Jump to content

Recommended Posts

Posted

We're trying to sort out what data obligation each party has in a proposed Cashless Catering system.

 

Our setup is a little unusual because our catering in provided by a third party (ex-LA spin off) and it's not the school who are implementing this. The catering company has identified BioStore / Fastrack as their preferred supplier.

 

During initial discussions we've raised the question of Data Protection and are trying to establish what the data flow is and who is the data controller at each stage. Neither the catering company nor Biostore have responded satisfactorily, in my opinion. The catering company have said "there are no data protection issues because it's all on site" and BioStore have said "it's all in your MIS so it's your responsibility". The catering company had not heard of GDPR.

 

Has anyone else set up a similar system? If so, what are your arrangements for DP?

 

As I see it, we will provide access to our MIS to enable Biostore to collect names, photos and other information to use in their system. That system, based on a server located in the school but not owned by us, will provide data to the POS equipment and collect data from it. It will also link in to an existing, school funded online payment system. I would imagine, at the least, that Biostore have some DP obligations regarding their system and the links to the MIS and payment system just like any other third party do. I would also expect the catering company to have DP obligations regarding access to the POS eqipment and controlling cards etc. I expect both these parties to have DP obligations to the parents wrt the collection of monies and feedback on what the children have eaten. I also expect both parties to have a DP obligation to the children wrt telling their parents what they've had for lunch, and that this obligation would include getting explicit permission from all those 13 and over when the new legislation based on GDPR come into force.

 

That's a lot of expectation; am I expecting too much?

  • Thanks 1
Posted

I mean it sounds a lot like our setup, two separate entities school/catering side here but I think a lot of those areas are yours and not theirs to deal with.

 

You're the one giving data to a 3rd party, so it's your job to check it fulfils with DP etc and permission is granted by the parents. While it's their job to ensure it's held safe, it's not their job to do the checking/parent consent etc, you need to provide that over and shouldn't be sending the data via the integration if that's the case it's not authorised.

 

Assuming you're using something like ParentPay it's your "site" the parents log into to view students food details etc, so that's your side again. What is posted up to parentpay if you want that restricted is a question for your school to raise to the catering company etc again.

 

Steve

  • Thanks 2
Posted

This is something we are helping a few companies clear up ... even things like where a data processor ends up putting in a direct relationship with the parent and even becoming a data controller for that parent (effectively sharing it with the school).

 

An important thing to remember is where a company provides you a system to process data (you are both controller and processor) there is still an onus on the company to help you understand what is being processed. Some folk get it ... some folk take more time.

Explain to them that you need to understand what their system does.

 

Drop me a PM if you want to talk about it more.

  • Thanks 1
Posted

The catering company have said "there are no data protection issues because it's all on site" and BioStore have said "it's all in your MIS so it's your responsibility".

 

Questions:

 

For school:

1. Are you going to adopt the Biostore biometrics applications

2. Which data items precisely will be extracted from the MIS and does each one meet the test of 'necessary' and why (don't just accept "Biostore wants it")

3. Who owns (and has access to content and responsibility for security of) each server involved

4. Is there a direct data flow to the catering company and/or to Biostore from school and/or flow back

 

For catering co:

[cough]

1. You have employment data, as well as customer/client data even if you don't store pupil data. Suggest you get some Data Protection advice.

 

For Biostore:

1. What personal and other data does the POS equipment collect from a child - item by item basis

2. What personal and other data does Biostore extract and how often from the MIS

3. What sensitive data do you collect, process and retain / analyse or otherwise process (biometrics, ethnicity, photographs)

4. What payment data are collected from payers (holders of parental responsibility)

5. Where are these physically stored and shared

6. Are data stored on the 'controlling cards'

7. What in-house or third party analytics do you run on the data and what is its retention and onward use policy (for example of the purchase profiles)

8. What is the retention policy for each and how is future destruction managed

 

For all:

1. what is the legal basis for the collection or processing for each data type (i.e. personal / biometrics / financial)

2. who stores and shares with whom, feedback (what is that exactly) on what has been bought ("eaten" unproven)

on what legal basis are parents told what has been bought or other associated data

3. Is it possible in your part of this chain that personal data could be compromised (lost or leaked through malicious hacking, system outage, theft, human error) > If yes, who would contact the ICO and who would contact the individuals affected?

4. Who will document any necessary security and consent procedures for each part of the chain

5. Who will document pupil / parent communications for each part of the chain

6. Who is responsible for pupil / parent subject access requests

7. Who is the responsible DPO (children merit special protections under recital 38 and large scale monitoring and profiling, required)?

8. Who is responsible for assuring destruction of all personal data gathered for these purposes, when, and how is it communicated to pupils/parents at that time?

 

Re: "this obligation would include getting explicit permission from all those 13 and over when the new legislation based on GDPR come into force."

Note: there is no legal duty in this area that is age related under current DPA. 13 is likely to be the age at which parental authorisation for the collection of personal data will be required for information society services, excluding preventative or counselling services, where consent is the legal basis for processing. (GDPR article 8)

 

This is an area in which both pupils and parents need involved at any age. If biometrics involved, note requirement to have informed both holders of parental responsibility / parents, and active consent from one and lack of active objection neither as well as child necessary.

(Protection of Freedoms Act 2012)

 

I'd suggest all taking a look at this ICO page if not already done so, and decide the legal basis for each data processing activity: collection, copy/share of MIS data, flow, storage, processing (including any profiling of the child whether by biometrics or on what has been purchased over time), retention period and destruction.

 

What I can think of for now. I'd love to keep in touch on this one, and see what the outcomes and replies are. We could build a flow diagram from it, with decision points and if yes> if no> steps, which would be helpful for others I believe.

  • Thanks 3
Posted

Re. the "it is onsite / in your MIS, therefore your issue" comments, I think they're right - unless Biostore have access to the server on your site, I don't think there is a data processing implication on them. You are using equipment provided by them, but you are doing the actual processing. Similarly, unless your catering company can see any of the information stored in the cards/POS equipment, I don't think there's a concern there either.

 

Also remember even though the catering is a third party, they are working on sub-contract for you and using information provided by you, not obtained directly - therefore, I don't think they need to enter into any data processing agreement with the parents/students.

 

I'll be following this discussion with interest, as we are looking at something similar here, also with an external catering company, but one difference with us is we are trying to "impose" cashless on them, not the other way round.

Posted
Re. the "it is onsite / in your MIS, therefore your issue" comments, I think they're right - unless Biostore have access to the server on your site, I don't think there is a data processing implication on them. You are using equipment provided by them, but you are doing the actual processing. Similarly, unless your catering company can see any of the information stored in the cards/POS equipment, I don't think there's a concern there either.

 

Also remember even though the catering is a third party, they are working on sub-contract for you and using information provided by you, not obtained directly - therefore, I don't think they need to enter into any data processing agreement with the parents/students.

 

I'll be following this discussion with interest, as we are looking at something similar here, also with an external catering company, but one difference with us is we are trying to "impose" cashless on them, not the other way round.

 

("Impose" is also imposed not only on catering co. but on parents and children. Do you give *them* an option? It is their personal data, after all, not school's. Tip: AVoid what our school did. MIS should not extract and send to third party cashless co. without explicit permisison fisrt to set up accounts.)

 

Needs more information --hence the questions-- before you can decide where the controller and processor roles are. Other locations using Biostore /similar systems in past have been part-funded by the NHS and pass the children's data on to the Health Authority (or as was). That made them a joint-controller, so each situation needs detail as it ay not be obvious. There are shared responsibilties in any processing. Unless their systems never touch any of your data, can't see how they will avoid being processors, and possibly joint-controllers if purchase-profiling is not at your request, but by their design for example, and is not part of school's duty as public authority.

 

Some relevant parts of GDPR

Records of Processing - shared duties https://gdpr-info.eu/art-30-gdpr/

Joint Controllers https://gdpr-info.eu/art-26-gdpr/

Responsibility of the Controller https://gdpr-info.eu/art-24-gdpr/

Processor https://gdpr-info.eu/art-28-gdpr/

Security of processing https://gdpr-info.eu/art-32-gdpr/

need to demostrate accountability https://gdpr-info.eu/recitals/no-74/

  • Thanks 1
Posted
("Impose" is also imposed not only on catering co. but on parents and children. Do you give *them* an option?

 

No, but nor do we give them a choice about putting their personal information in SIMS, or sharing it with Google, Mathswatch etc. We do, however, ensure we only share what information is needed and only with organisations who will handle it appropriately.

 

These are areas for which consent to share is not required, remember. To date, no-one has complained or asked us not to share the data.

  • Thanks 2
Posted

Thank you far your responses, there is a lot to consider and it concerns me that so many people I deal with have no idea, or have not given any consideration to, data protection.

 

In no way was I trying to wriggle out of our responsibilities, I accept that we play a major role in all this.

 

Also remember even though the catering is a third party, they are working on sub-contract for you and using information provided by you, not obtained directly - therefore, I don't think they need to enter into any data processing agreement with the parents/students.

 

My thinking (and I'm happy to be proven wrong) is that they are generating and processing data; they are recording spend and processing the collection of money and they are reporting to parents about how the child is spending that money. I accept that any agreement with parents and pupils may come from the school, but it will have to name the other companies involved. And I want to make sure any data we provide is managed in an approriate manner; a blase "not my problem, pal" attitude won't cut it.

 

We've made some progress, and we now have a flow chart showing the data processes (ish) - I've attached it for those that are interested.

FasTrak Insatlltion Flow.pdf

  • Thanks 1
Posted
My thinking (and I'm happy to be proven wrong) is that they are generating and processing data; they are recording spend and processing the collection of money and they are reporting to parents about how the child is spending that money. I accept that any agreement with parents and pupils may come from the school, but it will have to name the other companies involved. And I want to make sure any data we provide is managed in an approriate manner; a blase "not my problem, pal" attitude won't cut it.

 

It depends exactly what data they have and what they do with it. If all their POS is doing is saying "charge £1.59 to card 6583", there's no DP risk. If the POS system knows the name of card 6583's owner, you have some further questions to answer (one of which is "does the POS need to know the name of the card owner?"), but even then unless the catering staff themselves can see that data, I'm not sure you have much to worry about. Of course, if the company are able to independently tell the parents of the owner of card 6583 what that child had for lunch last Tuesday, then you have more to check, and at that point I think you've become co-Controllers of the data.

  • Thanks 1
Posted

For catering co:

[cough]

1. You have employment data, as well as customer/client data even if you don't store pupil data. Suggest you get some Data Protection advice.

 

This ... a common one in so many organisations, not just EdTech!

  • Thanks 1
Posted
Re. the "it is onsite / in your MIS, therefore your issue" comments, I think they're right - unless Biostore have access to the server on your site, I don't think there is a data processing implication on them. You are using equipment provided by them, but you are doing the actual processing. Similarly, unless your catering company can see any of the information stored in the cards/POS equipment, I don't think there's a concern there either.

 

Also remember even though the catering is a third party, they are working on sub-contract for you and using information provided by you, not obtained directly - therefore, I don't think they need to enter into any data processing agreement with the parents/students.

 

I'll be following this discussion with interest, as we are looking at something similar here, also with an external catering company, but one difference with us is we are trying to "impose" cashless on them, not the other way round.

 

Simple response.

 

You can't be compliant unless you know what data you are collecting, why, etc. If a company will not tell you what is being processed by the software you buy from them, then how can you work out if you are meeting the rights of the data subject.

I mention this to some companies and they get it ... they really do get it (NetSupport, Impero, Smoothwall, RM) but other take some more convincing.

When you explain that some customers will walk away if they don't have this information ... they start to listen.

  • Thanks 1
Posted

Ok folks, a basic things for you.

 

If you get software from company x, you install it on your servers, you configure it and run it ... you are the data processor as well as the data controller.

Microsoft can't tell you the AD is GDPR compliant as it could or couldn't be depending on what you set up.

If a supplier is not doing the work for you, then it is hard to say they are the data processor. They are facilitating you being the data processor in that role.

If the data goes to their servers, or they remotely setup and manage the service, then start asking them about comliance and the data sharing agreement.

 

As always, if you have a particular sticky company, drop me a PM. I am doing a number of direct phone calls with certain companies so happy to add a few more in. Those phone calls are showing some fantastic practice, by the way. As I've said ... some companies really do get it.

 

- - - Updated - - -

 

All true. Not sure why you quoted my post though...

 

Purely a frame of reference and addition to your response.

Posted
No, but nor do we give them a choice about putting their personal information in SIMS, or sharing it with Google, Mathswatch etc. We do, however, ensure we only share what information is needed and only with organisations who will handle it appropriately.

 

These are areas for which consent to share is not required, remember. To date, no-one has complained or asked us not to share the data.

 

enjay it's not about complaints but handling data legally (and ethically).

 

If your catering option is biometric [which I don't know] there's a legal requirement to offer and respect parental and pupil choice under the 2012 legislation. You need to meet data protection, child rights law and privacy obligations, it would also be good to encourage good aplied and ethical practice.

 

Is there a free-for-all when starting to use an app in the classroom at teachers' will, or do you have an assessment process - is the app safe, secure, transfering personal data outside the EU, and what will become necessary, ethical - for example targetting kids with a bait-and-switch approach of paid premium option out of school later. There's some absolute trash out there reportedly using "AI" for example.

 

Google, Mathswatch etc we can help you with, if you want to give me a full list, but that audit is something your DPO needs to be doing *now* ahead of May 2018. Where do they store personal data, what's the legal basis for every use of data. Each third-party transfer may ahve more than one basis or thing to think about. Photographs for example, might be hard to show a necessary legal basis for a homework app, but OK for building access. But all biometric data needs special consideration.

Posted
Ok folks, a basic things for you.

 

If you get software from company x, you install it on your servers, you configure it and run it ... you are the data processor as well as the data controller.

 

Not necessarily true. If the software enables any information or data transfer to the software company, they are also data processors and might be controllers if they make autonomous decisions what they do with thsoe data.

Posted
Not necessarily true. If the software enables any information or data transfer to the software company, they are also data processors and might be controllers if they make autonomous decisions what they do with thsoe data.

 

This is talking about where no data is transferred. There are a number of examples around.

Posted

An example could be Microsoft. Whilst it is increasingly common to use their cloud services in one way or another, but some schools may still be standalone.

The AD stores a lot of personal data, but because there is no connection to any cloud service, no connection to any other service within the school (which may transfer data without you knowing), no connection to feedback services (so no anonymised or pseudo-anonymised Data is transferredy), and the AD is not used for authentication for any other service.

 

It is growing less but some assessment and curriculum tools still only used what is setup on a local server within the school. Any downloads from the provider are usually downloading content sets ... stuff that used be sent out via CDs.

Posted
Is there a free-for-all when starting to use an app in the classroom at teachers' will, or do you have an assessment process - is the app safe, secure, transfering personal data outside the EU, and what will become necessary, ethical - for example targetting kids with a bait-and-switch approach of paid premium option out of school later.

 

No. Teachers shouldn't subscribe to any of these without first speaking with me.

 

Google, Mathswatch etc we can help you with, if you want to give me a full list, but that audit is something your DPO needs to be doing *now* ahead of May 2018. Where do they store personal data, what's the legal basis for every use of data. Each third-party transfer may ahve more than one basis or thing to think about. Photographs for example, might be hard to show a necessary legal basis for a homework app, but OK for building access. But all biometric data needs special consideration.

 

We've already started our DPIAs, thank you.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...