Jump to content

Recommended Posts

Posted

The main elements of the bill are:

 

Set the age from which parental consent is not needed to processdata online at age 13, supported by a new age-appropriate designcode enforced by the Information Commissioner.

 

Again - not sure what "online data" has to do with our biometric data, this doesn't fit.

Posted

So reading the actual bill:

 

Child’s consent in relation to information society servicesIn Article 8(1) of the GDPR (conditions applicable to child’s consent in relationto information society services)—(a) references to “16 years” are to be read as references to “13 years”, and(b) the reference to “information society services” does not includepreventive or counselling services.

 

Again, this is relating to ISS - not the concern of a school.

 

The more I get in to this the more I think people are trying to make a square peg fit in a round hole, and I don't get why considering it's not for ease.

  • Thanks 1
Posted
The age proposed in the Data Protection Bill is 13 but this is currently subject to Parliamentary approval. I would stick with 16 to make life easier until the new Data Protection Bill comes into play.

 

16 still has the same problems, just less of them, as children turn 16 in Year 11. So if consent is being used, it needs to be re-obtained when the child turns 16.

 

Here's a thought - as they can't give that consent in advance, does this mean we have to delete biometric data on their 16th birthday, then ask them if we can use it, re-take the biometrics then serve them lunch? That would be a PITA...

Posted
Who has mentioned 16? Because the last time I checked a child is a child until 18 in this country, and yes GDPR mentions 16 as the age of consent but ONLY for ISS, therefore it must still be 18 for all other services/needs.
Posted (edited)
16 still has the same problems, just less of them, as children turn 16 in Year 11. So if consent is being used, it needs to be re-obtained when the child turns 16.

 

Here's a thought - as they can't give that consent in advance, does this mean we have to delete biometric data on their 16th birthday, then ask them if we can use it, re-take the biometrics then serve them lunch? That would be a PITA...

 

That wouldn't seem practical or reasonable to me. I think at the beginning of each term if you identify any children that turn 13/16 in that coming term and gain their consent. (or the beginning of each month, 1/2 term etc).

 

There would be times when the child is say 15yrs 10months and 3 days old but I would image the ICO would take into account that the school is endeavouring to apply with the spirit of the law and what it was actually intended for.

Edited by rom1984
Posted

The spirit of the law? You are all making laws up to make your life more difficult! Need photo consent? Parental will do until the child is 18. Need biometric consent? Parental will do until the child is 18.

 

Nobody has provided any hard fast legislation (or proposed legislation) that says otherwise.

Posted
The spirit of the law? You are all making laws up to make your life more difficult! Need photo consent? Parental will do until the child is 18. Need biometric consent? Parental will do until the child is 18.

 

Nobody has provided any hard fast legislation (or proposed legislation) that says otherwise.

 

Other than the document linked a few posts ago, you mean?

Posted
What document, and what bit? You can't just say "it says in a document I've read somewhere" - show me where it says "all persons 13 or older must provide their own consent"
Posted
What document, and what bit? You can't just say "it says in a document I've read somewhere" - show me where it says "all persons 13 or older must provide their own consent"

 

This one https://ico.org.uk/media/about-the-ico/consultations/2013551/draft-gdpr-consent-guidance-for-consultation-201703.pdf and page 26 which says "Parental consent will always expire when the child reaches the age at which they can consent for themselves."

 

It goes on to talk about age-verification for ISS, but I think the paragraph I've quoted about consent is universal.

Posted
What document, and what bit? You can't just say "it says in a document I've read somewhere" - show me where it says "all persons 13 or older must provide their own consent"

 

I'm talking about GDPR Article 8 where they mention the specific age 16. I said the UK DP bill will lower this to 13. I then replied to say that I think it would be reasonable to gain consent at, for example, age 12yrs and 10 months because you would be applying with the spirit of the law and what it was intended for. This is something the ICO would look at when looking at a data breach, has the organisation tried to apply with the spirit of what the law intends. All this, as you have said, is around data processing relating to Information Society Services.

  • Thanks 2
Posted

Ok, but I've already responded, posting sources, to counter these arguments.

 

So parental consent provided for an 11 year old will expire when that 11 year old reaches the age of consent. GDPR doesn't define the age of consent, except (and this is explicit) for ISS. The ICO don't define the age of consent. The new data protection bill again doesn't define the age of consent, except (and again it is explicit in this) for ISS. Therefore, nowhere in any of these bits of literature does it state that when a child turns 13 (or 16) we need to seek consent again.

 

So when does the consent end? Well, GDPR, the new data protection bill, nor any other relevant document I can find stipulate "parental consent is not valid when the child reaches their 13th birthday". Therefore, as far as I can gather parental responsibility comes in to play, which lasts up until their 18th birthday.

 

I feel like I'm going round in circles a bit, apologies if I'm not conveying my points very clearly. I know what we're doing with consent (and the reasons why), and it certainly doesn't involve sending a new consent form out when a child reaches 13 (or 16, or whatever other number people want to fabricate in myth).

  • Thanks 2
Posted
I have to say it does seem strange that the law may be taking away parental rights. I got a bad school report you not seeing it Just William would be pleased!!
Posted
So parental consent provided for an 11 year old will expire when that 11 year old reaches the age of consent. GDPR doesn't define the age of consent, except (and this is explicit) for ISS. The ICO don't define the age of consent. The new data protection bill again doesn't define the age of consent, except (and again it is explicit in this) for ISS. Therefore, nowhere in any of these bits of literature does it state that when a child turns 13 (or 16) we need to seek consent again.

 

So when does the consent end? Well, GDPR, the new data protection bill, nor any other relevant document I can find stipulate "parental consent is not valid when the child reaches their 13th birthday". Therefore, as far as I can gather parental responsibility comes in to play, which lasts up until their 18th birthday.

 

The age of consent is up for discussion as part of the Data Protection Bill, but you may be right that is only in relation to ISS.

Posted (edited)

I agree the GDPR, DP Bill ect doesn't explicitly mention age, other than for data processed for ISS. Apologies If I've caused any confusion! When talking about age of consent in the GDPR and DP Bill I was specifically talking about Article 8 as this is the only time the GDPR mentions a specefic age.

 

When the ICO refers to a child they mean anyone under the age of 18. But, the ICO allows competent children to exercise their own data protection rights, after all the data belongs to them and not their parents.

 

Schools need to decide at what age do they generally consider a child to be competent enough to understand their data protection rights. The GDPR/DP Bill does not give guidance on this. Schools can take article 8 and use that age to help them decide this but they don't have to. Ultimately it is up to each school to decide. If the school decide that a child isn't competent enough to understand processing data for biometrics until they are 18 then they will need to be able to justify this. Likewise if they decide at age 13 a child is competent enough, they will need to be able to justify this. The UN convention of rights provide that every child should be able to express their views and have them views taken seriously. Again the school would need to take this into consideration and if I child says at age 13,14,15 etc that they don't want their data processed (by way of consent), then the school should seriously consider it.

Edited by rom1984
Posted

The focus on consent will be a small area. It will be related to where legislation says you *have* to use consent (biometrics, etc.) or where guidance is to use consent.

In general there will be other lawful basis for collecting/processing. Reporting to parents is a statutory obligation so would not be done under consent ...

 

As for swapping consent, yes it will become ... interesting. Many of the MIS have or are bringing in ways to manage it, as some examples have already been mentioned.

Posted

What are peoples thoughts on this as an easy solution;

 

You processes data where as GrumbleDook says, you have to use consent (for example Biometric data). You get consent from the parent when they start in year 7 and this is recorded.

 

The school decides that by year 11 children are competent enough to decide by themselves if the school can process their biometric data.

 

You have an obligation to ensure the data you process is relevant, up to date and accurate. So in year 11 a letter is sent home addressed to the child to inform them that the school has consent to process their biometric data and informs them of their rights to withdraw their consent.

 

That way the original consent was done in line with GDPR (i.e. explicitly consented) and the school is complying with their obligations to take reasonable steps to ensure that data is still relevant, up to date and processed fairly/transparently.

 

Apologies to @Jamman960 feel like I've high jacked your thread!!

Posted
Or, you know, just include the fact that children have the right to revoke their consent in your policies, as stipulated by GDPR anyway. You're just giving yourself more work to do, there's absolutely nothing wrong with parental consent throughout a child's school life, as long as your privacy notices tell children of their rights.
Posted
Or, you know, just include the fact that children have the right to revoke their consent in your policies, as stipulated by GDPR anyway. You're just giving yourself more work to do, there's absolutely nothing wrong with parental consent throughout a child's school life, as long as your privacy notices tell children of their rights.

 

Yeah that sounds really transparent :) If you put something in your policies and you don't tell people about it, what's the point of even having it in your policy in the first place? It's the equivalent of putting "no USB drives for staff" in your polices but then never telling or training staff about it. The GDPR obliges a data controller to be transparent, putting something in your policy and then not telling someone about it isn't transparent.

Posted
I disagree, your policies are there for people to read should they wish. They will be publicly available and structured for the intended audience. I appreciate it might be wise to put on the consent form "please see our privacy notice for further information about how we will use this information" but sending a letter saying pretty much what your privacy notice says is additional work for no purpose. GDPR is about being transparent - you do that by making sure your privacy notices are right. GDPR is NOT about running around after people saying "ah, but, you know, well". Most of the school's I've spoken to haven't got time to worry about GDPR, and then I come on here (for the first time in years) and there's a bunch of people making up their own rules to do a job that isn't required.
Posted
. I appreciate it might be wise to put on the consent form "please see our privacy notice for further information about how we will use this information" .

 

I actually did some GDPR training two weeks ago on consent and processing personal data and this was the exact type of example they used on how NOT to be transparent.

 

If you think a 16 year old is not competent enough to make their own decision around their data then that's fine, your policies should reflect this.

 

The schools that I have worked in, and dealt with, are really making a conscious effort to comply with the GDPR and I think that can only be a good thing. If you are dealing with special category data or children's data (or both!) then schools should really be putting effort into complying with GDPR, especially around security, transparencies and acting fairly.

 

Thankfully my experience is opposite to yours.

Posted
I didn't say the school's I've spoken to weren't making a conscious effort to comply, I merely said among the multitude of other things they have to do every day, they haven't got time to go round making up myths that give additional workload for no reason. I'm sorry, but if my privacy policies are adapted for children, accessible, and even mentioned in consent forms I don't know what transparency is. I think a sensible additional measure would be to cover such a topic in IT lessons, but sending a letter home at a predefined age isn't required. What age do you send it home? 13? 11? Who's to say all your students are ready to read something like that at 11 or 13? GDPR boils down to two things for me - proper policies/procedures in place, and good training. But no, it's definitely not about going round and asking who wants help with the toilet paper.
Posted (edited)

It's obviously not required to send a letter home at a predefined age, the GDPR can't tell every organisation how to apply the law to their place of work. Each organisation needs to decide that for themselves.

 

Your school may decide that a child can never be competent enough to decide about, for example, biometric data.

 

The next school may think that by Year 11 the students will be competent enough. They may decide in the interest of fairness and transparency that they tell them about their rights in an IT lesson (great idea!)

 

The next school may think that by Year 10 they are competent, but they are going to let students know via a letter of their rights.

 

The next school may think that by Year 9 they are competent, but because it is in their privacy notice on their website they aren't going to say anything.

 

If the school gets consent to process data in year 7, and by year 11 they decide that the child is competent enough to make the decision themselves, I personally think its fair to explicitly tell the child they are processing their data based on their parents consent and because they are now competent to understand the processing of the data, that they can freely make the consent/withdraw the consent themselves.

 

Your school may disagree with this, that is fine. Every organisation will put procedures in place that they think helps them comply with the GDPR. Its not a case of your wrong and I'm right (even though I am - I kid!) . They are just options that a school can use to help demonstrate such principles as transparency, fairness, lawfulness etc.

 

The example of the No USB's in a policy is a real life example, if a data breach happens via a USB drive and the organisation points to a policy to say that it says no USB drives the ICO won't give this much credit. They will ask the organisations questions such as how did you tell staff about this, when did you tell them, how often are they reminded, how regularly are they trained, are they aware of the GDPR, are they aware of the data subjects rights etc. This would be the same of anything in your policies, the questions would be similar.

Edited by rom1984
  • Thanks 1
Posted

I'l leave with these thoughts because I don't want to highjack the thread anymore;

 

I think the question the school would need to consider is; "is consent that was given years ago, before the child was competent to understand, still relevant now that the child is competent to understand."

 

If the school thinks the consent is no longer relevant, because the child is now competent enough to understand themselves, they need some fair and transparent way to tell the child.

 

If they decide the child is now competent but the original consent is still relevant, then they don't need to do anything. The onus would be on school to justify why the consent was still relevant in cases of a data breach.

 

If they decide the child isn't competent until after 18, then they don't need to do anything. Again the onus would be on the school to justfy why they felt the person wasn't competent enough to understand.

Posted

so I'm confused here - When I did my groupcall GDPR training they said that the age of consent was 13. The only thing they said this would really affect is using student photos on social media and/or print advertising media. But you couldn't assume consent at the age of 13 & had to collect it somehow.

 

If I understand the above, it's ok to use pre-existing parental consent if given?

Posted
If I understand the above, it's ok to use pre-existing parental consent if given?

That's what we're debating, I say yes (in a nutshell). Also, I'd say any photos collected for educational reasons such as GCSE Coursework Evidence don't come down to consent - that legal basis is probably public interest.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...