Jump to content

Recommended Posts

Posted

After spending months on GDPR compliance and getting all the obvious stuff in order you start getting into the little details on things that we've done for years without questioning it.

 

Firstly, our Year 11 Yearbook which we've done every year. We've now gone out and gained consent from staff and students who want their photos and names in it. That's all fine. Then the staff who are organising it have come along and asked "What about the company printing it?". Do we need a contract in place with the company who are going to print it? We use different printers all the time depending on cost and what they are good at producing. Do we need a contract in place with anyone we use where photos are printed? Do we need data sharing agreements etc? Most of the printing companies don't see themselves as data processors and don't have these in place!

 

Secondly, I've been asked about photography on the night! In the past we've had a member of staff as a photographer. The photos are then available for the students to look at and download if they want. Now I guess we need to get a signed consent for this too?

 

I think we are going to get to a point where we no longer produce Yearbooks or take photos at official events! It's just too much work!

Posted

With the printers for the yearbook it would be a case of making sure as much as you can that they will keep your data safe. This will mean asking the printers for their data privacy statement for example they will not sell the photos onwards or reuse in other non related print material etc most big publisher will have a data privacy policy however some of the small local companies may not.

 

Also I would say it is about ensuring that you have taken all the necessary steps to safeguard the data (photos) like do not supply on a non-encrypted memory, if you are uploading the photos is the site secure and password protected etc

Posted

Are you making all recipients of this book sign agreements that they will not share it, or its contents outside the group?

 

Thought not.

 

A common sense risk assessment based approach is all that’s needed in my opinion.

Posted
I’d look at what the severity would be to the data subject if the data was breached – for example if the printing company lost the pictures or they were stolen. I’d argue that the severity would be so small that you would just accept it as a known risk with no need to put any measures in place. At the most, I might just send an email to say the pictures are the schools property and cannot be used outside your contractual agreement.
Posted (edited)
After spending months on GDPR compliance and getting all the obvious stuff in order you start getting into the little details on things that we've done for years without questioning it.

 

Firstly, our Year 11 Yearbook which we've done every year. We've now gone out and gained consent from staff and students who want their photos and names in it. That's all fine. Then the staff who are organising it have come along and asked "What about the company printing it?". Do we need a contract in place with the company who are going to print it? We use different printers all the time depending on cost and what they are good at producing. Do we need a contract in place with anyone we use where photos are printed? Do we need data sharing agreements etc? Most of the printing companies don't see themselves as data processors and don't have these in place!

 

Secondly, I've been asked about photography on the night! In the past we've had a member of staff as a photographer. The photos are then available for the students to look at and download if they want. Now I guess we need to get a signed consent for this too?

 

I think we are going to get to a point where we no longer produce Yearbooks or take photos at official events! It's just too much work!

 

Good questions: For all sensitive personal data (photos being a prime one). The DPO could do a risk assessment, get consent and add it to the school policy.

Is the company GDPR compliant? they should be able to send you their GDPR policy. Once you have consent and both sides have a policy. I'd say that's all good to go.

 

If the company doesn't have GDPR compliance???

 

Can you imagine if they lost printing for your school that contained name of the child with a photo, name of parents and addresses? The school will have to report it to HT/Governors and the ICO. Questions will be asked of the company and the school. One could be "did you check that the company is GDPR compliant".. now that's where the school could be in a little spot of bother.. you would have two choices... admit that you was aware they didn't have GDPR compliance and continued to do business with them or didn't ask. It's one of the many reasons we are getting emails asking us to OPT in and that companies are informing us on their updated policies for GDPR compliance.

 

Cover your bottoms, cover your bottoms and cover your bottoms :)

 

If they are printing basic stuff with no personal details, I'd still get a copy of their GDPR policy (as part of our supplier company list that have staff contact details) and voila done.

 

**Update** Just read through a bit more. Photographs can be owned by the company (usually a small business owner) until you purchase them, get GDPR complaince policy and the school policy should already cover image rights etc. You may need to tweak it. A useful common sense practice on events or photography classes is to ask students if they wish to opt out of the photos they can. Making sure no one else is clearly visible without consent.

 

Consent, policies and compliance :)

 

We have probably been a bit over cautious here but in fairness we've managed to get about 90% compliance because of it.

Edited by mthomas08
Posted
**Update** Just read through a bit more. Photographs can be owned by the company (usually a small business owner) until you purchase them, get GDPR complaince policy and the school policy should already cover image rights etc. You may need to tweak it. A useful common sense practice on events or photography classes is to ask students if they wish to opt out of the photos they can. Making sure no one else is clearly visible without consent.

 

We are taking the photos and producing the Yearbook. All the company are doing is printing the documents for us. This is why it seems like such a hassle!

Posted
Good questions: Can you imagine if they lost printing for your school that contained name of the child with a photo, name of parents and addresses? Consent, policies and compliance :)

 

.

 

What exactly would the risk be if the photo's were lost or stolen? I'm presuming an end of year book wouldn't contain the persons address. Maybe not even a full name but even then.

 

The parent/child has consented that the picture can go into the book. They do so imo knowing that their picture will be pretty much going into the public domain. So a lost/stolen picture wouldn't really present any additional risk that they haven't already consented to?

 

The risk seems so insignificant that for me it would be a risk that I would be willing to accept. The GDPR doesn't expect us to remove every single risk there is. Unless I'm missing a risk that I haven't thought of!

Posted
What exactly would the risk be if the photo's were lost or stolen? I'm presuming an end of year book wouldn't contain the persons address. Maybe not even a full name but even then.

 

The parent/child has consented that the picture can go into the book. They do so imo knowing that their picture will be pretty much going into the public domain. So a lost/stolen picture wouldn't really present any additional risk that they haven't already consented to?

 

The risk seems so insignificant that for me it would be a risk that I would be willing to accept. The GDPR doesn't expect us to remove every single risk there is. Unless I'm missing a risk that I haven't thought of!

This. I don't see how the printers losing the digital document is any different to someone who has bought/received a printed year book losing that - exactly the same data is out there, and nobody is going to be making the kids sign agreements or reporting a breach when they lose their copy.

  • Thanks 1
Posted
The parent/child has consented that the picture can go into the book. They do so imo knowing that their picture will be pretty much going into the public domain. So a lost/stolen picture wouldn't really present any additional risk that they haven't already consented to?

 

Have the parents/children consented to use in the yearbook though? Ours have consented to publicity use which could arguably extend to yearbooks, but when we use photos in publicity they are anonymised - yearbooks are not.

 

I would say you need a copy of the printers' privacy policy to ensure they're storing them appropriately, not selling them, etc. but as you say, impact of loss is minimal.

 

As for photos on the night taken by staff and shared internally, I think that's fine. Ideally the camera would be a school-owned one, as with any other photography.

 

Of course, all this assumes none of the children in the year group are on the no photo list.....

Posted

We're doing this right now...

 

* Parents have explicitly consented to the child being included and that is on file for posterity

* Printers have been asked for, and have responded with, a GDPR compliance statement.

* We've additionally asked for confirmation that after the print run is complete the printers will have deleted the data from their system.

* We've emailed them a link to a onedrive location, requiring a known MS ID, with a password protected spreadsheet and an encrypted zip file of photos in it. The photos are not named, they're labelled by UPN, the UPN is in the spreadsheet and we've phoned through the passwords - they aren't the same.

* Once the printers have confirmed they have downloaded the data we remove it from onedrive - it's still on our system should we need it.

 

How did we do?

Posted
That's a solid process. If you wanted to go an extra step (although I don't think you need to) you could use admission numbers not UPNs, as those are totally meaningless outside your own school.
Posted (edited)
We're doing this right now...

 

* Parents have explicitly consented to the child being included and that is on file for posterity

* Printers have been asked for, and have responded with, a GDPR compliance statement.

* We've additionally asked for confirmation that after the print run is complete the printers will have deleted the data from their system.

* We've emailed them a link to a onedrive location, requiring a known MS ID, with a password protected spreadsheet and an encrypted zip file of photos in it. The photos are not named, they're labelled by UPN, the UPN is in the spreadsheet and we've phoned through the passwords - they aren't the same.

* Once the printers have confirmed they have downloaded the data we remove it from onedrive - it's still on our system should we need it.

 

How did we do?

 

Don't label them by UPN, the number can be used to extrapolate where someone went to school and what year they were assigned the number if you have the right knowledge to deconstruct them using the Get Information About Schools website. This is why it should only be shared with those who need it for school business and not the general public (not even the student or parents). :)

 

CLLLSSSSYYXXX

 

C = Check Letter

L = Local Authority Code

S = School Code

Y = Year of Assignment

X = Unique Serial Number

 

 

EDIT - Misread and thought it was shared with parents for some reason, printer will be fine so long as the UPN isn't published in the book. Will leave it here anyway, learning to read UPN numbers is super handy.

Edited by CAM
  • Thanks 1
Posted
Good questions: For all sensitive personal data (photos being a prime one).

Just a quick note - photos are not generally "sensitive" personal data, just personal data. Sensitive data is things like medical data, SEN status and the like.

Posted
Don't label them by UPN, the number can be used to extrapolate where someone went to school

 

I think the fact this is a school year book also gives you that information!

  • Thanks 1
Posted (edited)
Have the parents/children consented to use in the yearbook though? Ours have consented to publicity use which could arguably extend to yearbooks, but when we use photos in publicity they are anonymised - yearbooks are not.

t.....

 

 

The OP said in his first thread that they had consented to be in the book - "We've now gone out and gained consent from staff and students who want their photos and names in it."

Edited by Edutech98
Posted (edited)
I think the fact this is a school year book also gives you that information!

 

Nope. Not unless the UPN was assigned at your school in Year 11.

 

Example: Your LA is 876 and your school is 6709.

 

If your student was assigned to your school in Year 11 this year and the first UPN generated this year, the UPN would be C876670917001

 

Another student was assigned at a primary school with the LA 806 and school 3107 back in 2002 and the 103rd generated UPN for their year. The number follows them through their school life (or should do...). The UPN would be W806310702103

 

By using Get Information About Schools you can match the LA and School codes to the establishment and reveal the student's school history (any match in these fictional UPNs that I've pulled out my head is purely coincidental by the way!).

 

Ignore the check digits as I am deliberately leaving them incorrect to prevent any real UPNs being matched by accident. They are generated with a complex algorithm.

Edited by CAM
Posted
That's a solid process. If you wanted to go an extra step (although I don't think you need to) you could use admission numbers not UPNs, as those are totally meaningless outside your own school.

 

Apparently it has to be done by UPN because the photographers who come in to take the yearbook photos (who have also been vetted for GDPR complaince and included in our supplier data map) have special software that automagically ties up the name to the UPN and names the file as it is taken. It's mainly for MIS photos but they use the same system for the yearbook.

Posted
Apparently it has to be done by UPN because the photographers who come in to take the yearbook photos (who have also been vetted for GDPR complaince and included in our supplier data map) have special software that automagically ties up the name to the UPN and names the file as it is taken. It's mainly for MIS photos but they use the same system for the yearbook.

 

Fair enough. Our photographers do the same but with admission number.

Posted
The OP said in his first thread that they had consented to be in the book - "We've now gone out and gained consent from staff and students who want their photos and names in it."

 

Good spot. In which case, the only concern would be anyone on the no photo list. They presumably wouldn't consent for the year book anyway, but you would need to be mindful of them when taking photos at the prom.

Posted
Nope. Not unless the UPN was assigned at your school in Year 11.

 

Example: Your LA is 876 and your school is 6709.

 

If your student was assigned to your school in Year 11 this year and the first UPN generated this year, the UPN would be C876670917001

 

Another student was assigned at a primary school with the LA 806 and school 3107 back in 2002 and the 103rd generated UPN for their year. The number follows them through their school life (or should do...). The UPN would be W806310702103

 

By using Get Information About Schools you can match the LA and School codes to the establishment and reveal the student's school history (any match in these fictional UPNs that I've pulled out my head is purely coincidental by the way!).

 

.

 

I'm still not sure what risk this protects against though? If someone knows the persons name, what school they went to and what year they left, and the person is happy this information is going to be seen by people they do not know, does it really matter if the UPN then gets leaked? Realistically what impact would it have on the data subject that is more than the risk of having an unknown person knowing your name, photo, school leaving date and school info.

Posted
I'm still not sure what risk this protects against though? If someone knows the persons name, what school they went to and what year they left, and the person is happy this information is going to be seen by people they do not know, does it really matter if the UPN then gets leaked? Realistically what impact would it have on the data subject that is more than the risk of having an unknown person knowing your name, photo, school leaving date and school info.

 

Really? Well, let us know, what was the name of your first school? And your mother's maiden name and street you grew up on whilst you are at it. ;)

Posted
Really? Well, let us know, what was the name of your first school? And your mother's maiden name and street you grew up on whilst you are at it. ;)

 

The Heys, Humphrey and I think it was West Malbourgh Street. It was honestly a serious question. I really can't see what the additional risks are past the general risks that they have already agreed to. I've asked a couple of times if there are any realistic risks that I've not though off, which is entirely possible, but none have been put up which makes me thing there aren't any that we would need to mitiage against.

Posted
The Heys, Humphrey and I think it was West Malbourgh Street.

 

Thank you. We are all now one step closer to hacking your iCloud and other accounts which use shared secrets for security checks. You may not put sufficient information in one place, but put little bits in enough places and someone who could aggregate it would have quite a lot.

  • Thanks 1
Posted
This is why you never answer those "What is your superhero name and power" surveys on Facebook. They look harmless but are used to harvest such personal details for account breaches.
  • Thanks 1
Posted
Good luck hacking any of my accounts with that data! I don't use any real data for "secret questions" - all completely random and then they go into Schneier's Password Safe encrypted with TwoFish. I can't imagine a secret password asking what was your school UPN number tho :D Any such way, the fact they've consented to having their pictures in the year book already covers the risk of knowing your name, photo, school, year date. Putting any more mitigation in just seems like its wasting the schools time and money because there is no need imo.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...