Jump to content

Recommended Posts

Posted (edited)

Sorry for what is likely the latest in a long long line of GDPR-based questions, but I was reading this thread:

http://www.edugeek.net/forums/data-protection-information-handling/195907-gdpr-usb-pen-drives.html

 

And I am now somewhat concerned about what GDPR means in relation to sending off USB drives, CDs, DVDs etc to exam boards, potentially with personal information, unencrypted. Should we be making any changes to our procedures in regards to this? Even if it is as simple as encrypting the media and sending a password separately. Thanks in advance!

Edited by Gorbyhail
Posted
The 1998 Data Protection Act and the GDPR requires to put in place appropriate security to prevent personal data being accidentally or deliberately compromised. So if you are sending personal data and you feel there is a risk that the data could be accidentally or deliberately accessed by a unauthorised person then you should put measures in place such as encryption.
Posted
So if you are sending personal data and you feel there is a risk that the data could be accidentally or deliberately accessed by a unauthorised person then you should put measures in place such as encryption.

 

Only if the item gets misdelivered in the post, and the recipient opens post addressed to someone else - which is illegal.

Posted
Only if the item gets misdelivered in the post, and the recipient opens post addressed to someone else - which is illegal.

 

It doesn't necessarily have to be opened for it to be a breach though. The ICO recently fined a Police force £150k for sending an unencrypted DVD in the post that never arrived at its destination. The DVD was never found but they were still fined for sending unencrypted sensitive data in the post...

 

https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2017/05/greater-manchester-police-fined-after-victim-interview-videos-go-missing/

Posted (edited)
It doesn't necessarily have to be opened for it to be a breach though. The ICO recently fined a Police force £150k for sending an unencrypted DVD in the post that never arrived at its destination. The DVD was never found but they were still fined for sending unencrypted sensitive data in the post...

 

https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2017/05/greater-manchester-police-fined-after-victim-interview-videos-go-missing/

 

That's possibly more to do with what was sent (and lost) rather than the manner in which it was sent. From the ICO's report with that:

 

When people talk to the police they have every right to expect that their information is handled with the utmost care and respect. “Greater Manchester Police did not do this. The information it was responsible for was highly sensitive and the distress that would be caused if it was lost should have been obvious.
Edited by enjay
  • 9 months later...
Posted

Just to add to this thread.... today I have just read an email from AQA asking for all media to be sent by encrypted means, however, using a pre-defined password that is common knowledge for all exam centres. This seems risky to me due to the password being common knowledge amongst so many centres/schools/colleges.

 

In my view they have made this move purely to ease their operation (probably had complaints from moderators regarding accessing protected media and managing multiple passwords) and have opted for something that weakens data protection.

 

What are peoples thoughts on this??

Posted
Just to add to this thread.... today I have just read an email from AQA asking for all media to be sent by encrypted means, however, using a pre-defined password that is common knowledge for all exam centres. This seems risky to me due to the password being common knowledge amongst so many centres/schools/colleges.

 

In my view they have made this move purely to ease their operation (probably had complaints from moderators regarding accessing protected media and managing multiple passwords) and have opted for something that weakens data protection.

 

What are peoples thoughts on this??

 

I read the letter (assuming we got the same one) as the password being unique for each school. Now I'm going to have to track down our exams officer.

 

Only if the item gets misdelivered in the post, and the recipient opens post addressed to someone else - which is illegal.

 

You'd struggle to secure a prosecution unless it was wilful (not a "it's my house and it landed back-side up on the mat, so yes - I opened it and then realised").

 

And you'd still have a data breach to deal with.

  • Thanks 1
Posted

The AQA email our exams officer forwarded on to us says:

Your school’s media encryption password is: XXXXXXXXX

Which I would read as being a unique password for our school.

As long as they're careful/compliant when sharing the password I don't see this as a problem. It's probably safer than "please include this form that asks for the password with your physical media" that I remember from last year.

  • Thanks 1
Posted
Just to add to this thread.... today I have just read an email from AQA asking for all media to be sent by encrypted means, however, using a pre-defined password that is common knowledge for all exam centres. This seems risky to me due to the password being common knowledge amongst so many centres/schools/colleges.

In my view they have made this move purely to ease their operation (probably had complaints from moderators regarding accessing protected media and managing multiple passwords) and have opted for something that weakens data protection.

What are peoples thoughts on this??

 

We had battles with the exam boards last year when trying to be GDPR compliant and sending student work via an encrypted USB and emailing them the password - they didn't like it! Plus they managed to lose two of the memory sticks which weren't cheap. We've added a postscript stating if they lose it we will bill them for a replacement.

 

It's good to see that they are finally becoming more GDPR compliant and asking for us to encrypt the data we post. I read it that the code they supplied is specific to our school and only given to the examiners marking the paper. Why they haven't come up with a secure portal for us to upload the work to yet I don't know...

  • Thanks 1
Posted
Just to add, I would expect that they changed the password whenever a new set of exams were due so that ex-employees wouldn't be able to log in in the future.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...