Jump to content

Recommended Posts

Posted

A parent at one of our schools has requested to remove a pupil's details from all electronic systems in the school. The child is still a pupil at the school but they have asked to remove (not disable) any and all information regarding the pupil from Class Dojo, Google GSuite, LGfL, and even the school's MIS (Integris G2).

 

Also, we are getting conflicting information regarding consent. Do schools have to get explicit consent to sync data to Google GSuite and Office 365?

 

Thanks in advance.

Posted (edited)

I'm pretty sure the right to remove personal data only applies when it's no longer necessary for you to hold that data. You don't have to get specific consent if you're using a system that is required for day-to-day operation.

So if they're still in school and the use of Classdojo, G Suite and LGfL is necessary for day-to-day operations, then they have no right to removal.

MIS - well that's covered by the Limitation Act, KCSIE, The Education Regulations. All of that should be under your data retention policy...

 

This is what the school's DPO is for.

@GrumbleDook is the guy/tiger around here for this though :D

Edited by paulkerton
Posted

Absolutely not, we have a duty of care or whatever it's called to students when they're in school. We certainly need to keep medical details, emergency contacts, record of attendance and safeguarding. That's just a start of our legal obligation while a student is at school.

 

In terms of requiring explicit consent for storing data outside of the school, such as in the cloud - I don't believe so. The onus is on us to ensure we're storing data in compliance with GDPR, regardless of where that data is physically stored.

Posted

You certainly don't need to remove the child from all your systems.

 

Check here: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/

 

The only issue would be if you asked for consent to prices their data. Hopefully your DPO would have told you not to do that. For MIS, it is clearly essential for your organisation to operate.

 

The purpose of your organisation is to educate. If using O365 or other cloud platforms is a key part of how you provide that service, then you don't need consent unless you can reasonably deliver it without holding that data. Realistically, even if the teachers printed out everything for that one child (and I think you would have a strong case that that's an unreasonable requirement) you would still need to hold the child data on the system so that you can manage the work that they are set.

Posted
Such a request for a pupil that is still at the school is especially unusual. For many legal reasons, the school needs to retain a significant amount of data to fulfil their public duty. Has the request come direct to you? I'd refer it to the head. In my opinion, I'd also raise this not just with the DPO, but also the DSL as an incident - it doesn't sound like the parent is fulfilling their duty of care and for me that is a safeguarding issue to be investigated by the DSL. The school also needs to check the request has actually come from the parent - and is there more than one parent/guardian to consider? Do let us know the outcome, it's an interesting case study.
Posted
Fake names for non MIS stuff?

 

Real Name: Aaron Argon

Preferred Name: Narron Nargon

That would be a GDPR breach - I guess the "" is relevant here - I find it so hard to tell at times @mavhc :D

Posted

Why would it be a breach?

 

Lots of people have a preferred name set.

 

Now there is no personal information about the child as it's all fake on the non required for legal stuff places.

Posted
Why would it be a breach?

 

Lots of people have a preferred name set.

 

Now there is no personal information about the child as it's all fake on the non required for legal stuff places.

I'll let you research the answer. If you get no joy, run it by the ICO.

Posted
Why would it be a breach?

Lots of people have a preferred name set.

Now there is no personal information about the child as it's all fake on the non required for legal stuff places.

 

It's still personally identifiable though, and now you've got personal identifiable AND inaccurate information.

Posted

Schools has a legal right to hold that information in the course of providing a legal provision (education). Or words to that effect.

 

This overrides any sort of consent by the parent and/or right to deletion.

 

Fairly simple really.

  • Thanks 2
Posted
It's still personally identifiable though, and now you've got personal identifiable AND inaccurate information.

 

How is it personally identifiable?

Posted
How is it personally identifiable?

Because it's hardly pseudononymisiation to hide a name by removing the first letter off. Plus, its still in some way attached to a record that has information like date of birth, gender, address, telephone number as well as the original name in the record if you're just using the preferred name field.

 

I wonder who Onald Rump who lives at 1600 Pensylvania Avenue, Washington DC might be? Got a second address of Rump Tower... Hmmm...

Posted

Just a brief one to highlight something in my previous post:

 

Your DPO should know all this and be supporting whoever is making this decision.

 

It's great that you're there and asking sensible questions, but it's the law that the school employs someone qualified to deal with this kind of scenario. That person must not be in the IT support team.

  • Thanks 2
Posted

In your Record of Processing Activity you will have listed out the purposes and lawful bases for the processing of the personal data you hold.

Where consent is the lawful basis, then consent can be withdrawn and the personal data has to be removed.

For other lawful bases, then the parent is using the right to object to the processing of personal data. That is a different beast.

It is not an explicit right, and has to be looked at proportionally to the purpose and lawful basis.

The use of those products will be for the running of the school, delivery of education, the protection/safeguarding of children and the pastoral support provided by the school. Lawful basis of Public Task or Legal Obligation (depending on which bit you are looking at).

This is for where the school is the Data Controller and the supplier is Data Processor. The moment the Supplier is using the data for their own purposes then they are a Data Controller in their own right as well.

This is where the arguments exist.

 

You then have the added bonus that these suppliers are US based, or use companies that have HQs in the US, and are affected by the Schrems II judgement (quashing Privacy Shield). Guidance is still ... well ... sketchy at best on what the impact for schools are.

 

In reality ... If you need the data, then you need it.

You just have to make sure that you have it documented, that you have risks logged and monitored and where anything can be done to gain more information (such as pressing ClassDojo on SCCs and UK based hosting) then you have done what you can.

 

Probably the most important thing in all the above?

Make sure that you are the data controller. If the supplier is using the personal data for their own purposes, then stop it. G Suite for Education has a core package that leaves them as the Data Processor. If you enable the children's accounts to access YouTube, then Google are using that data for their own purposes. I am not saying block YouTube ... just don't have students logged in when accessing it and turn that additional service (and any others) off.

  • Thanks 1
Posted
Because it's hardly pseudononymisiation to hide a name by removing the first letter off. Plus, its still in some way attached to a record that has information like date of birth, gender, address, telephone number as well as the original name in the record if you're just using the preferred name field.

 

I wonder who Onald Rump who lives at 1600 Pensylvania Avenue, Washington DC might be? Got a second address of Rump Tower... Hmmm...

 

I didn't literally mean change the first letter. Make some another random name. So now the only link between real and fake name is on MIS. Could even leave it off that, just put it in people's brains.

Posted

Because why store personal data when you don't need to, isn't that the whole GDPR thing?

 

Better to just have a random number on the 3rd party website, then if it's hacked, no problem

Posted
Because why store personal data when you don't need to, isn't that the whole GDPR thing?

 

Better to just have a random number on the 3rd party website, then if it's hacked, no problem

 

1 - It is not a 3rd party website ... it is a data processor. A 3rd party is something different and if you see it in an agreement you should challenge it.

2 - Having accurate data that is usable is important. Pseudononymisation is put in place because there is a need to add in protections, not because it seems like a good idea.

3 - If you need XXXXXXX to do something (maybe welcome a child to their learning tools) then why make it YYYYYY?

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...