Gorbyhail Posted May 14, 2018 Posted May 14, 2018 (edited) Sorry for what is likely the latest in a long long line of GDPR-based questions, but I was reading this thread: http://www.edugeek.net/forums/data-protection-information-handling/195907-gdpr-usb-pen-drives.html And I am now somewhat concerned about what GDPR means in relation to sending off USB drives, CDs, DVDs etc to exam boards, potentially with personal information, unencrypted. Should we be making any changes to our procedures in regards to this? Even if it is as simple as encrypting the media and sending a password separately. Thanks in advance! Edited May 14, 2018 by Gorbyhail
Edutech98 Posted May 14, 2018 Posted May 14, 2018 The 1998 Data Protection Act and the GDPR requires to put in place appropriate security to prevent personal data being accidentally or deliberately compromised. So if you are sending personal data and you feel there is a risk that the data could be accidentally or deliberately accessed by a unauthorised person then you should put measures in place such as encryption.
Diello Posted May 15, 2018 Posted May 15, 2018 We had a similar query, and AQA pointed us here: http://filestore.aqa.org.uk/admin/nea/AQA-ENCRYPT-NEA-MEDIA.DOCX
enjay Posted May 15, 2018 Posted May 15, 2018 So if you are sending personal data and you feel there is a risk that the data could be accidentally or deliberately accessed by a unauthorised person then you should put measures in place such as encryption. Only if the item gets misdelivered in the post, and the recipient opens post addressed to someone else - which is illegal.
Gorbyhail Posted May 15, 2018 Author Posted May 15, 2018 We had a similar query, and AQA pointed us here: http://filestore.aqa.org.uk/admin/nea/AQA-ENCRYPT-NEA-MEDIA.DOCX Did they say this is going to be compulsory?
Rob_D Posted May 15, 2018 Posted May 15, 2018 There's a pretty lengthy discussion of this here. The last few of pages have a few links to exam bodies requirements/guidance. http://www.edugeek.net/forums/data-protection-information-handling/193477-gdpr-exam-bodies.html 1
Edutech98 Posted May 15, 2018 Posted May 15, 2018 Only if the item gets misdelivered in the post, and the recipient opens post addressed to someone else - which is illegal. It doesn't necessarily have to be opened for it to be a breach though. The ICO recently fined a Police force £150k for sending an unencrypted DVD in the post that never arrived at its destination. The DVD was never found but they were still fined for sending unencrypted sensitive data in the post... https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2017/05/greater-manchester-police-fined-after-victim-interview-videos-go-missing/
enjay Posted May 15, 2018 Posted May 15, 2018 (edited) It doesn't necessarily have to be opened for it to be a breach though. The ICO recently fined a Police force £150k for sending an unencrypted DVD in the post that never arrived at its destination. The DVD was never found but they were still fined for sending unencrypted sensitive data in the post... https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2017/05/greater-manchester-police-fined-after-victim-interview-videos-go-missing/ That's possibly more to do with what was sent (and lost) rather than the manner in which it was sent. From the ICO's report with that: When people talk to the police they have every right to expect that their information is handled with the utmost care and respect. “Greater Manchester Police did not do this. The information it was responsible for was highly sensitive and the distress that would be caused if it was lost should have been obvious. Edited May 15, 2018 by enjay
DannyG555 Posted March 14, 2019 Posted March 14, 2019 Just to add to this thread.... today I have just read an email from AQA asking for all media to be sent by encrypted means, however, using a pre-defined password that is common knowledge for all exam centres. This seems risky to me due to the password being common knowledge amongst so many centres/schools/colleges. In my view they have made this move purely to ease their operation (probably had complaints from moderators regarding accessing protected media and managing multiple passwords) and have opted for something that weakens data protection. What are peoples thoughts on this??
pete Posted March 14, 2019 Posted March 14, 2019 Just to add to this thread.... today I have just read an email from AQA asking for all media to be sent by encrypted means, however, using a pre-defined password that is common knowledge for all exam centres. This seems risky to me due to the password being common knowledge amongst so many centres/schools/colleges. In my view they have made this move purely to ease their operation (probably had complaints from moderators regarding accessing protected media and managing multiple passwords) and have opted for something that weakens data protection. What are peoples thoughts on this?? I read the letter (assuming we got the same one) as the password being unique for each school. Now I'm going to have to track down our exams officer. Only if the item gets misdelivered in the post, and the recipient opens post addressed to someone else - which is illegal. You'd struggle to secure a prosecution unless it was wilful (not a "it's my house and it landed back-side up on the mat, so yes - I opened it and then realised"). And you'd still have a data breach to deal with. 1
Rob_D Posted March 14, 2019 Posted March 14, 2019 The AQA email our exams officer forwarded on to us says: Your school’s media encryption password is: XXXXXXXXX Which I would read as being a unique password for our school. As long as they're careful/compliant when sharing the password I don't see this as a problem. It's probably safer than "please include this form that asks for the password with your physical media" that I remember from last year. 1
TMBS Posted March 14, 2019 Posted March 14, 2019 Just to add to this thread.... today I have just read an email from AQA asking for all media to be sent by encrypted means, however, using a pre-defined password that is common knowledge for all exam centres. This seems risky to me due to the password being common knowledge amongst so many centres/schools/colleges. In my view they have made this move purely to ease their operation (probably had complaints from moderators regarding accessing protected media and managing multiple passwords) and have opted for something that weakens data protection. What are peoples thoughts on this?? We had battles with the exam boards last year when trying to be GDPR compliant and sending student work via an encrypted USB and emailing them the password - they didn't like it! Plus they managed to lose two of the memory sticks which weren't cheap. We've added a postscript stating if they lose it we will bill them for a replacement. It's good to see that they are finally becoming more GDPR compliant and asking for us to encrypt the data we post. I read it that the code they supplied is specific to our school and only given to the examiners marking the paper. Why they haven't come up with a secure portal for us to upload the work to yet I don't know... 1
DannyG555 Posted March 14, 2019 Posted March 14, 2019 Thanks all. I mis-read the email the first time. After re-reading it does imply that the password is unique to each school! My bad!
AndyCrow Posted March 15, 2019 Posted March 15, 2019 Just to add, I would expect that they changed the password whenever a new set of exams were due so that ex-employees wouldn't be able to log in in the future.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now