Jump to content

Recommended Posts

Posted

As I'm now I the main conduit between our organisation and our DPO, a number of interesting questions have come my way. One is around forms of consent and how to record it.

 

Unfortunately my organisation is still skewed to paper records, so often they ask our 'clients' (under 18 children and young people) to sign a paper document to give consent to various data collection/sharing items. So the record we have is paper based. The document may additionally be signed by a parent. This can be scanned or photo'd and stored in our system against the client and the idea is that the original is shredded. We also record the answers against the clients account. Sometimes the document is a completed electronic Word document or PDF form where the client types in their name and date. It always amused me that people use a cursive font - I know that makes no difference, but that's an aside!

 

The question on these two options is, is one better than the other and how do they sit from a GDPR perspective. Being a techie, I'd much rather a auditable, trackable electronic consent form, but the organisation isn't ready for that yet.

Posted

I don't think one is inherently better than the other, by the sounds of it you're returning a document with consent(s) granted on it either way. As far as I know with GDPR you need to record the consent, who gave it, how, and when. We record all of this in our MIS.

 

We're moving more towards Google Forms for this kind of thing, as it records all of that with a few name fields and a tick box. We create the forms, email them to parents, and they fill them in, no paper copies required.

Posted
I'd like to move to more electronic forms - it'll probably be MS Forms, but the concept is much the same. We'd probably have to still support some paper as electronic isn't viable for some parents.
Posted

I agree with @DaveAshworth - you don't need to retain the actual method by which they consented, just that their consent was given (that said, the original is useful in case challenged, but a Word document with someone's name in a cursive font is easy enough to fake).

 

Generally, we obtain consent via the payment system, which is easily recorded, easily queried and definitely from the consentee (he says, making up a word!). Otherwise, it is a Google/MS Form, but those are more commonly used for "yes I'm coming to parents evening" rather than "yes my son go take part in that event". There's also consent via paper for the rest of this year until our admissions finally goes paperless. Where relevant, the consent is then recorded in the MIS.

Posted

All good and well people using cursive font, most now just use a normal one but we would only accept an electronic document like that from their email address, if it comes from anything else unless verified then no.

 

Even if they complete it on paper which is the easiest way, scan/photo and record that electrically and shred the paper simple answer. People say that electronic isn't viable for some everyone has a smart phone these day so poor excuse. Having paper means its accessible and your not discriminating anyone but as long as there is an alternative means then I would say go with what works in getting consent then make it all electronic, no paper to go missing/get lost then.

Posted (edited)
everyone has a smart phone these day so poor excuse.

 

That's not true, and the belief everyone has a smart phone causes a lot of problems for those people who don't. Nothing wrong with using electronic as the main means of consent, and indeed with assuming 99.9% of people have a smart phone, but you definitely need an option for those who don't (and also potentially for those who are illiterate....)

Edited by enjay
  • Thanks 1
Posted
I agree with @DaveAshworth - you don't need to retain the actual method by which they consented, just that their consent was given (that said, the original is useful in case challenged, but a Word document with someone's name in a cursive font is easy enough to fake).

 

Generally, we obtain consent via the payment system, which is easily recorded, easily queried and definitely from the consentee (he says, making up a word!). Otherwise, it is a Google/MS Form, but those are more commonly used for "yes I'm coming to parents evening" rather than "yes my son go take part in that event". There's also consent via paper for the rest of this year until our admissions finally goes paperless. Where relevant, the consent is then recorded in the MIS.

 

The following setsOut what is needed with respect to record keeping around Consent.

 

https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/consent/ for more information.

 

Keeping an actual record of the consent being given is a simple way to manage this, As it also supports the accuracy side of data protection. You do need to be carful of ROT though.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...