PyROm Posted January 24, 2018 Posted January 24, 2018 This is just a thought of mine, not something that has happened but something I might want to mention to the staff. If a staff member used a website that requires a user to sign up (for free) in order to use it and told the class to sign up (without getting parental consent first), would this be allowed (as its the student not the school submitting data) or would it be a breach of the GDPR? I am guessing that if the student was below the age of consent re: GDPR it would be a breach on behalf of the school, if they were over the age then I am guessing its OK?
jthompson Posted January 24, 2018 Posted January 24, 2018 We're taking the position that we need to account for that sort of thing under GDPR, and advising staff not to promote any third-party services in that way (unless due diligence has been done by the school).
dapaulio Posted January 24, 2018 Posted January 24, 2018 I had a similar thought just last week and I too are of the opinion that it should be accounted for under GDPR. Its a bit of a issue really as under normal circumstances and by the school's policy all software, cloud based or other wise; Free or paid should have been approved by me before registration, however it has become apparent that even today i find 3rd party software/sites that they use where i have no knowledge of, as the teacher in question has taken it upon themselves to register themselves and their students on a website. Alot of emails have been circulated from various GDPR leading staff about this in particular even before GDPR and not many if any have returned declaring the use of a website where student data has been uploaded. Its an absolute nightmare
free780 Posted January 24, 2018 Posted January 24, 2018 Well you should standardise on Office 365 of G-Suite. Azure can force users to use a work account to Dropbox etc. https://docs.microsoft.com/en-us/azure/active-directory/active-directory-appssoaccess-whatis Need a subscription though. You could of course block Dropbox etc for staff.
PyROm Posted January 24, 2018 Author Posted January 24, 2018 Although storage is a problem, I was thinking wider. Eg any website that requires a signup will usually want full name, email and dob.
GrumbleDook Posted January 25, 2018 Posted January 25, 2018 Age dependant they could self consent. It wouldn’t be a valid consent if being instructed by a teacher ... it is forced and so dubious as to the validity. In short, this short not happen. No service should be signed up for until a DPIA is complete. Under COSHH, you wouldn’t just let anyone bring chemicals into school, especially in a random container and just leave it lying around. Same applies. 1
enjay Posted January 26, 2018 Posted January 26, 2018 Any software or website subscription should be approved by me, but as others have said, we're finding this isn't always the case. I'm in collusion with the Finance Manager now to pick up any such orders, but so many of these are free. Teachers are also being reminded to speak to me first. As for the actual question (!), I think if the teacher suggests the students register then it isn't a breach, but if the teacher REQUIRES them to register as part of the lesson, it would be different.
forkies Posted January 26, 2018 Posted January 26, 2018 I would assume you could put the services/suppliers in your privacy notice or consent form and then have them consent to these at that point? Instead of having parents or the students consent on every single individual app/service.
GrumbleDook Posted January 27, 2018 Posted January 27, 2018 I would assume you could put the services/suppliers in your privacy notice or consent form and then have them consent to these at that point? Instead of having parents or the students consent on every single individual app/service. Consent is generally not the issue. If the service is required for delivery of the curriculum you might use the basis of public interest, as consent is only *1* legal reason for processing ... This would be picked up during a DPIA, or as part of you audit of data maps / data sharing agreement. If it is consent, then you cannot do it on bulk, as that is not giving the parent/child the chance to opt in to what they want ... you are coercing them to choose all or nothing, so the consent would *not* be valid. Consent has to be freely given each time it is asked about.
Meldrew Posted January 27, 2018 Posted January 27, 2018 As for the actual question (!), I think if the teacher suggests the students register then it isn't a breach, but if the teacher REQUIRES them to register as part of the lesson, it would be different. My understanding is that suggesting students register is enough. Certainly it would be a fine line to decide if a teacher instructed or suggested something. We are going with both, the difficulty will be ensuring that I get informed beforehand to do the GDPR compliance check. Meldrew
AngryITGuy Posted January 27, 2018 Posted January 27, 2018 This has been something we have been thinking about too and we are taking a similar approach to @jthompson all current third party websites and applications will be checked for GDPR compliance so we can create a list of approved third party services (data processors) and anything new will have to be checked by whoever is given the role of GDPR. And anything that doesn’t meet compliance will be given the boot! Consent isn’t the only issue here as mentioned by @GrumbleDook it has to be explicitly given under GDPR but the fact that the third party is processing personal data of an EU citizen it has to be checked for GDPR compliance. If the third party site is part of the curriculum or suggested by an exam board you may get away with consent as it needs to be used for the curriculum but I don’t think this omits GDPR compliance. At the end of the day after May if your school gets a written request for all data held on someone or a request for data deletion can you be sure that these third parties and other data processors can provide you with the information or delete the information for you within the allocated time to respond.
GrumbleDook Posted January 29, 2018 Posted January 29, 2018 My understanding is that suggesting students register is enough. Certainly it would be a fine line to decide if a teacher instructed or suggested something. We are going with both, the difficulty will be ensuring that I get informed beforehand to do the GDPR compliance check. Meldrew Yes, due to the position of authority that a teacher holds the suggestion or recommendation is enough to imply coercion. This is not a new concept as it applies to other areas as well. Another example of handling data protection being an extension of existing practice.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now