Jump to content

Recommended Posts

Posted

This strikes me as utter stinking cowpats, but wiser heads than mine live here, so I want to see if this is as ridiculous as I think it is. The company we use to take online payments from parents and communicate via text/email (I'll keep them nameless for now) are claiming they can no longer automatically update their data from our MIS:

 

Unfortunately, due to the new GDPR regulations we are now unable to transfer any changes to personal data after initial implementation.

 

The only details that we can pick up via the synchronisation tool is the name, class and year group.

 

Surely, surely this is absolute nonsense? Data Protection regulation has always required us to ensure data is kept up-to-date and accurate, and that must take precedence over any concerns they might have about processing. Because their only concern can be in the processing: they do have the data (just out of date), and we're now having to update manually, so their only objection can be that they themselves don't want to do the processing, even though we have either legitimate basis or consent for any data they'd be taking.

 

Our DPO is phoning them to ask what their logic is, but: what the dickens, EduGeek? Can anyone fathom this? Has anyone else come across this? This is something they did do before May 2018, so it's not using GDPR as an excuse for a bad product; they've taken this functionality out as a result.

 

I am mystified and irritated in equal measure.

Posted
They may be requiring that the parents themselves give them the information - that way they have consent directly from the individual. They don't wish to process information which you have collated under whatever legal basis. One of our providers has made a similar move.
Posted

Sounds like a cop out to me. There's nothing in the GDPR says you can't share data, I bet you're sharing data live with a number of third parties for different systems. Garbage especially given that they've already got an initial version of the data in question.

 

As long as you have an appropriate agreement in place with the supplier, and list them on your privacy notices as someone you share data with, you should be good to go. Maybe run a DPIA to be watertight.

Posted
They may be requiring that the parents themselves give them the information - that way they have consent directly from the individual. They don't wish to process information which you have collated under whatever legal basis. One of our providers has made a similar move.

 

But then they're happy for us to update the data manually. And they've not even asked if our forms have a checkbox along the lines of "I am happy for this data to be shared with third parties contracted specifically to provide services for the school only on the basis that it is used for school business" etc., which would be a box-ticking exercise anyway AFAIC but surely be enough if that was their concern?

 

Sounds like a cop out to me. There's nothing in the GDPR says you can't share data, I bet you're sharing data live with a number of third parties for different systems. Garbage especially given that they've already got an initial version of the data in question.

 

As long as you have an appropriate agreement in place with the supplier, and list them on your privacy notices as someone you share data with, you should be good to go. Maybe run a DPIA to be watertight.

We are using the exact same sync tool to synchronise data to other suppliers, yes. One more part of the ridiculousness. I wish it were as easy as "should be good to go" but the task at hand, fundamentally, is just convincing them they're overreacting :(

Posted
But then they're happy for us to update the data manually.

 

In which case it's definitely complete cobblers.

 

You are sharing with them, and they are holding, a dataset which receives regular updates. That, in GDPR terms, is what is happening.

 

Whether you update manually or in a automated fashion is purely a technical point, not a GDPR one.

 

Too late to back out of this contract?

Posted

Given you control the automated source (SIMS > Middleware > their systems), there's no difference. They're still processing your manual changes on their systems.

 

Is this a "they can't be bothered to pay Groupcall to modify the report definitions to be less grabby of data they don't need" problem? As in, their automated tool isn't compliant because they're lazy?

Posted
Given you control the automated source (SIMS > Middleware > their systems), there's no difference. They're still processing your manual changes on their systems.

 

Is this a "they can't be bothered to pay Groupcall to modify the report definitions to be less grabby of data they don't need" problem? As in, their automated tool isn't compliant because they're lazy?

 

They've had to modify GroupCall already though to stop it doing what it was doing, so they could have just modified it to grab what it actually needed (fundamentally, contact details, which is directly relevant to their service anyway). It really does seem like they actually believe this bobbins.

Too late to back out of this contract?

 

They've been our online payment provider for... seven years? More? And honestly been brilliant in all that time, so it's not a straw at risk of breaking a camel's back. It's just infuriating. I want to grab them and shake some sense into them.

Posted

How very frustrating. What's the point of any system these days if it isn't automatically populated with MIS data?

 

That said, I'm not sure how our data gets into our comms package.....

  • Thanks 1
Posted
In which case it's definitely complete cobblers.

 

You are sharing with them, and they are holding, a dataset which receives regular updates. That, in GDPR terms, is what is happening.

 

Whether you update manually or in a automated fashion is purely a technical point, not a GDPR one.

 

Too late to back out of this contract?

 

You are forgetting that the payment provider is probably also working as a Joint DC in this circumstance. They have a direct relationship with the parents too ... especially where they are managing parents with children in different schools.

 

Why *should* they believe what the schools says? They have to rely on what the parents say. Schools have been known to get things wrong, you know. MIS are not infallible.

Posted
You are forgetting that the payment provider is probably also working as a Joint DC in this circumstance. They have a direct relationship with the parents too ... especially where they are managing parents with children in different schools.

 

Why *should* they believe what the schools says? They have to rely on what the parents say. Schools have been known to get things wrong, you know. MIS are not infallible.

 

True I suppose.... but then in that case, wouldn't the payment provider need their own opt in permissions for every parent?

Posted
You are forgetting that the payment provider is probably also working as a Joint DC in this circumstance. They have a direct relationship with the parents too ... especially where they are managing parents with children in different schools.

 

Why *should* they believe what the schools says? They have to rely on what the parents say. Schools have been known to get things wrong, you know. MIS are not infallible.

 

So in your far-more-knowledgeable opinion, this isn't an unreasonable stance for them to take, even though it hugely increases the risk of them having inaccurate data? It feels like a Catch 22 to me, except one option is practically speaking going to have far more impact on a regular basis whereas the other is (from my perspective) more theoretical?

 

And since they're not disabling automation in favour of asking parents to update directly (which I could see the logic of), but instead asking us to update manually, how is our word more trustworthy with the latter mechanism than the former?

 

(I'm not arguing with you here, genuinely trying to understand. Your expertise in this area far surpasses mine!)

Posted
True I suppose.... but then in that case, wouldn't the payment provider need their own opt in permissions for every parent?

 

Contractual necessity could be used, not consent. And even if they are using consent, then they would gather that when the parent signs in to *their* service.

Posted
So in your far-more-knowledgeable opinion, this isn't an unreasonable stance for them to take, even though it hugely increases the risk of them having inaccurate data? It feels like a Catch 22 to me, except one option is practically speaking going to have far more impact on a regular basis whereas the other is (from my perspective) more theoretical?

 

And since they're not disabling automation in favour of asking parents to update directly (which I could see the logic of), but instead asking us to update manually, how is our word more trustworthy with the latter mechanism than the former?

 

(I'm not arguing with you here, genuinely trying to understand. Your expertise in this area far surpasses mine!)

 

It is a pain in the backside situation based on schools having a broad range of time and engagement with parents to ensure correct info.

 

By asking for manual updates there is a better chance of visual verification of human error (typos and such).

 

If seen some schools and providers agree to encourage parents to check and update details (onus back on the parent).

 

Keep talking with them and see if there is a way you can use the difference between what you know and what they know to target individuals about updating information.

  • Thanks 1
Posted

I'd assume that uploading and synchronisation from MIS was part of the product description.

 

Talk to them nicely and see if you can persuade them to be a bit more sensible - otherwise I'd start talking breach of contract and looking at other suppliers.

Posted
Given you control the automated source (SIMS > Middleware > their systems), there's no difference. They're still processing your manual changes on their systems.

 

Is this a "they can't be bothered to pay Groupcall to modify the report definitions to be less grabby of data they don't need" problem? As in, their automated tool isn't compliant because they're lazy?

If the partner is using Groupcall Xporter (on Demand) then they write against the API, there is no change Groupcall side and so there is no charge.

 

I would be interested to know (privately if necessary) who this is, so that we (Groupcall) can understand why this is the case and if there is any assistance they need to enable this. I agree there is depth unknown here but on the surface seems barmy and totally against the rest of the market.

Posted
By asking for manual updates there is a better chance of visual verification of human error (typos and such).

 

I don't understand why they assume there'd be any difference between the accuracy the first time and the second time, though. The data is verified the first time it's manually entered into the MIS from a paper record. If anything, it's more likely to be wrong the second time because people are fed up of having to repeat a job.

 

If the partner is using Groupcall Xporter (on Demand) then they write against the API, there is no change Groupcall side and so there is no charge.

 

I would be interested to know (privately if necessary) who this is, so that we (Groupcall) can understand why this is the case and if there is any assistance they need to enable this. I agree there is depth unknown here but on the surface seems barmy and totally against the rest of the market.

 

PMing you :)

Posted
I don't understand why they assume there'd be any difference between the accuracy the first time and the second time, though. The data is verified the first time it's manually entered into the MIS from a paper record. If anything, it's more likely to be wrong the second time because people are fed up of having to repeat a job.

 

Part of the presumption is that there is only 1 email address in use here ...

Some parents are known to use multiple addresses.

1 for all school related activities, 1 dealing payments, 1 dealing with banking ...

 

If they are saying that you need to manually enter it as then you are checking if there is a difference between what is in there and what you think it should be ... then it is down to *you* to go and check with the parent about the discepency.

Personally, I would prefer a system to hold the change and try to contact me (as a parent) to say that an update is being made and can I verify it. If I don't verify it, then it reports back to you and *then* you chase.

  • Thanks 1
Posted
Part of the presumption is that there is only 1 email address in use here ...

Some parents are known to use multiple addresses.

1 for all school related activities, 1 dealing payments, 1 dealing with banking ...

 

If they are saying that you need to manually enter it as then you are checking if there is a difference between what is in there and what you think it should be ... then it is down to *you* to go and check with the parent about the discepency.

Personally, I would prefer a system to hold the change and try to contact me (as a parent) to say that an update is being made and can I verify it. If I don't verify it, then it reports back to you and *then* you chase.

 

Right, that makes sense, cheers. DPO hadn't heard back from anyone as of last night, but if I can catch up with her I'll see if they've said anything yet...

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...