Jump to content

Recommended Posts

Posted

The actual cameras themselves are more of a risk than the numberplate characters it spits out. Pretty sure anyone can just watch the street to see who's going in an out anyway.

 

Just don't store the data for years I guess.

Posted
The actual cameras themselves are more of a risk than the numberplate characters it spits out. Pretty sure anyone can just watch the street to see who's going in an out anyway.

 

Just don't store the data for years I guess.

 

Now you are trying to justify the risk you (as in the school) create when collecting and processing data with a non-equivalent scenario.

 

Yes, anyone can watch who goes in and out ... but who does it constantly, checking against other known information?

 

Just because one thing you do is risky it doesn’t mean that other things *aren’t* risky.

Posted

It's not risky if someone else can easily replicate it, because the risk is the data will get stolen, I assume. And who's going to steal data that's not secret?

 

If I want to know who's driving into a school I'd just put on a high vis jacket, get a ladder, and put a solar powered camera on a nearby pole. Way easier than breaking in and crawling into the ceilings of the school.

Posted
It's not risky if someone else can easily replicate it, because the risk is the data will get stolen, I assume. And who's going to steal data that's not secret?

 

If I want to know who's driving into a school I'd just put on a high vis jacket, get a ladder, and put a solar powered camera on a nearby pole. Way easier than breaking in and crawling into the ceilings of the school.

 

Risk is not defined as to whether someone else can do it ... it is about what could go wrong if *you* do it. The fact that it might have risks elsewhere is not the important part of this. It is what you are doing to create and mitigate risk.

  • Thanks 2
Posted

So what's the risk of the system in the school car park?

 

Surely the risk is higher if it's more valuable information, because then people will be more determined to steal it.

 

The risk is different if it's a list of number plates in the MI5 car park, because that's more valuable, and they have multiple secret entrances so you don't know it's the MI5 car park, so it's more difficult to replicate.

Posted

This has been a lengthy and interesting discussion but let’s start to summarise things.

 

I’ll post it in here though a chunk could go into various other threads

 

The law is pretty clear on some things and even if you think the law is an ass ... it is the law. You cannot moan about staff wanting to break copyright and then pick and choose your own bits. That would be hypocritical.

 

If you collect data you must have a clear purpose for it, a lawful basis, only collect what you need and get rid of it when no longer needed.

 

Where there is risk, you need to evaluate, document your decisions and manage those risks. These are risks to the data subjects that could occur because of *your* processing and not a justification about other people being equally as bad. Please see the comment above about being hypocritical.

 

Physical and logical security is something we have all griped about needing to get on top of in schools, to raise the profile of how important it is, to establish good practices and to rule out Heath-Robinson solutions that will compromise your networks as soon as someone starts running airsnort. Again, the legislation says you need to be accountable on this. Show me the evidence that you have looked at it, considered it, worked on it and secured it. Refusal to document is ... well ... hypocritical. After all, we expect it of others.

 

This stuff is not hard, it is not rocket science to understand and whilst it might seem fun to poke about with half-cocked answers in some of these discussions ... we have to face that as professionals we need to do what is required, and where that is not possible we raise the risks and get someone with a bigger pay packet to sign things off. Where the risk is high, even after you have tried to mitigate it ... guess what ... the law says you have to talk to ICO about it.

 

Other than the above advice, I don’t think I can add much more right now ... so signing off for the night.

  • Thanks 3

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...