Jump to content

Recommended Posts

Posted
In a meeting yesterday someone said content filtering is automated decision making, presumably because it scans a page's contents and then decides whether or not to permit the page. I hadn't thought to classify filtering in this way, but I can see their point. What do you think?
Posted

It's obviously automated decision making, but it's not making a decision about personal data (unless the data is on the webpage in which case it's been made public anyway) ...right?

 

I think that clause exists for stuff like job sites scanning a CV for keywords before deciding whether or not to pass it on to the company.

Posted
I wouldn't have thought this would be relevant for GDPR as the automated decision making is not related to a person but only to webpages that are being requested. Automated decision making would relate to things such as applying for a mortgage where the answers to questions asked about you and your circumstances may result in you being refused funds.
Posted

Okay, I see the distinction you're both making. The data on which the filter is making a decision is not personal data about the individual, or to put it another way, the decision affects the individual but it isn't based on the individual.

 

BUT... The ICO say (Source - https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/rights-related-to-automated-decision-making-including-profiling/):

 

"The GDPR has provisions on:

  • automated individual decision-making (making a decision solely by automated means without any human involvement); and
  • profiling (automated processing of personal data to evaluate certain things about an individual). Profiling can be part of an automated decision-making process."

 

So, the second of those bullet points is clearly aimed at your job site or mortgage lender, but doesn't content-based web filtering come under the first of those bullet points, a decision made solely by automated means?

Posted
Okay, I see the distinction you're both making. The data on which the filter is making a decision is not personal data about the individual, or to put it another way, the decision affects the individual but it isn't based on the individual.

BUT... The ICO say (Source - https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/rights-related-to-automated-decision-making-including-profiling/):

"The GDPR has provisions on:

  • automated individual decision-making (making a decision solely by automated means without any human involvement); and
  • profiling (automated processing of personal data to evaluate certain things about an individual). Profiling can be part of an automated decision-making process.

So, the second of those bullet points is clearly aimed at your job site or mortgage lender, but doesn't content-based web filtering come under the first of those bullet points, a decision made solely by automated means?

 

Interesting question this - but humans made the decision on which categories to block for groups of people, the automation is categorizing sites nothing more.

Posted
The first point relates to individual decision making but filtering will block anyone who trys to access banned sites.

 

Not necessarily. It might block the page from students but allow staff to see it, or block it from a Year 7 but allow a Year 13 to see it (not relevant here as we have a single student filtering group, but I know some schools differentiate by year group)

 

- - - Updated - - -

 

Interesting question this - but humans made the decision on which categories to block for groups of people, the automation is categorizing sites nothing more.

 

Agreed. Humans decide which categories to block but an automated process decides which category a site falls in to.

Posted (edited)

Further down the same page:

 

The restriction only covers solely automated individual decision-making that produces legal or similarly significant effects. These types of effect are not defined in the GDPR, but the decision must have a serious negative impact on an individual to be caught by this provision.

A legal effect is something that adversely affects someone’s legal rights. Similarly significant effects are more difficult to define but would include, for example, automatic refusal of an online credit application, and e-recruiting practices without human intervention.

 

 

Edit - so quick answer no - filtering isn't covered by GDPR - the most hooky claim I could think of is that you're removing the right to free speech on specific platforms, but as we don't technically have free speech rights enshrined in law in this country, and as I suspect even the harshest filtering will still allow access to government websites to access public services, I just don't see how it could be...

Edited by crispybits
Posted
the most hooky claim I could think of is that you're removing the right to free speech on specific platforms,

 

But anyone using the system should have signed an AUP thus saying that they're OK with being censored/monitored.

Posted

Also, I think a key word is "automated individual decision making" and the filtering decisions aren't individual, they are (at most) year-group specific.

 

So, I think you've all convinced me I was right to start with and web filtering isn't automated decision making. The curve ball now is this - the person who suggested otherwise was "interviewing" to be our DPO!

  • 2 weeks later...
Posted
Interesting question this - but humans made the decision on which categories to block for groups of people, the automation is categorizing sites nothing more.

 

Broadly I agree, however, I don't think its the filtering per se that causes a problem, but the logging thereof when the automated categorization process makes a mistake.

 

Consider the hapless teachers that searched for "Can I grow potatoes inside?" which generated a log entry for a drugs search because the word "pot" is in potato. (And no I didn't configure the system, a 3rd party did).

 

Also, the second teacher that searched for a cucumber image (they were learning about healthy eating), and generated a porn block.

 

The issue is what happens to those records since they are recording an incorrect search event result and how they might be used against those members of staff or school in future. If somebody has reason to demand a report of blocks by type per staff member or pupil, they wouldn't necessarily see the context.

 

Should they be deleted or corrected "if" that is technically possible?

 

I think its also chilling for IT support staff as I would certainly be unwilling to replicate or test certain situations that might cause inappropriate records to be held against me.

Posted
Most would be a little cautious about that but IT staff do have a very good reason for needing to check these things. There are going to be blocks against my name against 888.com despite not being a gambler, pXXXhub despite not doing such things at home let alone at work but as responsible adults things need checking and testing. I don't want to be able to see porn on my near-unfiltered machine let alone see it on anyone elses so it's important that such checks are made especially on installation of new filters etc.
  • Thanks 1
Posted
Most would be a little cautious about that but IT staff do have a very good reason for needing to check these things. There are going to be blocks against my name against 888.com despite not being a gambler, pXXXhub despite not doing such things at home let alone at work but as responsible adults things need checking and testing. I don't want to be able to see porn on my near-unfiltered machine let alone see it on anyone elses so it's important that such checks are made especially on installation of new filters etc.

 

All of this...

 

Plus, I use 888.com to force an override page - gambling is not blocked on the lightly filtered accounts. If I need a teacher to have supervised access to something that would normally be blocked, a visit to 888.com and the entering of a different set of credentials on the override page that appears gets them to Vimeo or Pinterest which are normally blocked. I've used it, maybe 6 times in 3 years. Attempting to access p**nhub gives a hard block even on 'unfiltered' accounts and sometimes it's necessary to prove to people it's there.

Posted

Why are you blocking staff from accessing Pinterest?! I don't think you should block staff from 888.com either (and we don't here), but that's a separate discussion.

 

There is a specific p*** website I use when I want to hit the block page - I always use the same one and the frequency with which I visit it makes it clear it is for testing purposes not recreation. I'd happily justify that if challenged.

Posted
Why are you blocking staff from accessing Pinterest?! I don't think you should block staff from 888.com either (and we don't here), but that's a separate discussion.

 

There is a specific p*** website I use when I want to hit the block page - I always use the same one and the frequency with which I visit it makes it clear it is for testing purposes not recreation. I'd happily justify that if challenged.

 

Pinterest - Specific incident.

Gambling - Policy handed down from governors.

 

I always use the same pages too.

Posted
Basic principle to apply here: Safeguarding trumps everything.

 

Genuine question: While that is obviously the answer you will get from senior people in education, is actually the case that Safeguarding trumps everything where the law is concerned? Would a Safeguarding concern (not necessarily an issue) actually be a defence for breaching GDPR rules for example?

 

Common sense says so, but then again also can 'because Safeguarding' really be an excuse for anything?

  • Thanks 1
Posted (edited)
Genuine question: While that is obviously the answer you will get from senior people in education, is actually the case that Safeguarding trumps everything where the law is concerned? Would a Safeguarding concern (not necessarily an issue) actually be a defence for breaching GDPR rules for example?

 

Common sense says so, but then again also can 'because Safeguarding' really be an excuse for anything?

 

Yes, as long as the action is proportional and reasonable. So, as an example of the top of my head, if a student says "I'm about to kill myself because my step-dad is touching me" you can phone social services without waiting for written consent to share their information. If, however, your response to their statement was a Facebook post encouraging any of that child's friends to phone and talk them down, that would not be okay.

 

Equally, if someone found your medical register lying around on your desk when you weren't there, you couldn't say "ah but I need it for safeguarding, so that wasn't a breach".

Edited by enjay
Posted (edited)
Safeguarding does not trump GDPR. However your legal obligation under keeping children safe in education would give you a valid legal basis under which you can process some data. You'd still have to justify that you were processing the data under that legal obligation and do so with adequate protections. Edited by IrritableTech
  • Thanks 2
Posted

So I've been digging. However I am not a lawyer. Seek one if you need official clarity.

 

Article 23(i) of GDPR allows for an exemption for "the protection of the data subject or the rights and freedoms of others"

 

This appears to be covered in the DPA 2018 by Schedule 3: Data Protection Act 2018. I interpret this to cover safeguarding is by way of part 3 and 4 of this schedule.

 

That said GDPR Article 22 (Automated individual decision-making, including profiling) is not on the exemption list!

 

But this isn't a problem I don't think. To my reading dynamic URL/Content filtering of internet access is not covered by the Article 22 definition "The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her."

 

My emphasis.

 

I would argue that automated filtering decisions and even logging of such decisions does not produce legal or similarly significant affects. A human has to investigate the logs/alerts before any action is taken that could be described so. Thus it is not automatic processing, and the problem never exisited.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...