woody Posted May 10, 2018 Posted May 10, 2018 Hi I have just learned that a member of staff has gone through the process of applying for a collective passport for a school trip in Paris. I was made aware of this because the Principal's PA was asked by the passport office to verify the application, and she questioned it because they were asking her to send student information in a word document over email. Instead, she securely shared the document as a onedrive link which required verification at the recipient end, but they rejected this and asked for the word document attached to an email again. The information in the application form which was asked to be re-sent for verification includes Student names, DOBs, Town and country of birth, and current town of residence. Obviously this is personally identifiable data which will come under GDPR and the DPA 1998. You can see the application process and get to the application form here: https://www.gov.uk/collective-group-passports/how-to-apply What is going on here???? Just thought I would put this out there and see if anyone had come across it before? Thanks
FN-GM Posted May 10, 2018 Posted May 10, 2018 If the email is sent via TLS it should be fine. I think all .gov.uk accept TLS.
Bigbird7 Posted May 10, 2018 Posted May 10, 2018 I’d be inclined to let the ICO know that a government agency is requesting information in this way without giving appropriate advice
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now