Jump to content

Recommended Posts

Posted

Our school has a tradition of putting up pictures of vulnerable students in the staff room, along with some description of what their issue is. I'm sure we're not the only school.

 

As DPO I've said that we should not do this. Also, there are other better mechanisms of informing staff about vulnerable students that don't require essentially publicly posting information about these students - the staff room is used by cleaners, people carrying out maintenance at the school, a local church volunteer group, and potentially all manner of other adult visitors.

 

I have been told by the DSL that "safeguarding trumps data protection", hence these pictures and text must stay. This has been backed up by the Headteacher.

 

I think it's a gross oversimplification to say that safeguarding trumps data protection, because the two don't need to compete in this situation. Staff can be as informed, if not better informed, by other mechanisms.

 

Thoughts?

Posted

I would think this highlights the previous position as to why you as an NM realistically cannot be a DPO, I would resign as a DPO and save yourself a world of pain not being an SMT member in a school with that role.

 

https://ico.org.uk/for-organisations/education/ - that's a source for a lot of this and relation to education.

 

GDPR And Safeguarding In Schools: What You Need To Know - Data Protection - UK - Thats worth a look, that being said, Sensitive Data being up on a wall where anyone can potentially read it is probably something that's not great.

Posted

Oh sweet $deity.

 

Nothing *trumps* data protection ... there are exemptions, there are judgements and decisions made on risk assessments (DPIAs) and then there are people not wanting to look at other options or the impact this has.

 

If they have done the DPIA then fine ... they’ve made a decision and when it gets challenged they have to justify it, including to ICO and in the courts. If they are happy with that then there is little they can do (and no lawyer will ever say x trumps y!!)

 

In this case, like many I’ve seen, the risk of data being seen by people who have no right to see it, who could use this data for their own purpose or who increase the risk that the information will spread to those who have court orders preventing them from having contact is going to be high ... this *is* safeguarding ... so they are making a poor safeguarding decision at that point.

 

I would challenge it and happy to speak to you and them if you want.

 

If, as DPO, you have advised them and they have ignored your advice then make a particular note of it in your next report to the Governors... force the DSL to take advice from others and finally recommend they get a legal clarification on it.

 

I am starting to see more DPOs and DP leads in schools having to cover themselves now ... not because of their own liability but making sure everyone knows where the buck stopped should something go wrong ... and more on a safeguarding point than data protection!

  • Thanks 1
Posted

Possibly different in a school where pupils are generally not in school at the same time as cleaners, but there have been several cases reported where cleaners have been the first people to come across students in difficulty. We always work on the principle that every adult or volunteer in school has a responsibility for safeguarding and should also understand that they come across confidential information which mustn't be disclosed.

 

There is a data protection issue here, but in my view safeguarding does trump data protection, in that a pupil's safety should never be put at risk in preference to data protection, but there is a balance to be struck. In short, you need to do a risk assessment which will be dependent on who had access to your staff room.

 

A compromise where there's some way of covering them during the hours there's no control over who is in the room (ours is sometimes used for governors' meetings and I personally think it's inappropriate for them to have access to that information) might be the best way forward.

Posted (edited)

Our cleaners are very much contract based and not normally in areas with students. The problem is though that any adult visitor can end up in the staff room for tea etc.

 

 

My feeling is that displaying it is just unnecessary. We have weekly staff briefings where vulnerable students can be highlighted. Another example was given of it being necessary for covers teachers, but (1) what's the guarantee that a cover teacher will go to the staff room or even know to look at this particular display and (2) it would be far more effective if the cover supervisor ensured that all cover teachers were briefed about vulnerable students as part of their handover.

Edited by Decision
Posted (edited)
@jmak pleeeeaasseeee don’t use the word “trump”. It doesn’t exist ... if anything, safeguarding is the *purpose* for processing data!
Apologies for the bad choice of word. What I meant is that nothing we do in school is more important than keeping children safe. I'm aware that data protection is part of that - as well as being a legal requirement.

 

Never mind the fact that for at least the last two years, trump has been one of the most offensive words in the English language....

Edited by jmak
  • Thanks 1
Posted
I would think this highlights the previous position as to why you as an NM realistically cannot be a DPO

As the Headteacher has agreed with the DSL I'm not sure it would make a great deal of difference. My experience of these political situations is that another member of SLT could as easily be overridden.

Posted

Ok, the questions go like this ...

 

Have we done everything possible to reduce any risks associated with the use of this data?

 

They answer “yes”.

 

You ask “have you considered and taken action to reduce or remove the risk of unchecked individuals from seeing this data such as visitors (adult and children), people using the facilities when no children are around, etc.

 

They answer “yes”.

 

Note that if the answer is no then this is a data protection *and* a safeguarding fail.

 

We go on to ask what action have you taken then?

 

They answer “none”.

 

So you have explored every option? Having the VC board with a lockable cover that the site manager opens each morning and closes each night, or the DSL closes when the risk is particularly high such as open evenings, shows and events?

 

“Erm.... but that costs money or time or both.”

 

So you are justifying a safeguarding decision on money?

 

“No ... but what happens if a cleaner or visitor discovers a vulnerable child.”

 

The board is open to the cleaners if you feel they must know. They must also be included in any training associated with this ... oh, and you do pay them whilst they are being trained off course...

 

“But what about visitors?”

 

You mean you have visitors wandering around unaccompanied in areas where there may be vulnerable children? Can you explain to me why?

 

“Erm ... open evenings.”

 

Well staffed and and carefully managed open evenings?

 

“Of course”

 

Where key staff sweep the building for offending graffiti, rubbish ... oh, and stray pupils?

 

“Yes ... erm ...”

 

“But what about an emergency issue?”

 

You mean where you circulate an email to key staff so they can brief their departments, or gather everyone in to the staff room for a briefing?

 

“But not everyone will see it because they are teaching and we can’t take them away from that!”

 

And a Notice in the staff room would be seen by them when they are teaching?

 

....

 

Like I said ... it *is* safeguarding ... in the same way H&S is ... and Online Safety is.

  • Thanks 1
Posted
As the Headteacher has agreed with the DSL I'm not sure it would make a great deal of difference. My experience of these political situations is that another member of SLT could as easily be overridden.

The only thing I would say which sparked my reply to being with, is that DPO is a legal position really and I don't think on reading your previous threads and this, that it would be a position I would want to be in, it has certain legal ramifications which just don't seem worth the worry for an NM which is usually at the lower level of management in any school(SMT grade ones exist, but are a rarity), if it was me I would want out of it and the politics associated with it, from an NM point of view, I would really only be wanting to get involved in the access requests that people make of you for data within your systems.

 

But that is just my position in relation to what I have read, I understand that your's is obviously different.

Posted

A network manager *cannot* be a DPO in the same school.

 

I missed that in the earlier posts.

 

There is a massive conflict of interests and you really do need a level of senior position in the school where you can take it to the Governing Body ... as that is who the DPO reports to, not the Head individually.

Posted

An exemption doesn’t give you a free for all ... the five bullet points in “At a glance” really are key.

 

The example I gave of the board that gets opened and closed each day is an option already discussed with ICO and at the DfE working group (the example was actually for key data held in classrooms but kept on the inside of a cupboard door that could be opened as required but the principles apply when we expanded it).

Posted
I suspect you will find the SLT can justify having the information readily-accessible to staff, so I suggest instead finding a way to make it accessible to staff but not visitors. Here, we have a Google Doc containing names, year groups and photos for vulnerable learners - that document is linked from our intranet page, so is one-click away for staff and inaccessible to visitors.
Posted

Ouch. I don't imagine that the DSL is also a data protection expert and qualified to make the assertion that safeguarding wins. As DPO you've been appointed to advise whether their actions are compliant with data protection legislation. There are parallels between data protection and safeguarding, not least in the approaches which will embed them effectively by raising awareness and managing risk.

 

It's unlikely that posting notices on a board in a room not used by all staff who need to know, but also used by people who don't need to know, is the most effective way and measurable way to communicate important information to those who need it. Can the school provide evidence that those who need to know do and that those who don't need to know don't?

 

Safeguarding includes not exposing vulnerable students to undue risk, so a Data Protection Impact Assessment to look at how information about those students, which might include special category data, is being managed would be an appropriate mechanism to consider alternatives and record how the school has decided to act. Should the school decide to ignore the DPO's advice, then that too should be recorded.

 

As DPO, do you report regularly to the Governors or to the Head?

  • Thanks 1
Posted
Ok, the questions go like this ...

Have we done everything possible to reduce any risks associated with the use of this data?

They answer “yes”.

... reduced thread quote ...

And a Notice in the staff room would be seen by them when they are teaching?

....

Like I said ... it *is* safeguarding ... in the same way H&S is ... and Online Safety is.

@GrumbleDook, I agree 100% with your sentiment, but having now worked with a fair few heads now from inside the school as an employee, outside as a parent and governor, I know this scenario of conversation at times is never permitted to flow. I have the recent experience where effectively the conversation gets killed right at the start. A direct quote from last week, "sometimes you just have to do". Fortunately, this is not the norm and often a sensible professional dialogue can happen. My point: it's a strong reason why the DPO role needs to sit with someone insufficient authority to stop being shot down. We very nearly went outsourced for DPO, but SLT ducked out last minute due to cost and stuck the role with a new deputy head who has no expertise, no training and is way, way short of meeting the requirements for the role. From experience with my school where I govern, I've seen the outsource solution work well - it's an investment, not a cost!

 

My advice to @Decision in this situation is to use other levers to protect the children from their head and DSLs if they won't listen to reason. Take it to the governors, go to Exec Head if that's your structure, check and use your policies. I hope it would never come to it, but ultimately you can take it outside the organisation, to ICO, DfE etc. It's very tough to do especially if you are trying to hold your job without adding a large amount of stress, but as we all know, safeguarding is *ALL* our responsibilities. In this case, I wonder if you (and maybe a colleague) can schedule a meeting with the head and DSL (and maybe Chair of Governors), at a time outside the heat of the teaching day and have a calm discussion, they might think again.

  • Thanks 2
Posted
I attended a Level 1 safeguarding course for a school that I'm a governor at last week, given by the LA safeguarding lead. At no less than three times the trainer stated that safeguarding overrides data protection. i tried to push the data protection is safeguarding point and that the two should always be considered together which did seem to be accepted. If this is a consistent message being given to schools by safeguarding trainers then DPOs face an uphill battle!
Posted
I attended a Level 1 safeguarding course for a school that I'm a governor at last week, given by the LA safeguarding lead. At no less than three times the trainer stated that safeguarding overrides data protection.

There are certainly exemptions from GDPR concerning serious harm data and child abuse data in Education, but these are exemptions from right of access rather than total exemptions from any GDPR rights. See https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/exemptions/#ex30

 

A Data Protection Impact Assessment sounds like a structured and emotion free way forward in the circumstances outlined in the original @Decision post - examine the purpose of sharing information about vulnerable children, who it needs to be shared with, what risks this carries, the impact of it reaching unintended people, how effective communication will be measured, etc.

Posted
I attended a Level 1 safeguarding course for a school that I'm a governor at last week, given by the LA safeguarding lead. At no less than three times the trainer stated that safeguarding overrides data protection. i tried to push the data protection is safeguarding point and that the two should always be considered together which did seem to be accepted. If this is a consistent message being given to schools by safeguarding trainers then DPOs face an uphill battle!

 

I think it is a misinterpreted message. The point these trainers are probably trying to make is you don't need to obtain consent to share information where a child's welfare is at risk. In that respect, safeguarding overrides GDPR, but it is not the case you can do whatever you want in the name of safeguarding regardless of GDPR. For example, you don't need to obtain consent before contacting Social Services, but when you do, you should share information in a secure manner.

Posted
Our school has a tradition of putting up pictures of vulnerable students in the staff room, along with some description of what their issue is. I'm sure we're not the only school.

 

As DPO I've said that we should not do this. Also, there are other better mechanisms of informing staff about vulnerable students that don't require essentially publicly posting information about these students - the staff room is used by cleaners, people carrying out maintenance at the school, a local church volunteer group, and potentially all manner of other adult visitors.

 

As a DPO you have obligation to report this to the Head and tell him it needs to be resolved - provide other solutions. As a DPO you can report this straight to the Governors bypassing the HT and even consult with the ICO.

 

I have been told by the DSL that "safeguarding trumps data protection", hence these pictures and text must stay. This has been backed up by the Headteacher.

 

Why? No seriously - why? Why does it trump it?

 

Also why do they need that data plastered on a wall for all to see? Why is it not sent in an email to all staff which can be viewed and deleted easily. Why is this data not in a very secure area on a shared drive? We are told what we need to know regarding students with difficulties. Do we need to know all of them? No. Instead we are trained on what to watch for. Any issues - you pass on to the child protection officers. That is the procedure (also recently updated by law).

 

We have details on MIS for any staff member that teaches those students. HOYs/Offices are fully aware of what students need what etc. Do I need to know every single student that has learning issues or behaviour problems? no.

 

Who does the DSL have to report to? I assume LEA? I'd even contact them to find out if your school should be doing it. I wouldn't.. it is a risk.

 

I think it's a gross oversimplification to say that safeguarding trumps data protection, because the two don't need to compete in this situation. Staff can be as informed, if not better informed, by other mechanisms.

 

It is an excuse to do as they please - regardless. If a guest adult can see those details.. like it or not that is a risk and frankly I'd question if the DSL was fit for the job. What stops that guest taking a photo and sticking it on social media? nothing. What stops that adult from seeing some one they know and discussing it with people they shouldn't? Not every adult will be trained to be dealing with such sensitive matters like we are in education.

 

If the school refuses to listen to you... all you can do is make sure you've done everything physically possible... because the question will be raised what YOU did to stop this from happening.

 

The fact there are more secure options available just goes to show your school is not doing enough to be GDPR compliant in my view.

 

A guest should never see such data - the end.

Posted
I think it is a misinterpreted message. The point these trainers are probably trying to make is you don't need to obtain consent to share information where a child's welfare is at risk. In that respect, safeguarding overrides GDPR, but it is not the case you can do whatever you want in the name of safeguarding regardless of GDPR. For example, you don't need to obtain consent before contacting Social Services, but when you do, you should share information in a secure manner.

 

Exactly.

 

If there is a serious risk of of a child being in the middle of a major incident, nothing stops the child protection officer gathering all data needed to prevent it.

 

BUT

 

This doesn't mean the child protection officer can plaster a wall full of students with problems just to make peoples lives easier. And let's face it.. this is about nothing else but making the lives easier. That's not what child protection or GDPR is about. Both are about protecting individuals.

 

Can it be done better? yes - I've provided ideas.

Is the data safe on a wall where school guests can see it? - no and the fact that any DLS/Child protection officer can say otherwise.. is questionable.

 

Ask your self this. If you went to your local LEA offices and they put on the wall all the children in that area that are at high risk in their guest areas (even just for adults) do you think they will be strung up? yes. Would the LEA do it? no. Enough said.

 

And as for the trainer stating that Child Protection stamps on GDPR - both are laws and both can't be ignored just because of laziness or creature comforts. That trainer is giving the wrong type of message and frankly should be strung up too. Our DPO/CPO don't trump on each other. They do what is necessary to protect our children and their data. It takes one adult that could be questionable to see details about one student and target them individually for abuse. Where did they get that data? on a wall....

 

Our DPO and CPO would be fuming at this.

  • Thanks 1
Posted
We have details on MIS for any staff member that teaches those students. HOYs/Offices are fully aware of what students need what etc. Do I need to know every single student that has learning issues or behaviour problems? no.

 

On that point, I would disagree with you. I've seen a few instances where a situation with a vulnerable student/SEN student/student with behavioural issues could have been handled better or escalated into something which could have been avoided, but the support staff member involved hadn't been made aware (an email had been sent to teachers@). The consequences of one such instance could have been very stressful for the staff member involved.

Posted
I attended a Level 1 safeguarding course for a school that I'm a governor at last week, given by the LA safeguarding lead. At no less than three times the trainer stated that safeguarding overrides data protection. i tried to push the data protection is safeguarding point and that the two should always be considered together which did seem to be accepted. If this is a consistent message being given to schools by safeguarding trainers then DPOs face an uphill battle!

Unfortunately, the training isn't always great. I, along with a couple members of SLT, attended a GDPR session run by a vary large Education service provider in Surrey (who run much the some course for governors) got someone in from a non-education environment. The said schools with less than (I think 250) employees didn't need a DPO. Thy instructor clearly had no idea about 'public office' so a bunch of head/bursars etc. from small primaries schools went away with completely the wrong idea. The course, whilst inexpensive, was clearly put together in a rush and badly rolled out. This was a clear case of the training organisation jumping on the bandwagon.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...