Roberto Posted April 13, 2018 Posted April 13, 2018 should schools now 'decline' to offer that service as it's a risk to "process" the data of non-students I'd strongly suggest this is a risk you should be thinking about, yes. If the exam board won't co-operate with you to find a solution then how far is it reasonable for your school to stick its neck out on their behalf? Not very, I'm thinking.
MkII Posted April 13, 2018 Posted April 13, 2018 "As the data belongs to your school and you are responsible for the transmission by what-ever-means" OK, i'd been resisting joining in on this thread - does it ? (belong to the school) A student chooses to do a Russian GCSE with AQA (that's there choice when picking options). As part of that they have to do an oral examination to achieve their grade. Some examinations are done by internal staff, but equally at some levels (e.g. A2) the exam board will send an external examiner in. Does the data "belong to the school" if it's between a student and the exam board and the school are just 'posting' it on the behalf of the exam board / student via the method that the exam board and student have approved? On that note, if we continue: In the scenario that the examination board send an external examiner in to perform an oral with a student, and the "school" is recording that - should the school be asking the examination board to provide consent that they are happy for their examiner to be recorded (and the examiner also provide consent that he is happy to be record for that purpose) For minority subjects e.g. Japanese etc, which very few students do, I know we have in the past acted as a centre for the oral component for the local schools (so the examination board can send one examiner and do all the local students) - should schools now 'decline' to offer that service as it's a risk to "process" the data of non-students I think the statement should read "As the data belongs to your school and you are responsible for the security of that data transmission by what-ever-means" ~The data belongs to the subject (the natural human being). Only the subject can ultimately give consent. The school as processor has to follow their directives from the controller. The examiner is his own subject and must consent for any data identifying him being recorded. Any data which you are passing on has to be done in line with the regs. If the examiner deals directly with the students then he needs to go through all the hoops as data processor the same as we would.
enjay Posted April 13, 2018 Posted April 13, 2018 My head is still stuck on "who is the Data Controller of the recording?". Here are some thoughts on that: Exam boards pass results information on to other organisations such as Fischer Family Trust (and presumably OFSTED and the press). If the the schools are the Data Controllers for the exam papers, how can exam boards pass that data on? Doesn't that make the exam boards the Data Controllers of the papers? Also, the exam boards send the papers to the school, the student then writes on them, and the school then returns the paper to the exam board. Presumably since the paper starts with the exam board, it is there data to control, not ours. If that's the case with printed material, I don't see why it would be any different with digital material. Therefore, even though the practice the exam board is requesting isn't compliant, it is the exam board who are being non-compliant, not the school. No?? 1
MkII Posted April 13, 2018 Posted April 13, 2018 If the exam board is the data controller, which I think is a fair assumption... someone there decided what data was needed, then you are the data processor acting on their direction. If you know the regulations and you're sure you're breaching them, you would be culpable for not following them. Surely not even a covering letter would let you breach the regs?
enjay Posted April 13, 2018 Posted April 13, 2018 If the exam board is the data controller, which I think is a fair assumption... someone there decided what data was needed, then you are the data processor acting on their direction. If you know the regulations and you're sure you're breaching them, you would be culpable for not following them. Surely not even a covering letter would let you breach the regs? Does the military defence of "only following orders" help? Yes, I'm breaching the regs but the exam board have told me to, so is liability on them not me? Especially if I can prove I've contacted the exam board to express my concern.
DrCheese Posted April 13, 2018 Posted April 13, 2018 Does the military defence of "only following orders" help? I don't believe so - It's on you to ensure that your data is going somewhere that meets GDPR guidelines. If they tell you they aren't compliant with it and you send it off, that's still on you. 1
MkII Posted April 13, 2018 Posted April 13, 2018 I don't believe so - It's on you to ensure that your data is going somewhere that meets GDPR guidelines. If they tell you they aren't compliant with it and you send it off, that's still on you. Article 28 GDPR determines that obligations of processors in particular include: To comply with the GDPR data processing principles and to protect the rights and freedoms of data subjects; To demonstrate compliance with the GDPR; To maintain records of processing activities and make them available upon request by supervisory authorities; To appoint data protection officers or representatives; To cooperate with supervisory authorities in the performance of their tasks; To ensure a level of security by taking appropriate technical and organisational measures; Specific obligations as regards transfer of data outside the EU. I don't think so either
enjay Posted April 13, 2018 Posted April 13, 2018 I suspected as such. So, what's the response? We can't exactly refuse to submit students' coursework...
MkII Posted April 13, 2018 Posted April 13, 2018 If they refuse to comply with the regulations as you understand them, I guess the next step is to report the issue to ICO and get them to rule.
leegcvcc Posted May 1, 2018 Posted May 1, 2018 Isn't this what DPOs are for? To tell non-DPOs what to do in order to be compliant? I'm clearly well behind everyone here with GDPR but what is the difference between sending paper recorded delivery and an unencrypted USB stick? I'm also guessing video clips are possibly more damaging that paper or digital files not containing images
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now