Jump to content

Recommended Posts

Posted

Hi all - question about physical information displays within the school.

 

We have a number of noticeboards up for various reasons round the school, and often on these noticeboards personally identifiable information is displayed like names and photographs.

 

Some of these noticeboards are in areas where we also do public hire of school rooms on evenings and weekends.

 

Am I right in thinking that this constitutes a data breach, not just when GDPR comes in but under the current DPA? We get consent from parents to use information on in-school displays but I know not 100% of parents give this and I'm fairly sure the lists will still contain their child as there isn't any awareness (as far as I can tell) on which kids are not under consent.

 

Also, if a list is on the wall in a locked room only accessible to staff, but I can stand at the window with any half decent camera and get a legible copy of that list, this would be a breach too?

 

Thanks for any pointers

Posted

Unless you are the DPO, walk slowly away from this and pass it back to them. This minefield is not going to get smaller! There are so many things like this that need proper clarification and explanation, and sorting them ad-hoc is a massive waste of manpower.

 

Your displays need to conform to the parental consent. Easiest is to find/export the list, email it out to staff, and make them aware.

 

Information should be properly secured - if it can be seen by a visitor to the school (and recorded) then that is an issue. Blinds over windows are generally no good due to fire regs, so these things shouldn't be displayed in line of sight.

  • Thanks 1
Posted
It's not official yet and may not happen but I may well become the DPO come May - if I do it will be after some more training to get more familiar with this minefield but for the time being I'm trying to muddle this all out as far ahead of schedule as possible...
Posted

Guessing you're not the NM, or will cease to be come May? If so, then yes these points do need considering. You'd be best off drafting a displays policy which highlights your points above

 

The list of 'non consent' students must be consulted when displays are created (and you should have the authority to enforce this if it's breached;

Confidential or sensitive information should be not be displayed where it can be viewed by school visitors

etc etc.

 

This sort of policy would be a good idea in any case!

Posted
I'm not IT staff any more - I don't have any power over what IT systems we use or control of any budget for any data software (I only have an advisory role with regard to that stuff now)
Posted

Ah fair play. I think the majority of us here certainly wouldn't envy you in that role!

We're listening to a GDPR webinar in the background here currently and so far the "simple" terms sound like Microsoft's wording of some group policies.

 

"Enable this setting to disable the enablement of disabled settings"

 

"Identifiable data is data that identifies identities or identity of identifiable identities"

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...