Jump to content

Recommended Posts

Posted
The question is asking whether we have practices in place to ensure all parents are treated equally, but it sounds like we don't need to, we only need the consent of one person with PR. Or is it that we only need one for medical consent, but should strive to have both for parents evenings, etc.? Obviously, having both is preferable and would avoid that horrible story from last year when some children were home alone with a dead parent.

 

No you have to ensure both parents are treated equally in almost all respects (unless one of them has a court order saying the other gets nothing). So for things like information home to parents, voting on school governors, invites to parents evenings, newsletters, reports about their child and so on - all that must go to both parents if they're separated; neither the live-in parent nor the student has the right to stop that. Consent for stuff is pretty much the only bit you can just speak to one.

 

Questions 1 and 6 on the request are, really, pretty darned legit.

Posted
You would still want practises in place to ensure all parents are treated equally though, for example can both parents book parents evening, can both parents be given newsletters, text messages etc. This is more about what the school does to engage both parents which evidence suggests will improve the life chances of the child rather than deciding who can consent.

 

Indeed. Although this is another area where raw numbers pulled from MIS don't accurately reflect what happens on the ground. We have lots of families where both parents are at home but only one receives newsletters, emails. re parents evening, etc., and others where only one is at home but both receive the emails.

Posted
I'm not going to go looking for the policy, I manage the network I don't have anything to do with those sorts of policies, however I'm sure one exists and we get consent from (and when sending communications out it goes to) both parents unless there is a court order preventing us from contacting one of the parents. (That's another thing to add into the mix which may confuse the data even more)

 

Well the question is do you have a policy which covers ..., so the answer is yes we have a policy, the policy being that you contact both parents unless there's a court order stopping you.

Posted

:mod:

 

Personal attacks have again been made in this thread.

 

Arguments are more than a little circular.

 

If you cannot contribute to this thread without attacking the person then please leave the discussion.

 

We do have the power to block individuals from the thread if we choose to use them.

 

We are also discussing closing this thread until the judgement is known.

 

If you wish to continue to debate FoI requests then play nicely.

 

Posts that do not abide by forum rules, and those quoting posts that do not abide by forum rules, will simply be removed from now on.

 

Final warning. Thank you.

 

:mod:

  • Thanks 4
Posted (edited)

You know what, I really love roundabouts... but there are so many times you can go round in a circle until you get dizzy... just like this thread. May I suggest this thread closes until there is a reason to post? (i.e. if the decision of the validity of the FOI request is upheld or overturned?).

 

---Update---

 

Honestly, (and I can't believe I'm saying this, this is me, who loves to argue!) I think locking the thread is the correct way to go.

 

Great minds think alike...

Edited by DJ-1701
  • Thanks 1
Posted
Only the resident parent's consent is needed, unless it's a matter of "long term and significant impact" orthe separated parent has specifically asked for their consent not to be inferred. If that's the case, you have to specifically ask them.

 

EDIT: Gov's guidance here: https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/489901/Parental_Responsibility_Advice_for_School_January_2016.pdf

 

OK, so the legal stuff. Unless there's a court order specifying who the child "lives with", which is in the part after the phrase "The court orders", not before, then there is no resident parent, both parents are equal under the law. When it comes to consent it's Parental Responsibility that matters, not Residency. The term Residency itself has been deprecates since the Children and Families Act 2014, when it was changed to "lives with". The concept is exactly the same, they just keep changing the name, was "Custody" until The Children Act 1989, then became "Residency" and when people worked out that was just another term for custody it was changed again to protect the guilty.

 

PR is the critical thing for schools. When parents live together you are safe in assuming they agree about consent. When they separate you should act on any request to seek consent separately. When there's a court order about contact with the child you should assume they don't agree (after all they had to go to court to sort out the child seeing one of the parents) and you should seek consent from both.

 

How on earth would a school decide if a matter was of "long term and significant impact"? If you adopt a policy which says "if in doubt, ask for consent", you're less likely to find yourself in difficulty.

Posted
Honestly, (and I can't believe I'm saying this, this is me, who loves to argue!) I think locking the thread is the correct way to go.

 

.

 

hear, hear :D

  • Thanks 1
  • 4 weeks later...
Posted

The only part I'd disagree with in there is this:

 

It is entirely reasonable that a school should maintain a policy of never operating hyperlinks to unknown websites and should instruct staff accordingly.

 

...

 

That Mr. Maloney’s website is unquestionably benign and designed for a lawful purpose is neither here nor there. The School cannot know that on receipt of the request Email and cannot sensibly be expected to undertake research to discover whether his website can be safely accessed.

 

If you're going to say it's reasonable to have a policy of never opening links to "unknown" websites then surely it follows that they must be expected to have a means of investigating a website to discover it can be suitably accessed, otherwise they'd never be allowed to stray past their intranet.

 

But yeah, the judgement is right.

Posted
As discussed, it's an easy attack vector. People have to respond to an FOI, so when one comes flying in the door with a link to it, the link usually gets opened. SO easy to exploit and doesn't take the usual amount of doctoring you need to create a spoof PayPal/Bank email to achieve the same result.
Posted
If you're going to say it's reasonable to have a policy of never opening links to "unknown" websites then surely it follows that they must be expected to have a means of investigating a website to discover it can be suitably accessed, otherwise they'd never be allowed to stray past their intranet.

I get what you're saying, it would probably be worth appending something like "where the hyperlink is not trusted, expected or fitting within the context of the communication."

 

As much as it is explained (and could be argued 'fitting within the context') I think it's acceptable to categorise a link in an email from someone you don't know and weren't expecting as 'untrusted'.

 

I think that anybody wanting to improve the chances of having their FOI request (or any communication, for that matter) responded to would do well to bear this in mind, and keep all of the information in the actual email. No external links, no attachments, the basics of e-mail give you more than enough to convey your message appropriately.

  • Thanks 1
Posted

It would have been interesting to hear the explanation surrounding the point 9(ii):

His website was secure. He described how it functioned. Websites provided less unauthorized access to data than mail servers which store Emails
  • Thanks 1
Posted
The only part I'd disagree with in there is this:

 

It is entirely reasonable that a school should maintain a policy of never operating hyperlinks to unknown websites and should instruct staff accordingly.

 

If you're going to say it's reasonable to have a policy of never opening links to "unknown" websites then surely it follows that they must be expected to have a means of investigating a website to discover it can be suitably accessed, otherwise they'd never be allowed to stray past their intranet.

 

I think it comes down to how you define "unknown". A website on an unsolicited email is completely unknown, a website in the top results in Google is not unknown, as it could only have got there by either being popular or being sponsored by the host (and here I'm assuming Google don't accept sponsorship from malicious sites).

Posted (edited)
I think it comes down to how you define "unknown". A website on an unsolicited email is completely unknown, a website in the top results in Google is not unknown, as it could only have got there by either being popular or being sponsored by the host (and here I'm assuming Google don't accept sponsorship from malicious sites).

 

Depends on your google-fu; his site is #6 in Google results when I search for "Brian Maloney FOI", so it's risky to try and use that criteria to judge safety I think.

 

Edit: Hit number 1 is this page: https://www.kelsi.org.uk/news-and-events/news/primary/update-regarding-response-to-foi-request-from-mr-maloney

 

Last paragraph:

 

To ascertain the number of hours it would take, you take the number of pupils on roll, multiply by 5 and divide by 60. If the school has less than 200 pupils, you may need to say it would take 10 minutes per pupil record to look at each file and extract and collate the contact information if you want to maintain it would take too long to deal.

 

This is the kind of thing that irritates me about this whole affair. The request is invalid for the reasons the ICO and appeals court outlined, but this advice to *make up the time it takes you to deal with the request* is indicative of a pretty poor attitude towards FOI.

Edited by djrscally
Posted
I think it comes down to how you define "unknown". A website on an unsolicited email is completely unknown, a website in the top results in Google is not unknown, as it could only have got there by either being popular or being sponsored by the host (and here I'm assuming Google don't accept sponsorship from malicious sites).

But then you have to think of the average user. Yes we might know ways to find out if a site is legit but would (and no offence intended here) the average school secretary receiving an email with a link know how to check this?

Posted

I didn't realise you can see how many requests every user has submitted, I thought they were anonymous, makes for some interesting reading about who submits what type of requests and how many.

 

I might try and find the person who submits most, I bet there is someone out there submitting them daily to places!

Posted
I didn't realise you can see how many requests every user has submitted, I thought they were anonymous, makes for some interesting reading about who submits what type of requests and how many.I might try and find the person who submits most, I bet there is someone out there submitting them daily to places!
Data miners working for marketing companies submit thousands to gov.
Posted
But then you have to think of the average user. Yes we might know ways to find out if a site is legit but would (and no offence intended here) the average school secretary receiving an email with a link know how to check this?

 

No, which is why we train the "average school secretary" not to click on unknown links. I think that was my point, and certainly was the ICO's point.

 

@djrscally was suggesting a policy of "don't click unknown links" meant people are stuck within their own intranet, but I disagree. What I meant was I think it is okay to click an previously-unknown link which is printed in a magazine or on a known/reputable website, but not to click a previously-unknown link from an unsolicited email.

  • Thanks 1
Posted
Data miners working for marketing companies submit thousands to gov.

 

Which annoys me. That isn't what FOIA was intended for.

  • Thanks 1
Posted
Which annoys me. That isn't what FOIA was intended for.

No definitely not, I bet that's the costliest abuse of it too.

 

@djrscally was suggesting a policy of "don't click unknown links" meant people are stuck within their own intranet, but I disagree. What I meant was I think it is okay to click an previously-unknown link which is printed in a magazine or on a known/reputable website, but not to click a previously-unknown link from an unsolicited email.

 

Yeah you're probably right.

Posted (edited)
Data miners working for marketing companies submit thousands to gov.

Which annoys me. That isn't what FOIA was intended for.

 

Yup, unfortunately FOIA is able to be abused this way, and there's money to be made abusing it, so people do.

We can refuse to take part in "market research" just because (though, annoyingly, TPS doesn't bar "market research" calls) but it takes more to refuse an FOI request.

 

FWIW, I think @bmaloney's request was certainly more in line with the spirit of the act, and privately speaking I do think they're trying to make a point that does need making, it was just improperly formatted and it's important both sides stick to the rules otherwise we end up setting a precedent for answering questions that fail to comply.

Edited by Garacesh
precedence -> precedent
  • Thanks 3
Guest
This topic is now closed to further replies.



×
×
  • Create New...