Jump to content

Recommended Posts

Posted
Hi all, can I just check for school trips, we are sending travel companies/trip organisers a lot of personal data including medical information all with parental consent. Am I right in thinking we need to ensure these companies are GDPR compliant and ask them to supply us with a privacy notice before sharing and that should suffice?
Posted

The contract(s) between the organisation(s) and the school should have appropriate language regarding data sharing and probably forms a data-sharing agreement between the two parties for the purpose of the trip. They'll very likely have a privacy policy available as well.

 

TLDR: Read the contract small print. Follow up with company if unsatisfied.

  • Thanks 1
Posted (edited)
It’s not a privacy notice that you need here. As pete says you should have appropriate contracts in place with them that cover data sharing. Experience so far is that only the larger providers are up to speed. Edited by Bigbird7
Posted
if you email/post the data you should encrypt it, either by password protecting the doc's or encrypting the email.
Posted
It isn't just the travel companies - if you're doing an exchange, you're likely telling the host families about medical conditions. Not really sure how you're meant to handle that - get all the French parents to sign data sharing agreements?!
Posted

We get a data policy - make sure it's up to scratch and add the supplier to the data map. The letters now all have a little section about sharing data with the trip provider where appropriate: "The trip provider [name] conforms to all current and appropriate data handling rules. Data shared will include names, addresses, next of kin details and contact information and may include sharing of medical conditions if required" There is also a note under the sign here line about "By signing and authorising your child to attend you are consenting to sharing data as indicated above to allow the school and the trip provider to fulfill H&S and insurance obligations."

 

This is mainly for residentials TBH, oridinary school trips we control the data still. The passenger list for coaches etc is held by the person from the school who is responsible rather than the coach company.

Posted

I'd personally do it as a data controller/processor contract setting out what your expectations are. For the exchanges I'd do the same and just set out what the exchange parent can and cannot do with the data. I'd do the exchange a bit more looser than a company with some reasonable expectations on how they should protect the data.

 

I'd stay away from getting parental consent to share the data or mentioning consent in the data sharing context, you would be doing it as public interest or legitimate interest rather than consent.

 

Consent would need to be a specific opt in, you couldn't do it as a letter saying sign here to let your child go and by doing so you consent to having their data shared - that's not GDPR consent. Also the consent can't be a condition of the agreement it should be separate. So if you choose to do it by consent, you need to give the parent the option to opt out but still be able to go on the trip which would be a safe guarding problem. So would be better not to use consent and use public interest or legitimate interest.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...