Jump to content

Recommended Posts

Posted

"I'm guessing you skipped the part where he's trying to force schools to use his automated system to respond rather than a valid FOI request."

 

Again he is entailed to ask. Yes it doesn't have to be done that way but I don't think it is professional for people and/or organisations to be obstructive.

Posted

And then when people refuse he should do it the right way rather than trying to make out everyone's wrong and needs to comply to "his way".

 

Thus the whole issue in this thread, it's been said, he doesn't agree, loop around.

 

A prime example is the fact that most schools when responding to FOI need to keep a copy of their own replies for filing away etc, which again isn't possible in "his way"

 

Steve

Posted

"And then when people refuse he should do it the right way rather than trying to make out everyone's wrong and needs to comply to "his way". "

 

Agreed, but then there are other comments of here that not related to that.

 

Im not taking sides here, I just think this is getting out of hand unjustifiably.

 

PS: Quotes not working so thats why I am using quotation marks.

Posted (edited)
Saving myself 200 days of work, 8 hours a day is not for my own amusement. There are very good reasons to constrain the response, for instance the form ensures that answers requiring a numerical response are actually natural numbers. If I didn't do that I would get a mixture of numbers and words such as Zero, 5, Nine, three, None, 12, etc. Now technically that's correct, but it requires human intervention to convert it to something useful. Whereas the school could actually have used a number to respond to a question requiring a number as a response, but perhaps they do this for their own amusement?

 

More likely they just wouldn't twig that it's easier for you to aggregate the responses if they're provided in a numerical format - not everyone wears an analysis hat so they probably just wouldn't realise why you want it that way.

 

Requesting responses via a form of some kind (whether Google or a custom one as in this case) when you're making requests to a large number of authorities with the intention of building a large dataset is pretty reasonable, and doesn't invalidate the request by any means (though I agree the lack of contact information without accessing a link probably did make it technically invalid) - authorities don't have to use your preferred format though, and may have good reason not to do so, so you probably ought to acknowledge that possibility in the request and give a "second best" preference like an Excel sheet or something.

Edited by djrscally
Posted

Some quick fire facts here: @bmaloney's requests are legible, legal and should be complied with. Don't dally, the more you sit there overthinking it, the more time *you* are wasting (you being your school)

Whilst a quick peruse of his WDTK profile shows he is pretty much an "ambulance chaser" type person, the motive isn't questionable. Just comply.

Social media requests are feasible. Won't take much to knock up a FOI page on your website and point SM requests to that.

We're all here for the same purpose, Mr Maloney appears to be looking out for the best interests of children & related parties, and certainly we are too. Keeping things civil on both sides is a must, and also BOTH sides should accept where changes should be made.

Chill!

  • Thanks 2
Posted
40% of 23000 schools is a statistically significant figure. It’s enough to do data analysis on.

 

About 4292 responses so far, out of 16,000, so that's about 25% of schools overall, but it's usually the bigger schools who are better at this. So far I have responses for over 1,000,000 children's records. In one LA only one school has responded. You can't draw any conclusions from that unfortunately.

Posted
And then when people refuse he should do it the right way rather than trying to make out everyone's wrong and needs to comply to "his way".

 

Thus the whole issue in this thread, it's been said, he doesn't agree, loop around.

 

A prime example is the fact that most schools when responding to FOI need to keep a copy of their own replies for filing away etc, which again isn't possible in "his way"

 

Steve

 

With all due respect, I did think of that one. I find it very annoying when you submit a complaint or a request to a contact form and you don't get a copy of your request by email, so my form is designed to send a copy of any submission to the original contact email and the secondary email of the person filling in the form if that's different. The form also has a captcha to prevent spammers using it to send emails to random people through my sight, well at least make it difficult for them. So far I haven't seen any evidence of that.

Posted
With all due respect, I did think of that one. I find it very annoying when you submit a complaint or a request to a contact form and you don't get a copy of your request by email, so my form is designed to send a copy of any submission to the original contact email and the secondary email of the person filling in the form if that's different. The form also has a captcha to prevent spammers using it to send emails to random people through my sight, well at least make it difficult for them. So far I haven't seen any evidence of that.

 

You sending them back an email isn't the same as them having a log of what's been sent, who's been processing it blahblah.

 

What stops you modifying a result and sending that information back to the school in an email? They have no proof what was sent over originally or when etc

 

Steve

Posted
You sending them back an email isn't the same as them having a log of what's been sent, who's been processing it blahblah.

 

What stops you modifying a result and sending that information back to the school in an email? They have no proof what was sent over originally or when etc

 

Steve

 

Don't quite understand this objection, they can just record the values they filled in to the form in their FOI requests log. You don't have to have an exact carbon copy of the bytes that were sent in response to the FOI, just as long as you know that a) You responded and b) the information you supplied.

Posted
Don't quite understand this objection, they can just record the values they filled in to the form in their FOI requests log. You don't have to have an exact carbon copy of the bytes that were sent in response to the FOI, just as long as you know that a) You responded and b) the information you supplied.

 

And lets say in 20 days you get a message saying the data's not been received how do you prove you sent it?

 

Or how the data that's then shown up on the other end of this survey is what you submitted?

 

There's a reason whole county data teams have responded and said not to use it :p

 

Steve

Posted
And lets say in 20 days you get a message saying the data's not been received how do you prove you sent it?

 

Or how the data that's then shown up on the other end of this survey is what you submitted?

 

There's a reason whole county data teams have responded and said not to use it :p

 

Steve

 

Same way you'd prove you responded to a physical mail request; you show them your FOI log. I guess you could screenshot it if you were super paranoid, but I'd consider that unnecessary. Same applies to proving what data you sent when you respond via snail mail.

 

Hardly seems likely anyway; if someone was gonna fudge the data regardless of the responses I doubt they'd bother making the requests in the first place; recent news has shown nobody bothers fact checking anyway.

Posted
@bmaloney I am curious to know how you got a bulk list of all the schools email addresses?

 

I started with eduBase which gave a list of the websites for most schools. I then wrote a script to trawl those sites to get email addresses, which got a lot of them, then I found another site where one of these lists was posted and merged those in. Sometimes my scraped results were better than the list, so I used mine.

 

For some authorities, particularly in Wales, there were no websites and it's been a case of trawling the LAs site for contact details. Ofsted report provide some and https://www.goodschoolsguide.co.uk/ provide others. When I sent out the requests I got some bounces as schools have changed their details recently, so those needed updating. I'd be happy to publish the list, but I suspect that may annoy some people here.

Posted
And lets say in 20 days you get a message saying the data's not been received how do you prove you sent it?

 

The same way you would prove you'd send it if they had requested the information via snail-mail...

Posted
Same way you'd prove you responded to a physical mail request; you show them your FOI log. I guess you could screenshot it if you were super paranoid, but I'd consider that unnecessary. Same applies to proving what data you sent when you respond via snail mail.

 

Hardly seems likely anyway; if someone was gonna fudge the data regardless of the responses I doubt they'd bother making the requests in the first place; recent news has shown nobody bothers fact checking anyway.

 

That's the main point, what's to stop me fudging the data? To prove I haven't I would have to publish all the data I've received. Why not, I'm not precious about it. FOI responses are public information, anyone else could make the same requests and get the same data. It would be unscientific if someone couldn't repeat the experiment and get the same results.

Posted
I started with eduBase which gave a list of the websites for most schools. I then wrote a script to trawl those sites to get email addresses, which got a lot of them, then I found another site where one of these lists was posted and merged those in. Sometimes my scraped results were better than the list, so I used mine.

 

Doesn't that run the risk of contacting the same school more than once? Even if you filtered to only email each domain name once, lots of schools have more than one domain name so you might end up emailing [email protected] and [email protected] The school could then refuse because it would be a repeat request, which obviously you don't want.

Posted
Doesn't that run the risk of contacting the same school more than once? Even if you filtered to only email each domain name once, lots of schools have more than one domain name so you might end up emailing [email protected] and [email protected] The school could then refuse because it would be a repeat request, which obviously you don't want.

 

They can only refuse the latter request though.

Posted
The same way you would prove you'd send it if they had requested the information via snail-mail...

 

One enhancement I do intend to make is to present a "review your submission" screen so you can see, and print off, a copy of the data you're submitting before you send it. This would satisfy the requirement before sending and allow the responder a pause for thought. I'd retain the email confirmation because that shows it's been received.

 

It would be much more constructed to discuss what the requirements are for systems which collect FOI information in this way rather than trying to find ways to refuse the request. I've proposed using a separate device for submitting the information which is kept isolated from the school's sensitive data, you can get a tablet for as little as £30 these days which would address all the security issues. If you can get hold of a 2nd hand smart phone that would do the trick too, as long as it's wiped first of course.

 

I've had a number of responses from schools who've got hold of another school's request. There's one school in Kent whose request did the rounds, Crockham Hill I think. Other schools were appending their data to Crockham Hill's request which had their unique link in it and sending it back via email, which makes it very difficult to identify them.

 

I've also had confidential information from schools sent to me by email. One was a reply to a solicitor about a child arrangements order for one of their pupils. Another had put some comments on the request which included children's names and some comments and a second person had sent me the annotated email without checking what was in it. If they had been using my form this would not have happened.

Posted
Doesn't that run the risk of contacting the same school more than once? Even if you filtered to only email each domain name once, lots of schools have more than one domain name so you might end up emailing [email protected] and [email protected] The school could then refuse because it would be a repeat request, which obviously you don't want.

 

I only have one website for each school, eduBase doesn't list more than that, or rather didn't.

Posted

Let me get this right, you are using a unique code to surreptitiously track if users have clicked the link or not. Is this allowed under privacy law for individual users?

 

Whilst this isn't a reason to prevent the school from responding to the request, it does raise an immediate alarm bell and comes across as rather insidious and underhanded in my book. (And no, this isn't seeking a reason to not comply as any FOI requests I receive are immediately passed to the FOI Officer for consideration in compliance with LA policies).

Posted (edited)
Let me get this right, you are using a unique code to surreptitiously track if users have clicked the link or not. Is this allowed under privacy law for individual users?

 

Whilst this isn't a reason to prevent the school from responding to the request, it does raise an immediate alarm bell and comes across as rather insidious and underhanded in my book. (And no, this isn't seeking a reason to not comply as any FOI requests I receive are immediately passed to the FOI Officer for consideration in compliance with LA policies).

 

 

 

Every single marketing email that has ever been sent to you attempts to do this, without you even noticing, by including content like an image of a single white pixel that is loads a file (linked to your email address, I.E. named [email protected]) from a server under their control. It's a well established practice to enable them to target their emails at people who actually read them.

 

It's perfectly legal.

 

Ref: https://en.wikipedia.org/wiki/Web_beacon

 

EDIT: Besides, in this case he's just checking the school has responded since he said he's just getting the generic school email address. Given the volume he has to go through, pretty reasonable.

Edited by djrscally
Posted
Every single marketing email that has ever been sent to you attempts to do this, without you even noticing, by including content like an image of a single white pixel that is loads a file (linked to your email address, I.E. named [email protected]) from a server under their control. It's a well established practice to enable them to target their emails at people who actually read them.

 

It's perfectly legal.

 

Ref: https://en.wikipedia.org/wiki/Web_beacon

 

I know about web beacons, hence why images are automatically disabled in my E-mail clients. :)

Posted
I know about web beacons, hence why images are automatically disabled in my E-mail clients. :)

 

That's all it is. When you have 3 different schools all names St. Thomas' Roman Catholic Primary School, and you've sent them all requests how do you make sure the responses are associated with the right Public Authority. It's not personal data, it's the school's data, which is public anyway.

 

I'm not putting a GPS tracker on you and I'm not interested in your internet habits, I don't have time to do that with 16,000 schools.

 

Acymailing, the tool I use to send these requests, does this by default. It also shows me that 1000 more schools have opened my emailed requests than have responded in any way, refusal or otherwise. I wouldn't know about those who don't download images, so there are probably significantly more who have seen the request and decide to do absolutely nothing.

Posted

You aren't interested in Internet habits, but proceed to declare the habits of schools who haven't responded? Do you have a privacy policy for handling the data of those who receive your E-Mail? I'm pretty sure marketing companies are supposed to when they contact you. Are you also making users aware that by reading the E-Mail or clicking on the link that their activity has been tracked? Are you protecting this information that identifies individual schools who are not responding from being stolen or accessed without authorisation? What if an IP address and time is recorded for an employee accessing from home, are you now venturing into personal Internet habits?

 

I know you aren't a public body but can I make a FOI request anyway for this?

  • Thanks 1
Guest
This topic is now closed to further replies.



×
×
  • Create New...