Jump to content

Recommended Posts

Posted

Our Swipe cards have staff/pupil name, photo and school address.

 

If one is lost does this constitute a breach?

 

I'm thinking we should drop the photo?

Posted
Our cards have school name and student name only. No photo for this reason. Staff ID however does but I believe the 'breach' is only reportable if you believe harm or negative is impact possible to the individual/s of which the data concerns.
  • Thanks 1
Posted
Our Swipe cards have staff/pupil name, photo and school address.

 

If one is lost does this constitute a breach?

 

I'm thinking we should drop the photo?

 

If they lose their own card?

Posted (edited)

Every company in the EU, not just schools, that issues ID faces the “what if it gets lost” problem.

 

Yes, there’s a potential DP problem if it contains unnecessary information. There’s also a security risk if it opens doors, etc.

 

You need to do a risk assessment and treat this with common sense. Actually, you don't. This decision MUST be made by the head of your school/MAT probably with reference to the governors/Trustees.

 

ID isn’t much use if it doesn’t identify the person. The photo is there to prove that the badge belongs to the person wearing it.

 

Without the photo, anyone could hang it round their neck and pass themselves off as the name on the badge.

 

An ID badge needs photo, name and a “function” (student, staff, governor, cleaner...) so it can clearly be seen by anyone whether a person is allowed to be where they are. Without this you are creating a both a Safeguarding and a security risk. I suggest both those risks are bigger than the the ICO fine if someone loses one.

@GrumbleDook?

Edited by elsiegee40
  • Thanks 2
Posted

I'm struggling to see how this would be a Data protection issue - if anything I'd argue that not including both a photo + name is an issue as per @elsiegee40's comment on safeguarding.

 

I mean, using the logic above - If the school chooses to set homework and the students are required to take their exercise book home to do said homework, as the exercise book contains the students name and work, it's personal data. Therefore school's should stop setting homework after the May :)

  • Thanks 1
Posted

Don't see it is a data protection breach - my ID has my name, photo and place of work. The reason for the photo has already been discussed; the fact Mr Enjay works at this school is public record anyway, as we give parents of list of key staff and I'm named on our website too, both directly and in newsletters.

 

If my ID also opened doors, there'd be a security and safeguarding risk if I lost it but not a data protection one.

Posted
If my ID also opened doors, there'd be a security and safeguarding risk if I lost it but not a data protection one.

But much less of an issue compared to a physical key since if your ID is lost you can easily disable the card from opening a door.

Posted
But much less of an issue compared to a physical key since if your ID is lost you can easily disable the card from opening a door.

 

Yes and no. If you found my keys in the Tesco car park, you wouldn't know what they open; if you found my access control ID card, you would.

 

Somewhat related to this topic, our staff all have key fobs with their initials on, so if a set is found it can quickly be returned to the owner. This does come with the downside it also tells the finder which doors they can open (and possibly which car!), but it was felt this was acceptable in exchange for the quicker return of the keys. What do other people think to this?

Posted

Ours staff ID badges include...

 

-ID badge - Containing name, photo, school name,

-Printer/Copier access/release,

-Door access,

-Bar code for signing in and out.

 

Would a lost staff badge mean we would need to log as a data breach?

Thanks in advance!

Posted
Ours staff ID badges include...

 

-ID badge - Containing name, photo, school name,

-Printer/Copier access/release,

-Door access,

-Bar code for signing in and out.

 

Would a lost staff badge mean we would need to log as a data breach?

Thanks in advance!

 

I think that depends on how quickly you block the card. If the staff member reports their card missing and can confirm the last activity on it was them, I don't think it is a breach; if, however, the card has been used to release printing or open a door which the staff member says wasn't them, you have a breach. The next problem you have is, what was breached? So, someone used the card to open an office door, but that doesn't tell you what they saw when in that office.

Posted

Our staff, sixth form and visitor badges all carry names and photos, and can be easily distinguished as one of those three types. Lanyards are also colour-coded with either "STAFF", "SIXTH FORM" or "VISITOR" written on them. This is primarily for safeguarding, so that people on site are either in a uniform, wearing a photo ID, or making their way to/from reception.

 

The sixth form cards are generally ordered in bulk at the beginning of the year: I would hope that those are sent to us via a suitable delivery service, otherwise that might constitute a breach.

 

Something else to consider might be whether students are encouraged to put away their passes once they leave the school site. I'm sure we've all had those moments where we realise we're still wearing our pass in the supermarket after work.

Posted
This is primarily for safeguarding, so that people on site are either in a uniform, wearing a photo ID, or making their way to/from reception.

 

Your visitors are allowed to make their own way to/from reception? What if they stop off somewhere en route? Here, visitors are only allowed to move around unescorted if we've seen proof of DBS. We have two different colours of lanyard on the visitors passes to denote which they are. Parents are often an exception to this, as their children will often meet them in the car park and walk them to the meeting - they should go via Reception, but that's harder to enforce (it may be easier in your school, depending on what access to the site is like)

 

Something else to consider might be whether students are encouraged to put away their passes once they leave the school site. I'm sure we've all had those moments where we realise we're still wearing our pass in the supermarket after work.

 

That's safeguarding not DPA/GDPR. but yes, it is probably best to encourage them to remove their passes.

Posted
Your visitors are allowed to make their own way to/from reception? What if they stop off somewhere en route?

 

It's a pretty direct route. They can't very well sign in in the car park.

Posted
I'm obviously not suggesting they sign in in the car park, I'm questioning what they do once they've signed in - are they free to make their own way back from the meeting room to reception, and what stops them taking a detour? I don't know your site layout, so it might be fine of course.
Posted
Sorry. When I said they make their way to and from reception, I suppose I wasn't clear that that was before signing in and after signing out. Once they've signed in, they wait in reception until the person they're meeting with comes to meet them. They're then accompanied the whole time that they're on site, until they're back in reception to sign out. If they're DBS cleared, and have a suitable pass (i.e. not a vanilla visitor pass), then they don't have to be accompanied.
  • 1 year later...
Posted
Every company in the EU, not just schools, that issues ID faces the “what if it gets lost” problem.

 

Yes, there’s a potential DP problem if it contains unnecessary information. There’s also a security risk if it opens doors, etc.

 

You need to do a risk assessment and treat this with common sense. Actually, you don't. This decision MUST be made by the head of your school/MAT probably with reference to the governors/Trustees.

 

ID isn’t much use if it doesn’t identify the person. The photo is there to prove that the badge belongs to the person wearing it.

 

Without the photo, anyone could hang it round their neck and pass themselves off as the name on the badge.

 

An ID badge needs photo, name and a “function” (student, staff, governor, cleaner...) so it can clearly be seen by anyone whether a person is allowed to be where they are. Without this you are creating a both a Safeguarding and a security risk. I suggest both those risks are bigger than the the ICO fine if someone loses one.

@GrumbleDook?

 

Sorry to resurrect an old thread

 

My issue with having a name and photo of especially younger pupils is that if they lost their cards out of school, someone could approach them and know their name and lure them into a false sense of security and then entice them to go with them with this information.

 

Perhaps agree that it's not a GDPR issue rather a Safeguarding one.

Posted (edited)
Sorry to resurrect an old thread

 

My issue with having a name and photo of especially younger pupils is that if they lost their cards out of school, someone could approach them and know their name and lure them into a false sense of security and then entice them to go with them with this information.

 

Perhaps agree that it's not a GDPR issue rather a Safeguarding one.

 

Younger students generally don’t have photo ID in school. Their uniform identifies them as a student.

 

Student ID usually only comes in at 6th form, and usually where there is no uniform for sixth formers, so that students can be easily identified by anyone as such and differentiated from staff members or a local yob that has decided to invade the site.

 

Subject to risk assessment, I think that photo ID for sixth formers can be justified.

 

And photo ID is definitely a Safeguarding thing.

Edited by elsiegee40
Posted
Subject to risk assessment, I think that photo ID for sixth formers can be justified.

 

And photo ID is definitely a Safeguarding thing.

 

They were finally introduced here when we were due an Ofsted and there were rumours of them slating other schools for not being able to immediately identify people at random (or to be able to have knowledge of which students were on site and which weren't, which is why our 6th Form ID cards are used to swipe in and out).

Posted

I've seen some companies do employee passes that just have the holder's photo and a colour indicating their status (i.e. Which areas they're allowed in). If you're worried about names, then that could be an option.

If you want names, a first name, or first name and last initial (such as Steve M) might be a compromise - although the first name is likely to be what somebody would use to lure a child.

 

If you also left any branding off it, then if somebody found one they wouldn't necessarily know where it was from unless they'd seen kids wearing them.

Posted

These cards are to print. The only reason for the ID is to reunite them if they should be lost.

Kids can log in using their AD username and password, but swiping is a lot faster.

The LA do this for a lot of schools so we're surprised this hasn't been challenged before.

 

We could go for username and photo. Shame half the cards have been printed already

Posted

You use what the school has defined int eh purpose.

 

You will often find student / staff cards have multiple purposes ...

 

Identify individuals

Access control solutions (including building access, access to software / systems ... whether it is library software or to log into the AD)

Payment systems

 

There are a few others you could put in but some of those bring up interesting privacy concerns (Discussion on use of RFID is a separate issue).

 

Look to see if any of these need a DPIA.

Assess the risks and make a decision that is clearly documented and justifiable.

 

Then go with want you are left with.

 

It will be slightly different for every school ... but there are some common questions you might ask yourself (Look at the ICO guidance on DPIAs for more advice).

 

It can work where there is phot ID on the card and it is used for payments and access control.

 

Is losing it a data breach? If an individual lost their own Photo ID ... it would be debatable (I've had 4 different opinions on this so far). If the school lost a load of cards? Yes, then that would be a breach.

  • 3 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...