Jump to content

Recommended Posts

Posted

Hi All,

 

Hoping that someone can help me here...We are looking to sign up new year 7 parents to the systems we use in school (SIMS Parent & Wisepay) ready for their start in September. We have been given initial data from our local council, (names, dob, email addresses etc) which were filled in as part of the application process.

 

The question is can we use this information to setup the user accounts or will this be breaking GDPR rules as we are not the ones who have obtained this information, and would therefor be "giving" it to other companies.

 

Regards,

 

jrma91

Posted
No, you are not breaking GDPR rules, but your policies should explain what data you use and why. ICO provide a lot more detail, but for starters you might find visiting https://ico.org.uk/for-organisations/in-your-sector/education/education-gdpr-faqs/ helpful. Out of interest ,do you have a Data Protection Officer to call upon? Somewhere along the line, you should have received GDPR training, especially if you deal with personal data in your role.
  • Thanks 3
Posted
No, you are not breaking GDPR rules, but your policies should explain what data you use and why. ICO provide a lot more detail, but for starters you might find visiting https://ico.org.uk/for-organisations/in-your-sector/education/education-gdpr-faqs/ helpful. Out of interest ,do you have a Data Protection Officer to call upon? Somewhere along the line, you should have received GDPR training, especially if you deal with personal data in your role.

 

We do have a GDPR person, but they are just as unsure as the rest of us! In a normal circumstance we would post out lots of forms for the parents to complete, we would get the the address from local council, but we are looking to do it electronically using SIMS Parent. They are saying that because it is electronic that we don't have specified consent, but others are saying that because the parents know that any information that is used in the application process is passed onto schools, and that the parents would know this, otherwise how would the then receive an information pack in the post.

 

I hope that my ramblings make sense?

Posted

Others with more expertise will be along, but one misconception that I can help with is that it makes no difference whether the information is electronic or paper. The regulations refer to data, not to the medium they're held in.

 

Another place to start is to look at the reason for processing. Consent is only one of them and should only be used as a last resort (apart from anything else, it could be withdrawn at any time, which gives a huge headache).

Posted
We do have a GDPR person, but they are just as unsure as the rest of us! In a normal circumstance we would post out lots of forms for the parents to complete, we would get the the address from local council, but we are looking to do it electronically using SIMS Parent.

Same data being used for same purpose... it’s just the method of doing it that is changing.

 

They are saying that because it is electronic that we don't have specified consent, but others are saying that because the parents know that any information that is used in the application process is passed onto schools, and that the parents would know this, otherwise how would the then receive an information pack in the post.

 

I hope that my ramblings make sense?

You need to sack your DPO and get a new one.

 

GDPR applies to ALL personal data whether electronic or paper.

 

You are changing the way you are doing something that you do not need consent for. Enrolling children in a school does not need consent.

 

You cannot use the data collected for any other purpose than the business of educating the child without consent. I imagine you will be getting consent for the more run of the mill stuff like sending the school newsletter when you register them.

@GrumbleDook can probably put this more eloquently than me

  • Thanks 1
Posted (edited)

As others have correctly stated you do not need consent for this process.

You have a legal obligation to maintain parental records of your pupils and so as long as the data is stored securely and then only used for specific reasons and retained for the length of time stated in your policies, it is fine.

This information should be on your school's Privacy Notice so that parents understand why the data is collected.

As previously stated your DPO should have this covered.

Edited by elsiegee40
  • Thanks 1
Posted (edited)

Most of the responses have this covered now .... but let's look at the flow of this @jrma91.

 

The council (a data controller) shares information with you, the school (another data controller) about children and parents as part of their remit as part of the admissions process. This is to allow you, as a school, to fulfil your responsibilities. Once you have that data, you are using it for the purposes that you specify and under the appropriate lawful basis.

 

You are transparent about your use of this data because it is in Privacy Notice, but you might have a concern that the parents have not seen it yet because they have yet to see a copy in your admissions pack. Simple solution ... when you send out the details for them to log into whatever system, you provide them with the details of the PN and explain things in clear language. The thing you have to remember is to ensure that you have a clear down process for all systems should any child not join you in September.

Edited by elsiegee40
  • Thanks 3
Posted

Understanding the difference between controllers and processors will also help you here and there is plenty of information online about this. Here is a blog that might help and the ICO has lots of information on this: https://www.itgovernance.co.uk/blog/the-gdpr-everything-you-need-to-know-about-data-controllers-and-data-processors

 

Also understanding the lawful basis for processing, as other people have mentioned. Most of the processing of personal data in school does not need the consent of the individual.

Here is a checklist to work through to see where you might need to focus your compliance activities: https://www.itgovernance.co.uk/blog/is-your-school-gdpr-compliant-checklist

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...