Jump to content

Recommended Posts

Posted
Got an invite to "sign up" for SIMS parent app from my kids' school yesterday. If you had an existing SIMS ID you could log in with that. Otherwise it offered sign in with MS, Google, Facebook or Twitter. Realistically most parents who are using the internet at all will have at least one of those. I was impressed with how smoothly it went and I presume it will make it more straightforward for the school to get the data into SIMS.

 

Direct from what it acquires from various social media sites? :p

Posted
Got an invite to "sign up" for SIMS parent app from my kids' school yesterday. If you had an existing SIMS ID you could log in with that. Otherwise it offered sign in with MS, Google, Facebook or Twitter. Realistically most parents who are using the internet at all will have at least one of those. I was impressed with how smoothly it went and I presume it will make it more straightforward for the school to get the data into SIMS.

 

Direct from what it acquires from various social media sites? :p

 

Even the person that sets it up in the school has to choose one if they don't have a SIMS ID and your system is hosted in the school... What concerns me is the phrasing used when trying to integrate with an account... for example with Outlook, could read that they have access to the account (SIMS ID Live... This app would like to: Sign in as you)... but I assume from the details when you expand the drop down that's not what they are saying?

 

SIMSID.png

Posted
Direct from what it acquires from various social media sites? :p
Yeah - I would have preferred to be able to create a SIMS ID, but didn't seem to be able to. I used my Google account on the basis I was doing it from my android phone, so Google already have the information. Anyone using Facebook realistically won't be telling them anything new...
Posted
Is anyone using Google Forms to collect the initial consent?

 

We are looking at the SIMS Lite parent app but think we will get more uptake of initial consent if they don't have to create a login etc

 

Was just going to provide a google form asking for their name, student name, reg group, tick this box for consent etc

 

Parents can authenticate via Google, Facebook, etc. although in the light of recent news stories, I'm not sure if that is a reassurance or a concern!

 

How are you planning on getting the invites out to parents, though? Our concern is it seems to work by emailing the parents an invitation code - unfortunately, we're cautious about that, as we've been burned in the past by an admin mis-typing an email address in SIMS and us emailing fred.bloggs59@ not fred.bloggs95@, so would prefer a method which we know for 100% certainty is going to the right person.

Posted
Parents can authenticate via Google, Facebook, etc. although in the light of recent news stories, I'm not sure if that is a reassurance or a concern!

 

How are you planning on getting the invites out to parents, though? Our concern is it seems to work by emailing the parents an invitation code - unfortunately, we're cautious about that, as we've been burned in the past by an admin mis-typing an email address in SIMS and us emailing fred.bloggs59@ not fred.bloggs95@, so would prefer a method which we know for 100% certainty is going to the right person.

 

The only way to be sure then is to do it in person via parent’s evening etc. We run data cleansing/validation most parents evenings, with form teachers getting the parents to check their details on the spot. Not enough time to do this before 25th though.

Posted
You only have to be making progress towards compliance by the 25th

 

Actually, I believe everyone has to be compliant by the 25th. Though no doubt a lot of places will be making progress towards compliance, especially due to the lateness of ratification and instruction.

Posted
Actually, I believe everyone has to be compliant by the 25th. Though no doubt a lot of places will be making progress towards compliance, especially due to the lateness of ratification and instruction.

 

Technically yes, but I doubt the ICO are going to start handing out fines on the 26th. I imagine it will be some months before they start getting involved, and even then I suspect they'll leave you alone if you can show you're heading in the right direction and have a timed plan.

  • Thanks 1
Posted
From what I can see with parent app you can't currently monitor 2 children from different schools under the same email account which is annoying. With regards to data collection are you completely replacing paper forms or do they still need to be sent out and collected? I would like year 8 and onwards to update info on the app and Year 7 to be gathered via paper copy?
Posted
Am I correct in thinking that consent for Sixth Form (Students 16 years and older) we need to get the consent from them? Parent consent obtained at the beginning of their school career wouldn't be enough? This is in relation to photos for website etc
Posted
Am I correct in thinking that consent for Sixth Form (Students 16 years and older) we need to get the consent from them? Parent consent obtained at the beginning of their school career wouldn't be enough? This is in relation to photos for website etc

 

Don't think so, no. I think their parental consent is still good until 18, but above 16 the student can withdraw it themselves. No harm in reminding the students what their parents consented to and their rights to withdraw.

Posted

We've been advised by our lawyers to apply Gillick competency and therefore gain consent from all our pupils (11-18), which we do via Firefly.

 

However, being a school we come under GDPR's Public Task basis and therefore consent is not strictly required.

Posted
However, being a school we come under GDPR's Public Task basis and therefore consent is not strictly required.

 

Careful. Not everything you do as a school is covered by public task. That is only good for things you HAVE to do, e.g. take registers, record medical information, and any online resources you use in lessons, e.g. Mathswatch. Public task doesn't cover permission to put photos on your website, because that isn't an essential part of your operation.

Posted
Actually, I believe everyone has to be compliant by the 25th. Though no doubt a lot of places will be making progress towards compliance, especially due to the lateness of ratification and instruction.

 

Our DPO appointed by the local authority isn't in place yet to advise us what we should be doing. The LAs advice to us was we only need to be working towards it. I bet that will hold up in a court of law.

  • Thanks 1
Posted
The various GDPR seminars I've been to all say that we have to have a plan in place and to be implementing the actions. None of them suggested that any educational establishment would have all actions completed by 25th May. After all, we still have a school to run and all this is additional workload.
  • Thanks 2
Posted
This one https://ico.org.uk/media/about-the-ico/consultations/2013551/draft-gdpr-consent-guidance-for-consultation-201703.pdf and page 26 which says "Parental consent will always expire when the child reaches the age at which they can consent for themselves."

 

It goes on to talk about age-verification for ISS, but I think the paragraph I've quoted about consent is universal.

 

Did this get resolved? ICO did a joint session at Academies Show last week with DfE.

 

Consent under GDPR is literally about only valid as a legal basis for processing for marketing use of photos by schools, and not much else at the moment, unless you decide you will make things optional. (See p19/20)

 

For example: Google Ts&Cs say additional services are consent based, but they are not as it's unlikley it's freely given, and parents are not explained how ads and tracking work and data are used. We're yet to meet a school in which they are. Consent unlikely to be an acceptable legal basiss for processing where school really wnats the child to, as it musty not disadvantage them, and must be freely given and able to refuse. Rarely valid for a public authority. Rarely valid for children. Because it's not valid where power imbalance means "freely given" is under any pressure at all to do so.

 

There is no universal "age of consent" in GDPR. Article 8 does not apply in schools because you operate apps on a statutory basis not consent.

 

Consent *is* required for any biometrics because of the legisation in Protection of Freedoms Act (2012), not GDPR, and one or more parent can object up to 18 no matter what child says, and child can object no matter what adult says. Basically default is object for biometrics with active opt in. Can opt in if consent is freely given, and able to withdraw at any time.

  • Thanks 1
Posted
Parents can authenticate via Google, Facebook, etc. although in the light of recent news stories, I'm not sure if that is a reassurance or a concern!

 

How are you planning on getting the invites out to parents, though? Our concern is it seems to work by emailing the parents an invitation code - unfortunately, we're cautious about that, as we've been burned in the past by an admin mis-typing an email address in SIMS and us emailing fred.bloggs59@ not fred.bloggs95@, so would prefer a method which we know for 100% certainty is going to the right person.

 

Are parents "authenticating" an account already set up -- or consenting (which is not likely valid legal basis in school) to their details being shared with the company? Authenticating sounds like the account has already been sent their details and they make it active. Whether or not they want to use an account, parents need told *before* the data is shared with the third-party. Ditto ParentPay et al.

Posted
Are parents "authenticating" an account already set up -- or consenting (which is not likely valid legal basis in school) to their details being shared with the company? Authenticating sounds like the account has already been sent their details and they make it active. Whether or not they want to use an account, parents need told *before* the data is shared with the third-party. Ditto ParentPay et al.

 

Not sure I agree with you there Jen. We the school are sharing the information under public duty, because that is how we have chosen to handle parents confirming contact or medical details, paying for events, etc. Just like how we share details with Google or Mathswatch as part of how we have chosen to deliver the curriculum. We might put other provision in place for those parents who can't/won't use the online portals, but I don't think we need to pull data if they don't like it being up there.

 

Your online banking or ISP are the same - they have online portals through which their customers' data could be accessed, but they don't wait for customers to sign up before putting their records in that system. All that changes when you register is you can start accessing electronic data which was already there.

  • Thanks 1
  • 2 months later...
Posted

Photos, on websites, minibuses, around school.

 

1. Should they be removed as soon as the student has left school?

2. What about students who left 5 years ago? Does all of this apply?

3. What if the pupil and parents disagree with each other, only allow photos if all of them agree?

4. If they ask for photos to be removed, do they have to specify which, or just say "on the website"?

5. How are you tracking who's in what photo, so you can remove them when asked? Tagging on the CMS? Keeping a spreadsheet list somewhere? Another database?

Posted
Not sure I agree with you there Jen. We the school are sharing the information under public duty, because that is how we have chosen to handle parents confirming contact or medical details, paying for events, etc. Just like how we share details with Google or Mathswatch as part of how we have chosen to deliver the curriculum. We might put other provision in place for those parents who can't/won't use the online portals, but I don't think we need to pull data if they don't like it being up there.

 

Your online banking or ISP are the same - they have online portals through which their customers' data could be accessed, but they don't wait for customers to sign up before putting their records in that system. All that changes when you register is you can start accessing electronic data which was already there.

 

Sorry for the late reply (missed yours). I think we're saying the same thing, the difference being often it is not the school managing the data, now it's been sent to a third-party processor. Consent is not a valid basis for most data processing in schools > therefore you need another, which as you say is most often public task.

 

I don't think I suggested pulling data, but there is certainly a pre-requirement to tell parents it is being shared. *That* duty existed under DPA 1998, principle 1, fair processing. Regardless that the same duty also exists under GDPR. This is probably the largest change management task that exists in the education sector today on data processing. The fact that few do it (pre notfication to parents of third-party data distribution) is not a reason not to start doing it lawfully.

 

Further, the Right to Object (RTO) which applies to data shared under the public task or legit interest (and is not absolute, but is for consent, so say, photos for school marketing purposes), can only be exercised, if you know the data are being processed. And where there is an alternative and less invasive and lower risk way to do it. i.e. your health absence reasons can be phoned direct into the office admin, not sent via the servers of an Australian based app provider, the RTO should be upheld. Would be happy to chat more, if you think this is not right and also to get your input on the ICO Code of Practice consultation on Age Appropraite design. More info on RTO: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-object/

Posted
Not sure I agree with you there Jen. We the school are sharing the information under public duty, because that is how we have chosen to handle parents confirming contact or medical details, paying for events, etc. Just like how we share details with Google or Mathswatch as part of how we have chosen to deliver the curriculum. We might put other provision in place for those parents who can't/won't use the online portals, but I don't think we need to pull data if they don't like it being up there.

 

Your online banking or ISP are the same - they have online portals through which their customers' data could be accessed, but they don't wait for customers to sign up before putting their records in that system. All that changes when you register is you can start accessing electronic data which was already there.

 

This is usually done as the school as data controller for the children and the school / partner as joint data controllers for the parents.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...