Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted
Not sure you are correct at all. The explicit purpose is "running a school", and the legal basis is "public task". You appear to be trying to say the law is so prescriptive that you would say "can be used in this text field here, for census purposes and for putting kids in year groups, but nothing more", which is not at all right.

 

the lawful basis is legal obligation, as stipulated in the Education (Pupil Registration) regulations which requires a school to collect DOB for the purpose of maintaining an Admission/Attendance Register etc

 

http://www.legislation.gov.uk/uksi/2006/1751/pdfs/uksi_20061751_en.pdf

 

Variations for Scotland etc.

 

If a school decides to use another lawful basis, it must state it and make sure parents are aware of it etc. A school cannot on a whim decide it will use data collected for another purpose altogether with no due process.

Posted

It's absolutely not appropriate to use DOB information in this manner. Date of Birth is very much PII data, and is not really an appropriate thing to use to identify a child.

It sounds like somebody at the MAT has been on a training course, but left their common sense in a jar by the door. I would definitely be challenging this decision and resisting with all of my might to get it overturned. It's bloody ridiculous!

GDPR is important, but if you have been applying a little bit of common sense in your policies prior to GDPR being enforced, you really shouldn't have too much to worry about. GDPR is just an enforcement of all of the things that everybody should have been doing anyway. The analogy that I use when talking about GDPR best practice is "Would you walk up to a random stranger in the street, hand him/her your credit card, then whisper your PIN number in their ear?" The obvious answer is no, so why would you hand your personally identifiable data to a random company or person unless they could provide robust reassurance that the information would be strictly confidential, stored securely and would only be stored for as long as was absolutely necessary to complete the task that it was provided to achieve.

I have always drummed it into the teaching staff here that if they don't absolutely need to keep something, destroy it! If you don't have the information, you can't be hung for it!

Unless there's a legal requirement to store information, shred it as soon as you are finished with it.

  • Thanks 1
Posted
the lawful basis is legal obligation, as stipulated in the Education (Pupil Registration) regulations which requires a school to collect DOB for the purpose of maintaining an Admission/Attendance Register etc

http://www.legislation.gov.uk/uksi/2006/1751/pdfs/uksi_20061751_en.pdf

Variations for Scotland etc.

If a school decides to use another lawful basis, it must state it and make sure parents are aware of it etc. A school cannot on a whim decide it will use data collected for another purpose altogether with no due process.

That is one small aspect of our legal duties. We as schools have a legal obligation to educate children. Part of that duty is to discuss those children, and it is the 21st century, so email is normal way to do this. Your limitation does not work, and would be absurd. Each school will have their privacy notice, and they list their use of data within. Below is part of a boilerplate Privacy Notice, as provided by our LEA:

 

Why do we collect and use pupil information?We collect and use pupil information under legal and statutory obligations within the Education Act1996, The Children Act 2004; Education and Inspections Act 2006; Education Act 2011; and theFamily and Children’s Act 2014.We use the pupil data:• to support pupil learning• to monitor and report on pupil progress• to provide appropriate pastoral care• to assess the quality of our services• to comply with the law regarding data sharingThe categories of pupil information that we collect, hold and share include: Personal information (such as name, unique pupil number and address) Characteristics (such as ethnicity, language, nationality, country of birth and free schoolmeal eligibility) Attendance information (such as sessions attended, number of absences and absencereasons) Assessment information Relevant medical information Special educational needs information Exclusions / behavioural information

 

You are trying to state that we need to specify every single use of every bit of data, down to the specific method of usage each day. That is not the intent of the law, and would render operating a school impossible. It is also something we have not been told to do by the ICO, our LEA or by our DPO.

  • Thanks 1
Posted

 

You are trying to state that we need to specify every single use of every bit of data, down to the specific method of usage each day.

 

Not quite.

 

Why would the school in this case use DoB rather than the UPN?

Posted
We have recently been told not to use students names in emails but to refer to them by initials and dob. despite the inconvenience of having to look up dates of birth I am also concerned that staff at the receiving end will not have time to decipher and the information wrongly assign the information to another student with the same initials.

Are other schools doing this. We use gmail

 

Louise

 

We use their student ID from CMIS for their login and email ie Joe Bloggs student ID is 1234 so his email is [email protected]

 

The idea of this is he can not be identified easily by external senders.

 

In school the display name is “SURNAME, Firstname (1234)” so can they be found in the address book easily by staff.

 

If student replies or sends an email externally then yes there name is in the display name but they should known who they are sending the email too meaning it’s a trusted person.

Posted
Not quite.

Why would the school in this case use DoB rather than the UPN?

If the school determines that the best way of communicating within the school is to use the DOB in each email, then fair enough. The key is showing why you have come to that decision. As stated earlier, I personally think the idea is absurd, but if the school/Trust/LEA can justify it, that's up to them.

However, a UPN provides more information - the initial school they started at, the year of allocation, which for many will be able to give their age, plus the UID for that child. The guidance by the DfE states that you shouldn't really use it this way, and that if you need to identify children in school to use the admission number.

 

So, the hurdles for using the latter are far higher than the prior.

  • Thanks 1
Posted

spot on re the UPN and the extra legal limitations placed on it e.g. not to be put on paper, not to share it with parents etc

 

The key there is that in the documentation re UPN the ICO has advised schools that it is OK to use the admission number "as a general pupil reference number within the school".

 

There is no similar advice re the use of the DoB.

Posted

So, the hurdles for using the latter are far higher than the prior.

 

Exactly.

 

The full name isn't classified as sensitive personal data, the DOB/UPN are. If using basic personal details (full name) for using website services.. the scrutiny of such website would be low.. compared to one using DOB/UPN/Addresses etc.

 

if you're going to replace the full name with something.. it needs to be basic personal details or less.. a made up name/number etc.

 

We use full names in email addresses and our DPO doesn't even question this and he's had the full works of GDPR training (even our GDPR LEA auditor and advisor didn't care about the usernames/email addresses).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...