TwistedHelixis Posted July 14, 2021 Posted July 14, 2021 One of the schools I help in has recently disbanded the Governors and the LA have taken over for the moment. The school has been a Google School for many years and all their files are in Google shared drives etc. I created each of the new LA Governors an email account + group + shared drive, but they are refusing to use these saying they already have a secure LA account. I sent the head an email explaining it's not really about the security side of things but data protection, retention of pupil data and GDPR compliance but they are still not using the school's supplied systems. Do we just forward what they need to their email accounts as it is the LA requesting this?
paulkerton Posted July 14, 2021 Posted July 14, 2021 Do we just forward what they need to their email accounts as it is the LA requesting this? Who would be expected to respond to a SAR? Do the LA provide DPOs or do the school have to provide their own?
GrumbleDook Posted July 14, 2021 Posted July 14, 2021 Governors are not likely to be accessing personal data of pupils or staff, and if they are then it would be for particular reasons such as appeals or similar. The sending of emails from M365 and Google Workspace for Education is done over TLS and kept secure, IIRC for encryption in transit might not be a worry. The main issue is that if the school has the policy to work in a given way for particular reasons, until that policy is updated or scrapped, someone, somewhere, needs to document who made the decision for it to be ok to work in this new way. Don't forget that the risk assessment should be driven by your DPO. Go and see what they say. 1
GrumbleDook Posted July 14, 2021 Posted July 14, 2021 Who would be expected to respond to a SAR? Do the LA provide DPOs or do the school have to provide their own? The school is the controller, not the LA. The school would have to respond ... but it would make for an interesting discussion with the LA DPO. 1
paulkerton Posted July 14, 2021 Posted July 14, 2021 The school is the controller, not the LA. The school would have to respond ... but it would make for an interesting discussion with the LA DPO. Exactly my point
TwistedHelixis Posted July 14, 2021 Author Posted July 14, 2021 Who would be expected to respond to a SAR? Do the LA provide DPOs or do the school have to provide their own? The school has their own. Governors are not likely to be accessing personal data of pupils or staff, and if they are then it would be for particular reasons such as appeals or similar. You say this but I have seen plenty of other occasions 'school data' has been shared on Governor documents, does it not make 100% sense for any documents to always be under the school's control and never have any grey areas?
TwistedHelixis Posted July 14, 2021 Author Posted July 14, 2021 Pick your hill to die on carefully. Definitely going to be one of those situations. I am an external IT tech and strictly speaking this is nothing to do with me, but I am trying to steer them in the right direction if I can.
paulkerton Posted July 14, 2021 Posted July 14, 2021 I am an external IT tech and strictly speaking this is nothing to do with me, but I am trying to steer them in the right direction if I can. This is a DPO job though. I would generally agree that the data should stay within the controller remit here, and that they should use school accounts. However, ultimately you implement what you're asked to do - but you should also make sure you get anything in writing so they can't try and deflect the blame when they decide to go against best practice. After all, https://www.bbc.co.uk/news/uk-politics-57642791 1
GrumbleDook Posted July 14, 2021 Posted July 14, 2021 You say this but I have seen plenty of other occasions 'school data' has been shared on Governor documents, does it not make 100% sense for any documents to always be under the school's control and never have any grey areas? If school data isn't being sufficiently anonymised before sharing with governors, that is something to put on the risk assessment. What has your DPO said? 1
TwistedHelixis Posted July 14, 2021 Author Posted July 14, 2021 (edited) The problem is most schools probably don’t even realise how to make data properly anonymous. Simply putting some letters or a number to represent a user’s data still doesn’t mean the data is anonymous. If that data is in someone’s personal account how would we even know how they have made it anonymous, nobody can even check? I am sure I read somewhere that schools need to do everything within reason to keep their data under their own control, how is letting Governors use their own accounts within reason? I would have thought something so simple as using a school supplied username / password (something primary kids can do) is within the realms of reason. I wonder what the real reasons are for Governors not wanting to use a different account? TBH this is a completely separate minefield for a different post. Edited July 14, 2021 by TwistedHelixis
psydii Posted July 14, 2021 Posted July 14, 2021 Data formatted and presented properly to governors should be anonymised through aggregation if the governors expect the report to be granular to the individual student level then there is a problem with the relationship between governors and the school. And the LA has now taken over. Even if the reports are not well anonymised, there should also already be the appropriate paperwork to cover the sharing of data between the school and the LA, there should be no problem with LA accounts being the recipients of the data. (assuming these accounts are covered by the existing agreement). Having to manage multiple accounts is a pain in the ***, I can totally sympathise with their position. As I can with yours. But again, choose your battles wisely. 1
jmak Posted July 14, 2021 Posted July 14, 2021 Is it a completely Google school or is there an Active Directory set up? Is there any option to federate accounts?
TwistedHelixis Posted July 14, 2021 Author Posted July 14, 2021 But again, choose your battles wisely. :-) :-)
dmj Posted July 15, 2021 Posted July 15, 2021 I'm pretty sure the DPO will have already signed off the local authority as a data processor, get that confirmed then just send them email. They won't get access to your shared drives, but you could export it as a zip and send them some dvd's or something.
paulkerton Posted July 15, 2021 Posted July 15, 2021 and send them some dvd's or something. No. No. No. Do not do this. Dear God, no. https://www.bbc.co.uk/news/uk-england-kent-44371759
dmj Posted July 15, 2021 Posted July 15, 2021 No. No. No. Do not do this. Dear God, no. https://www.bbc.co.uk/news/uk-england-kent-44371759 It was tongue in cheek, I'm just assuming the LA isn't going to have provision for sending an entire google drive.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now