Jump to content

Recommended Posts

Posted (edited)

Our current Privacy Policy states:

We routinely share pupil information with:

 

  • schools that pupils attend after leaving us
  • outside agencies
  • our local authority
  • youth support agencies (pupils aged 13+)
  • the Department for Education (DfE)

 

but then goes into no further detail about what we share with outside agencies, who they are, or why.

There's a section below for 13+ explaining about passing info off to the LA and youth support services (but not mentioning specific services by name), 14+ qualifications and 16+ stuff, as well as what information we give to the DfE and linking the relevant laws and regulations.

 

Am I wrong in thinking we should be a bit more explicit about who we ship off pupil data to for digital services?

We have G Suite accounts for everybody, they want YouTube switched on (which G Suite alerts me has extra Ts&Cs to consider), and we have several outside organisations synchronising with SIMS via Wonde (Library stuff, maths websites, school vouchers..)

 

Does all this come under 'it's okay because we're doing it to provide an education'? Am I just being too paranoid and transparency-focussed?

 

Edit: It looks like they've just copied the pupil privacy policy verbatim from this gov.uk page and added a bit or two in.

Edited by Garacesh
Posted

Theoretically all of the outside agencies and service providers should be named however this is obviously a very long list. That said the school should have a document listing all the processes and processors that you engage with.

If the Privacy Notice has been written by your DPO and signed off by Governors it is their responsibility.

In preparing the policy and sanctioning the various products DPIAs should have been carried out to prove that they are accountable to any possible risk in the processing the data.

 

Its not OK just because its Education as guidelines need to be followed and I don't think you are being paranoid. Perhaps a quite word with the DPO or whoever you report into to confirm that they are happy with what you are being asked to implement.

Posted

Also remember that there is a difference between ‘sharing’ and ‘processing’.

The agencies mentioned in the DfE model policy are other Data Controllers who will be using the data for their own purposes.

Google, etc. are your Data Processors and are operating under your instructions.

As Andy says, chat to your DPO about it.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...