Jump to content

Recommended Posts

Posted

I am in the process of updating our Trust data protection, e-safety and ICT policies and one thing that has come up is retention of photographs.

 

There's a couple of parts to this.

 

1. Should photos of children taken as part of lessons etc... be deleted when they leave school?

2. Should photos of children taken for use in the MIS be deleted when they leave the school?

Posted (edited)
I am in the process of updating our Trust data protection, e-safety and ICT policies and one thing that has come up is retention of photographs.

 

There's a couple of parts to this.

 

1. Should photos of children taken as part of lessons etc... be deleted when they leave school?

2. Should photos of children taken for use in the MIS be deleted when they leave the school?

 

To add to this ; 3. Should photos of children taken as part of activities (ie trips) be deleted when they leave school?

Edited by fiza
Posted
I am in the process of updating our Trust data protection, e-safety and ICT policies and one thing that has come up is retention of photographs.

 

There's a couple of parts to this.

 

1. Should photos of children taken as part of lessons etc... be deleted when they leave school?

2. Should photos of children taken for use in the MIS be deleted when they leave the school?

1. Why were they taken? Were the subjects asked if they could be retained for future (specified) use. You may wish to maintain them for archive/historical reasons... or marketing reasons... or whatever,, but you still need their permission

2. What reason do you have for retaining them beyond it being a pain to delete them? It could be argued that the SIMS photo is part of the educational record that you must retain... but you need to be clear why exactly it should be part of that.

Posted
To add to this ; 3. Should photos of children taken as part of activities (ie trips) be deleted when they leave school?
Likewise, do have the subjects' permission to retain them? Have you told them what uses they may be put to if you retain them? You may wish them to be part of a historical archive, but you can't just use them again at any later date without their permission. And you have to accept that they might come back after they have left and say delete the lot from the archive
  • Thanks 1
Posted
Does this mean then for each photo you need a record of who is included in it? Just in case at some point they ask for any photos of them to be deleted.
Posted
Does this mean then for each photo you need a record of who is included in it? Just in case at some point they ask for any photos of them to be deleted.
To spin it around, if you don't record the name, is it personal data? Once you've got rid of the photos from the MIS and you've just got 30 years worth of random photos of children, could you (the data controller) realistically work out who was in the photos?
  • Thanks 1
Posted
I hope removal of leaver photos is necessary. Regardless I may just spout it around anyway. I would gain so much space back on my file server [emoji57] seems like a valid excuse that won’t get questioned
Posted
To spin it around, if you don't record the name, is it personal data? Once you've got rid of the photos from the MIS and you've just got 30 years worth of random photos of children, could you (the data controller) realistically work out who was in the photos?

 

Of course it’s personal data. Just because you can’t recognise the children doesn’t mean that nobody else can do so.

Posted (edited)
Of course it’s personal data. Just because you can’t recognise the children doesn’t mean that nobody else can do so.

 

mm, doesn't the context matter? I've previously seen/read somewhere that photographs of crowds are not classified as personal data, providing no one person is the focus of the photograph. If you cropped a group photograph to a single person, it would then become personal data and subject to the original DPA.

 

[edit: although references I can find atm tend to take the view that school groups are personal data]

Edited by minimoo
Posted
Does this mean then for each photo you need a record of who is included in it? Just in case at some point they ask for any photos of them to be deleted.

 

That would be logical. You can't use the photo for anything if you don't know who is in it. And why keep it if you can't use it?

Posted
mm, doesn't the context matter? I've previously seen/read somewhere that photographs of crowds are not classified as personal data, providing no one person is the focus of the photograph. If you cropped a group photograph to a single person, it would then become personal data and subject to the original DPA.

 

Define a crowd. At what resolution can you identify individuals? Are we talking thousands? Where are they?

 

A crowd walking over London Bridge at rush hour makes it hard to identify individuals. A group of students in school uniform ... or simply in a room/locality identified with the school... becomes immediately more identifiable and thus needs careful handling for Data Protection

Posted

I don't know what other schools do, but if they are anything similar to us, I can see photos/videos of children coming up in the following ways:

 

a) School MIS storing a photo for identification purposes

b) Recording / Photo taken of something in a lesson

c) Recording / Photo taken at a school trip / school event

d) Group Photograph taken when students leave school (the sort that photography companies sell to parents)

 

Equally, we've recently pulled some photos/documents out of an old school archive - e.g. photos from WW2 of students being evacuated, an old film of someone in royal family at the school, whilst the electronic sharing of information so readily these days is a problem - I do wonder if in 30-40 years time, we might also regret that some things haven't been kept. And just to clarify that statement - for A above, sims should really have a method to batch remove leavers photos ( the purpose was for identification, after the student has left you generally don't need to be able to identify them. Unless you argue they are part of education record - but then that's name+photo together nicely), for B - there's probably often not much value to keeping in general. I'd suspect that particular category is out of laziness.

 

Where i'm thinking of crowd is for C/D:

 

a) Students go on school trip with staff, as a group they share photos with each other on file server of the trip

 

b) school has a event where photos/recording are going to be taken e.g. concert. Presumably in this case, signage/a line on ticket/invitation stating the event is being recorded would cover any photos of the audience, and having a consent form for students doing music/drama that by taking part they will be consenting to the recording covers that.

Posted
1. Why were they taken? Were the subjects asked if they could be retained for future (specified) use. You may wish to maintain them for archive/historical reasons... or marketing reasons... or whatever,, but you still need their permission

2. What reason do you have for retaining them beyond it being a pain to delete them? It could be argued that the SIMS photo is part of the educational record that you must retain... but you need to be clear why exactly it should be part of that.

In both cases, the children are below the age of 13 here, so this falls to their parents, who sign a permissions form outlining, IIRC, 4 or 5 use cases for photos and asks for permission for each of these from their parent/guardian.

 

No time limits are specified for any of the cases.

Posted (edited)
Of course it’s personal data. Just because you can’t recognise the children doesn’t mean that nobody else can do so.
The same data can be personal or not depending on who is the controller. From the ICO:

 

A single piece of data, which is not personal data for one data controller may become personal data when it is passed to another data controller.

 

Example

An estate agent takes a photograph of a high street shop to market the property. The photograph is held in digital form by

reference to its address or by reference to the client name on the agent’s computer. The photograph is used solely to produce

photographic prints to display and distribute to potential purchasers.

The photograph of the shop includes images of pedestrians who were walking past the shop at the time the photo was taken. The estate agent is not processing the shop data to learn anything

about any of the pedestrians whose images were captured by chance on the photo, nor is it likely that the estate agent would ever process the photo for that purpose. The estate agent is unlikely to possess the appropriate software to digitally enhance

the photo to identify individuals. Therefore, in the hands of the estate agent, the photo does not contain personal data about the

pedestrians as it is not processed to learn something about those individuals and nor is it likely to be processed by the estate agent for this purpose.

 

If we consider the example of the data contained in the images of the pedestrians captured on the shop photo by the estate agent in the above example, in certain circumstances, this data may be personal data about the pedestrians in the hands of another data controller.

 

Example

If, at about the same time as the photograph was taken by the estate agent, a bank raid took place on the same high street, the police might make a public appeal for information about movement on the high street at that time. The estate agent might supply the police with a copy of the photo in response to the appeal. The police would then process the digital photo, not to learn anything about the shop but, using photo enhancing technologies, to attempt to identify potential witnesses or suspects. The photo would then be being processed to learn something about the individual pedestrians and, in the hands of the police, may be personal data about such individuals.

 

Therefore, data may not be personal data in the hands of one data controller (for example, the estate agent) but the same data may be personal data in the hands of another data controller (for example, the police) depending on the purpose of the processing and the potential impact of the processing on individuals.

 

I'm not saying that school archive photos are directly analogous to the above example, but in the above example, the estate agent would be displaying the photo publicly so people who could recognise the individuals might see it.

 

Photos which don't have an associated record of who is in them wouldn't be of much use for educational or assessment purposes, but could tell the story of the school. If they're not identifiable by the data controller they're not personal data, so can be kept without additional justification.

 

I think the answer might be to tell parents that we keep an archive of photos to preserve a history of the school, but that they won't be used in a way that identifies individuals.

Edited by jmak
Posted

So, taking your estate agent / police example, if we keep the photos on school servers, they're not personal information; if, however, we publish them on our website - where other people might be able to see them and do further analysis, they might become personal information. Correct? Actually no, the difference between my example and the ICO one is the DC changed when it was passed to the Police, but we could publish photos to our hearts content as they aren't personal data for us. Yes?!

 

Schools being allowed to keep old photos is entirely the right thing, as they play a vital part in telling our history, not just the history of the school, but of us as a community. I can imagine how different my History A-Level would have been, for example, if we hadn't been able to study photos and video from the periods. We have some lovely photos in our archives and on display going back over 100 years showing past students and some of the uses of this site before it became a school, e.g. WW2 hospital, country manor house, etc. It would be a real shame (and that isn't nearly a strong enough word) if we had to destroy all these because we don't have permission from the subjects (and can't obtain because the subject is unidentifiable and in many cases dead) to keep them.

 

On a lighter note, one of these photos on display is some students on motorbikes. My technician swears one of those students is him, but as it really isn't identifiable, we definitely don't need permission to keep it!

  • 3 weeks later...
Posted
Just got back from the meeting with the head and apparently school nearby is preparing to keep data for each child in separate location - I guess folder - as per GDPR (in their opinion) - so just wonder is that what will come to? Do we really need to identify each kid in a photo - for any enquiries about that child - while they still in school?
  • Thanks 1
Posted
Just got back from the meeting with the head and apparently school nearby is preparing to keep data for each child in separate location - I guess folder - as per GDPR (in their opinion) - so just wonder is that what will come to? Do we really need to identify each kid in a photo - for any enquiries about that child - while they still in school?

 

Will that even work, what about a photo with 5 children in it, if it is under a folder for child A - E but then child E says he doesn’t want it stored you still have it under child A - D folders.

Posted
Will that even work, what about a photo with 5 children in it, if it is under a folder for child A - E but then child E says he doesn’t want it stored you still have it under child A - D folders.
Just get rid of the cameras and start using Facebook. Once they've been named a few times, Facebook's facial recognition magic will automatically tag them in all the files - much easier to find them so that you can delete if you need to [emoji854]

 

:troll:

  • Thanks 1
Posted

So we can retain photo's of children as long as we have permission from parent/guardian? Photo's in our case would be used for Inspection purposes re: evidence of doing activities.

 

But should parent or child (+13) request that we delete ALL their data, we need to be able to identify what photos they are in? As jmac implied, Facebook FTW

Posted
I actually just got an advert offering to replace manual roll calls with facial recognition...I doubt this is gonna fly but maybe they'll tweak it to a "locate photos of a specified student" jobbie instead :D
Posted
I actually just got an advert offering to replace manual roll calls with facial recognition...I doubt this is gonna fly but maybe they'll tweak it to a "locate photos of a specified student" jobbie instead :D

 

Unless that system is very quick and able to work from a distance of several metres (highly unlikely) this sounds like something which would take significantly longer than a traditional roll call (assuming you even do a roll call, rather than just count heads then look for who is missing!). Sounds like a technological solution to a non-problem!

Posted
Unless that system is very quick and able to work from a distance of several metres (highly unlikely) this sounds like something which would take significantly longer than a traditional roll call (assuming you even do a roll call, rather than just count heads then look for who is missing!). Sounds like a technological solution to a non-problem!

 

Yeah to me too, I'll still go see it at BETT though, could be popcorn worthy even if it doesn't work.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...