Jump to content

Recommended Posts

Posted

Feel foolish posting this, but having read other posts on the site, it seems like there is plenty of common sense going on here.

One of our AHTs created panic in the staffroom today by saying that all exercise books will need to be locked away to avoid GDPR breaches - name and class code visible to others would be a serious issue. This then left teachers feeling they couldn't take marking home and that we'd have to spend money we don't have on loads of lockable cupboards.

 

I can see that, for example, information about FSM or date of birth left visible on an exercise book, but surely not name, class and teacher?

 

If anyone could help it's be great, especially if they can point to a source that supports it.

Posted
Feel foolish posting this, but having read other posts on the site, it seems like there is plenty of common sense going on here.

One of our AHTs created panic in the staffroom today by saying that all exercise books will need to be locked away to avoid GDPR breaches - name and class code visible to others would be a serious issue. This then left teachers feeling they couldn't take marking home and that we'd have to spend money we don't have on loads of lockable cupboards.

 

I can see that, for example, information about FSM or date of birth left visible on an exercise book, but surely not name, class and teacher?

 

If anyone could help it's be great, especially if they can point to a source that supports it.

 

If you had to lock them away, you'd also have to refuse to let the pupils have them unsupervised incase they took them home and/or lost them. Just somebody reading far too much into it I think!

  • Thanks 1
Posted
If you had to lock them away, you'd also have to refuse to let the pupils have them unsupervised incase they took them home and/or lost them. Just somebody reading far too much into it I think!

 

Well a student could do anything with their own data couldnt they? So a student taking a book and losing wouldn’t fall back on the school?

 

I get the impression that this isn’t what was in mind for GDPR though. Surely it’s about making sure that the data is handled properly (not leaving named books on the bus) rather than coming up with elaborate systems to anonymise everything. I have read about schools insisting that only initials are used on books. There is a school down the road that is seriously looking into using QR codes on books so teachers have to scan to see who’s book it is! That just seems a crazy interpretation of the rules.

Posted
Well a student could do anything with their own data couldnt they? So a student taking a book and losing wouldn’t fall back on the school?

 

I get the impression that this isn’t what was in mind for GDPR though. Surely it’s about making sure that the data is handled properly (not leaving named books on the bus) rather than coming up with elaborate systems to anonymise everything. I have read about schools insisting that only initials are used on books. There is a school down the road that is seriously looking into using QR codes on books so teachers have to scan to see who’s book it is! That just seems a crazy interpretation of the rules.

 

Because nobody else could possibly scan a QR code!

 

I take a risk based approach to potential issues, so:

- what is the data sensitivity level: Low.

- likelihood of a data breach: Low

- are there any risk mitigation that can be made: not much, maybe staff should ensure that piles of books aren't left in a car overnight.

 

Overall risk: low to negligible.

  • Thanks 1
Posted
In a few years all the workbooks will be in gsuite/ofiice365. Then you get encryption and authentication. But yes the risk is fairly low.
Posted (edited)
This then left teachers feeling they couldn't take marking home and that we'd have to spend money we don't have on loads of lockable cupboards.

 

I can see that, for example, information about FSM or date of birth left visible on an exercise book, but surely not name, class and teacher?

 

If anyone could help it's be great, especially if they can point to a source that supports it.

 

What the responsible person probably should do is "risk assess" the threat (e.g. likelyhood of breach, nature of information likely to be lost in a breach) and make a reasoned decision as to what is appropriate and write that up as policy/guidelines for staff to follow. GDPR is not supposed to stop organisations from doing what needs to be done, rather it's supposed to make the organisation think about whether or not something is a risk, and if so is the risk neccessary or appropriate.

 

I'd suggest that for taking work home you could say it should be kept securely in transit and stored securely when not in use. This might suggest that marking should be locked in the car boot during transit rather than left on the seat of an unattended car and once home couldn't be left out on the dining room table unattended, not that it couldn't be done at home at all.

Edited by Roberto
  • Thanks 1
Posted
Feel foolish posting this, but having read other posts on the site, it seems like there is plenty of common sense going on here.

One of our AHTs created panic in the staffroom today by saying that all exercise books will need to be locked away to avoid GDPR breaches - name and class code visible to others would be a serious issue. This then left teachers feeling they couldn't take marking home and that we'd have to spend money we don't have on loads of lockable cupboards.

 

I can see that, for example, information about FSM or date of birth left visible on an exercise book, but surely not name, class and teacher?

 

If anyone could help it's be great, especially if they can point to a source that supports it.

 

I think they need to calm down a bit. Basic personal data is okay, classrooms and marking books to take home are fine.

 

What you need to be doing though is training staff to lock classrooms and be vigilant when taking bits home. Course work will have full names but nothing more and they will be in classrooms which should be locked when not in use anyway. They can take folders home and the majority of it again will be full names only. Be safe, be secure and show you are educating staff.

 

The sensitive data is when you start some tougher stances on security. Do they leave them laying around for all to see? Do they have endless paper copies that they don't need? (insert the legit reasons). It's not about stopping them from doing their job but it's about safety/security and awareness. The teacher won't get strung up for leaving a classroom unlocked and a visitor stole the course work... and the risk/breach factor is very minimal.. but they should get a little talking to about locking the classroom.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...