sarahstacey Posted March 27, 2020 Posted March 27, 2020 Good afternoon, I hope all is well with you and yours.. I'm after some advice about the use of Zoom. Our school is using Google Classroom to deliver lessons while we are closed and as part of that we are using Google Meet. However our music department has instructed their peripatetic staff to deliver lessons via Zoom.. I would rather it was all kept within Classroom etc as that is within our google domain. From a GDPR perspective where do we stand as the pupils are connecting directly to the peris, pupils dont have school email accounts so they must be using their own or their parents accounts to sign up to zoom. Thanks for any guidance.
mavhc Posted March 27, 2020 Posted March 27, 2020 They can sign in with Google, oauth all the things! What does Zoom's privacy policy say?
hardtailstar Posted March 27, 2020 Posted March 27, 2020 AFAIK you don't need to sign up for zoom. Just need app or exe installed then use meeting ID and password.
sparkeh Posted March 27, 2020 Posted March 27, 2020 You may want to read about zoom sharing data with Facebook. https://www.techradar.com/uk/news/video-calling-app-zooms-ios-version-is-sharing-user-data-with-facebook 1
jmak Posted March 27, 2020 Posted March 27, 2020 (edited) I joined a Zoom meeting a couple of days ago. No idea what information the host had to give, but I just used the URL which contained the meeting ID (in plain text). I did have to run an exe, but didn't give any data. I used a Windows machine, so no issue with the app sharing with Facebook. Edited March 27, 2020 by jmak
Arthur Posted March 28, 2020 Posted March 28, 2020 (edited) You may want to read about zoom sharing data with Facebook. Zoom's Use of Facebook’s SDK in iOS Client Zoom takes its users’ privacy extremely seriously. We would like to share a change that we have made regarding the use of Facebook’s SDK. We originally implemented the “Login with Facebook” feature using the Facebook SDK for iOS (Software Development Kit) in order to provide our users with another convenient way to access our platform. However, we were made aware on Wednesday, 25 March 2020, that the Facebook SDK was collecting device information unnecessary for us to provide our services. The information collected by the Facebook SDK did not include information and activities related to meetings such as attendees, names, notes, etc., but rather included information about devices such as the mobile OS type and version, the device time zone, device OS, device model and carrier, screen size, processor cores, and disk space. Our customers’ privacy is incredibly important to us, and therefore we decided to remove the Facebook SDK in our iOS client and have reconfigured the feature so that users will still be able to log in with Facebook via their browser. Users will need to update to the latest version of our application that’s already available at 2:30 p.m. Pacific time on Friday, 27 March 2020, in order for these changes to take hold, and we strongly encourage them to do so. Example information sent by the SDK on installation and application open and close: Application Bundle Identifier Application Instance ID Application Version Device Carrier iOS Advertiser ID iOS Device CPU Cores iOS Device Disk Space Available iOS Device Disk Space Remaining iOS Device Display Dimensions iOS Device Model iOS Language iOS Timezone iOS Version IP Address We would like to thank Joseph Cox from Motherboard for bringing this to our attention here. We sincerely apologize for the concern this has caused, and remain firmly committed to the protection of our users’ privacy. We are reviewing our process and protocols for implementing these features in the future to ensure this does not happen again. Edited March 28, 2020 by Arthur 1
hardtailstar Posted March 28, 2020 Posted March 28, 2020 @Arthur that was quick [emoji3]If you are quicker than @Arthur then you earn a gold medal! Highly prized among the Edugeek community. 2
sparkeh Posted March 28, 2020 Posted March 28, 2020 If you are quicker than @Arthur then you earn a gold medal! Highly prized among the Edugeek community. Whilst I totally agree, I was really referring to how quickly Zoom changed their practices. [emoji23] 1
hardtailstar Posted March 28, 2020 Posted March 28, 2020 Whilst I totally agree, I was really referring to how quickly Zoom changed their practices. [emoji23] haha!
mavhc Posted March 29, 2020 Posted March 29, 2020 Noticed today that Zoom's own user accounts are limited to 32 char passwords, suspicious
markwilfan Posted March 29, 2020 Posted March 29, 2020 https://www.theregister.co.uk/2020/03/27/doc_searls_zoom_privacy/
Claireashton Posted March 30, 2020 Posted March 30, 2020 There's an article from the BBC about this very thing: https://www.bbc.co.uk/news/technology-52033217 The article explains a chequered history and that ..."some experts still think that the firm has a rather blase attitude to security."
Theblacksheep Posted March 30, 2020 Posted March 30, 2020 People that do not consent to the video being recorded and stored by Zoom, only have the option of leaving the meeting.
fredesq Posted March 30, 2020 Posted March 30, 2020 I've been told by our data protection person that was told by our dedicated 3rd party DPO that because of GDPR, students aren't allowed to use their webcams if in a video chat with their class. Has anyone else heard of anything similar?
elsiegee40 Posted March 30, 2020 Posted March 30, 2020 I've been told by our data protection person that was told by our dedicated 3rd party DPO that because of GDPR, students aren't allowed to use their webcams if in a video chat with their class. Has anyone else heard of anything similar? @GrumbleDook? 1
GrumbleDook Posted March 30, 2020 Posted March 30, 2020 @GrumbleDook? I’m doing a fair bit of reviewing of Zoom at the moment to get to the bottom of a few things and their legal team where being pretty helpful until the PR nightmare meant things had to go via PR and be checked. Still chatting with them to clear things up. As for GDPR and webcams? Let’s look at this as how schools manage risk. Webcams give a look into the personal life of individuals unless they have a dedicate space to use them, or are taking precautions. Data Protection/Privacy is risk-based and so if it is felt that this is too great an intrusion then that is fine. The school will be advised by their DPO and make a relevant decision. The school decides based on what risks it could lower and how they plan to do that. For some schools it will be fine, for others maybe not so much. This is what DPIAs are for. I’ll see what can be done to help everyone on this. 3
hardtailstar Posted March 30, 2020 Posted March 30, 2020 I've been told by our data protection person that was told by our dedicated 3rd party DPO that because of GDPR, students aren't allowed to use their webcams if in a video chat with their class. Has anyone else heard of anything similar? I’m doing a fair bit of reviewing of Zoom at the moment to get to the bottom of a few things and their legal team where being pretty helpful until the PR nightmare meant things had to go via PR and be checked. Still chatting with them to clear things up. As for GDPR and webcams? Let’s look at this as how schools manage risk. Webcams give a look into the personal life of individuals unless they have a dedicate space to use them, or are taking precautions. Data Protection/Privacy is risk-based and so if it is felt that this is too great an intrusion then that is fine. The school will be advised by their DPO and make a relevant decision. The school decides based on what risks it could lower and how they plan to do that. For some schools it will be fine, for others maybe not so much. This is what DPIAs are for. I’ll see what can be done to help everyone on this. Our school is only video calling 6th formers for lessons. Both students and staff were told basically to have a plain wall behind them with no other personal property behind so that only the student/staff was visible in the webcam. 1
garbage46 Posted March 30, 2020 Posted March 30, 2020 Pupils connecting adults who are not school staff via webcam sounds well dodgy from a safeguarding perspective, espcially when you throw in potential recording of video! Has this been run past your DSL and or safeguarding lead?
sarahstacey Posted March 30, 2020 Author Posted March 30, 2020 Thanks for this GrumbleDook, that would be really helpful. We are reviewing the situation.
sarahstacey Posted March 30, 2020 Author Posted March 30, 2020 Thank you everyone for your comments, a tricky time for all. Stay safe!
GrumbleDook Posted March 30, 2020 Posted March 30, 2020 Pupils connecting adults who are not school staff via webcam sounds well dodgy from a safeguarding perspective, especially when you throw in the potential recording of video! Has this been run past your DSL and or safeguarding lead? Which is why Safeguarding staff should always be involved when doing DPIAs ... it is not the job of an individual but that of a team. 3
sparkeh Posted April 2, 2020 Posted April 2, 2020 (edited) I still wouldn’t touch zoom with a barge pole https://www.theguardian.com/technology/2020/apr/02/zoom-technology-security-coronavirus-video-conferencing?CMP=Share_iOSApp_Other Any one of the points listed would stop me using it. Edited April 2, 2020 by sparkeh
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now