then transferred to a staff share than have photographs on a personal device and/or personal storage area on the network.

 

When training staff, I always tell them that this rule at our school was as much to protect them as to protect the kids. If an allegation is made, it's far better that you don't have any photos that the authorities end up wading through; much less stressful.

 

At my school we had ipod touches that the staff used to take photos

Posted

Don't forget the piece of paper with everyone's name on, that might get lost too.

 

ie don't worry that much, not like anyone in the area who could steal the sd card couldn't have also taken photos themselves.

Posted
The use of personal devices is usually discouraged for Safeguarding reasons.

 

Far better to have photographs taken on a school device and then transferred to a staff share than have photographs on a personal device and/or personal storage area on the network.

 

When training staff, I always tell them that this rule at our school was as much to protect them as to protect the kids. If an allegation is made, it's far better that you don't have any photos that the authorities end up wading through; much less stressful.

 

At my school we had ipod touches that the staff used to take photos

 

This. The two things are being muddled.

 

I think over complication is getting in the way here. If you have multiple cards they are more likely to get lost. Just use one, that stays in the camera while out on a trip and it is in your policy that it gets wiped as soon as images are removed, images are transferred before the camera is returned. If someone is checking in the camera, making sure the battery goes back on charge, maybe they could do a quick format on it.

 

If a picture on an SD card is against Data Protection then all our websites need to be taken down, what is the difference?

  • Thanks 1
Posted

One potential issue with use of personal devices is all the online backup and photo sharing which devices can do. This can lead to photos being inadvertently shared, sometimes very quickly.

 

If I take a photo on my personal phone, it is immediately uploaded by Google Photos app to my personal Drive; that in turn is syncing with my laptop via Google Backup and Sync, and my laptop is a shared device. So... whenever I take a photo on my phone, that photo can be viewed within minutes by my wife.

Posted

This is always an important question, are photos considered personally identifiable information by them selves?

 

I recognise that there are safeguarding considerations for pictures but as a data protection question are photos more of a risk than the class register, being as one is a list of names with no other context and one is a lot of pictures with no other context?

 

Again I recognise that uniforms and logos are identifiable but they are visible on some lists and if you see the group before stealing the list.

 

Continuing on this stream of thought would we have to securely dispose of and disclose a breach if one is misplaced?

Posted (edited)
This is always an important question, are photos considered personally identifiable information by them selves?

 

Potentially, yes. If you have famous or high-profile students/parents, if you have students in witness protection or with court orders preventing someone from knowing where they are. I can easily imagine someone might take loads of photos at a group event, pick their favourite and then check no-one on the "not for publicity" list is included, but those students may still be in some of the other shots.

 

but as a data protection question are photos more of a risk than the class register, being as one is a list of names with no other context and one is a lot of pictures with no other context?

 

More of a risk? Probably not. You should be equally careful with both data sets.

Edited by enjay

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...