Jump to content

Recommended Posts

Posted

I thought it used to be a safety rule that no identifying info should be contained in pupil email addresses, the risk being that a stranger could make themselves seem familiar.

 

Is this not the case now?

 

Thanks

Posted
We use surname and initial in student email addresses but have a rule in Gmail that year 7-10 cannot send or receive external emails. Y11-13 can as they need to send off applications etc. Never seen a rule stating no identifying info should be in the email address.
Posted

I've said it before and will say it again, if that was ever a rule, it's a silly one. It makes it more difficult for students to remember yet another random set of letters and numbers when they need to be concentrating on learning. It's too much.

May as well refer to each student as a number and completely dehumanise them. Yes it identifies a pupil as a POSSIBLE student of the school, but so does using a pair of eyes and happening to pass the school gates when they're going in. Their addresses on letters also identify them.

Posted

Numbers can work fine ... the panic about dehumanising is over used at times ... learning an important number and making use of it is a key concept children have to pick up.

NI number, payroll number, phone number, army number, driving licence number ...

 

It should also be explained clearly to learners that it is a protective barrier ... helping to add a bit more of a shield to them.

 

As the children grow older then yes ... add their name as an alias ... it is part of growth.

 

One thing I would say is to avoid identifiers in the number such as year of entry ... this gives an approx age ...

 

As for it being too much? Heck, they learn whatever strange variant they are given when signing up for social media sites or gaming sites ... they will adapt.

Posted (edited)

We use the schools own generated exam numbers, which is useful for the kids when they come to sit exams, and they make no sense to anyone outside of school.

 

So what age is appropriate for kids identities to be shared like this?

Edited by MkII
Posted
Numbers can work fine ... the panic about dehumanising is over used at times ... learning an important number and making use of it is a key concept children have to pick up.

NI number, payroll number, phone number, army number, driving licence number ...

 

It should also be explained clearly to learners that it is a protective barrier ... helping to add a bit more of a shield to them.

 

As the children grow older then yes ... add their name as an alias ... it is part of growth.

 

One thing I would say is to avoid identifiers in the number such as year of entry ... this gives an approx age ...

 

As for it being too much? Heck, they learn whatever strange variant they are given when signing up for social media sites or gaming sites ... they will adapt.

So where younger students are blocked from sending or receiving external emails does it matter that we include their year of entry and their surname in their email address?

Posted
Numbers can work fine ... the panic about dehumanising is over used at times ... learning an important number and making use of it is a key concept children have to pick up.

NI number, payroll number, phone number, army number, driving licence number ...

...

As for it being too much? Heck, they learn whatever strange variant they are given when signing up for social media sites or gaming sites ... they will adapt.

 

 

Good points, although out of those I only know my NI number :D And indeed, that latter bit is correct; the biggest benefit of being called SomethingBigGuns2013823 is usually not getting subjected to the same level of spam as when you're one of the first to jump on the Gmail bandwagon and have the pick of the addresses :D Too many people think they have my email address legitimately and I get emailed everything from people's actual wills and legal documentation to fast food ordering receipts :(

 

Ours match our students usernames which does include YoE but no full name; first two characters of each name.

Posted (edited)
We use surname and initial in student email addresses but have a rule in Gmail that year 7-10 cannot send or receive external emails. Y11-13 can as they need to send off applications etc.

All of our school-provided email addresses bar pupils from emailing anybody who isn't part of the school gmail domain, but I suspect this may need to change in future years.. My problem here is this isn't really a rule that can be 'relaxed', you can't possibly whitelist all the legit addresses, so email is either on, off, or moderated (and I'm sure as hell not paid enough to moderate all Y10/11 emails)

 

Is there anything definitive that says their should be no PII in the email address? We currently use [2 Digit Year of Entry (if they came in Y7)][surname][Forename-Initial] (eg 14BloggsJ)

 

If I'm going to have to say "No, we can't do that, child protection." if when I'm asked to relax the rules, I'd like to have something concrete I can use to back my corner.

Edited by Garacesh
Posted

I think there was some very old advice from someone like Becta about this.

 

We use initial + surname for the address, with the full name as their display name. This does potentially mean you could guess one of our students' addresses, or use this format with random name combinations like jsmith@, but it also means we can identify students in the address book so staff can email them / identify the source of an email they're sent.

Posted (edited)
with the full name as their display name.

Valid point, I hadn't considered that. It's the same here. email from 14BloggsJ@[domain] displays in GMail as "Joe Bloggs <14bloggsj@[domain]>" and presumably as similar in other mail clients/websites.

 

So realistically, one email from a user contains a Forename, Surname, what school they attend, and (if you're smart enough to figure it out..) an approximate age. Definitely enough PII to have me concerned about DPA/GDPR.

Edited by Garacesh
Posted

The advice from Becta (paraphrasing) was make it age appropriate, use it in stages to educate about the real world and remember to identify risks on a school, class/group and individual level.

 

The last bit is most relevant ...

 

The problem is that most would look at this solely from an online safety point of view rather than from an all round position...

 

There is nothing to say that you can’t do it ... as long as you have reviewed why you are doing it and can justify the decision.

Posted
Valid point, I hadn't considered that. It's the same here. email from 14BloggsJ@[domain] displays in GMail as "Joe Bloggs <14bloggsj@[domain]>" and presumably as similar in other mail clients/websites.

 

So realistically, one email from a user contains a Forename, Surname, what school they attend, and (if you're smart enough to figure it out..) an approximate age. Definitely enough PII to have me concerned about DPA/GDPR.

 

You're giving more information than we do. For us the email would come from "Joe Bloggs (student) ".

 

We decided against blocking external recipients in the days before G Suite, when students were often emailing work home. Possibly worth a review of that now we're fully G Suite.

Posted (edited)
You're giving more information than we do. For us the email would come from "Joe Bloggs (student) ".

We need some way of identifying year group A) for our benefit ('Joe Bloggs in year 10 has no files in his user area, can they be recovered?') and because we constantly have multiple pupils with the same Surname/First-Initial combo.

The vast majority of the time it's parents naming their kids John and Jane, Edward and Eliza, Stephen and Sophie, etc. But not always.

Edited by Garacesh
Posted
We need some way of identifying year group A) for our benefit ('Joe Bloggs in year 10 has no files in his user area, can they be recovered?') and because we constantly have multiple pupils with the same Surname/First-Initial combo.

The vast majority of the time it's parents naming their kids John and Jane, Edward and Eliza, Stephen and Sophie, etc. But not always.

 

We put students in cohort folders in AD, so I would check "Joe Bloggs in Year 10" that way. We don't have many duplicate names; when we do we just add a 1 to the end of their username since their full name is in the display name anyway. We do have a few students with the same fore- and surname, so whoever arrived second (typically the younger one) has the display name Joe P Bloggs. I think these students have got used to forwarding emails to each other, too! If duplicate names/usernames were more of an issue, I might do something different.

Posted (edited)
We put students in cohort folders in AD, so I would check "Joe Bloggs in Year 10" that way.

Yeah we do that too. Same with things like user areas, so there aren't usually clashes there. This is just the way it was when I got here. It could be changed, but it would create a lot of hassle.

Alas we're getting off-topic.

 

I reckon sooner or later someone, probably PSE1 or Skills for Life, are going to ask me to unblock it because job/college/work experience applications. And whilst knowing the pupils age/name/school is completely justifiable and not an issue for those specific circumstances, it's everything else that they could email that raises my concerns.

 

Since it isn't feasible to whitelist everything, I'd probably recommend a moderated approach. But I wonder does that come with its own set of issues, like if the kids are emailing off CV's that means I2 have access to their home addresses, phone numbers, etc. Fine I could get some of that info via SIMS if I wanted to, but still. And if the kids start signing up for services using their school email, I2, by virtue have access to all of those accounts since I can intercept password resets (which again, I could do anyway just by taking control of their entire account, so, does it really matter?), PLUS, and here's the bigg'un, what if for example they send an email discussing personal medical issues, or something related to a criminal offence.

 

Again, given how G Suite operates, I have access to all of this information anyway. For example I can change any users' password and seize control of their account, or I can use Vault to pull back all emails sent by a user even if they've been deleted. But there's a fine line between reactive and proactive security, and I feel any attempt at proactive security would be considered too invasive. Maybe it could legally all be rendered kosher by a big 'Outgoing/Incoming emails are moderated.' disclaimer, but I wouldn't know for certain.

 

1: Or PSHCE or whatever other bloomin' acronym it is now.

2: Or whatever other poor sap gets put in charge of moderating incoming/outgoing emails.

Edited by Garacesh
Posted
Thanks for the comments everyone. I remember now we had this guidance from our LA that I saw in the early naughties. So not sure if it's current. I'll check.
Posted

Had a catch up with ICO on a few things today ... they cannot comment on safeguarding practices but remind you that you need to take that into account.

 

As for the personal data itself? It's a risk management exercise. Make sure you have a lawful basis for processing any personal data, regularly review your DPIA on it and justify your choice.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...