Jump to content

Recommended Posts

Posted
Good luck hacking any of my accounts with that data! I don't use any real data for "secret questions"

 

Same here. Lots of people are not as sensible though.

 

I can't imagine a secret password asking what was your school UPN number tho

 

True, but they often ask the name of your first school or the place you were born. A UPN issued for KS1 or KS2 SATS exams tells someone your first school, and depending on where that school is, gives a very strong indicator as to the place you were born.

Posted
Same here. Lots of people are not as sensible though.

 

 

 

True, but they often ask the name of your first school or the place you were born. A UPN issued for KS1 or KS2 SATS exams tells someone your first school, and depending on where that school is, gives a very strong indicator as to the place you were born.

 

But the person has already consented that their name, likely place of birth, school name, date of leaving etc is being published with the knowledge that people they do not know will see it. We don't need to put steps in place to protect a UPN because it might reveal the school a data subject goes to because they have already consented that this information will be widely seen by people they do not know. The person has accepted the risk and has consented to it. An photo, name, school name and date of leaving is much more valuable to an attacker than an UPN, and the person has consented for the more valuable data to be seen by people they do not know.

 

An attacker can't do something with a persons UPN that they can not do with the persons name, picture, likely year of birth, school name, date of leaving - and the data subject has already consent to this risk so there is no additional risk that would cause the subject severity of their rights and freedoms.

 

I just think were being a bit too risky and wasting schools time/money putting in security when we don't need to be. Just send the pictures to the publisher and get them printed. If the publisher has an unlikely data breach and the pictures get breached, its not a big deal because the data subject has already consented that there picture is pretty much going to be seen by 100's of strangers anyway.

Posted
But the person has already consented that their name, likely place of birth, school name, date of leaving etc is being published with the knowledge that people they do not know will see it. We don't need to put steps in place to protect a UPN because it might reveal the school a data subject goes to because they have already consented that this information will be widely seen by people they do not know. The person has accepted the risk and has consented to it. An photo, name, school name and date of leaving is much more valuable to an attacker than an UPN, and the person has consented for the more valuable data to be seen by people they do not know.

 

You're confusing issues now. The person has consented to their name, photo, MOST RECENT school (but nothing about their likely place of birth) being published in a year book. In order to achieve that, you have also shared UPN, which indicates FIRST school and likely place of birth, with the printing company. I might be happy for you to print my child's name and photo in their Year 11 year book, but I might not be happy for you to share their place/region of birth with the printers.

 

You need to do a DPIA on the printers, and I think consider whether you need to give them the UPN or if you could give them something less sensitive such as an admission number. You also need consent to share the child's information with the printers, not just for the final printed book which the other students see.

Posted
But the person has already consented that their name, likely place of birth, school name, date of leaving etc is being published with the knowledge that people they do not know will see it. We don't need to put steps in place to protect a UPN because it might reveal the school a data subject goes to because they have already consented that this information will be widely seen by people they do not know. The person has accepted the risk and has consented to it. An photo, name, school name and date of leaving is much more valuable to an attacker than an UPN, and the person has consented for the more valuable data to be seen by people they do not know.

 

An attacker can't do something with a persons UPN that they can not do with the persons name, picture, likely year of birth, school name, date of leaving - and the data subject has already consent to this risk so there is no additional risk that would cause the subject severity of their rights and freedoms.

 

I just think were being a bit too risky and wasting schools time/money putting in security when we don't need to be. Just send the pictures to the publisher and get them printed. If the publisher has an unlikely data breach and the pictures get breached, its not a big deal because the data subject has already consented that there picture is pretty much going to be seen by 100's of strangers anyway.

 

First off, if you actually read the post that I made you will see what I added shortly after posting it that I made an error and it is fine for the printer and the UPN reading guide is left up because it is useful. Just don't publicly display the UPN.

 

Secondly, it doesn't matter what the data is being used for as you have to protect it. If a list of photos, names, DOBs, etc was exposed it would cause significant embarrassment to the company. That is how you determine how confidential something is and the data being sent to a printer must be protected even if it will be displayed in a year book.

 

Thirdly, the level of exposure of details in a year book is considerably smaller than the details ending up on Pastebin, 4Chan or some random Russian website. The upload of the book by students will already be covered as an offence by both privacy and copyright law.

Posted (edited)
The Heys, Humphrey and I think it was West Malbourgh Street. It was honestly a serious question. I really can't see what the additional risks are past the general risks that they have already agreed to. I've asked a couple of times if there are any realistic risks that I've not though off, which is entirely possible, but none have been put up which makes me thing there aren't any that we would need to mitiage against.

The issue isn't always about risk - GDPR is about privacy by default. If certain information is not needed for a task, then by default it must not be used for it. UPNs are personal data and can be used to find out more about a person than just their name and photo (which is what is needed for this project). If there is a specific operational need to use UPNs then this would need to be justified and consent gained to allow that data to be used that way.

 

Put simply - the school doesn't own that data. Each person that data is about does. GDPR turns the way we think about data around and makes us, as processors, make sure we don't use data if we don't need to, and if we do need to we have one of the list of legal reasons for doing it - the relevant one here being consent.

Edited by localzuk
Posted (edited)

@enjay - Your not sharing an actual place of birth with the printers, your sharing a UPN. The UPN, like the persons most recent school, gives a likely indication of where the person was born. The person has consented to this, the person knows if the attacker knows your school, they can have a good guess of where you were born and get it right more times than not.

 

I agree @CAM - there is no need to publish the UPN, but I don't see any real risk of the printers having it past what has already been consented to.

 

^^ The whole of article 32, security, is to do with risk management so GDPR, and this case, absolutely has to do with risk. I agree follow the principle of data protection by design, but in the UPN case the printers need the info to match the persons name to it.

@localzuk - realistically, what can a person find out about a person from the UPN that is more than the persons name, picture, school, date of leaving, likely place of birth that would effect the persons right or freedoms? I can't think of anything.

Edited by Edutech98
Posted
I agree follow the principle of data protection by design, but in the UPN case the printers need the info to match the persons name to it.

 

Why can't they use admission numbers? That said, I agree with you about the risk management, and the impact of a load of UPNs being disclosed is minimal. As long as you have done a DPIA on the printing company, and are happy what how they're (not) sharing or aggregating the data, I don't see a problem with it.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...